Magic Lantern (software)

Magic Lantern (software)
Magic Lantern
Original author(s) Federal Bureau of Investigation
Operating system Microsoft Windows
Type Keylogger

Magic Lantern is keystroke logging software developed by the United States' Federal Bureau of Investigation. Magic Lantern was first reported in a column by Bob Sullivan of MSNBC on 20 November 2001[1] and by Ted Bridis of the Associated Press.[2]

Contents

How it works

Magic Lantern can reportedly be installed remotely, via an e-mail attachment or by exploiting common operating system vulnerabilities, unlike previous keystroke logger programs used by the FBI.[3][4] It has been variously described as a virus and a Trojan horse. It is not known how the program might store or communicate the recorded keystrokes.

Purpose

In response to a Freedom of Information Act request filed in 2000 by the Electronic Privacy Information Center, the FBI released a series of unclassified documents relating to Carnivore, which included the "Enhanced Carnivore Project Plan". Sullivan's confidential source said that redacted portions of that document mention "Cyber Knight",

a database that sorts and matches data gathered using various Carnivore-like methods from e-mail, chat rooms, instant messages, and Internet phone calls. It also matches files with captured encryption keys.

Example deployment method

The FBI intends to deploy Magic Lantern in the form of an e-mail attachment. When the attachment is opened, it installs a trojan horse on the suspect's computer. The trojan horse is activated when the suspect uses PGP encryption, often used to increase the security of sent e-mail messages. When activated, the trojan horse will log the PGP password, which allows the FBI to decrypt user communications.[5][6]

Spokesmen for the FBI soon confirmed the existence of a program called Magic Lantern. They denied that it had been deployed, and they declined to comment further.[7]

Antivirus vendor cooperation

The public disclosure of the existence of Magic Lantern sparked a debate as to whether anti-virus companies could or should detect the FBI's keystroke logger.

Concerns include uncertainties about Magic Lantern's full potential and whether hackers could subvert it for purposes outside the jurisdiction of the law.[8][9]

Bridis reported that Network Associates (maker of McAfee anti-virus products), had contacted the FBI following the press reports about Magic Lantern to ensure their anti-virus software would not detect the program.[10] Network Associates issued a denial, fueling speculation as to which anti-virus products might or might not detect government trojans.[11]

CNET News has surveyed 13 security companies about their contacts with and level of cooperation with law enforcement authorities.[12]

Graham Cluley, a technology consultant from Sophos, said "We have no way of knowing if it was written by the FBI, and even if we did, we wouldn’t know whether it was being used by the FBI or if it had been commandeered by a third party".[13] Another reaction from this came from Marc Maiffret, chief technology officer and cofounder of eEye Digital Security who states: "Our customers are paying us for a service, to protect them from all forms of malicious code. It is not up to us to do law enforcement's job for them so we do not, and will not, make any exceptions for law enforcement malware or other tools."[14]

When asked if Magic Lantern would need a court order to deploy, FBI spokesman Paul Bresson would not comment, stating: "Like all technology projects or tools deployed by the FBI it would be used pursuant to the appropriate legal process."[15][16] Proponents of Magic Lantern argue the technology would allow law enforcement to efficiently and quickly decrypt messages protected by encryption schemes. Implementing Magic Lantern does not require physical access to a suspect's computer, unlike Carnivore, a predecessor to Magic Lantern, since physical access to a computer would require a court order.[17]

Following the media coverage of Magic Lantern, F-Secure (a Finnish anti-virus company), announced their policy on detecting government spying programs: "F-Secure Corporation would like to make known that we will not leave such backdoors to our F-Secure Anti-Virus products, regardless of the source of such tools. We have to draw a line with every sample we get regarding whether to detect it or not. This decision-making is influenced only by technical factors, and nothing else, but within the applicable laws and regulations, in our case meaning EU laws.

We will also be adding detection of any program we see that might be used for terrorist activity or to benefit organized crime. We would like to state this for the record, as we have received queries regarding whether we would have the guts to detect something obviously made by a known violent mafia or terrorist organization. Yes we would."[18]

