From 34998539d82c7150b8b59814ca2a5df1c8e43c9f Mon Sep 17 00:00:00 2001 From: 46halbe <46halbe@berlin.ccc.de> Date: Sun, 30 Oct 2011 00:11:53 +0000 Subject: committing page revision 7 --- .../2011/analysiert-aktueller-staatstrojaner.en.md | 89 ++++++++++++++++++++++ 1 file changed, 89 insertions(+) create mode 100644 updates/2011/analysiert-aktueller-staatstrojaner.en.md diff --git a/updates/2011/analysiert-aktueller-staatstrojaner.en.md b/updates/2011/analysiert-aktueller-staatstrojaner.en.md new file mode 100644 index 00000000..cc7ae061 --- /dev/null +++ b/updates/2011/analysiert-aktueller-staatstrojaner.en.md @@ -0,0 +1,89 @@ +title: Chaos Computer Club analyzes new German government spyware +date: 2011-10-26 11:00:00 +updated: 2011-10-30 00:11:53 +author: presse +tags: update, pressemitteilung, staatstrojaner +previewimage: /images/0zapftisdiffed_1.png + +The Chaos Computer Club (CCC) has recently received a newer version of the "Staatstrojaner", a government spyware. The comparison with the older version, already analyzed by the CCC with the actual Sniffer-code from December 2010, revealed new evidence. Despite the claims of the responsible parties, the trojan can still be captured, loaded with any code and also the allegedly "audit trail" can be manipulated. The CCC is calling for a complete waiver of Trojans in pre-trial applications. + + + +On October 8th 2011, the CCC published the documentation and binary data +regarding a German "Staatstrojaner". \[0\] This was used for the +officially called computer infiltrations, trivially called +"source-telecommunication surveillance". Its application in pre-trials +and law enforcement meanwhile was admitted by many states. + +Despite the CCC has published solid technical evidence, the authorities +responsible for internal affairs, as well as the manufacturer DigiTask, +denied the existence of any illegal functionalities \[1\],\[2\],\[10\], +and pleaded that the analyzed Trojan was allegedly an outdated software +version. + +The excuses vary from "trial" to "prototype", DigiTask still insisted on +October 11th 2011 to its governmental customers, that almost all +problems are being solved in newer versions. The manufacturer DigiTask +and the authorities view the functionality of code-reloading as a +"natural need", for which the implication of fundamental rights +violation is relative in any way. It serves a purpose, and therefore the +aim justifies the means. + +Therefore, the CCC now presents a more detailed technical documentation +of a newer version of the "Staatstrojaner" from the year 2010.\[3\] The +testimony of DigiTask \[10\] is the basis of a detailed report that +serves as a euphemistic attempt to conceal its illegal nature. At the +same time, both disassembled versions of the Trojan, commented by the +CCC, were made publicly available in order to ensure the traceability of +the findings and to facilitate further research by interested parties. +\[4\] + +„Even during the last three years, the authorities and their providers +were clearly not capable of developing a "Staatstrojaner" which would +meet the minimum of requirements for juridical evidence, basic law +compliance and security against manipulation”, a CCC spokesperson summed +up about the new findings. “By these concrete and principal reasons, it +is logical not to expected that this would succeed in the future." + +The diagnosis of the new CCC report presents a strong contrast to the +claims by the Interior Secretary Ole Schröder, who was the one who +apparently had drawn the short straw and be the one to justify and +answer questions of the parliament. There, he claimed: "The software is +designed for each individual case and previously checked, so that it +can't do more than it is allowed to." \[8\] Under the previously +mentioned conditions, it is evident that the test wasn't very intense – +how could it, without available source code. + +## Links: + +- \[0\] The first press release regarding the "Staatstrojaner": [Die + erste Pressemitteilung zum + Staatstrojaner](http://www.ccc.de/en/updates/2011/staatstrojaner "Erste Pressemitteilung") +- \[1\] + +- \[2\] + +- \[3\] German: [Technical + Report](http://www.ccc.de/system/uploads/83/original/staatstrojaner-report42.pdf) +- \[4\] [Dissamblies with comments of both version of the + trojans](http://www.ccc.de/system/uploads/85/original/0zapftis-release-2.tbz) + and the + [binaries](http://www.ccc.de/system/uploads/84/original/0zapftis-3.6.44-binaries.tbz) +- \[5\] Videos: \ + (medium + resolution)\ + (high + resolution) +- \[6\] Frank Braun: „[0zapftis – (Un)Zulässigkeit von + ,Staatstrojanern‘](http://www.kommunikationundrecht.de/delegate/resources/dok751.pdf?fileid=dok751.pdf_kur&type=asset)“. + In: Kommunikation & Recht 11/2011, S. 681-686 +- \[7\] [FAQ zum + Staatstrojaner](http://pi10.tumblr.com/post/11835810799/faq-zum-staatstrojaner) +- \[8\] [Plenarprotokoll 17/132 des Deutschen + Bundestages](http://www.bundestag.de/dokumente/protokolle/plenarprotokolle/17132.pdf), 19. + Oktober 2011, S. 15604, +- \[9\] Ulf Buermeyer, Matthias Bäcker: [Zur Rechtswidrigkeit der + Quellen-Telekommunikationsüberwachung auf Grundlage des § 100a StPO, + HRRS](http://www.hrr-strafrecht.de/hrr/archiv/09-10/index.php?sz=8) +- \[10\] [testimony of + DigiTask](http://www.ccc.de/system/uploads/80/original/Stellungnahme_DigiTask.pdf) -- cgit v1.2.3