France Passes New Bill Allowing Police To Remotely Activate Cameras On Citizens' Phones (gizmodo.com) 132
An anonymous reader quotes a report from Gizmodo: Amidst ongoing protests in France, the country has just passed a new bill that will allow police to remotely access suspects' cameras, microphones, and GPS on cell phones and other devices. As reported by Le Monde, the bill has been criticized by the French people as a "snoopers" charter that allows police unfettered access to the location of its citizens. Moreover, police can activate cameras and microphones to take video and audio recordings of suspects. The bill will reportedly only apply to suspects in crimes that are punishable by a minimum of five years in jail and Justice Minister Eric Dupond-Moretti claimed that the new provision would only affect a few dozen cases per year. During a debate over the bill yesterday, French politicians added an amendment that orders judge approval for any surveillance conducted under the scope of the bill and limits the duration of surveillance to six months, according to Le Monde.
"For organized crime, the police can have access to the sound and image of a device. This concerns any connected device: telephone, speaker microphone, computer camera, computer system of a car... all without the knowledge of the persons concerned," French advocacy group La Quadrature du Net said in a statement on Twitter last month, machine translated by Gizmodo. "In view of the growing place of digital tools in our lives, accepting the very principle that they are transformed into police auxiliaries without our being aware of it poses a serious problem in our societies." In 2021, France passed a bill that would expand the French police force's ability to monitor civilians using drones -- all in an effort to protect officers from increasingly violent protestors, according to French President Emmanuel Macron.
"For organized crime, the police can have access to the sound and image of a device. This concerns any connected device: telephone, speaker microphone, computer camera, computer system of a car... all without the knowledge of the persons concerned," French advocacy group La Quadrature du Net said in a statement on Twitter last month, machine translated by Gizmodo. "In view of the growing place of digital tools in our lives, accepting the very principle that they are transformed into police auxiliaries without our being aware of it poses a serious problem in our societies." In 2021, France passed a bill that would expand the French police force's ability to monitor civilians using drones -- all in an effort to protect officers from increasingly violent protestors, according to French President Emmanuel Macron.
Will the bill also ban black electrical tape? (Score:5, Insightful)
Re: (Score:2)
I was thinking more of a hole in the subject's trouser pockets and underwear!
Re: Will the bill also ban black electrical tape? (Score:3)
In France, only outlaws have phones that can't be spied upon.
Re:Will the bill also ban black electrical tape? (Score:4, Insightful)
What about the microphone and GPS.
This what you get when governments do stuff for the citizens own good.
Let me see the logic here: Police wrongly shoot person, people protest, police get more power. Now they can hunt you down more easily.
Re: (Score:3)
Whoosh!
Anyway ... padded/soundproof/aluminized phone case? Or just a hard battery disconnect switch for when you want to carry the phone with you without it being "always on."
Re: (Score:3, Informative)
Whoosh what? I was not disagreeing with you, I knew you where being sarcastic, just saying we need more.
Re: (Score:2)
Anyway ... padded/soundproof/aluminized phone case? Or just a hard battery disconnect switch for when you want to carry the phone with you without it being "always on."
Disable very fundamental functionality in your phone for the win!
hard battery disconnect switch
What are you smoking? Have you even seen the inside of a modern phone? How are you going to wire in a battery disconnect switch?
Re: (Score:2)
I can't believe nobody has said it yet:
FARADAY CAGE
Clamshell belt case for your phone, lined with copper mesh.
No signal, no tracking.
Re: (Score:2)
Re: (Score:2)
1. If you just leave your cell at home, why did you cancel your landline?
I take mine out with me a couple of days a week when it's useful to do so.
I'm quite happy to be outside without it though.
Re: (Score:3)
Police wrongly shoot person, people protest, police get more power.
The Government first sent this project for discussion in the Parliament on May 13, long before the events you refer to.
Re: (Score:3)
I am sure it did, but you would have thought that police shooting people would have gave them pause to not increase their powers.
Re:Will the bill also ban black electrical tape? (Score:4, Insightful)
They can pass all the laws they wat, but does the means exist today to do this? Heck, even if you OWN a phone you can't remotely activate the camera/mic without specific software. gps tracking exists, but is currently locked to various management accounts.
