TorrentFreak

The place where breaking news, BitTorrent and copyright collide

French 3 Strikes Suspended Due To Anti-Piracy Security Alert

Following a weekend security breach at Trident Media Guard, the outfit spearheading data collection for France’s 3 strikes anti-piracy drive, the country’s HADOPI agency has severed interconnection with the company. This means that, pending an enquiry, French file-sharers are no longer being tracked, a major embarrassment for the government.

tmgOn Saturday evening, with the invaluable assistance of blogger and security researcher Olivier Laurelli, aka Bluetouff, TorrentFreak first reported that Trident Media Guard (TMG), the private company entrusted to carry out file-sharing network monitoring for the French government, had been hacked.

As became evident, the term ‘hacked’ was probably overly generous to TMG, since according to Bluetouff the company had left the equivalent of its front door open.

“A virtual machine leaked a lot of information like scripts, p2p clients to generate fake peers, local physical addresses in the datacenter and even a password that could lead to a major global TMG security breach,” he explained.

TorrentFreak obtained and listed some of the files in question in our earlier report, but as the contents of the leak were examined in more detail, it became evident that TMG had not only leaked out its own data, but that belonging to the subjects of their monitoring.

The day after our report, Guillaume Champeau of Numerama, a publication which follows French file-sharing issues in-depth, contacted TorrentFreak to say he had been able to show that IP addresses linked to the 3-strikes process may also have been leaked. He informed the HADOPI agency of his find which led to them to report that they were taking the matter “very seriously”.

Indeed, that concern has been followed by an announcement from Eric Walter, the secretary-general of HADOPI. Walter, a friend of French President Nicolas Sarkozy, who now confirms that “as a precaution Hadopi has decided to temporarily suspend its interconnection with TMG.”

What this effectively means is that since TMG is the only company licensed to do this work for the government, from now on and pending a review, the French 3 strikes regime for dealing with illicit file-sharing is suspended. Data gathered before Saturday evening, however, can still be used.

This suspension will be seen by some as a major embarrassment for President Sarkozy. France has taken a particularly hard-line approach to unlawful file-sharing and the government has continually brushed aside calls from the public and various watchdogs to consider more carefully the privacy and related rights issues connected with such a regime.

Update: According to French news sources the three strikes regime is set to continue, but data will not be transferred to Hadopi via the usual electronic transfers, but on physical media.

Related Posts

Previous Post | Next Post

  • http://pulse.yahoo.com/_IZ5BM5GNLA54OADSWGSXAMA7SY Jay

     How about just saying “I told you so?”  

    That’s all we need to do Sarkozy.

    • Lurker

      -France uses 3 strikes.
      It’s not very effective.
      -Frances uses Trident Media Guard
      It’s not very effective.-Internet uses Battering Ram.
      IT’S SUPER EFFECTIVE! 

      • Ash Ketchum

        Well you know the motto for the French anti-P2P folks is “Gotta catch’em all.”

        • Ninja

          I have an incredibly funny image of Sarkozy using Ash’s clothes holding a pokeball in his hand. Pure win! 

        • Ninja

          That’s in my mind btw… I’d share if I could lmao 

        • Momo
        • Ninja

          And now Ms Bruni is pregnant. Although the kid might not be as ugly as Sarkozy it fills me with despair when I think there’s a little Sarkozy Junior in development. The world is bad enough with just one lol

    • Lurker

      -France uses 3 strikes.
      It’s not very effective.
      -Frances uses Trident Media Guard
      It’s not very effective.-Internet uses Battering Ram.
      IT’S SUPER EFFECTIVE! 

    • hotdog

      Oh the jokes i could come up with right now. lol I would send them a picture of facepalm to their mailbox.

    • puddi puddi

      First crossly, now another down.  I hope this hacking trend picks up some more steam soon…

      The people have finally got back their say in their own government back again, I hope we get that over here in the US too :)

        Our voiced opinions and voting systems don’t mean shit, but we can still hack what we want.

      • Anonymous

        The best thing about these data breaches is that they can often prove they are arrogant, doing things wrong and to expose questionable acts. After what happened to Andrew Crossley then TMG & HADOPI are right to be very concerned.

