Weekly Report: JPCERT/CCが「APT-C-60による2026年の攻撃」を公開

4 hours 22 minutes ago
JPCERT/CCは、「APT-C-60による2026年の攻撃」を公開しました。2026年に確認されたAPT-C-60の攻撃について、初期侵害方法、LNKファイルの挙動、攻撃インフラに使用された正規サービスを解説しています。また、確認した通信先やファイルハッシュなどのIoCをあわせて掲載しています。

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

6 hours 13 minutes ago

Legal intern Suzanne Castillo was the principal author of this post.

The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the National Association of Criminal Defense Lawyers (NACDL).

We argued that electronic device searches at the border should require a warrant based on probable cause, but at minimum, regardless of whether an officer searches by hand or with forensic software that plugs into a device and downloads its entire contents for search, the same Fourth Amendment standard should apply to all device searches at the border.

Unfortunately, the court rejected that argument and ruled that a lower standard applies to manual searches, allowing the government to conduct extraordinarily invasive electronic device searches without any suspicion of wrongdoing, simply because the border officer chooses to search by hand rather than with a forensic tool.

The Border Search Exception Meets Your Phone

The Fourth Amendment requires that government searches of persons or property be reasonable, which usually means obtaining a warrant based on probable cause from a judge.

But a warrantless search can still be reasonable if it falls within an exception to the warrant requirement, including the exception that allows officers to search your belongings at the border. The border search exception allows warrantless searches of persons or property crossing the U.S. border, including the functional equivalent of the border such as international airports, given the government’s interests in controlling who and what may enter the country.

Historically, courts have categorized border searches of luggage, vehicles, and personal effects as “routine” and thus reasonable even if conducted without any suspicion that the traveler has engaged in wrongdoing; courts have also held that more invasive “nonroutine” searches, such as certain body searches and searches that damage property, require reasonable suspicion.

But a person’s privacy interests in the personal data on a phone or laptop are extraordinarily different than their limited privacy interests in the contents of their suitcase.

The Supreme Court addressed cell phone privacy in Riley v. California (2014), holding that the search-incident-to-arrest exception to the warrant requirement did not apply to cell phones, thereby generally requiring a warrant for phone searches, at least at the interior of the country. The court recognized the unprecedented privacy interests people have in their cell phones and how even brief manual searches can reveal the “sum of an individual’s private life,” including our political affiliations, religious beliefs, sexuality, and more. Accordingly, the Supreme Court held that because electronic device searches bear “little resemblance” to searches of bags or physical containers, they should be evaluated differently.

Following Riley, the Fourth Circuit considered two border device search cases involving forensic searches, in which border officers used external software to extract and analyze a device’s data.

In U.S. v. Kolsuz (2018), the Fourth Circuit held that a forensic search of a cell phone at the border “must be considered a nonroutine border search, requiring some measure of individualized suspicion” of a transnational offense, but the court declined to decide whether the standard is only reasonable suspicion or instead a probable cause warrant.

Then in U.S. v. Aigbekaen (2019), the Fourth Circuit held that a forensic device search at the border in support of a purely domestic law enforcement investigation requires a warrant. The court also reiterated the general Kolsuz rule for a forensic border-related device search: the “Government must have individualized suspicion of an offense that bears some nexus to the border search exception's purposes of protecting national security, collecting duties, blocking the entry of unwanted persons, or disrupting efforts to export or import contraband.”

In Belmonte Cardozo, manual searches were finally before the court.

A Disappointing Decision

Jose Belmonte Cardozo was already on the U.S. government’s radar when he traveled from Bolivia to the U.S. and was met by a U.S. Customs and Border Protection (CBP) officer at Washington Dulles International Airport. The officer manually searched his cell phone and found child sexual abuse material (CSAM), considered “digital contraband,” leading to Belmonte Cardozo’s arrest and criminal prosecution.

At issue on appeal was what standard should apply to manual device searches at the border. The Fourth Circuit held that, unlike forensic searches, manual searches are “routine” and thus reasonable under the Fourth Amendment without a warrant or individualized suspicion.

The court’s holding hinged on four differences between manual and forensic searches: (1) in a manual search, a person does the searching, not a machine; (2) a manual search’s breadth depends on the officer’s time and energy, while forensic searches are comprehensive; (3) manual searches reveal only what a user can typically access, while forensic searches can uncover deleted files, cached fragments, metadata, and more; and (4) manual searches are subject to an officer’s fading memory or imperfect notes, while forensic searches create a permanent copy.

