Roll up, roll up for THE WORST IDEA EVER
Wow. Just, wow.
Heard about this earlier on today courtesy of Alex E - and I still can't quite get my head around it:
"The FBI has recently adopted a novel investigative technique: posting hyperlinks that purport to be illegal videos of minors having sex, and then raiding the homes of anyone willing to click on them"
Shall we play a game of "Let's think of how many ways this can be abused"? Not only did they NOT apparently check the referrer address (ie the site you left to visit the trap links, which means you could have ended up there from unrelated EMail spam that harvested the addresses OR you could have arrived via a fake WIN FREE IPODS, YAY message from a practical joker), they also seem to make no allowance for the fact that random idiots could have been using an unsecured wireless connection to visit the URLs either.
Worse still, ass Bruce Ediger said on the Funsec mailing list:
"Also, how do they account for programmatic access? Googlebot, msnbot "Yahoo! Slurp", and a few other apparent bots scan my web server all the time. For giggles, I put a "robots.txt" file forbidding access to a couple of enticingly
named directories ("porn", "payroll", stuff like that) that didn't actually
exist in the htdocs/ directory. At least one person or bot has tried to access
those directories. I have to conclude that a mis-guided recursive "wget" of
the wrong IP address might get my door kicked in and all my computers
confiscated."
The final nail in the coffin is that the "expert opinion" guy makes it sound like the people caught by this did more than simply click one hyperlink to seal their doom:
"The individuals who chose to log into the FBI sites appear to have had no pressure put upon them by the government"
"Log into the sites"?? wow. Where did he get that one from? How did clicking a random link turn into an epic quest to log into child pornography websites?
All in all, worst idea ever (Thanks Ferg)

