FBI Installing Spyware

from Slashdot:

"There have been rumors for years about the FBI remotely installing spyware via e-mail or by exploiting an operating system vulnerability from afar -- and now there's confirmation. Last month, the FBI obtained a federal court order to remotely install spyware called CIPAV (Computer and Internet Protocol Address Verifier) to find out who was behind a MySpace account linked to bomb threats sent to a high school near Olympia, Wash. News.com has posted a PDF of the FBI affidavit, which makes for interesting reading, and a summary of the CIPAV results that the FBI submitted to a magistrate judge. It seems as though CIPAV was installed via e-mail, as an article back in 2004 hinted was the case. In addition to reporting the computer's IP address, MAC address, and registry information, it also gave the FBI updates on which IP addresses the user(s) visited. But how did the FBI get the spyware activated and past anti-virus defenses? Two obvious ways are for the Feds to find and exploit their own operating system backdoors, or to compromise security vendors..."

Comments (5)


Breaking news, the internet has been crashed.

U.P. Man:

So you are saying it is bad that the FBI got a warrant to make use of current technology?


Hah, UP; ably hoist on their own dangerous petards.

Paul Hamilton:

The key questions in the article are the ones in the last two sentences. Something like that should be detected and removed, but apparently it wasn't. So does that mean that this guy was lax about his security or does it mean that the government has some unknown sort of spyware, or in the worst possibility of all, does it mean that the companies who provide security for our computers are deliberately not including protection from intrusions from the government.

U.P. Man:

First, I expect the government to attempt to break all security measures. It's a byproduct of them making sure government computers are safe.

Second, Not all security vendors reside in the US.

And again I ask, do you think they should not use the most current knowledge and technology that they can? The FBI did get a warrant to do this right?


