News: 1628159472

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Das tut mir leid! Germany's ruling party sorry for calling cops on researcher after she outed canvassing app flaws

(2021/08/05)


A "left-wing" German infosec researcher was this week threatened with criminal prosecution after revealing that an app used by Angela Merkel's political party to canvass voters was secretly collecting personal data.

Germany's respected Chaos Computer Club (CCC) [1]announced it would stop reporting any weaknesses in the centre-right wing Christian Democratic Union's (CDU) web-facing infrastructure to the party after it procured a criminal prosecution against Lilith Wittmann.

"I got an email from the Cyber Security Police of Berlin," she told The Register . "Could you please provide us your address, so we can send you... legal documents? And then I was like, that's weird. I didn't do anything wrong. Let's tweet about that. Let's find a lawyer who can look into that."

[2]

Although the prosecution is due to be [3]withdrawn after an apology from the CDU, the episode shines a light on some German politicians' attitudes to vulnerability disclosures.

[4]

[5]

In May, during federal elections in Germany, the CDU equipped its door-knocking activists with an app called CDU Connect. The app was used for recording data on homeowners: did they welcome political activists knocking on their doors to find out who they were going to vote for? Did they shoo the CDU's foot soldiers away, or did they invite them in for a cuppa and a chat? At the time, Wittmann told us, the CDU insisted that data collected in the app was anonymous.

This was incorrect, Wittmann said. The researcher revealed her findings in a [6]blog post (auf Deutsch), explaining on a phone call with The Register that all she did was sniff an API token, "man in the middle" style, "to figure out how the API works." Having done that, she discovered personal data was indeed being processed by the app.

[7]The perils of non-disclosure? China 'cloned and used' NSA zero-day exploit for years before it was made public

[8]C'mon, biz: Give white hats a chance to tell you how screwed you are

[9]Google, Facebook, Chaos Computer Club join forces to oppose German state spyware

After Wittmann reported the exploitable vulns to the CDU, the party shut down CDU Connect. There was, so the infosec researcher said, no specific agreement between her and the political party about what details could or could not be included in a public writeup so she included them all. Local media picked up on it at the time, and then the moment had passed. Or so everyone thought.

A few days ago the police [10]got in touch , said they were following up on the app breach, and asked for Wittmann's postal address.

We're sorry for that thing we definitely didn't do

German daily newspaper Die Welt [11]reported yesterday that CDU managing director Stefan Hennewig confirmed the party had told police of an alleged data theft and denied the party had accused Wittmann of stealing data – but then apologised anyway for naming her in the CDU's police report.

Unsere Anzeige richtet sich NICHT gegen das Responsible Disclosure Verfahren von Lilith Wittmann. RD-Verfahren sind ein guter Weg, um Betroffene auf Sicherheitslücken aufmerksam zu machen. Ich halte diese Verfahren für einen wichtigen Baustein, um IT-Sicherheit zu erhöhen. (2/5) — Stefan Hennewig (@StefanHennewig) [12]August 4, 2021

Netzpolitik, a left-wing political collective with strong links to Germany's hacker community, berated the CDU in a [13]blog post titled "Screw up. Back Down. Repeat" while declaring that "conservatives have understood neither decency nor the basic principles of digital society".

Wittmann told us she considers herself "far left." We're not sure if that translates well into English but she attributed the CDU's police report to her political leanings and previous criticism of the conservative party.

[14]

"And also in my report, in the end, I told them how incompetent I think they are from a political perspective," she said. "I'm a security researcher... but in other perspectives, I'm also a political activist."

While the immediate reaction in Germany has averted any negative consequences for Wittmann, her approach may not have been the wisest. Regular readers might compare this to [15]the Apperta saga , when a responsible disclosure went wrong thanks to pre-existing disagreements. Similarly, political disagreements saw a female-focused social media network [16]threaten to sue a British infosec firm which pointed out its entire user database was publicly accessible.