But in identifying these technical differences, the court never explains why they justify a lower standard for manual searches.

The Fourth Circuit’s holding is problematic because, as we argued in our amicus brief, manual searches reach the same categories of data as forensic searches—data that can reveal highly personal aspects of our identities and our lives. It does not matter if a search is conducted by an agent’s thumbs or by software: the end result is equally as invasive, therefore all device searches should fall under the warrant requirement, or at least the same Fourth Amendment standard.

The court repeatedly emphasized that the search here lasted only two minutes, suggesting that the time-limited search was not privacy-invasive. But an individual’s privacy interests in their personal data don’t change based on how their phone is searched or how long. Scrolling for two minutes through someone’s personal text messages or photos is an invasion of privacy that may reveal intimate details about the person even in that short period of time.

Moreover, as devices’ native search functions improve, manual searches can surface personal information in seconds through keyword searches, even for photos, where it might have taken an hour of scrolling to find the same information, further showing that a time-limited search is not necessarily less privacy-invasive. What matters is not the breadth of the search itself, but the unprecedented (and growing) breadth of data on our phones.

A Silver Lining

There’s one silver lining: by relying on the fact that the search lasted two minutes, the Fourth Circuit left open the possibility that lengthier manual searches could trigger heightened suspicion requirements. But until a clear line is drawn, border officers within the Fourth Circuit’s jurisdiction can use manual searches to sidestep heightened Fourth Amendment standards that would otherwise apply. In the meantime, EFF will keep fighting against extraordinarily invasive warrantless, suspicionless device earches at the border, and for robust privacy standards to protect our most personal data.

Sophia Cope

【JCJ オンライン講演会】米国で社会主義勢力が台頭 米政治の転換点になるのか ―― 11月の中間選挙で台風の目に、日本はどうすればいいか  講師:本田 浩邦さん (獨協大学経済学部教授)8月15日(土)午後2時から4時

12 hours 44 minutes ago
■講演タイトル:米国で社会主義勢力が台頭 米政治の転換点になるのか ―― 11月の中間選挙で台風の目に、日本はどうすればいいか■開催趣旨アメリカでは、この間、トランプ政権の移民排斥、ガザやイランに対する戦争政策に対する国民的な巻き返しが急速に広まっています。ニューヨーク、シアトル、ボストン、ミネアポリなど各地で社会主義を公然と標榜する草の根の政治運動団体「アメリカ民主社会主義者」(DSA)の候補が当選を果たし、自治体レベルの政治革新に取り組んでいます。また6月のニューヨークで..
JCJ

New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression

20 hours 10 minutes ago

Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate with others and participate in public debate, and foster innovation online. These laws generally shield platforms, to varying degrees, from legal liability for user content: the responsibility for unlawful speech should rest primarily with the speaker, not with those who merely host it.  

These liability protections are not a gift for platforms. They exist so that platforms are not encouraged to proactively monitor and filter what we say online, or to remove even lawful speech simply to avoid legal risk. 

This is why a recent judgment by the EU Court of Justice, Coyote System (Joined Cases C-188/24 and C-190/24), is concerning: it could deprive online platforms of liability protection because of how they organize and disseminate user content. The consequences for freedom of expression could be significant. 

Liability Protections in the EU 

The European Union has long embraced a system of limited liability for online service providers. Under the e-Commerce Directive and now the Digital Services Act (DSA), platforms benefit from liability exemptions for user content. To discourage censorship, they also cannot be required to generally monitor user content or actively search for illegal activity. But that liability protection comes with qualifications: Platforms lose this benefit if they play an "active role" such that they have knowledge of, or control over, user-provided information (Recital 42 ECD, Recital 18 DSA, and case law, for example para. 113 in L’Oréal v eBay). For hosting services, providers must remove or disable content they know to be illegal. The DSA has introduced extensive due diligence obligations for platforms but left these foundational immunities intact. The message is clear: platforms bear responsibility for proper systems and processes, but generally not for users' speech. 

Coyote System, however, could undermine this balance. Confronted with a case about restrictions on navigation systems that transmit information to drivers about roadside checks, the Court formulated a general test for when an intermediary ceases to be a "neutral" host and therefore loses the hosting liability exemption. In essence, the Court held that where an intermediary's algorithm goes beyond merely categorizing and indexing user information to determine, "under what conditions, how and in which order of priority" (para. 122) information is disseminated, the intermediary "controls" that information and is deprived of protection under the e-Commerce Directive. 

