« More on the pending WHOIS hearing. | Main | DoJ announces Blaster Press Conference. »

Anonymization may be possible in Germany.

According to this press release, the JAP anonymizing proxy (think of it as anonymizer.com plus Chaumian mixes) is anonymizing again: The District Court in Frankfurt/Main decided yesterday that the enforcement of the judicial instruction by the Lower District Court in Frankfurt to the partners of the AN.ON project ... is to be suspended.

To help with an ongoing investigation, allegedly involving child porn, Germany's federal police agency had asked the lower court in Frankfurt for an order that would lift the anonymity of those accessing a specific web site. The court ordered the anonymization service to comply with law enforcement's demands.

A mechanism for tracking accesses to certain target IP addresses was implemented; technically, the last mix in a chain would detect the "criminal" target, and would then collaborate with earlier mixes to lift anonymity for this specific access. (Details here.) This scheme was implemented in late June, and was not announced for legal reasons. Since JAP is Open Source Software, the change was ultimately discovered, and then publicized widely. (See alt.2600 [via Max Dornseif's disLEXia], Heise [in German], The Register [some facts incorrect] for early publications.)

In addition to implementing the deanonymization scheme, the original court's decision was appealed: The decision had been based on rules in the code of criminal procedure which deal with turning over data that have been collected legally, in the past. Wiretaps (i.e., data recording orders) are dealt with elsewhere, and can only be used when prosecuting a specific list of crimes. Child porn is not on this list. (Details in this press release.)

The present decision suspends enforcement of the original court order. The appeal is still pending.

Even if the final decision is favorable for the anonymization service (which might seem likely), quite a few interesting questions will remain open: What, for instance, if the investigations had dealt with one of the crimes on the wiretap list? What if the anonymization software had been proprietary, without a possibility for those running the service to change the code?

Finally, what impact will the presence of the anonymizer's "crime detection" feature have on courts' decision, the next time that law enforcement asks for surveillance?

TrackBack

TrackBack URL for this entry:
http://log.does-not-exist.org/mt/mt-tb.cgi/526

Listed below are links to weblogs that reference Anonymization may be possible in Germany.:

» Law is code is law from Wendy: The Blog
The flip side to Prof. Lessig's famous observation that "code is law' is that law can be made code as well. Thomas Roessler brings us up to date on the JAP anonymizing proxy, which was forced by court order to compromise its users' anonymity to track v... [Read More]

» Anonymization: The battle continues. from No Such Weblog
The battle about the JAP anonymizing proxy continues: After a decision of the Lower District Court in Frankfurt to add surveillance features to the system had been suspended by the District court (details; code is law analysis), German federal police... [Read More]

» More on the anonymization battle. from No Such Weblog
Mailing list discussion about the search against the JAP anonymizing proxy is taking off on FITUG's debate mailing list; a quickly-updated unofficial archive is here.... [Read More]

» Anonymization Service wins in Court. from No Such Weblog
Heise News reports that the district court in Frankfurt/Main has found that there was no base in law for an earlier order from a lower court that had required the JAP anonymizing proxy to implement a "crime detection feature." This... [Read More]

About

This page contains a single entry from the blog posted on August 28, 2003 9:24 PM.

The previous post in this blog was More on the pending WHOIS hearing..

The next post in this blog is DoJ announces Blaster Press Conference..

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.35