        I should also add, from what I hear, that Mr Crossley is due before the Solicitors Regulation Authority next month. An event that poor Andy is dreading and once desired to make go away with a behind the scenes deal. The SRA have got much ammo on him from over 500 complaints directly to them and the judge strongly criticised his behaviour and branded ACS:Law a “copyright exploitation organization”

        We can only hope they make an example of him. Getting involved in a get rich quick scheme and upsetting many innocent people is hardly a solicitor serving the interests of the court and the justice system.

        • Him

          if they make as big an example and give him as much of a punishment as they did over the data breach, it will be a complete waste of time! the old school tye brigade will always win!

      • Anonymous

        The best thing about these data breaches is that they can often prove they are arrogant, doing things wrong and to expose questionable acts. After what happened to Andrew Crossley then TMG & HADOPI are right to be very concerned.

        I should also add, from what I hear, that Mr Crossley is due before the Solicitors Regulation Authority next month. An event that poor Andy is dreading and once desired to make go away with a behind the scenes deal. The SRA have got much ammo on him from over 500 complaints directly to them and the judge strongly criticised his behaviour and branded ACS:Law a “copyright exploitation organization”

        We can only hope they make an example of him. Getting involved in a get rich quick scheme and upsetting many innocent people is hardly a solicitor serving the interests of the court and the justice system.

  • FightingN

    AH SO THESE PEOPLE ARE CAUSING TROUBLE :-P

  • Flying Dutchman

    The Internet sees censorship as damage and routes around it, but when times are dire, it will stand and fight. Eventually, the evil Censorship demon and it’s minions will be driven out of Cyberspace by a huge F*cking lazor with the power equal to the Internet itself!

    • http://www.facebook.com/PCR.Tech.SC Tim Holmes

      That couldn’t have been said any better, and I agree with you.

  • Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sabado — Bitelia

  • Anonymous

    Next time, elect a leader that isn’t a whipped husband. Then you won’t get arbitrary laws that benefit his wife’s company.

  • Pingback: French 3 Strikes Suspended Due To Anti-Piracy Security Alert | Torrentfreak.com

  • Arb

    aint payback a bitch

  • Momo

     I don’t know much about French politics, but now that Strauss-Kahn has been knocked out of the race, does that mean you’ll get another five years of Monsieur et Madame Sarkozy?

    • Ugly American

      Like it would make a dick’s worth of difference – Sarkozy-Kahn, Socialist-Con, Mickey Mouse or a head of lettuce, the French are usually wrong. They’ve been pissing on their own culture for the last few hundred years – stupid fvcks.

  • history repeating…

    Was there any real doubt that the French govt would fail at this?

    The French as a people are great, but their govt stumbles from fail to fail throughout history.

    • Ugly American

      EXACTLY! Like most Americans, the French believe nearly everything they see on TV – anything some politician says = 100% true.

  • John Space

    The greedy give three strikes, the INternet delivers a big blow. 

  • Nils

    I like how almost no one has relayed this information in France.

  • http://www.facebook.com/people/Don-Dilly/1624894683 Don Dilly

    They should get used to it as the french gov’s snooping attempts will show them up as asses everytime.

    Ultimately (hopefully) it will get increasingly difficult to find a company willing to do the work as doing so turned them in to public enemy No1.

    Though said in a different more extreme context, I keep thinking back to a quote from an IRA spokeman after the bombing of the Grand Hotel Brighton an assassination attempt on Maggie Thatcher.

    ‘remember we only have to be lucky once. You will have to be lucky always’

    It is a quote applicable to any company willing to undertake snooping or blackops on behalf of governments or their corporate paymasters.  just ask HBgary.

  • Observer

    Sarkozy must be partying hard now that his opponent is behind bars in New York thus increasing his odds of being reelected. Now give french filesharers a break Sarkozy!

  • Pegart

     This just came to me.

    As they suggest that the IPs are unique to each person as they were an internet name of sorts, that means that when they generate fake IPs, they make fake IDs of sorts, which if I’m not mistaken is illegal!

    • Guest101

       Brilliant, fantastic, you are one of your kind.
      Now lets start a class action because the government is creating unwanted new citizens!

    • Guest101

       Brilliant, fantastic, you are one of your kind.
      Now lets start a class action because the government is creating unwanted new citizens!

    • Plop

      The most pertinent issue is that anyone should now be able to use TMG’s customised peers to generate fake uploader IPs which is yet another nail in the coffin/should cast sufficient doubt over the validity of any legal system trying to push the spurious notion that an IP can be linked to a specific person. that an IP can be linked to a specific person.

      • puddi puddi

         so question now is… someone please link to the software?

