R.S. van Wegberg
Please Note
25 records found
1
APT to Disagree
A Comparative Analysis of Attribution in Commercial TI
“Tell Them They Are a Responsible Entity, Not a Customer”
Understanding Practitioner Challenges in Sector CSIRTs
Money for Nothing, Supervision for a Fee
Investigating the Effects of the 5th Anti-Money Laundering Directive on Cryptocurrency Exchanges in the Netherlands
By converting between currencies, cryptocurrency exchanges provide access between the traditional and cryptocurrency ecosystem, making them susceptible to money laundering. The European Union extended the scope of the 5 Anti-Money Laundering Directive (AMLD5) to include cryptocurrency exchanges, requiring them to obtain a registration, conduct customer due diligence, and report unusual transactions. It is, however, unknown whether the measures introduced by the implementation of AMLD5 lead to less risk exposure and what impact it has on cryptocurrency exchanges. This paper uses a mixed-methods approach to explore the effects of the Dutch implementation of AMLD5 measures on cryptocurrency exchanges active in the Netherlands. We analyzed over 335,000 transactions and complemented them with seven qualitative interviews with Dutch cryptocurrency exchanges and the supervisory authority. We find that the Dutch implementation of AMLD5 imposed high administrative burdens and substantial fees on relatively small exchanges that do not pose high money laundering risks. This raises questions about the alignment of the goals and consequences of the regulation.
Understanding public acceptance of data collection by intelligence services in the Netherlands
A factorial survey experiment
Intelligence services must balance values such as national security and privacy when collecting data, with each scenario involving specific contextual trade-offs. While citizens benefit from effective intelligence operations, they also risk having their rights infringed upon. This makes citizen perspectives on acceptable data collection for intelligence and national security salient, as their legitimacy is also contingent upon public support. Yet, important aspects of citizen perspectives are understudied, such as the influence of contextual factors related to the use of intelligence collection methods. This study, inspired by Nissenbaum's contextual integrity framework, uses a factorial survey experiment with vignettes among a representative sample of 1423 Dutch citizens to examine the influence of threat type, duration, data subject, collection method, data type, and data retention on public acceptance of surveillance. Additionally, the study considers the impact of respondents' trust and privacy attitudes. The findings reveal significant influence of both contextual variables – particularly threat type, data subject, and data retention – and respondent predispositions – particularly trust in institutions, trust in intelligence services' competence, and privacy concerns for others. The findings imply that more in-depth contextual knowledge among the public may foster support for intelligence activities.
The term 'deepfake' refers to artificial or 'fake' content on the internet made using 'deep learning' or 'machine learning' algorithms. This technology was immediately (ab)used to fabricate non-consensual sexual deepfakes involving celebrities and later on not-famous people. In light of the technological advancements and frequent incidents with sexual deepfakes, we assume they are here to stay. As a result, many states confronted with this issue consider the implementation of legislation criminalising sexual deepfakes.In our paper, the authors aim to provide an answer to the question 'How do sexual deepfakes proliferate online, to what extent is the non-consensual production, distribution, possession of, and/or access to sexual deepfakes of adults currently criminalised, and to what extent should it be criminalised in the future?' with a combined empirical and legal approach. To that end, they have conducted an explorative analysis of the online market for sexual deepfakes. The empirical research was focused on Telegram groups, in particular Dutch-language groups, and combined with a legal analysis of the legal frameworks on sexual deepfakes in Belgium and the Netherlands. The research shows that sexual deepfakes proliferate on the clear web and public Telegram groups. Subsequently, the authors have examined to what extent the non-consensual production, distribution, possession of, and/or access to sexual deepfakes are already criminalised and to what extent they should be criminalised. From the legal analysis they conclude that - if there is any positive obligation to criminalise sexual deepfakes of adults at all - it is limited to the production and subsequent distribution of sexual deepfakes of existing people.
The Unpatchables
Why Municipalities Persist in Running Vulnerable Hosts
All detections were accurate. Our approach also uncovers a major misalignment between systems that the responsible CERT attributes to the municipalities and the systems the practitioners at municipalities believe they are responsible for. We then interviewed the professionals as to why these vulnerable systems were still exposed. We identify four explanations for non-patching: unaware, unable, retired and shut down. The institutional framework to mitigate cyber threats assumes that vulnerable systems are first correctly identified, then correctly attributed and notified, and finally correctly mitigated. Our findings illustrate that the first assumption is correct, the second one is not and the third one is more complicated in practice. We end with reflections on how to better remediate vulnerable hosts. ...
All detections were accurate. Our approach also uncovers a major misalignment between systems that the responsible CERT attributes to the municipalities and the systems the practitioners at municipalities believe they are responsible for. We then interviewed the professionals as to why these vulnerable systems were still exposed. We identify four explanations for non-patching: unaware, unable, retired and shut down. The institutional framework to mitigate cyber threats assumes that vulnerable systems are first correctly identified, then correctly attributed and notified, and finally correctly mitigated. Our findings illustrate that the first assumption is correct, the second one is not and the third one is more complicated in practice. We end with reflections on how to better remediate vulnerable hosts.