Google, Apple, samsung, etc. would need to write software to include this access ... i'm kind of curious if this brings about a showdown between the law (and France) and the device mfgs.
In the united states, they already tried to force apple to give police back door access - they refused (it didn't exist - private key encryption) and it was ruled they couldn't be compelled to create one. Now, if they DID push through something like this ... people would be a LOT less inclined to use that device. Or, on the reverse, much more inclined to use a device that allows installing software that can prevent/control/override remote control. i.e. Android +/- some of the boot security etc. that's offered especially by samsung.
The day someone can get remote access to the camera/mic on my device without my knowledge (and not a hacker/virus that's my own fault) is the day I stop using that device forever. Even on my work phone I refuse to allow location services for any work-related app. I get weekly reminders to turn it on and ignore them weekly. They expect me to be reachable in emergency pretty much 24/7...and if they insist on location tracking i'll insist on compensation for those on-call hours.
Re: (Score:2)
The day someone can get remote access to the camera/mic on my device without my knowledge (and not a hacker/virus that's my own fault) is the day I stop using that device forever.
I believe you and I am the same, but I don't think that will be common most people will continue on. But life will become harder and harder to do without a phone, probably won't even be able to do a bank transaction without 2 factor authentication on your phone. Then how will you buy food?
Re: (Score:2)
Then how will you buy food?
Cash.
Re:Will the bill also ban black electrical tape? (Score:5, Interesting)
You are perfectly trackable simply by mobile tower triangulation, even without a sim-card.
As for surveillance, police doesn't need "Google, Apple, samsung, etc." to write anything.
They can setup fake services, networks, carriers... whatever is needed for your phone or computer to connect to and download and install "the update" all on its own.
Or, even simpler, have you arrested for "disorderly conduct" and dump whatever they want onto your phone while it is in evidence - then later simply construct a parallel explanation [wikipedia.org] regarding how the surveillance software got there.
The point is not whether the police have the tech to "hack into" people's phones. That's just a question of them hiring people who do.
It's that they can do so LEGALLY and use any information gathered that way perfectly LEGALLY in any kind of investigation and later in court.
Re: (Score:3)
The first approach you describe would be next to impossible to do without either
- compromising the CA certificates on your phone (and thus already having access to your phone, e.g. through malware or through the vendor),
- obtaining control over at least one such a CA (which likely won't suffice thanks to RFC 6844) or
- obtaining the private keys of the services they'd want to impersonate.
- compromising the software repository or other vendor services your phone uses
That would be a gargantuan effort and doing
Re: (Score:2)
Or pass a law requiring phone vendors to include such a backdoor for the police. I don't see that going through silently or smoothly though, but I may be very wrong here.
Re: (Score:2)
I believe I already mentioned that option ;)
compromising the software repository or other vendor services your phone uses
Re: (Score:2)
Compromising includes a level of secrecy and avoiding detection. When it's written into law, it's out in the open I guess...
Re: (Score:2)
That would be a gargantuan effort and doing so at a large scale would be extremely difficult.
Luckily for the French police, it will only affect "dozens of cases a year".
So all is well.
As I said below, techies often try to outsmart a bullet.
The law covers any "electronic device" used for snooping and spying on the owner. Method or difficulty of implementation is irrelevant.
Legality of action is what matters as this covers anything that is definable as an "electronic device".
Car, computer or electric toothbrush. It is legal to use it to spy and snoop on people.
Re: (Score:3, Insightful)
Updates are signed with Google's private key on Android, and I'm sure on iOS too. The whole point of using certificates and signing is to prevent people setting up fake websites and networks that your device blindly downloads from.
The most likely way they will access your device is via an app you already have. Find an exploit in that, and use the permissions you already gave it. Best not to give chat apps permissions like camera and microphone. Take a photo using the camera app and then import it into the c
Re: (Score:3)
You are committing a classic techie fallacy - trying to outsmart a bullet.
Method is as irrelevant as the hand with which a police officer might hold a truncheon while beating in your skull.
The issue is the legality of action.
