Feeds

How to find stolen laptops

The legal eye

Protecting against web application threats using SSL

A more 'civil' discovery for IP addresses

The problem with the "John Doe" lawsuit model that we currently have is that it encourages the filing of lawsuits where the remedy sought by the court is mostly frivolous. In many of the cases where a lawsuit is filed against, for example a virus writer, a spammer, or a purveyer of malware, we don't really seek monetary damages, or redress of defamation. What we really want is just to find out where it is coming from and make it stop. Besides, the spammers and other miscreants likely have no money to satisfy a judgement, and may not even eventually be found to be subject to the courts in a particular jurisdiction. The remedy for the most part is the discovery itself.

Since Courts can only settle "cases and controversies" and can only award damages or other injunctive relief, how can we use them to get this massive discovery?

If we can establish that we only seek IP address information when it is reasonable and appropriate, and that there are adequate privacy safeguards concerning the collection and use of information, we might be able to streamline the discovery process.

Take, for example the electronic LoJack service. Imagine a standing court discovery order from an appropriate court that says the following: if a computer protected by this service is reported stolen, and it finds itself on a strange network, and "pings" home with its IP address, then and only then the owner or the provider of the LoJack services is entitled to an order of discovery from the ISP from which the IP address is associated, permitting discovery of the customer data associated with that IP address.

If the target is piggybacking off several different IP addresses, the discovery order permits discovery of all of them, which is up to the ultimate user. The information may ONLY be used for the purposes of either filing a lawsuit against the perpetrator, or to turn over to law enforcement, or other reasonable purposes. The court might also appoint a "Special Master" responsible for overseeing the discovery process.

In practical terms, this is how it would work. The LoJack system would ping back the company with an IP address, date, time, etc. This information would be used to generate a discovery demand - automatically and digitally. The Special Master would be required to review each such demand for accuracy. The demand would then be automatically transmitted to the appropriate ISP that is associated with the IP address, which could (but would not be required to) automate the process of producing the requested records. The requested records would then be available to the Special Master in accord with the standing discovery order. In this way, discovery of the relevant information could occur in minutes, rather months.

Now there are, of course problems with such an approach. By making discovery so easy, it may encourage abuse. Clerical and other mistakes will not only be made, but will be automated. Judicial oversight will be reduced to a somewhat ministerial function, with most oversight assigned to the Special Master who is subject to not only boredom but corruption.

Since computer crime is instantaneous and international, the approach would have to be harmonised with international privacy laws, discovery laws, and jurisdictional laws. And there would have to be significant oversight with sanctions for abuse or misuse of the system. If we had all of these safeguards, we could streamline discovery of discrete classes of information (say IP log information) in discrete classes of cases. That might put a bunch of lawyers out of business. And what would be so bad about that?

This article originally appeared in Security Focus.

Copyright © 2007, SecurityFocus

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.