      • Ninja

        Which leads us to the obvious conclusion that they will be completely pwned by the more tech aware guys (if they ever catch those).

        HADOPI has been giving ammunition to counter suing since it was born lmao. 

  • Yowzers

     Don’t the French love a good revolt? Now would be a good as time as any.

  • Anonymous

    I am only happy to hear that our French friends can currently file-share without risk of being molested. I am sure data rates in France will peak on the good news.

    I expect that there is much more to this story than what is already stated but HADOPI being suspended goes to show how serious this is. I trust our more skilled readers have been busy to ensure that TMG do not resume operation.

    HADOPI is not dead yet but in this War all battles count. No retreat, no surrender

  • Anonymous

    I am only happy to hear that our French friends can currently file-share without risk of being molested. I am sure data rates in France will peak on the good news.

    I expect that there is much more to this story than what is already stated but HADOPI being suspended goes to show how serious this is. I trust our more skilled readers have been busy to ensure that TMG do not resume operation.

    HADOPI is not dead yet but in this War all battles count. No retreat, no surrender

  • Anonymous

    LOL

  • Anonymous

    LOL

  • bada-bada

    Those guys are not to quick fixing their security either. When the first article about the breach came out, their vm was still available online.

  • bada-bada

    Those guys are not to quick fixing their security either. When the first article about the breach came out, their vm was still available online.

  • kabuki

    Are you talking about this virtual mashine? http://91.189.105.145/

  • kabuki

    Are you talking about this virtual mashine? http://91.189.105.145/

  • haha

     http://thepiratebay.org/torrent/6398159/Trident_media_guard_leaks

  • Whatever

    That a security researcher ( =someone that doesn’t take pro-active steps against the MAFIAA) discovered it at that time doesn’t mean that it was safe, wasn’t “hacked” or that nobody tampered with the data before.

    Now we only have to wait for a torrent with server data that pre dates the discovery by a few months to sink TMG into the deepest ocean and all previous collected data to be invalidated.

    Then all French internet users will then have their execution delayed for a long time.

    (What might really destroy that company would be proof of months of tampering with the IP data.  Even creating a rumour claiming that it happend might go a long way)

  • Whatever

    That a security researcher ( =someone that doesn’t take pro-active steps against the MAFIAA) discovered it at that time doesn’t mean that it was safe, wasn’t “hacked” or that nobody tampered with the data before.

    Now we only have to wait for a torrent with server data that pre dates the discovery by a few months to sink TMG into the deepest ocean and all previous collected data to be invalidated.

    Then all French internet users will then have their execution delayed for a long time.

    (What might really destroy that company would be proof of months of tampering with the IP data.  Even creating a rumour claiming that it happend might go a long way)

  • Acce

    Les trois prises c’est un système stupide. Tous les français moindrement un peu aux aguets savent comment ne pas se faire prendre. Entre temps, avec une administration comme celle de Sarko, on peut s’attendre a plus de conneries de ce genre. J’avais une seedbox sur un serveur OVH en France et je ne me suis jamais fait prendre. De toute façon, même avec DSK ou Le Pen, ce genre de politique aurait probablement été implantés…

  • Acce

    Les trois prises c’est un système stupide. Tous les français moindrement un peu aux aguets savent comment ne pas se faire prendre. Entre temps, avec une administration comme celle de Sarko, on peut s’attendre a plus de conneries de ce genre. J’avais une seedbox sur un serveur OVH en France et je ne me suis jamais fait prendre. De toute façon, même avec DSK ou Le Pen, ce genre de politique aurait probablement été implantés…

  • Grumpygit

    I got a ? about “p2p clients used to generate fake peers”

    Are the fake peers generated by TMG non-french IPs or do they just simply filter out their fake IPs after collection?

    What’s to stop another AP company NOT WORKING FOR THE FRENCH GOVERNMENT connecting to the tracker and collecting IPs including the “fake peers” then accusing innocent non-french people of copyright infringement?

    or

    What’s to stop me connecting to a tracker with a modified client, generating fake french peers and then TMG collecting them….not knowing their fake

    Surely this makes a mockery of IP collections?

    • maybe

      I’m sure i remember reading somewhere that the Pirate Bay was adding fake IPs to their trackers for similar reasons.

      • Grumpygit

         yes that’s true. But i would consider it a bit different when the companies collecting IPs for legal/civil action are also generating fake peers

    • Whatever

      As long as they don’t actually download data (and succeed) from you, your last sentence is completely correct.

