36 ms·
> The documents are written on simple copy paper and lack any kind of security features. Wait, sorry, sorry, sorry, hold up, full stop...could you repeat that
by usrbinbash 3y ago
> The documents are written on simple copy paper and lack any kind of security features.
Wait, sorry, sorry, sorry, hold up, full stop...could you repeat that again?
These orders arrive AS GODDAMN PAPER PRINTOUTS?!?
Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key?
- csunbird 3y agoOh wow! In my country, legal documents like this arrive with a QR code or confirmation code attached that can be used to verify legitimacy of the document on the official e-government internet site.
- deaddodo 3y agoEvery valid warrant has a verification authority contact. You are allowed to withhold access until verification can be made, and generally it can be done in 5-30mins. I worked in a data center once, and we would have FBI contacts that would come in regularly to access criminal data (CP, terrorist communique, heavy piracy, etc). We would verify the warrant before secure entry+accompany them to the specific requested entity. I know procedures are similar + even more stringent for the medical field. Things get even more complex for small local authorities, but the idea that "just having a slip of paper" is enough is ridiculous; unless the person accepting the request is dumb/lazy/uninformed/undertrained/etc, as in any social engineering feat (in your case, the responsible person decides to not bother with the QR because their phone connection is bad, it takes too long, etc; for example).
- PrimeMcFly 3y ago> You are allowed to withhold access until verification can be made, and generally it can be done in 5-30mins. So it's not like on TV where if they have the paper they can just show it to you and barge past you by force? For arrest warrants that makes sense, but they portray search warrants the same way.
- pixl97 3y agoSearch warrants can be more aggressive if they believe the searched are going to be oppositional and attempt to destroy evidence. Now for a typical business where law enforcement is going after someone else's data it's more laid back as the most law enforcement expects is the company to get on the phone with a lawyer to see if they should comply type thing.
- PrimeMcFly 3y agoThat makes sense, thanks.
- deaddodo 3y ago> So it's not like on TV where if they have the paper they can just show it to you and barge past you by force? Even in these cases, they still have to give you the warrant and you're able to take it up with the issuing authority/take to court the executing officers. But yes, arrest warrants and personal search warrants can be executed expediously for evidentiary / flight concerns. It's the exception, not the rule.
- Schiendelman 3y agoYes, and until we pass real consequences for data breaches - protections for individuals - none of this will change.
- bdavbdav 3y agoI think their point is that the fault here is on the system that requires people comply with non verifiable warrants, as opposed to the people handing over the data.
- esaym 3y agoWhat, gmail is better?
- eqvinox 3y ago> Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, Yes. Or a PDF attachment on an e-mail, possibly scanned from something that was printed a few minutes earlier because someone had to sign it with a pen. > trivially verify with the ordering entities public key You're underestimating the complexity of establishing a PKI infrastructure to handle federal, state and local authorities, signalling which keys have what exact authority, revoking compromised keys, … and then doing tech support for some redneck judge that owns more guns than electronic devices.
- hnfong 3y agoHaving a cert from a validated *.gov CA doesn’t seem that complicated, or at least, should be “just as complicated” as setting up properly TLs certs. Getting the tech adopted might be difficult (like you say some judges may not see the point of it) but the PKI doesn’t have to be super complicated… Having different authorities provide signatures for different types of documents may or may not be needed, in theory it is more secure, but just checking the domain name suffix should be a good start. And every tech literate person has a general idea how to tell “valid” domain names from phishing sites, so the scheme translates well
- ben_w 3y ago> Having a cert from a validated *.gov CA doesn’t seem that complicated, or at least, should be “just as complicated” as setting up properly TLs certs. You're not wrong, but you are overestimating the tech skill level of the average non techie. I'm travelling right now, and a surprising fraction of restaurant websites here aren't https.
- hnfong 3y agoYes, but we're talking about the judiciary here, not restaurants... Surely they'd have a minimal IT department...
- hn_throwaway_99 3y ago> Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key? Was honestly having a difficult time determining (a) if this was sarcasm or (b) you just have no idea of the technical competence of many of these jurisdictions, not to mention the complexity of managing this type of public key verification system for the number of jurisdictions involved.
- autoexec 3y agoAt one place I worked for we used to get them via fax! That said, you could call and verify that the person the document claimed to send it actually did.
- vintermann 3y ago> instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key? They wouldn't want that, because they don't want it to be easy to prove that they demanded surrender either.
- wruza 3y agoIt’s amusing how much HN expects from “the outer world”. Companies can adopt new tech in 1-2 years. Industries have around 5-10 years inertia. Bureaucracies like courts still live in the past millenia. You should be happy that they are using email. The best security measure they will implement after this article going wide is something like “only emails from @<domain> are valid, but we’ll destroy you anyway in case a judge mistakenly sends you an order from his own gmail”.
- mulmen 3y ago> Bureaucracies like courts still live in the past millenia. You should be happy that they are using email. This is a feature. We don't want courts to "move fast" because the consequence of breaking is far more severe than losing a few files on Google Drive.
- fallingknife 3y agoIf you don't move fast with new tech, you are broken. E.g. the article in this post.
- respondo2134 3y agoThe implied assumption here is that everything needs to adopt new tech. Lots of things are essentially "as perfect as we're going to get them" and everything new is a very marginal improvement or a big step backwards.
- mulmen 3y agoThe only thing broken is Verizon’s lawyer’s phone.
- wayfinder 3y agoI mean digital signatures have really only been a thing for like 20 years, and barely because people only started caring about it more in the past 10. While the US has been around for nearly 250 years. And truthfully, despite a highly technical crowd, how many of y’all have actually ever sent or received a digitally signed email? If you’ve tried, you know why no one ever does it.
- multjoy 3y agoThe much-derided SnOOPEr'S CHarteR in the UK (which actually formalised and regulated stuff that was already being done) means that while it's not a judge signing off warrants for comms data, it involves police gatekeepers (and believe me, getting a warrant to blow someone's door off is a piece of piss compared to writing up a comms data application), who then send it to an independent decision making body who then return it to the police who then upload the request to CSP systems using a pre-agreed portal with appropriate authentication. This touchstone of 'judicial oversight' is frequently nonsense. You can't tell me that every judge who has to give a warrant for a DUI blood draw at 3am in smalltown US is giving the matter any kind of scrutiny, nor that that judge has any legal or judicial experience at all.
- yladiz 3y agoThe point of sending a letter, compared to an email, isn’t only about proving who issued the subpoena, but also being able to prove it was received. You can’t really prove an email was received, but you can send a verified letter proving it was delivered.