This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Fbi Installs Spyware To Gather Evidence

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.securityfocus.com/brief/550
2007-07-18 - "…The FBI sent the Trojan horse to the administrator of the MySpace account "Timberlinebombinfo". The program is designed to record the IP address, dates, and times when data is sent, but not the content of the messages. Both Wired News* and CNET News.com** have additional coverage of the use of the CIPAV Trojan horse. The student whose identity was stolen was ostracized at school and has since enrolled in a different district, the Olympian reported. The ninety day sentence is the maximum allowed under the standard sentencing guidelines for juveniles…"

* http://www.wired.com/politics/law/news/2007/07/fbi_spyware
7.18.07 - "FBI agents trying to track the source of e-mailed bomb threats against a Washington high school last month sent the suspect a secret surveillance program designed to surreptitiously monitor him and report back to a government server, according to an FBI affidavit obtained by Wired News. The court filing offers the first public glimpse into the bureau's long-suspected spyware capability, in which the FBI adopts techniques more common to online criminals. The software was sent to the owner of an anonymous MySpace profile linked to bomb threats against Timberline High School near Seattle. The code led the FBI to 15-year-old Josh Glazebrook, a student at the school, who on Monday pleaded guilty to making bomb threats, identity theft and felony harassment. In an affidavit seeking a search warrant to use the software, filed last month in U.S. District Court in the Western District of Washington, FBI agent Norman Sanders describes the software as a "computer and internet protocol address verifier," or CIPAV… Under a ruling this month by the 9th U.S. Circuit Court of Appeals, such surveillance – which does not capture the content of the communications – can be conducted without a wiretap warrant, because internet users have no "reasonable expectation of privacy" in the data when using the internet…"

** http://news.com.com/8301-10784_3-9746451-7.html

.
FYI…

- http://preview.tinyurl.com/yw6r2m
18 July 2007 (ZDnet) - "Companies that produce security software may soon be ignoring certain spyware, and potentially even infecting their customers through auto updates, under orders from US government agencies. In the case decided earlier this month by the 9th US Circuit Court of Appeals, federal agents used spyware with a keystroke logger – call it fedware – to record the typing of a suspected Ecstasy manufacturer who used encryption to thwart the police. A CNET News.com survey of 13 leading antispyware vendors found that not one company acknowledged cooperating unofficially with government agencies. Some, however, indicated that they would not alert customers to the presence of fedware if they were ordered by a court to remain quiet. Most of the companies surveyed, which covered the range from tiny firms to Symantec and IBM, said they never had received such a court order. The full list of companies surveyed: AVG/Grisoft, Computer Associates, Check Point, eEye, IBM, Kaspersky Lab, McAfee, Microsoft, Sana Security, Sophos, Symantec, Trend Micro and Websense. Only McAfee and Microsoft flatly declined to answer that question…"

.