Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

German officials admit to deploying intercept software

Several German state governments have admitted using the Quellen-TKÜ software to intercept encrypted voice communications

Officials in a number of German state governments have owned up to using the Quellen-TKÜ Trojan Horse software in criminal investigations to intercept encrypted telecommunications on PCs. At least one state said it has suspended use of the software, after the Chaos Computer Club discovered that it could be controlled by anyone, not just law enforcement officers.

Bavarian Interior Minister Joachim Herrmann said on Monday that interception of encrypted telecommunications using Quellen-TKÜ is a legally authorized law enforcement measure in the fight against serious crime. Bavaria has always operated within the rules up to now, and all such intercepts have been preceded by a court order, as required by law, he said, according to a statement from the Bavarian Interior Ministry.

The legal restrictions on the use of such intercept software on PCs were set out in a 2008 ruling by Germany's Federal Constitutional Court, and require among other things that the software used be capable only of recording voice calls, much as a traditional wiretap would, and not be capable of eavesdropping at other times, or of capturing other data from the PC, such as screenshots or files.

Despite his reassurances about the legality of the Quellen-TKÜ, Herrmann said he had asked the Bavarian State Commissioner for Data Protection to carefully check that the appropriate technical measures were implemented with regard to the Quellen-TKÜ software, and that the state had complied with legal requirements. The ministry's specialists will conduct an intensive investigation into the matter, he said. Herrmann was due to hold a news conference in Munich at 4 p.m. on Tuesday to discuss the matter.

Doubts about the legality of the software were raised over the weekend by the Berlin-based Chaos Computer Club (CCC), which discovered that the software could accept instructions to download and activate new surveillance functions. CCC also discovered that those instructions were not authenticated: the software it tested will accept them from anyone, not just law enforcement officers.

After Bavaria's admission, the Ministry of the Interior for the German state of Baden-Württemberg said later Monday that it had used the same software as Bavaria to intercept calls in "individual cases."

Its use of Quellen-TKÜ was within the law, but nevertheless, Baden-Württemberg Interior Minister Reinhold Gall has temporarily suspended the state's use of the software as a precaution, pending a fuller investigation, the ministry said.

The German state of Hessen has also used Quellen-TKÜ, but only within the limits prescribed by the Federal Constitutional Court, Hessen Interior Minister Boris Rhein said Monday. Police in Hessen have so far used only legally compliant software versions that have been programmed under court order, he said.

However, he said he would seek clarification from the German Federal Interior Minister and discuss the matter with interior ministers from other German states.

Two other states, Brandenburg and Lower Saxony, have also admitted using software to intercept encrypted voice communications on suspects' PCs, according to local media reports.

Brandenburg police used the same Quellen-TKÜ software as that used in Bavaria, according to the Berliner Morgenpost, but the software used in Lower Saxony is different, the chief of the state police authority, Uwe Kolmey told North German radio station NDR on Monday.

German Federal Justice Minister Sabine Leutheusser-Schnarrenberger said that a "comprehensive and complete investigation" of the use of the software was now necessary to maintain German citizens' confidence in the rule of law.

The Federal Interior Ministry is now conducting inquiries to find out whether the monitoring software has been used by police authorities across Germany, but that ministry is not responsible for intelligence agencies such as the Federal Intelligence Service, Leutheusser-Schnarrenberger said in an interview with the Passauer Neue Presse, a transcript of which was published in German on the Justice Ministry's website on Tuesday.

Peter Sayer covers open source software, European intellectual property legislation and general technology breaking news for IDG News Service. Send comments and news tips to Peter at peter_sayer@idg.com.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: IDG
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: antivirus, Desktop security, German Federal Justice Ministry, government, Government use of IT, intrusion, malware, online safety, privacy, security, spyware
Latest Blog Posts
Whitepapers
  • Best Practices for Oracle License Management: Optimise Usage and Minimise Audit Liability
    With Oracle audits on the rise, organisations that can best align license agreements with actual database and option usage can reduce their financial risk and maximise the value of their Oracle investments. The goal is to “right-size” Oracle across the enterprise and gain control over the entire license management process – from accurate needs projections and licensing negotiations, to deployments and audit preparation. Read on.
    Learn more »
  • Traditional Backup is Dead - Are you prepared?
    Conventional backup and recovery approaches clearly can't keep up with ever-growing storage rates. It's time to take on a new strategy.
    Learn more »
  • Why Hackers have Turned to Malicious JavaScript Attacks
    Website attacks have become a serious business proposition. In the past, hackers may have infected websites to gain notoriety or just to prove they could—but today, it’s all about the money. Reaching unsuspecting users through the web is easy and effective. Hackers now use sophisticated techniques—like injecting inline JavaScript—to spread malware through the web. Learn about the threat of malicious JavaScript attacks, and how they work. Understand how cybercriminals make money with these types of attacks and why IT managers should be vigilant.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments