Bonum Certa Men Certa

Full Translation of Süddeutsche Zeitung Article About Blackhat Tactics (Keyloggers) in EPO (Updated)

See "Researchers link QWERTY keylogger code to NSA and Five Eye's Regin espionage malware"

NSA slide



Summary: The European Patent Office (EPO) finds itself at the centre of attention (unwanted attention) because of rogue activities

A FEW hours ago we wrote about the EPO's use of keyloggers, a practice so controversial (to say the least) that one can end up locked up in a cell for using it. Süddeutsche Zeitung, which wrote about the EPO before, is really putting some big pressure on the EPO right now (perhaps someone will resign soon). The German article has just been published by IP Kat in English. For our record we present it below:





The European Patent Office carried out secret surveillance on employees using keyloggers
€·         At the headquarters of the European Patent Office (EPO) two publicly accessible computers were fitted with cameras and surveillance technology during a period of several weeks.
€·         They were used in an internal procedure which involves a patent judge who is accused of having disseminated defamatory communications about the President of the EPO and other managers over a period of months.
€·         However, the action also affected many employees of the EPO, perhaps even members of the Administrative Council.


by Katja Riedel


The President of the European Patent Office (EPO) is set to travel to Brussels next week. There he will be received by the Legal Affairs Committee for "an exchange of views" according to the agenda. Benoît Battistelli is supposed to speak about the latest developments in patent law, the new patent courts and various other reforms.


There should be no lack of subjects for discussion in view of the ongoing state of crisis between Battistelli and many of the approximately 7,000 employees in Munich, Berlin, Vienna and The Hague. Since Battistelli initiated an extensive reform programme, which amongst other things has completely restructured the EPO’s career system, there have been vehement confrontations. Now a new and awkward subject has been added to the list: allegations of covert surveillance.

According to an internal document which the SZ has seen publicly accessible computers were placed under surveillance at the EPO towards the end of last year: by means of cameras and so-called keyloggers. This allows the recording of what the user types, which pages he accesses and how he communicates.

None of the users were aware that the devices had been installed

Some keyloggers are capable of taking snapshots of the screen. The camera records contemporaneously which person was operating the computer at the time in question. A particularly juicy detail here is that none of the users were aware that the devices had been installed - and the two computers which were equipped with these monitoring devices according to the confidential document of the internal investigation unit, were probably located on the first floor of the EPO headquarters at Erhardtstraße in Munich.

Namely, in a publicly accessible area, which was provided especially for the members of the Administrative Council - the highest authority in the European patent world - on which the representatives of the 38 member states sit. The visitors to the Patent Office who typically sojourn on the first floor also include patent attorneys. On Monday [8 June 2015] the EPO declined to comment on the internal document but did not contest its authenticity.

In the document drawn up by the Head of the EPO’s investigative unit and sent to the Data Protection Officer, the reason given for the surveillance measures was a defamation campaign against the President and other managers of the Office.

In fact, since the beginning of 2013, letters accusing Benoît Battistelli, and also his Croatian Vice President Zeljko Topic, of numerous misdeeds have been circulating. There were strong indications that these letters had been sent from the two computers in question to which not only every registered visitor but also every employee of the EPO could log in via a common password. Therefore, according to the internal communication, it was not possible to identify and monitor an individual user.

Covert surveillance of the terminals in question

Apparently the internal investigators had come across IP addresses that they could assign to both of the public computers. For this reason, according to their conclusion, there was no other option but to place the two machines in question under covert surveillance. If during the agreed six-week time window between 7th November and 18th December no further defamatory material was sent, neither the pictures nor the data would be analysed, it was stated. Until then, the information that was monitored would only be available to the members of the internal investigation unit and the IT technicians.

The matter is also particularly sensitive because during the period in which the surveillance was being carried out the 142th Meeting of the Administrative Council also took place in the building, namely on 10. and 11. December 2014.  In addition, the Budget and Finance Committee also met during the period in question.
The computers are apparently located near the room where the Council meets. Whether this body and the Office Administration, i.e. Battistelli, was involved in the procedure is unclear. This is not apparent from the document. This only includes handwritten notes of two of the signatories but the signatures are missing.

Even insiders expressed reservations

In fact not only was material sent, but also a suspected letter-writer was caught - hence the data were also analysed. A member of the Boards of Appeal of the Office, a patent judge, was apparently caught in the act and Battistelli immediately subjected him to a “house ban”. This was equal to a suspension and consequently a legally impermissible interference with the independence of that department [i.e. the Boards of Appeal], which was retroactively rubber-stamped by the Administrative Council.