Some things never change in infosec. ®

Get our [17]Tech Resources



[1] https://www.ccc.de/en/updates/2021/ccc-meldet-keine-sicherheitslucken-mehr-an-cdu

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQwLM-r5uDxoUdGZJPZssgAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.br.de/nachrichten/netzwelt/cdu-zieht-anzeige-gegen-it-sicherheitsforscherin-zurueck,Sf7RFxp

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQwLM-r5uDxoUdGZJPZssgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQwLM-r5uDxoUdGZJPZssgAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://lilithwittmann.medium.com/wenn-die-cdu-ihren-wahlkampf-digitalisiert-a3e9a0398b4d

[7] https://www.theregister.com/2021/02/23/microsoft_chinese_nsa/

[8] https://www.theregister.com/2018/09/18/financial_services_vulnerablity_disclosure_policies/

[9] https://www.theregister.com/2021/06/07/in_brief_security/

[10] https://twitter.com/LilithWittmann/status/1422546380275556352/photo/1

[11] https://www.welt.de/politik/deutschland/live232931519/Bundestagswahl-2021-Wirbel-um-Vorgehen-der-CDU-gegen-Digitalexpertin.html

[12] https://twitter.com/StefanHennewig/status/1422899621941161992?ref_src=twsrc%5Etfw

[13] https://netzpolitik.org/2021/cdu-gegen-hackerin-scheisse-bauen-rueckzieher-machen-repeat

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQwLM-r5uDxoUdGZJPZssgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2021/05/14/apperta_rob_dyke_disclosure_brouhaha/

[16] https://www.theregister.com/2020/09/11/giggle_female_app_data_breach_notification/

[17] https://whitepapers.theregister.com/



Classical attack

b0llchit

This is the classical go after the messenger, not the message attack. It sends a very strong signal to show who is "in charge" and what "may happen" when you try to challenge the status quo.

It does not matter that they now apologize or backpedal. They have already sent the signal and it is ear deafening. The political affiliation or wing or side does not matter. This type of behavior is found on all sides and is typical of a bully wanting (to stay in) power. The way to fight a bully is to expose the bully with unified front.

Re: Classical attack

JohnG

Also, those responsible for the app have almost certainly breached German data protection laws. Ms Wittmann had also informed the relevant data protection office of the issue, prior to her publication. The police should have gone after those who released and operated an app which failed to protect people's information (despite claiming the opposite) - but they went after the person who reported the actual crime instead.

Ms Wittmann put her own report here (in German) AFTER the app was shut down: https://lilithwittmann.medium.com/wenn-die-csu-und-die-volkspartei-digitalen-wahlkampf-machen-6d9e245efefc

Re: Classical attack

Charlie Clark

Yep, almost certainly a breach of GDPR and so a fine will be in the post to Konrad Adenauer Haus.

What the fuckwits probably don't realise is that this whistle has probably saved them from a much bigger one, when some of that data is either leaked or purloined.

Re: Classical attack

Irongut

> They have already sent the signal and it is ear deafening.

Well you would be surprised if it was eye deafening, nose deafening or perhaps finger deafening.

Anonymous Coward

Ah yes the old: You've pointed out someone's mistake, and that someone responses with anger/finger pointing/lawsuits in your direction, rather than checking if they made a mistake and correcting it.

The engineers mindset: When someone tells you you've got it wrong, initially believe them, go and check, have another someone verify it, fix if necessary (optionally) demonstrate to the initial someone you were right with the evidence to back up your claims (with politeness).

Blofeld's Cat

" ... engineers mindset ... "

Very similar to the scientific method.

In the early days of exoplanet research there was a press conference at which a research team announced that they had calculated the "year" of an exoplanet at 365.25 days.

There was a pause, after which the team leader said something along the lines of:

This is either a staggering coincidence, or we have got something wrong. We have checked our data many times and cannot find an error. Our research is all published on line and we would be most grateful if somebody could please point out where we messed up.

coincidence or cock-up

A Nother Handle

So which was it? Or are they waiting for the JWST to give a second opinion?