The law allows snooping through "laptops, cars and other connected objects as well as phones".
I.e. If it is an "electronic device", be it a phone, car, fridge, TV or computer - police can perfectly legally use it to spy on you.
How they get the access to your hardware (or hardware belong
Re: (Score:2)
The way we keep governments in check is to make it impractical.
I'm sure French intelligence has some secret zero day exploits, but they aren't going to share them with the police.
You demonstrably can't stop these kinds of laws, but you can frustrate them by securing everything. It's why default secure and encrypted is so important.
Re: (Score:2)
While I realize we are talking about France, isn't the UK actively trying to ban E2E? If they pull it off, how many more countries will follow? Quite a few I'm sure.
Re: (Score:2)
Fortunately the UK is too incompetent to actually ban E2E.
Re: (Score:2, Insightful)
They can setup fake services, networks, carriers... whatever is needed for your phone or computer to connect to and download and install "the update" all on its own.
No your network cannot install anything on your phone without your express permission, and even then they can't do it without a SIM card present.
The only thing that the police can do is triangulate you based on your IMSI, but even then they'd need to know your IMSI having identified it by other means in the past (typically through your phone number if your SIM is present).
It's technology, not magic.
Re: (Score:3)
What you're describing is a whole world more expensive to do than "remotely activate the camera on XYZ phone, please".
They _could_ do all kinds to you - but they don't because you're not interesting enough to justify the spend. You're still not interesting enough, even if you've quite clearly committed a crime which would see you in jail for at least 5 years. If (under the French system, not the 3rd world kangaroo courts of the US) you were likely guilty of enough crimes for 100+ years on jail, then you _ar
Re: (Score:2)
Welcome to spyware on apps, especially from companies like Cisco which have been discovered installing back doors in their most expensive and secured systems.
there are apparently already hacks to do it (Score:2)
https://www.reuters.com/technology/exclusive-iphone-flaw-exploited-by-second-israeli-spy-firm-sources-2022-02-03/
Re: (Score:2)
They can pass all the laws they wat, but does the means exist today to do this?
Yes. It is already built into your phone. You do not have access to it, but the manufacturers, and therefore the government, have access.
Re: (Score:2)
What about the microphone and GPS.
In unrelated news, five startups announce plugins to keep all phone radios off until the user actively does something which requires them.
How? (Score:2)
Sure, black electrical tape works. But the question remains... what mechanism to they intend to use to remotely activate (and presumably monitor) a random citizen's camera?
Re: (Score:2)
what mechanism to they intend to use
Presumably with whatever hacking toolbox they have access to. The law just say they are allowed to do (which I understand as: to attempt).
Re: (Score:2)
Sure, black electrical tape works. But the question remains... what mechanism to they intend to use to remotely activate (and presumably monitor) a random citizen's camera?
It's a secret SMS. They send it to your 'phone, it activates the spying.
Re: (Score:2)
Black electrician tape? What if I don't know any black electricians to get tape?
Re: (Score:2)
They make it in white, too.
(and even in green)
Re: Will the bill also ban black electrical tape? (Score:2)
I was thinking that hopefully this will trigger a wave of phones with a physical switch to disconnect the camera and mic. Iâ(TM)m 100% sure small dumb phones that are primarily aimed at being burner phones for drug dealers will do that, hopefully higher end ones will too - or the manufacturers will just pull out of the market.
New business idea (Score:3)
An app that stops this from happening. Charge 5 Euros for it and you'll see a flood of downloads from France.
Re:New business idea (Score:5, Funny)
Re:New business idea (Score:5, Funny)
Re: (Score:2)
Final stage capitalism - selling you the rope you hang yourself with...
Re: (Score:2)
Hush! You don't say the quiet part loud!
Re: New business idea (Score:2)
Apple likely wouldn't allow such an app. And ArchieBunker would completely agree with Apple, because walled gardens are the only way to be safe. If you want to be unsafe, you should buy an Android phone and root it.
Re: (Score:2)
Who, precisely, would tell Apple about the misfeature? Microsoft, who owns the vault with the corporate escrow keys for nearly all Trusted Computing signature authoriities?
