RSN May Fundraising
FB Share
Email This Page
add comment
Print

Dilanian and Rodriguez report: "A hacker group's claim that it obtained from an FBI laptop a file with more than 12 million identification numbers has set off widespread speculation about why a federal agency would possess such information."

A hacker group says it obtained millions of identification numbers from iPhones, iPads and other devices from an FBI laptop. The agency denies having the data. (photo: wired)
A hacker group says it obtained millions of identification numbers from iPhones, iPads and other devices from an FBI laptop. The agency denies having the data. (photo: wired)


Claim of iPhone Hacking Raises Questions About FBI Data

By Ken Dilanian, Salvador Rodriguez, Los Angeles Times

05 September 12

 

A hacker group says it obtained millions of identification numbers from iPhones, iPads and other devices from an FBI laptop. The agency denies having the data.

hacker group's claim that it obtained from an FBI laptop a file with more than 12 million identification numbers for Apple iPhones, iPads and other devices has set off widespread speculation about why a federal agency would possess such information.

But the FBI disputed the allegation Tuesday, saying that "at this time, there is no evidence indicating that an FBI laptop was compromised or that the FBI either sought or obtained this data."

If the FBI's denials prove correct, the agency may have been the victim of a clever hoax by the group known as AntiSec that spurred thousands of headlines around the Web and left readers wondering how and why the FBI could have gotten access to Apple customer records.

The hackers said they found the file when they infiltrated a Dell laptop computer belonging to Christopher K. Stangl, a member of the FBI's Cyber Action Teams. They posted to a website a file containing 1 million of the so-called unique device identifiers, or UDIDs, to bolster their claim. They said the larger file included "user names, name of device, type of device, Apple Push Notification Service tokens" as well as ZIP Codes, cellphone numbers and addresses, though they did not release any of those details.

The hacker group said the file containing the data was called "NCFTA_iOS_devices_intel.csv". That set off a flurry of speculation among privacy activists that the data was linked to the National Cyber-Forensics and Training Alliance, a partnership of business, government and academia that includes a former FBI agent as its director of operations. No one from that organization responded to requests for comment.

The NCFTA, which is based in Pittsburgh, has billed itself as a clearinghouse through which companies can indirectly share cyber security-related data with the government. Cyber security legislation that failed to pass the Senate in July included provisions to expand such information sharing, so that the FBI and other agencies have help in tackling malware used in cyber crime.

"It's exactly the type of scenario that we were worried about happening with cyber security legislation," said Trevor Tim, an activist and blogger with the Electronic Frontier Foundation, a civil liberties group focusing on technology. "That these companies were going to use cyber information sharing provisions to hand over large swaths of data to the government that they would otherwise need a subpoena or a warrant or a court order."

After the Sept. 11, 2001, terrorist attacks, the FBI was given legal tools to request "third-party business records" without a court order, as long as it deemed those records "relevant to an investigation." Many consumer interactions with businesses on the Web produce records that are covered under those provisions and are not protected by the 4th Amendment requirement of a search warrant.

Most security experts said that the release of UDIDs into the wild in and of itself did not pose much of a privacy or security risk. It was no more harmful than a list of car VIN numbers, they said.

But if AntiSec's claims are true that the larger file accessed includes names, phone numbers and email addresses, the information could be used to track individuals, see what apps they've downloaded or lead to identity theft, said Ori Eisen, founder and chief innovation officer of security firm 41st Parameter.


 

Comments   

We are concerned about a recent drift towards vitriol in the RSN Reader comments section. There is a fine line between moderation and censorship. No one likes a harsh or confrontational forum atmosphere. At the same time everyone wants to be able to express themselves freely. We'll start by encouraging good judgment. If that doesn't work we'll have to ramp up the moderation.

General guidelines: Avoid personal attacks on other forum members; Avoid remarks that are ethnically derogatory; Do not advocate violence, or any illegal activity.

Remember that making the world better begins with responsible action.

- The RSN Team

 
+3 # CandH 2012-09-05 15:21
"But the administrative subpoena doesn’t just apply to utility records and drug cases. Congress has spread the authority across a huge swath of the U.S. government, for investigating everything from hazardous waste disposal, the environment, atomic energy, child exploitation, food stamp fraud, medical insurance fraud, terrorism, securities violations, satellites, seals, student loans, and for breaches of dozens of laws pertaining to fruits, vegetables, livestock and crops.

Not one of the government agencies with some of the broadest administrative subpoena powers Wired contacted, including the departments of Commerce, Energy, Agriculture, the DEA and the FBI, would voluntarily hand over data detailing how often they issued administrative subpoenas.

The DEA obtained the power under the Comprehensive Drug Abuse Prevention and Control Act of 1970 and is believed to be among the biggest issuers of administrative subpoenas. […]

Payne [DEA] then told Wired to send in a FOIA request, as did some of the local DEA offices we contacted, if they got back to us at all. “Would suggest a FOIA request to see whether you can get a number of administrative subpoenas. Our databases have changed over the years as far as how things are tracked and we don’t have access to those in public affairs unfortunately,” Payne said in an e-mail." http://www.wired.com/threatlevel/2012/08/administrative-subpoenas/
 
 
+8 # DaveM 2012-09-05 20:18
Why is the FBI keeping personal information on 12 million Americans are presumably neither suspected nor under investigation for a crime? Hardly a new question, but one that remains relevant, all the more so since the date in question can now be carried around by a single agent. How is this material intended to be used? The FBI is an agency of the Federal government. We pay their salary--in effect, we are their employers. Hey...the boss wants to know what you're doing with our information in your pocket!
 
 
+3 # RLF 2012-09-06 03:45
Big brother gets bigger and bigger...Police state coming!
 
 
+2 # dkonstruction 2012-09-06 08:40
anyone who is surprised or "shocked" by any of this (or that it would be supported by a democratic administration as well as a republican one) knows nothing about the history of the FBI...sad that we still live in Vidal's United States of Amnesia
 
 
+2 # mayordoug 2012-09-06 08:47
Someone PLEASE tell me how, or even if it is possible, to flush the "Patriot Act" down the drain.
 
 
+2 # dkonstruction 2012-09-06 09:07
Quoting mayordoug:
Someone PLEASE tell me how, or even if, we flush the "Patriot Act" down the drain.


mayordoug, sadly, i don't think we can so we need different/new tactics. the "answer" is to flood them with so much "information" that they cannot "keep track" of it all...if everyone in the country were to use certain words in all of their communications including phone and email we would have the gov't computers working overtime and there would be way too much for the human "sifters" to deal with....sort of like the old "Yippie" trick of using the phones (which they knew the FBI was tapping) to announce a gathering/demo at one location when in fact it was at another (which was not spread around using the phone).
 
 
0 # mayordoug 2012-09-06 14:26
I Love it! Let's see if we can actually get this idea going viral!
 

THE NEW STREAMLINED RSN LOGIN PROCESS: Register once, then login and you are ready to comment. All you need is a Username and a Password of your choosing and you are free to comment whenever you like! Welcome to the Reader Supported News community.

RSNRSN