      But
      like ants using fungus to create antibiotics against bacteria who then
      adapt there are a lot of counter measure that can be taken on both
      sides in an evolving  war.

      But usually it turns out the MAFIAA side is more sophisticated in fabricating evidence than getting real evidence and just rely on published IP addresses.

    • Anonymous

      All good points, but the companies involved generally initiate connections with the peers/IP addresses to confirm that they are live, and they send a BT-protocol message containing the info-hash to verify that they are active on that particular torrent.

  • http://laurelrusswurm.wordpress.com/ laurelrusswurm

    What this article describes as ‘hacking’ would be better termed ‘cracking.’

    • Whatever

      Please, don’t start that discussion.

      It is bad enough that this ALWAYS happens at tweakers.net (Dutch) when the article has anything todo with script kiddies, crackers, hackers, black/white/any color hats.

    • Anonymous

      It was more of a drive-by or opportunist theft. The door was wide open and unprotected. No 1337-skillz required.

  • Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sábado (ING)

  • Rftcrusher

    I hope this cyber war continues against governments and Corporations that go after its own citizens, that punish down-loaders worst then CEO’s that stole billions from its own people through bailouts and tax breaks, incentives, criminal fines as a business writeoff. Who ever hacked into this company, you have my deepest thank you. Hope you publish any smut and emails you find. Thanks again.

    • http://www.facebook.com/jordan.kratz Jordan Kratz

      my thanks as well

  • Anonymous

    Whoops, gotta wonder about that sometimes.
    http://www.total-anon.us.tc

  • Gov Official

    Would it not be possible to find out the IP addresses of all the gov officials who voted for this silly law and add them to TMG’s list and then get these guys cut off from the internet?

  • Anonymous forever.

    We all hope here in France that Sarkozy won’t be reelected. It is sad that the DSK affair happened, but it’s good that it happened at this time and not during the election campaign.

    As for Sarkozy Re election, people are fed up with his crap and his propaganda. All the actual survey show him way behind the possible Socialist candidates ( all of them, except one xD ) and, behind the threatening Front National, which would be a lot worse than Sarkozy if Marine le Pen is elected. So now all we can hope is ” wait and see ” but there is a general trend of ” All but Sarkozy ” running amongst the population.

    Hope that this trend will make it till the election.

    As for Hadopi… It’s been revealed that TMG did not hold up much of the garantees it should have and it’s never been controled since it’s working for Hadopi. Our administrative CNIL ( a juridiction concerning personal data over the internet and such ) gave them the right to work for Hadopi, but there is the risk that this right can be revoked for TMG, and if that’s the case, Hadopi Three Strikes machine will be shut down for month, if not forever.

    • Whatever

      “We ALL hope here in France that Sarkozy won’t be reelected.”

      Unless the votes are rigged, it shouldn’t be a problem then…
      Sarkozy… 0 Opposition… ALL

      Win

    • Whatever

      “We ALL hope here in France that Sarkozy won’t be reelected.”

      Unless the votes are rigged, it shouldn’t be a problem then…
      Sarkozy… 0 Opposition… ALL

      Win

  • http://profiles.google.com/skybon ????? ???????

    Rob the vans with CDs lol

  • Pingback: HADOPI stops monitoring for copyright infringement due to breach – SecurityShee.com

  • BTGuard - BitTorrent Anonymously

NewsBits

Even more news...

  • Blu-ray Anti-Piracy Tech Stops Discs and Promotes Purchases

    An anti-piracy system present in all official Blu-ray players since 2012 has received a fresh update...

  • Foxtel Breeds Pirates by Locking Up Game of Thrones

    One of the main reasons why people turn to piracy is the lack of legal alternatives....

  • UK Student Admits Breaching Sony Copyrights With Leak of PS3 SDK

    Last year an Internet user known as El Nomeo leaked version 3.70 of Sony’s Playstation3 SDK...

  • Pirates Can Be Identified Despite Sharing IP Addresses, ISP Claims

    Carrier-Grade Network Address Translation is a network mechanism through which many Internet subscribers can share the...

  • Feds Seize Cash from Major Bitcoin Exchange’s Dwolla Account

    The U.S. Government has taken a significant action against the web’s top Bitcoin exchange by seizing...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

PopularArticles

A selection of some TorrentFreak's classics dug up from our archives.