Law enforcement agencies struggle with criminals using end-to-end encryption (E2EE). A recent policy paper states: “while encryption is vital and privacy and cyber security must be protected, that should not come at the expense of wholly precluding law enforcement”. The main argument is that E2EE hampers attribution and prosecution of criminals who rely on encrypted communication - ranging from drug syndicates to child sexual abuse material (CSAM) platforms. This statement - in policy circles dubbed ‘going dark’ - is not yet supported by empirical evidence. That is why, in our work, we analyse public court data from the Netherlands to show to what extent law enforcement agencies and the public prosecution service are impacted by the use of E2EE in bringing cases to court and their outcome. Our results show that in cases brought to court, the Dutch courts appear to be as successful in convicting offenders who rely on E2EE as those who do not. Our data do not permit us to draw conclusions on the effect of E2EE on criminal investigations.
Investigating sentence severity with judicial open data
A case study on sentencing high-tech crime in the Dutch criminal justice system
Open data promotes transparency and accountability as everyone can analyse it. Law enforcement and the judiciary are increasingly making data available, to increase trust and confidence in the criminal justice system. Due to privacy legislation, judicial open data — like court judgements — in Europe is usually anonymized. And even if the court judgement has been made public, the rest of the case file is usually not published. Therefore, the question arises to what extent criminological research into sentencing can make use of anonymized open data. We answer this question based on a case study in which we use the open data of the Dutch criminal justice system that is available on https://www.rechtspraak.nl/Uitspraken. Over the period 2015–2020, we analysed sentencing in 25,366 court judgements and investigated the relationship between sentence severity and the offender’s use of advanced Information and Communication Technology (ICT). The most important results are, firstly, that offenders who use advanced ICT are sentenced to longer custodial sentences compared to other offenders. Secondly, sentencing research with open data is found to be feasible.
We create ‘vendor types’ based on latent profile analysis, clustering vendors that are similar regarding their experience, activity on other markets, and the amount of physical and dig- ital items sold. We then analyze how these types of vendors differ in their security practices. To that end, we capture their password strength and password uniqueness, 2FA usage, PGP adoption and key strength, PGP-key reuse and the traceability of their cash-out. We find that insecure practices are prevalent across all types of vendors. Yet, between them large differ- ences exist. Rather counter-intuitively, Hansa Market vendors that sell digital items – like stolen credit cards or malware – resort to insecure practices more often than vendors selling drugs. We discuss possible explanations, including that ven- dors of illicit digital items may perceive their risk to be lower than vendors of illicit physical items. ...
We create ‘vendor types’ based on latent profile analysis, clustering vendors that are similar regarding their experience, activity on other markets, and the amount of physical and dig- ital items sold. We then analyze how these types of vendors differ in their security practices. To that end, we capture their password strength and password uniqueness, 2FA usage, PGP adoption and key strength, PGP-key reuse and the traceability of their cash-out. We find that insecure practices are prevalent across all types of vendors. Yet, between them large differ- ences exist. Rather counter-intuitively, Hansa Market vendors that sell digital items – like stolen credit cards or malware – resort to insecure practices more often than vendors selling drugs. We discuss possible explanations, including that ven- dors of illicit digital items may perceive their risk to be lower than vendors of illicit physical items.
...
To answer this question, we analyze scraped data on the business-to-business cybercrime segments of AlphaBay (2015-2017), consist- ing of 7,543 listings from 1,339 vendors, sold at least 126,934 times. We construct new variables to capture product differentiators and price. We capture the influence of vendor characteristics by identifying five distinct vendor profiles based on latent profile analysis of six properties. We leverage these product and vendor characteristics to empirically predict the performance of cybercrime products, whilst controlling for the lifespan and type of solution. Consistent with earlier insights into carding forums, we identify prevalent product differentiators to be influencing the relative success of a product. While all these product differentiators do correlate significantly with product performance, their explanatory power is lower than that of vendor profiles. When outsourcing, the vendor seems to be of more importance to the buyers than product differentiators. ...
To answer this question, we analyze scraped data on the business-to-business cybercrime segments of AlphaBay (2015-2017), consist- ing of 7,543 listings from 1,339 vendors, sold at least 126,934 times. We construct new variables to capture product differentiators and price. We capture the influence of vendor characteristics by identifying five distinct vendor profiles based on latent profile analysis of six properties. We leverage these product and vendor characteristics to empirically predict the performance of cybercrime products, whilst controlling for the lifespan and type of solution. Consistent with earlier insights into carding forums, we identify prevalent product differentiators to be influencing the relative success of a product. While all these product differentiators do correlate significantly with product performance, their explanatory power is lower than that of vendor profiles. When outsourcing, the vendor seems to be of more importance to the buyers than product differentiators.