Let's be clear: the case is not about a service that ranked or recommended user-generated content in the way social media platforms do. It is about the collection and real-time relay of user alerts about roadside checks. However, the Court's reasoning is not confined to navigation services. Recommendation algorithms determine how and in what order user content is disseminated across virtually every major online platform. Should such platforms now cease to qualify as neutral intermediaries and lose the protection of the hosting liability exemption? The answer should be no. 

The Meaning of Control 

Control has never been understood this broadly. Nor should it be. Every hosting service provider, think of Facebook, Amazon or Bluesky, will have some control over users’ content. If that ability alone ruled the analysis, the liability exemption would become largely meaningless. Instead, the disqualifying “active role” must relate to the actual content itself, not merely the technical means by which that content is organised or disseminated. 

The Court’s own case law reinforces this conclusion: In YouTube and Cyando, it examined a platform that categorises, ranks and recommends user content through algorithms, yet still proceeded on the basis that it could generally benefit from the hosting liability exemption. To be sure, the Court was mainly addressing specific knowledge of illegal content rather than the separate category of control. Even so, the underlying premise is clear: those features do not, by themselves, place a platform outside of protection. Advocate General therefore explained that what matters is the providers "intellectual control of that content" (para 152). The relevant question is who controls the information itself, makes it their own, not who determines how it appears. 

That is precisely where Coyote System breaks new ground and offers a dangerous change of emphasis. By equating algorithmic organisation with content control, the ruling risks excluding social networks and other platforms from the liability exemption and encouraging proactive monitoring of what users say online and removal of lawful content. 

That outcome would have terrible consequences for freedom of expression in the EU. It’s also difficult to reconcile with the structure of the DSA, which certainly does not treat recommendation algorithms as incompatible with intermediary immunity. On the contrary, it accepts them as a defining feature of modern platforms, regulates them extensively through dedicated due diligence obligations, and still leaves the hosting liability regime untouched (it even integrated the YouTube ruling in its preamble!).  

This was no accident: During the DSA negotiations, proposals to deprive platforms of the hosting liability exemption if they optimize, classify, organize or otherwise promote online content were rejected, following successful advocacy by EFF and allies. Would the Court have decided this case differently under the DSA? Probably not. It’s more plausible that the EU judges were influenced by the specific nature of the service, which could explain why the judgment says remarkably, and sadly, little about why intermediary liability exists in the first place and the fundamental rights it serves. Coyote System did not merely transmit user reports but aggregated them into what the Advocate General described as a new "information layer," a distinction omitted by the Court. 

Chipping Away at Intermediary Liability Protections 

The danger is that the Court's broad language on algorithmic curation reaches well beyond that narrow category and, unintentionally or not, chips away at one of the most important safeguards for freedom of expression online.  

Unfortunately, Coyote System does not stand alone. It is the latest in a line of judgments that have gradually narrowed intermediary liability protections. Recently, in Russmedia, the Court privileged preventive content control in the name of data protection, paying little regard to the possibility of reconciling both regimes and the privacy costs of increased monitoring of user content. And in AGCOM, concerning Google's liability for YouTube videos uploaded by creators participating in its Partner Programme, the Court appears to leap from eligibility reviews to specific knowledge of illegal content. 

There is a political risk too. While the top court’s reasoning will be applied by national courts and further refined over time, the European Commission has shown little hesitation in incorporating landmark rulings into legislation. Just recently, in its digital omnibus proposal, it selectively restated part of a recent Court of Justice judgment to justify narrowing privacy rights of users. 

If these trends continue, freedom of expression online will become collateral damage in the EU. 

Christoph Schmon

[B] ウィシュマさん国賠訴訟が結審 遺族、入管の責任問う判決求める

22 hours 42 minutes ago
提訴から4年4カ月。名古屋入管に収容中に亡くなったスリランカ人女性、ウィシュマ・サンダマリさんの遺族が国に損害賠償を求めた裁判が7月22日、名古屋地裁で結審した。判決は12月11日に言い渡される。この日、満席となった法廷で、妹のポールニマさんは、著しく衰弱した姉が「病院に持って行って」「点滴お願い」と訴えていた収容中の映像に触れ、涙で言葉を詰まらせながら、国と入管の責任を明らかにする判決を求めた。スリランカにいる母スリヤラタさんと妹ワヨミさんのメッセージも代理人によって読み上げられ、結審の日に遺族3人の訴えが裁判所に届けられた。(岩中健介)
日刊ベリタ