Watch out for that link

by Chris 3/21/2008 10:59:00 AM

spy-gadgets-icon c|Net News posted an article about a technique the FBI is using to catch Internet surfers looking for child pornography:

Undercover FBI agents used this hyperlink-enticement technique, which directed Internet users to a clandestine government server, to stage armed raids of homes in Pennsylvania, New York, and Nevada last year. The supposed video files actually were gibberish and contained no illegal images.

You might think that clicking a link would not be enough for the FBI to get a search warrant for your house, but you would be incorrect:

While it might seem that merely clicking on a link wouldn't be enough to justify a search warrant, courts have ruled otherwise. On March 6, U.S. District Judge Roger Hunt in Nevada agreed with a magistrate judge that the hyperlink-sting operation constituted sufficient probable cause to justify giving the FBI its search warrant. 

I am all for catching online predators but lets look at this from a practicality perspective.  Here are a couple of scenarios I predict.

Scenario 1

Suppose you are running a wireless access point at your home and are using no (or even the pathetic WEP) encryption.  Some handy hacker decides that he wants to download his music/movies/porn from your WAP instead of his so the RIAA doesn't come knocking on his door.  You are now responsible for whatever that person decides to click while browsing the Internet.  Sure the FBI won't find any child porn on your computer but after they come storming into your home with a warrant and take all of your computer equipment it will be many months before you will ever see the hardware, and more importantly the data on that hardware.

You might think this scenario isn't going to happen but according to the article:

...even the possibilities of spoofing or other users of an open Wi-Fi connection "would not have negated a substantial basis for concluding that there was probable cause to believe that evidence of child pornography would be found on the premises to be searched." Translated, that means the search warrant was valid.

Scenario 2

Someone is running a Man-in-the-middle attack on a popular website that injects code into your http requests.  Included in your normal web traffic is a hidden link that goes to an illicit website possibly serving up porn or whatnot.  Would you even know that you have accidentally accessed the FBI's hyperlink?

Scenario 3

People truly intent on looking for child porn will read about the FBI's technique and will simply look towards Internet Proxy services to mask their identity.  A quick search on the internet and you can find services that provide anonymous access that would protect your online identity:

So this leaves only the truly lazy and/or stupid criminals to be caught by this technique.  Oh yeah I almost forgot, this also catches innocent people who have accidentally ended up on the FBI's link.

Now I may seem like a paranoid or conspiracy theorist for writing this entry but I believe this is just one step in the many steps of Americans losing our civil rights.  If the FBI can get a warrant because you clicked on a link then what is the next step?

Add comment


(Will show your Gravatar icon)  

biuquote
  • Comment
  • Preview
Loading




Powered by BlogEngine.NET Theme by Mads Kristensen Hosted by 1and1 Hosting Sign in
The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way. © 2008 Chris Blankenship

DSCODUC on Technorati  

Stop Spam Harvesters, Join Project Honey Pot   This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License  

Welcome to my blog

Welcome to my site

Villainy wears many masks,
none of which so dangerous as virtue…



LinkedIn   GeoURL

Recent Comments

Comment RSS

Wordle Gallery

Shelfari Book Library