Liberté, Égalité, Spyware: France okays cops snooping on phones
- Reference: 1688967190
- News link: https://www.theregister.co.uk/2023/07/10/in_brief_security/
- Source link:
That's the direct (via machine translation) language used in the French Senate's version of a justice reform [1]bill passed earlier. According to French publication Le Monde , The French General Assembly [2]just passed their version, albeit with a few amendments that will require the Senate to OK the changes before it can become law.
Under the provision, French police will have the right to activate cameras and microphones remotely, as well as gathering location data from devices belonging to suspects accused of committing crimes that are punishable by at least five years in jail. Police can gather data in that manner for up to six months, and any connected device – smartphones, laptops and even automobiles – can be used for surveillance.
[3]
Per Le Monde , lawmakers from French president Emmanuel Macron's Renaissance party added several amendments to what's been dubbed the "snoopers' charter" – requiring remote spying only be used "when justified by the nature and seriousness of the crime," and even then only for a "strict and proportional" length of time. Professions considered sensitive, including doctors, journalists, lawyers, judges and – of course – MPs can't be targeted under the law as passed by the General Assembly.
[4]
[5]
"At a time when police violence is only increasing, when political movements are being muzzled by surveillance and massive searches, parliamentarians are about to authorize the transformation of all connected objects into police snitches," French digital rights group La Quadrature du Net [6]said of the bill.
French justice minister Éric Dupond-Moretti said the bill will only apply to a few dozen cases per year and, rather than being a way for France to get government-sponsored spyware onto the devices of anyone accused of a crime, will save lives.
[7]
"We're far away from the totalitarianism of 1984 ," he claimed.
Mastodon't neglect this week's critical vulnerabilities
For much of the world it was just another week, but in the US it was Independence Day on Tuesday, making things a bit quiet. That doesn't mean there weren't some critical vulnerabilities identified, though.
Decentralized social network Mastodon leads the pack with a rather serious issue identified this week. [8]CVE-2023-36460 , with its CVSS score of 9.9, exists in Mastodon versions starting with 3.5.0.
The issue could let an attacker with a specially-crafted media file "cause Mastodon's media processing code to create arbitrary files at any location," according to NIST. Any file that Mastodon has access to could be overwritten as well. Mastodon users are advised to patch to version 3.5.9, 4.0.5 or 4.1.3, depending on the fork they're using.
Heard of the brand new [9]Firefox 115 ? It included several important security fixes, and Mozilla released some others, too:
Firefox 115 fixes [10]several high-severity vulnerabilities, including memory safety bugs that could be used to run arbitrary code and a use-after-free problem in the creation of WebRTC connections over HTTPS.
Firefox ESR 102.13 received patches for [11]similar vulnerabilities.
Thunderbird v. 102.13 fixes a few [12]issues alike to Firefox's, too.
CISA published a single critical ICS vulnerability, but it's definitely a critical one. Found in PiiGAP M-Bus software for the 900S, the [13]advisory includes nine separate CVEs ranging from a CVSS score of 5.9 all the way to 9.8. Issues include hard-coded credentials, plain text transmission of credentials, and failure to sanitize input, among others. As for vulnerabilities under active exploit, a [14]single critical case was identified this week in several versions of Arm Mali GPU kernel drivers. If leveraged by an attacker, it could lead to information disclosure or root privilege escalation.
Oil giant Shell clipped by Cl0p for the second time in three years
You would think an international oil company as large as Shell would learn its lesson after Russian cyber crime gang Cl0p abused a vulnerable file-transfer application to [15]steal and ransom employee data in 2021. That's not the case, though, as Shell just admitted Cl0p hit it in the same way again – this time by making use of its [16]hot new exploit in another file transfer app, MOVEit.
"A cyber security incident … has impacted a third-party software from Progress called MOVEit Transfer, which was running on a Shell IT platform," Shell [17]explained in a brief statement about the breach.
Shell said that it was not a ransomware event – in other words, it fell victim to the same SQL injection vulnerability, or maybe one of the [18]other vulnerabilities, reportedly being exploited by Cl0p. Shell revealed the stolen data related to employees of its BG Group subsidiary, adding there was no evidence of impact to other IT systems.
Cl0p last hit Shell two years ago in a similar manner – that time involving file transfer software made by Accellion, which has since rebranded as Kiteworks. Passport and visa scans belonging to employees were stolen in that incident.
[19]
To make matters worse, Shell's report of the breach comes just a day before Progress, maker of MOVEit, released a [20]service pack to address three additional [21]serious vulnerabilities in its code. Progress said the MOVEit service packs will be a regularly-released security measure to combat exploitation of its software, so anyone yet to flee to another service provider should get patching, lest you end up like Shell.
Hundreds of solar power plants at risk for Mirai takeover
There are more than 600 solar power facilities around the world running SolarView monitoring hardware and software that's vulnerable to a flaw under active exploit. It's tied to the [22]Mirai botnet , security researchers from Vulncheck [23]reported this week.
The exploit in question – [24]CVE-2022-29303 – allows remote command injection due to failure to sanitize user inputs, and could lead to takeover by a Mirai-style [25]botnet . If exploited, attackers could pivot to attack additional ICS hardware, as well as cutting off monitoring of solar power facilities, affecting productivity and revenue.
Vulncheck said that IoT search engine Shodan reports more than 600 SolarView systems are connected to the internet despite the fact they should be restricted to ICS networks. While patches for the exploit, found in version 6.00 of SolarView software, have been available since last year, less than one third of the affected systems have been patched, Vulncheck said.
To make matters worse, several newer CVEs identified by Vulncheck also affect SolarView systems, meaning even the patched third of systems could still be at risk.