Re: New business idea (Score:2)
There is no such vault. In fact Windows doesn't even expect there to be a certificate in the TPM at all, let alone one under some kind of PKI. Apple in particular directly issues signing certificates to developers, meaning there's only one certificate authority.
Re: (Score:2)
It's not a necessarily physical vault, but Microsoft keeps their TPM clients' keys in escrow. And Microsoft owns the signature authorities almost all TPM based software uses to authorize replacement or aggregation of other keys. It's not a really a privacy tool, it's a DRM tool, and Microsoft has deliberately and effectively retained the keys to the tower of permitted uses. It's very troubling if you don't trust Microsoft to keep such private keys secure from their own personnel or from abusive governments.
Re: New business idea (Score:2)
Re: (Score:2)
Re:New business idea (Score:4, Informative)
(You're probably joking but) for concerned users, the Librem 5 https://puri.sm/products/libre... [puri.sm] is a possible solution, it has physical kill switches for the microphone, camera and networking.
Re: (Score:2)
I have been ogling that for a while now, anyone used one in Europe before?
Re: (Score:2)
For the camera you can get one of those sliding webcam covers and stick it over it. A sticker over the microphone is pretty effective too, although less convenient if you ever need to use it.
Re: (Score:2)
Yeah, but those stickers are kinda ugly and awkward. I'd still prefer a phone that has my privacy built-in.
Protesting Tip (Score:5, Insightful)
Re: (Score:2)
Maybe so, but that tip will pretty much put an end to protesting by those under a certain age. So the government wins either way.
Re: Protesting Tip (Score:2)
OR, turn the damn thing off a long way away from the protests
Re: (Score:2)
A phone is useful to have at a protest (record happenings, coordinate with others, inform your family about your status, use the lights) so people will continue bringing them.
Re: (Score:2)
Re: (Score:2)
They're too useful for coordinating among the protesters, for calling emergency services, and for recording police abuse. There are many commercial Faraday cages available, easily tested., for carrying your phone safely.
Re: (Score:2)
(At the next anti-cell protest) "Uh, anybody here know how to do this, 'cause I was in charge of shitposting before..."
Re: (Score:2)
Re: (Score:3)
So many criminals are undone by their cellphone, it is quite comical really. "No Mr Policeman I was not in the vicinity of that crime at the time", "then how come your phone was their taking selfies of you in front of the criminal damage?"
That was actually my identical twin, Mr. Habeas Corpus. As for my phone, we have an arrangement, sir. I don't ask where my phone goes, and it doesn't ask where I go.
Re: Protesting Tip (Score:2)
Lol down modded by fascists who don't want French protestors to have useful information? Who knew macron had mod points?
A point of view (Score:3)
A point of view absent from TFS is that this is the modern equivalent of special police setting up microphones at suspects' houses, which has been available to the police for a very long time for serious crime with similar safeguards (approval by a judge).
Re: (Score:3)
Yes, but this doesn't require a case by case warrant. And anyway, just because it's been done in the past doesn't make it right. Warrantless surveillance is fascism.
Re:A point of view (Score:5, Informative)
I read in the approved document that it needs a case by case warrant, or you play on word on what a warrant is. Here the document: https://www.assemblee-national... [assemblee-nationale.fr] (click "Discussion ..."; then "Texte résultant ..."), see paragraph 85. It needs to be requested by the judge in charge of supervising the investigation (Procureur or Juge d'Instruction) and it needs to be validated by another judge specialized in supervising citizen freedom (Juge des libertés).
Re: (Score:3)
A point of view absent from TFS is that this is the modern equivalent of special police setting up microphones at suspects' houses, which has been available to the police for a very long time for serious crime with similar safeguards (approval by a judge).
If you want a more accurate analogy then the special police would have had to have ordered cameras pre-installed in every room in every house so they just had to turn them on. And then made the citizens pay for it to boot.
Scale, cost, and ease of execution matters. There are lots of things that we consider basic rights that have historically safeguarded not by law but by physics. It was simply impossible or financially ruinous for the government to be everywhere at once in past times. Now that we've invente
Re: (Score:2)
then the special police would have had to have ordered cameras pre-installed in every room
Your analogy would work if they asked Google/Apple/etc. to manually add a backdoor into every existing phone. They're not adding vulnerabilities, just plan to exploit existing ones. I think a better analogy is "police allowed to use lockpick and peek through entrance doors".
