>Am I supposed to feel sorry for the police now? Should we not fix security issues because law-enforcement may be relying on them?
Well according to law enforcement you're supposed to be in favor of anything that makes their job easier and removes them from accountability regardless of trade-offs. So yes, at least if you ask them.
> A team of European law-enforcement officials was hot on the trail of a potential terror plot in October, fearing an attack during Christmas season, when their keyhole into a suspect’s phone went dark.
There was no terror attack. Why is this the framing of the story?
It makes sense in literally every way you look at it.
Can't be used for political reasons ("look at us we stopped 10 attacks by the bad guys, reelect us because the last president only stopped 5"), avoid leaking info to potential accomplices, &c.
Of course you do, you just don't display it on every single mainstream news channels for 2 weeks straight like we do when an attack is successful.
Just like for every other crimes, if you look for details you'll find them but they won't be given to you in national news.
The prosecutions are covered by the news. There is one in the UK today.
The point is that a foiled plot doesn't get reported on when it's discovered only when the offender goes to trial.
There is no public record of each arrest by the police, as an example which might help understand this.
Furthermore there will be plots that are foiled, people arrested but prosecutions dropped due to lack of evidence or something and, again, the press offices in the police or government are not mandated to distribute that news.
Can’t speak for the UK, but in the US, literally every terrorism prosecution that involved a foiled plot in the past ten years or so has involved the FBI convincing some helpless, directionless loser to do a bad thing and then arresting said loser and claiming victory against Al-Qaeda. The entire plot had been made up by the FBI.
That’s not to say the guys who agreed to said plots were blameless. That’s to say that I’ve seen zero evidence that the FBI has brought any actual, independently motivated terrorists to justice by foiling their plots.
How about the 2009 New York City Subway plot[1]? I suppose it's possible that Zazi was a patsy, but if you take the Wikipedia page at face value it seems pretty damning.
That one looks legit. I’ll still claim I was right because it was … 10 years ago. ;-)
To be clear, “patsy” is too harsh a term for what I meant. There is value in diverting the attention of people intending to do harm from real plots to fake ones invented by the FBI. However, that is not “thwarting an attack”, and in my opinion does not justify excessive surveillance.
You would ask the question "How far would he have gotten if an FBI agent hadn't got involved?" There seems to be a pattern of "idiot makes vague threats on Twitter" => "FBI agent encourages him" => "FBI waits and eventually arrests, plot thwarted." in a lot of these stories, which seems to be the basis for your categorical assertion that
> every terrorism prosecution that involved a foiled plot in the past ten years or so has involved the FBI convincing some helpless, directionless loser to do a bad thing and then arresting said loser and claiming victory against Al-Qaeda
So I can see why you would think Jameson fits the pattern.
> Australi Witness urged the FBI source to put nails, glass and metal into the bomb, according to the FBI-authored complaint. He instructed the FBI source "to dip the screws and other shrapnel in rat poison in order to inflict more casualties," the complaint states.
But don't forget that places like GCHQ do not release information, so it would be very unusual to get "GCHQ helped identify these suspects". Here's one example where the GCHQ link was made clear (in news reporting), and it's pretty extreme.
Then congratulations are in order for the police, who did their jobs, and for Facebook, who secured their system.
Less flippantly, here’s the buried follow-up:
> “WhatsApp killed the operation,” the official said. The terror suspect is still under traditional surveillance. But human resources are spread thin, the official said, especially around the winter holidays, which in Europe extend into early January and are a time when terrorists have staged attacks on the continent. “He’s not the only suspect we have to follow.”
This clearly indicates that the police have alternative means of tackling the issue. This means that privacy can be protected — at a cost. Note that no one mentions this in the article. The dichotomy presented is “snooping or TERRORISM”, not “snooping or increased resources for police to track their terror suspects”.
Am I the only one who thinks terrorism incidents are really rare, and perhaps our government's efforts are perhaps better focussed on more common crimes, like car thefts, muggings, etc.
Isn't that exactly the point? We still talk about the 2015 tragedy, even though we have equally deadly tragedies every day, except from "boring" causes that don't make the news.
Maybe it's different in the USA. In France, more than a hundred killed in a night is very alarming news. Do you think Gendarmerie should forget about terrorists so they can focus on more "boring" causes?
Sad I need to say: I don't agree with the tone of the article. I was just responding to a comment that said exactly that.
> Do you think Gendarmerie should forget about terrorists so they can focus on more "boring" causes?
Yes. Terrorism works exactly because of irrational out-of-proportion reaction to the attack. The attack is only for show, and later harm is self-inflicted. e.g. after 9/11 more people died from increased road use caused by fear of flying, than from the attack itself.
Every day lots of people die in car crashes, from diseases, pollution, accidents, suicides, addictions, poverty, but these deaths are too common, too numerous, and not spectacular enough to get 24/7 news coverage — such deaths have been deemed acceptable, unlike terror deaths.
When there's a war on terror trillions of dollars appear out of thin air, but when a fraction of that is needed to improve healthcare or environment it's "but who's going to pay for it?"