See also

References

  1. ^ Sullivan, Bob (2001-11-20). "FBI software cracks encryption wall". MSNBC. http://msnbc.com/news/660096.asp?cp1=1. Retrieved 2007-11-20. [dead link]
  2. ^ Ted Bridis. "FBI Develops Eavesdropping Tools," Washington Post, November 22, 2001.
  3. ^ FBI's Secret Spyware Tracks Down Teen Who Made Bomb Threats July 18, 2007 Wired Magazine
  4. ^ [Threat of Terrorism On U.S. Infrastructure December 31, 2001 The New York Times
  5. ^ "FBI Has a Magic Lantern". Usgovinfo.about.com. http://usgovinfo.about.com/library/weekly/aa121401a.htm. Retrieved 2009-02-23. 
  6. ^ "The FBI's Magic Lantern". Worldnetdaily.com. 2001-11-28. http://www.worldnetdaily.com/news/article.asp?ARTICLE_ID=25471. Retrieved 2009-02-23. 
  7. ^ Article in the Village Voice, 24 May 2002
  8. ^ "Invasive Software: Who's Inside Your Computer?". George Lawton. July 2002. http://utopia.csis.pace.edu/dps/2007/jkile/2005%20-%20Spring/DCS823/Spyware/01016895.pdf. Retrieved 2009-03-12. 
  9. ^ http://www.kaspersky.com+(2001-12-11). "The FBI's "Magic Lantern" Shines Bright". Kaspersky.com. http://www.kaspersky.com/news?id=266. Retrieved 2009-02-23. 
  10. ^ AP story about Magic Lantern, 22 November 2001
  11. ^ Article in Wired, 29 November 2001
  12. ^ CNET News - Security firms on police spyware, in their own words, 17 July 2007
  13. ^ Jackson, William (2001-12-06). "Antivirus vendors are wary of FBI's Magic Lantern – Government Computer News". Gcn.com. http://www.gcn.com/online/vol1_no1/17572-1.html. Retrieved 2009-02-23. 
  14. ^ McCullagh, Declan (2007-07-17). "Will security firms detect police spyware? – CNET News". CBS Interactive, Inc. http://news.cnet.com/2100-7348-6197020.html?tag=tb. Retrieved 2009-02-23. 
  15. ^ "FBI Confirms ‘Magic Lantern’ Project Exists". Elinor Mills Abreu. At Home Corporation. December 31, 2001. http://www.si.umich.edu/~rfrost/courses/SI110/readings/Privacy/Magic_Lantern.pdf. Retrieved 2009-03-12. 
  16. ^ "THE CASE FOR MAGIC LANTERN: SEPTEMBER 11 HIGHLIGHTS THE NEED FOR INCREASED SURVEILLANCE". Christopher Woo & Miranda So. Harvard Journal of Law & Technology. 2002. http://jolt.law.harvard.edu/articles/pdf/v15/15HarvJLTech521.pdf. Retrieved 2009-03-12. 
  17. ^ "IMPLICATIONS OF SELECT NEW TECHNOLOGIES FOR INDIVIDUAL RIGHTS AND PUBLIC SAFETY". Amitai Etzioni. Harvard Journal of Law & Technology. 2002. http://jolt.law.harvard.edu/articles/pdf/other/Etzioni.doc. Retrieved 2009-03-12. [dead link]
  18. ^ "F-Secure Corporation's policy on detecting spying programs developed by various governments". F-Secure. http://www.f-secure.com/virus-info/bdtp.shtml. Retrieved 25 June 2011. 

Further reading

  • Amanda So and Christopher Woo. "The Case for Magic Lantern: September 11 Highlights the Need for Increased surveillance," Harvard Journal of Law and Technology. v15, p521. (discusses the legal framework surrounding the use of keystroke loggers in law enforcement)

External links


Wikimedia Foundation. 2010.

Игры ⚽ Поможем написать реферат

Look at other dictionaries:

  • Magic Lantern — (de l anglais signifiant littéralement « lanterne magique ») est un policeware développé par le Federal Bureau of Investigation (FBI). Grâce à ce logiciel, le FBI peut enregistrer tout ce que tape un utilisateur sur son clavier. Son… …   Wikipédia en Français

  • Magic lantern (disambiguation) — Magic lantern may refer to: Contents 1 In entertainment 1.1 In theater 2 Other uses …   Wikipedia

  • Magic Lantern — may mean:*magic lantern, the ancestor of the modern slide projector *Magic Lantern (software), the FBI s keylogger. *The Magic Lantern is the name of a theater in Prague which served as the headquarters for the reform movement (see Velvet… …   Wikipedia

  • Magic Lantern — Saltar a navegación, búsqueda Según una fuente mencionada por el servicio de noticias MSNBC, el FBI estaría desarrollando su propio troyano, para combatir al terrorismo. La idea del programa, es robar las contraseñas de todo aquel (en principio… …   Wikipedia Español

  • Magic Lantern (logiciel) — Magic Lantern Magic Lantern (de l anglais signifiant littéralement « lanterne magique ») est un policeware développé par le Federal Bureau of Investigation (FBI). Grâce à ce logiciel, le FBI peut enregistrer tout ce que tape un… …   Wikipédia en Français

  • Remote Forensic Software — Plastische Darstellung des „Bundestrojaners“ , vom Chaos Computer Club Als Online Durchsuchung wird der verdeckte staatliche Zugriff auf fremde informationstechnische Systeme über Kommunikationsnetze bezeichnet. Der Begriff umfasst dabei sowohl… …   Deutsch Wikipedia

  • Spy software — Шпионский программный продукт программный продукт определенного вида, установленный и применяемый без должного оповещения пользователя, его согласия и контроля со стороны пользователя, т.е. несанкционированно установленный. Именно в этом узком… …   Википедия

  • Amiga productivity software — This article is a split of main article Amiga software and refers to any productivity software that run on Amiga line of computers.See also related articles Amiga Internet and communications software and Amiga support and maintenance software for …   Wikipedia

  • Oasis (software) — Note: Oasis is also the name of library catalog software that is popular in Australia. Oasis is the name of a piece of software developed by the United States Central Intelligence Agency (CIA) that converts audio signals such as cellphone calls… …   Wikipedia

  • Canon EOS 60D — Typ …   Deutsch Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”