Re: (Score:2)
Not a better analogy because they could effectively spy on everyone at any time without being detected. With the advancement of AI how long before they are recording and filming everything through whatever means, back door or hack and using that footage you if you have been "bad".
The police should be reporting any vulnerabilities to google/apple/etc and getting them to fix it not using it to their advantage. It would be like the police noticing your lock was broken and instead of telling you, saying maybe I
Re: (Score:2)
They set up the phone taps at the switching offices, much as the NSA did with AT&T at the infamous room 641a where they tapped the fiber optic backbone of AT&T.
Re: (Score:2)
A point of view absent from TFS is that this is the modern equivalent of special police setting up microphones at suspects' houses
No it's not. This is the equivalent of the police using *your* microphone against you, and the technical facility to do so means the police have always had access to that microphone.
There's a world of difference between having to covertly setup something in someone's house, and having the legal authority to simply use something that person owns. This is unprecedented.
Good idea (Score:2)
Nobody trusts the French, especially not the French. You really have to watch these fuckers.
Doesn't this require cooperation from the makers? (Score:2)
It's not like the classic wire
I feel that the French leaders might pay attention (Score:3)
...to their history, which has created so many clever and humane devices, such as the guillotine. You can really see why the French get snarky with their leaders. You can't really see why they can't get good leaders but, Drumph and Bozo Johnson say that this is a universal problem.
Re: (Score:2)
Re: (Score:2)
I think the guillotine is more humane than those.
It is. It's also more humane than letting a bunch of fascists run the country, and subsequently run off with all the money.
send marshmallows (Score:2)
So when are they going to burn the fucking government to the ground?
Army? (Score:3)
Suspects (Score:5, Insightful)
I expect we will discover that there are lot of "suspects". When you get right down to it you can suspect everyone of having committed a major crime.
Re: (Score:2)
It only affects a few dozen per year, so naturally it makes perfect sense to put the whole country's privacy at risk. You know, for those few dozen cases.
Re: Suspects (Score:2)
Re: (Score:2)
To get it into your hands, they could simply call you. the cameria activation light is indeed optional. For some androids, look at these features:
https://www.youtube.com/watch?... [youtube.com]
Among the other popular apps on many phones, most users wouldn't even notice the burden on their batteries or their data charges.
Re: (Score:2)
"... the new provision would only affect a few dozen cases per year."
I expect that if anyone would actually like to know if or how it's being abused, it's quite easy.
Audit the living shit out of their usage claim, like you should.
Ah! Surely coming to the US *Real Soon Now* (Score:3)
Just be aware (Score:2)
How are they going to get Apple and Google to play (Score:2)
How modern left subverts freedom (Score:2)
Effectively outlaw protesting (Score:2)
Ripe for abuse (Score:2)
That which can be abused, will be abused.
Only news is they're admitting it (Score:2)
Closed source firmware (Score:2)
We really need to fight to pass laws banning the use of closed source firmware, like the GSM radio. All phones and PCs are infested with dark spyware devices and the sheeple just accept it.
Two words (Score:2)
Duct. Tape.
What if you do not have a phone (Score:2)
Re: (Score:2, Insightful)
"Act their nature?" Is that racist or what?
Re:That's all pretty great (Score:4, Insightful)
People aren't even pretending anymore.
Re: (Score:3, Insightful)
Given France's history, it's kind of bizarre for anyone to pretend that it's the black immigrants who burn things there.
Re: (Score:2)
Re:That's all pretty great (Score:4, Informative)
You really should pay attention to the news. France raised the retirement age from 62 to 64 and that did not go over well. Sanitation workers have been on strike for months.
Re: (Score:2)
You really should pay attention to the news. France raised the retirement age from 62 to 64 and that did not go over well. Sanitation workers have been on strike for months.
So the Paris Metro smells like urine again?
Re: (Score:2)
Jesus Christ dude