The lesson? Keep your ICS network and hardware segmented from the internet, regardless of your stellar patching habits. ®
Get our [26]Tech Resources
[1] https://www.senat.fr/leg/pjl22-569.html
[2] https://www.lemonde.fr/en/france/article/2023/07/06/france-set-to-allow-police-to-spy-through-phones_6044269_7.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZKvWxNjH2hWds0bXTWcVAgAAAZg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZKvWxNjH2hWds0bXTWcVAgAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZKvWxNjH2hWds0bXTWcVAgAAAZg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://twitter.com/laquadrature/status/1674047895643865089
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZKvWxNjH2hWds0bXTWcVAgAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://nvd.nist.gov/vuln/detail/CVE-2023-36460
[9] https://www.theregister.com/2023/07/05/firefox_115_browser_windows/
[10] https://www.mozilla.org/en-US/security/advisories/mfsa2023-22/#CVE-2023-37201
[11] https://www.mozilla.org/en-US/security/advisories/mfsa2023-23/
[12] https://www.mozilla.org/en-US/security/advisories/mfsa2023-24/
[13] https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01
[14] https://nvd.nist.gov/vuln/detail/CVE-2021-29256
[15] https://www.theregister.com/2021/03/29/shell_clop_ransomware_leaks_update/
[16] https://www.theregister.com/2023/06/01/moveit_transfer_zero_day/
[17] https://www.shell.com/energy-and-innovation/digitalisation/important-information-about-moveit-transfer-cyber-security-incident.html#iframe=L2Zvcm1zL2VuX2diX2N5YmVyX3NlY3VyaXR5X2luY2lkZW50X2NvbnRhY3Q
[18] https://www.theregister.com/2023/06/12/security_in_brief/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZKvWxNjH2hWds0bXTWcVAgAAAZg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023
[21] https://www.cisa.gov/news-events/alerts/2023/07/07/progress-software-releases-service-pack-moveit-transfer-vulnerabilities
[22] https://www.theregister.com/2017/11/07/mirai_botnet_sitrep/
[23] https://vulncheck.com/blog/solarview-exploitation
[24] https://nvd.nist.gov/vuln/detail/CVE-2022-29303
[25] https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/
[26] https://whitepapers.theregister.com/
Selected Targets
"Professions considered sensitive, including doctors, journalists, lawyers, judges and – of course – MPs can't be targeted under the law as passed by the General Assembly."
Because of course doctors, journalists, lawyers, judges and – of course – MPs are all fine upstanding citizens that would never indulge in any criminal activity
Because doctors are considered taboo, journalists and lawyers can fight back, and – of course – MPs won't shoot themselves in the feet.
Expect this snooping to become common use, since the powers that be don't really see why they shouldn't be able to use their shiny toys. Hey, they're the law, so the law doesn't apply to them, innit?
Also by "MPs" they obviously mean "our MPs", the opposition is fair game, if not a priority target (you need to know what those nasty criminals are up to at any moment)...
Re: Selected Targets
Define journalist.
Before he screwed it up (for the better?), then a post by some random guy with three followers and one retweet was good enough to be classed as "news".
Yes give the police more power....
Last time round in the " give the police more power" merry-go-round, what was added to the list was "allowed to shoot at anyone driving a car in the general vicinity of a policeman."
That one turned out well!
Re: Yes give the police more power....
ok, I'll probably get thumbed down to hell by putting some clarifications since it relates to a recent event :
- Kid was illegally driving a rented car registered in Poland. ( illegally because he was too young to have a driving license )
- Kid resisted licence/ID check twice in the previous minutes by reckless driving and almost drove over people in doing that.
- Kid tried to escape a third time as seen in the video.
Side note : it's common to have Polish registered rented car for drug money laundering purpose...
( and because Car rental in France double check the driving license and it's validity, renting a Polish car is a way to dodge that )
Ok, it doesn't clear the cop from shooting the kid... But a normal person wouldn't have tried to escape 3 times, would have had a driving license, and would have had a French registered car.... even a rented one.
No device penalty
Soon, you will be arrested and jailed for not carrying a snooping device (formerly known as a mobile phone).
Another provision is the penalty for not aligning your device in such way that you and all in your vicinity can be heard, seen and identified.
Re: No device penalty
It's already almost impossible to not have a snooping device, unless you're a hermit living from roots and berries: You need Internet access to deal with officialdom at any level.
Snooping, or Lawful Interceptions
I don't know all the details of the new law ( yet ).
But it's not something new in France.
French police forces have already the right to snoop on all the phone calls/SMS/MMS/Internet traffic logs after requesting and being granted it by a Judge for a criminal investigation.
Note that this right is not time limited, it's for the "duration of the investigation" when granted. ( which can last for years )
That's what we call the *Interception Légales* ( Lawful Interceptions ). [ obviously in the past there's been illegal ones, some of them performed by the resident of the Elysée Palace ]
Re: Snooping, or Lawful Interceptions
Different thing.
Those are all actions taken by the individual and intercepted at a 3rd party.
This allows them to do covert surveillance at any location they want and at anytime.
It's like having a camera and microphone in every single location in France.Just think how many locations and interactions you have in a weekend . All those are now fair game.
I hope Apple and Google track and remove the spyware.
French legislation requires that all camera apps on smartphones sold in France make a shutter sound when taking a photo, so that people can't be photographed unawares. I wonder how they'll resolve the apparent conflict.
There is no sound requirement when taking a video I guess, else video-conferences would get quite noisy in France...
"We're far away from the totalitarianism of 1984," he claimed.
"... mais nous y travaillons".