It seems you're writing from a USA perspective, that's alien from European reality. There aren't so many violent deaths over here and a sizeable proportion of them has been caused by islamic terrorism. Saying that police should ignore that threat shows a terrible level of misinformation.
On the other hand we spend much more in public healthcare than in wars. Are there other problems that take lives? Of course, but terrorism is one of the biggest problems that fall into police competences.
From the article, it sounds like they also use these tools to fight regular crime:
> The European official said NSO spyware had enabled his team to learn details of a separate gang of violent bank robbers and weapons traffickers and have police arrest them as they were about to commit a crime.
I assume the "terror suspect" was thrown into the headline to gather more sympathy for their cause.
The perspective of the law enforcement agencies, as usual, beggars belief.
IMO Facebook/WhatsApp were totally in the right here: they were not issued any legal documents or binding court orders, saw that their systems had been compromised, and therefore informed _all compromised users_ without discrimination.
Really though, using "terror suspect" here is like crying "think of the children": it's sensationalist garbage designed to drum up public support through fear.
This is the same old e2e encryption vs. overstepping law enforcement debate, but with the kinky old "what about terrorism" mixed with the currently fashionable "boo Facebook and other tech giants" angle.
Basically, Facebook did something (which I believe was) ethical and law enforcement agencies employing covert tactics that skirt the well-established legal processes got caught with their pants down.
I wonder if the evolution of law enforcement to this attack will be to have a court issue a gag order preventing said companies from notifying their users of attempted or successful attacks.
Doesn't the GDPR currently require companies to notify users about such attacks (does "personal data breach" also apply to client-side stored data)?
> When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
In fact, I would argue this makes the law enforcement agencies in question look incompetent since they should not have been trying to bypass the courts and traditional monitoring / investigation in such a manner that having a single zero day closed has such a significant effect on their investigation.
I'm happy Facebook is keeping users secure. When secret services are complaining about them, they are doing something right.
But isn't acknowledging cracking efforts a dumb move in the first place? Do "they" just want us to think that these protections work and it's a free-for-all behind the scenes? After all, if I were cracking phones, I'd want my targets to think Whatsapp is secure. So I could complain about how Whatsapp works against me even if it doesn't. And Facebook would be in on it because it's good for their reputation to be seen as protecting its users.
> When evidence gathered by his unit is used in court, efforts are made to hide the true source of the evidence.
This seems very shady.
> The European official said his own unit is so secretive that senior security and government officials in his own country don’t know about the methods and tools they deploy.
How can this stuff be regulated with things like this? if the government is kept in the dark about these things, how can they govern?
“WhatsApp killed the operation,” the official said.
Yeah, they detected anomalous activity, investigated, and alerted affected users. This sounds like a point in favor of WhatsApp and Facebook, looking out for the integrity of the apps of their users -- but it still won't convince me to stop using Wire and Signal and adopt WhatsApp.
Curious: does any version of this story say what model of phone the terrorist suspect was using? If it was an Android then quietly asking Google for tracking info on the phone should have been easy; if it was an iPhone this would be quite newsworthy since Apple asserts their phones are secure from attack and Apple as a whole have made a very big deal about privacy of user data, something which I think would be appealing to a terrorist trying to communicate covertly.
> encryption shouldn’t allow criminals to be “less accountable online than in real life"
This makes me angry. First about the statement about encryption, then about European law-enforcement officials being concerned with accountability.
But I really like to know about the security flaws in their video calling. I thought they use end-to-end encryption for that too. Sounds difficult to inject malware here. We really need details about the security flaws for an effective defense in the future.
36 comments
[ 3.0 ms ] story [ 86.7 ms ] threadAm I supposed to feel sorry for the police now? Should we not fix security issues because law-enforcement may be relying on them?
Well according to law enforcement you're supposed to be in favor of anything that makes their job easier and removes them from accountability regardless of trade-offs. So yes, at least if you ask them.
There was no terror attack. Why is this the framing of the story?
I am sure the news would love to run information about the prosecution of foiled terrorists.
Could it perhaps be that terrorism is a vastly overhyped threat, and that effectively zero people are undertaking it?
The point is that a foiled plot doesn't get reported on when it's discovered only when the offender goes to trial.
There is no public record of each arrest by the police, as an example which might help understand this.
Furthermore there will be plots that are foiled, people arrested but prosecutions dropped due to lack of evidence or something and, again, the press offices in the police or government are not mandated to distribute that news.
That’s not to say the guys who agreed to said plots were blameless. That’s to say that I’ve seen zero evidence that the FBI has brought any actual, independently motivated terrorists to justice by foiling their plots.
[1] https://en.wikipedia.org/wiki/2009_New_York_City_Subway_and_...
To be clear, “patsy” is too harsh a term for what I meant. There is value in diverting the attention of people intending to do harm from real plots to fake ones invented by the FBI. However, that is not “thwarting an attack”, and in my opinion does not justify excessive surveillance.
https://www.washingtonexaminer.com/ex-marines-isis-inspired-...