Re: coincidence or cock-up

Yet Another Anonymous coward

IIRC routine that calibrated out the Earth's motion didn't use enough significant figures.

Telescope was on Earth and was measuring very small shift in the position of another star, so had to take out the measurement point moving much more than the shift you are looking for.

Richard Boyce

The mice have commissioned a reserve planet, just in case the Vogons get a bit careless.

Not exactly a standard vuln report then

Santa from Exeter

She used it as a means to get a political dig in, not the actions of an ehtical hacker. IMHO she got confused and let the 'political activist' take over.

Political Leanings have bugger all to do with Infosec and should be kept separate.

How did this happen?

elsergiovolador

After so much evil, it seems like majority of population got amnesia and think Germany is the most virtuous country in Europe now.

Do you think Stasi and their methods disappeared overnight?

Do you think they are no longer plotting with Russia?

They are only half asleep, because in the end they got what they wanted - they rule the Europe, and Slavic people work for their factories on near poverty wages.

Make no mistake, as soon as the crisis crosses the tipping point, all bets are off with them.

Re: How did this happen?

GrumpenKraut

Yeah. Right.

Re: How did this happen?

Dan 55

In your head, in your head, they're still fighting...

Re: How did this happen?

Yet Another Anonymous coward

Obviously what they should do is quit Europe so that they can then make up their own data protection laws and the ruling party can simply declare this legal because sovereignty.

As a side effect they would then automatically rule the world.

Re: How did this happen?

Irongut

Take your 1940s attitudes back to the last millenium where they should have stayed.

Anonymous Coward

Of course the data collected by Connect isn't anonymous - it would be pointless if it was. The entire point of collecting canvass data is to find out who will or is likely to vote for you - as in the individual people. It's pointless having data that says "156 people in Division 22 say they will vote for you" without knowing *who* those 156 people are. You need to know who your pledges are so you can remind them that they are your pledges, and follow them up to confirm they have acted on their pledges. And, importantly, who supports other candidates so you can do everything to avoid reminding them there's an election. This is basic "elementary school" level election campagning, see Bob Heinlein's account of the 1934 election.

Anon, I use the UK version of Connect and have worked with people who have used the US and the Canadian version of Connect.

lglethal

And that would be fine if they had openly declared that was what they were doing, rather than claiming that they didnt collect any personally identifiable data.

Although even if they had declared that it would have been behove of them to actually secure said data so that a man-in-the-middle attack couldnt actually sniff out the data so easily.

So first they lied about what the app did, and what data they collected. Then they failed to secure said data. Then they went after the person who pointed out those things. All round fails...

Charlie Clark

No, it still wouldn't be legal without informed consent: including a signature in this case.

Version 1.0

Maybe the next move would be to create fake accounts and feed the app fakes. These days we're stealing peoples data, selling the data, and faking the data to make money from whoever wants to think that they are in control - politics is simply a financial world.

Doctor Syntax

"Some things never change in infosec."

And not just in infosec. Paging Ms Streisand.

Merkel is Petruchio?!

Lil Endian

I say it is the moon that shines so bright.

Claiming to apologise without admitting fault is a logical fallacy.

Cambridge: apology (noun) - an act of saying that you are sorry for something wrong you have done

By definition an apology can only be proffered with an admission of culpability. Claiming otherwise is narcissistic: we're bigger than you, what we say is right and you don't have a leg to stand on.

Yes, in the States there's the "I'm Sorry" law, but that proves nothing as a law is its own definition and laws are, well, a law unto themselves. And laws can be wrong.

Apologising for something you've not done is akin to attempting to take out insurance for something in which you have no vested interest, you just can't.

sushi, n.:
When that-which-may-still-be-alive is put on top of rice and
strapped on with electrical tape.