You would ask the question "How far would he have gotten if an FBI agent hadn't got involved?" There seems to be a pattern of "idiot makes vague threats on Twitter" => "FBI agent encourages him" => "FBI waits and eventually arrests, plot thwarted." in a lot of these stories, which seems to be the basis for your categorical assertion that
> every terrorism prosecution that involved a foiled plot in the past ten years or so has involved the FBI convincing some helpless, directionless loser to do a bad thing and then arresting said loser and claiming victory against Al-Qaeda
So I can see why you would think Jameson fits the pattern.
How about this guy?
https://edition.cnn.com/2015/09/10/us/9-11-memorial-bomb-plo...
> Australi Witness urged the FBI source to put nails, glass and metal into the bomb, according to the FBI-authored complaint. He instructed the FBI source "to dip the screws and other shrapnel in rat poison in order to inflict more casualties," the complaint states.
Doesn't sound too helpless to me.
https://www.bbc.co.uk/news/uk-england-tyne-51022706
But don't forget that places like GCHQ do not release information, so it would be very unusual to get "GCHQ helped identify these suspects". Here's one example where the GCHQ link was made clear (in news reporting), and it's pretty extreme.
https://en.m.wikipedia.org/wiki/Matthew_Falder
Maybe there was no terror attack because the intelligence gathered from the hacked phones prevented it.
Less flippantly, here’s the buried follow-up:
> “WhatsApp killed the operation,” the official said. The terror suspect is still under traditional surveillance. But human resources are spread thin, the official said, especially around the winter holidays, which in Europe extend into early January and are a time when terrorists have staged attacks on the continent. “He’s not the only suspect we have to follow.”
This clearly indicates that the police have alternative means of tackling the issue. This means that privacy can be protected — at a cost. Note that no one mentions this in the article. The dichotomy presented is “snooping or TERRORISM”, not “snooping or increased resources for police to track their terror suspects”.
https://en.wikipedia.org/wiki/November_2015_Paris_attacks
Sad I need to say: I don't agree with the tone of the article. I was just responding to a comment that said exactly that.
Yes. Terrorism works exactly because of irrational out-of-proportion reaction to the attack. The attack is only for show, and later harm is self-inflicted. e.g. after 9/11 more people died from increased road use caused by fear of flying, than from the attack itself.
Every day lots of people die in car crashes, from diseases, pollution, accidents, suicides, addictions, poverty, but these deaths are too common, too numerous, and not spectacular enough to get 24/7 news coverage — such deaths have been deemed acceptable, unlike terror deaths.
When there's a war on terror trillions of dollars appear out of thin air, but when a fraction of that is needed to improve healthcare or environment it's "but who's going to pay for it?"
On the other hand we spend much more in public healthcare than in wars. Are there other problems that take lives? Of course, but terrorism is one of the biggest problems that fall into police competences.
> The European official said NSO spyware had enabled his team to learn details of a separate gang of violent bank robbers and weapons traffickers and have police arrest them as they were about to commit a crime.
I assume the "terror suspect" was thrown into the headline to gather more sympathy for their cause.
IMO Facebook/WhatsApp were totally in the right here: they were not issued any legal documents or binding court orders, saw that their systems had been compromised, and therefore informed _all compromised users_ without discrimination.
Really though, using "terror suspect" here is like crying "think of the children": it's sensationalist garbage designed to drum up public support through fear. This is the same old e2e encryption vs. overstepping law enforcement debate, but with the kinky old "what about terrorism" mixed with the currently fashionable "boo Facebook and other tech giants" angle.
Basically, Facebook did something (which I believe was) ethical and law enforcement agencies employing covert tactics that skirt the well-established legal processes got caught with their pants down.
> When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
(Source: https://gdpr-info.eu/art-34-gdpr/)
But isn't acknowledging cracking efforts a dumb move in the first place? Do "they" just want us to think that these protections work and it's a free-for-all behind the scenes? After all, if I were cracking phones, I'd want my targets to think Whatsapp is secure. So I could complain about how Whatsapp works against me even if it doesn't. And Facebook would be in on it because it's good for their reputation to be seen as protecting its users.
There's always room to spin a conspiracy theory.
This seems very shady.
> The European official said his own unit is so secretive that senior security and government officials in his own country don’t know about the methods and tools they deploy.
How can this stuff be regulated with things like this? if the government is kept in the dark about these things, how can they govern?
Yeah, they detected anomalous activity, investigated, and alerted affected users. This sounds like a point in favor of WhatsApp and Facebook, looking out for the integrity of the apps of their users -- but it still won't convince me to stop using Wire and Signal and adopt WhatsApp.
Curious: does any version of this story say what model of phone the terrorist suspect was using? If it was an Android then quietly asking Google for tracking info on the phone should have been easy; if it was an iPhone this would be quite newsworthy since Apple asserts their phones are secure from attack and Apple as a whole have made a very big deal about privacy of user data, something which I think would be appealing to a terrorist trying to communicate covertly.
This makes me angry. First about the statement about encryption, then about European law-enforcement officials being concerned with accountability.
But I really like to know about the security flaws in their video calling. I thought they use end-to-end encryption for that too. Sounds difficult to inject malware here. We really need details about the security flaws for an effective defense in the future.