However, the tide of indignation ran high. Off the record even insiders expressed their reservations about Battistelli’s actions. Politicians from individual member states and patent attorneys expressed their outrage in public and even spoke of violations of fundamental rights.

The EPO declined to comment on the sensitive document citing a pending procedure as its reason. The Administrative Council is due to decide on possible disciplinary action at one of its forthcoming meetings.



Merpel added: "This flagrant invasion of privacy comes in the wake of evidence that Mr. Battistelli has engaged a firm specialising in counter-surveillance and threat monitoring. Not because of any imminent terror threat, mind you: all this came about originally because it was suspected that an employee was circulating material alleged to be defamatory. One cannot help thinking in terms of the old cliche about using a sledgehammer to crack a mouse."

"Merpel, who has grown rather tired of appealing to the Administrative Council members to hold the EPO management to the same governance standards as would be required in their own national Patent Offices and civil services, wonders if this latest news will convince some of those on the fence that a more robust approach is required when they next attend an AC meeting at the EPO."

Our own remarks on it can be found in our prior article about it.

Update (15/6/2015): There are now more translations, including in additional languages, namely French and Dutch [PDF].

Recent Techrights' Posts

"Many Applications Labelled as "Cybersecurity" and Given a Veneer of Legitimacy Are Really "Weaponised" and Abusive Code"
New from Dr. Andy Farnell
Security Advisory: Debian falls for social engineering hacks
Reprinted with permission from Daniel Pocock
 
Plagiarism by Bots: Guardian Digital, Inc (linuxsecurity.com) Still Creates Fake Articles About "Linux"
100% fake
[Teaser] [Meme] New Ways to Impoverish Patent Examiners (Entrusted to Block Unjust Monopolies or Monopoly Applications)
Coming tomorrow!
Apple Tax funds: railways, defective concrete blocks in Ireland's North and West
Reprinted with permission from Daniel Pocock
Daniel Pocock, Nomination for Ireland, Dublin Bay South, General Election 2024
Reprinted with permission from Daniel Pocock
Links 08/11/2024: TikTok Bans and Clownflare Issues/Perils
Links for the day
Gemini Links 08/11/2024: RPS, O.D.I.N., and RSS in Yahoo News
Links for the day
Donald Trump as Censor in Chief Can Now Leverage Censorship Companies and Fake Protection Disguised as 'Security'
Centralised CAs were trouble all along
Technology: rights or responsibilities? - Part VI
By Dr. Andy Farnell
A Death of a News Industry
A theme we explored thrice today
Deciphering Centralised CAs and Why Their Demise Should be a Goal
Encryption in transmission is good; but who controls the key exchange and certification/authentication/validation?
Links 08/11/2024: Strikes, Recessions, and Slowdowns
Links for the day
[Teaster] [Meme] New Ways of Wrecking (NWoW)
The EPO
Gateway for News and Blogs
In the long run, this site and its sister site (less overlap between them now) should hopefully become a popular destination for people who look for information, not chaff
Going Even Faster
We hope the site will be faster soon
Psychopaths Who Reaffirm Our Work's Value
Psychopaths and sociopaths lack empathy, so they're willing to go very far and stoop as low as they deem necessary
[Meme] How Low Can You Go at the European Patent Office?
Not just in terms of patent quality
More Cuts/End to Benefits for EPO Workers (Europe's Working Conditions Incompatible With the European Patent Convention)
"The Office is now reviving it but plans to introduce new cuts on benefits"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 07, 2024
IRC logs for Thursday, November 07, 2024
Gemini Links 08/11/2024: US Election, RetroChallenge 2024, and More
Links for the day
[Meme] Questioning Proprietary Software? Not OK...
A disaster long in the making
Links 07/11/2024: HTTP/3, Health Research, and Punditry
Links for the day
Gemini Links 07/11/2024: On Writing Publicly and Record Player Table
Links for the day
Open Source Security Foundation (OpenSSF) Hosted SOSS as Microsoft Propaganda Platform With Microsoft Front Group OSI
They essentially promote what they're attacking under false pretences [...] OSI is deeply corrupt. It's more toxic than arsenic.
Anti-Linux FUD, Now in LLM Form, Thanks to Brittany Day
They attack Linux with chatbots
[Meme] When You Discredit People Who Discredit Secret Code
proprietary systems with hundreds of millions of transistors (and hundreds of millions of lines of code)
The High Cost of Making Scepticism of Proprietary Voting Machines a "Trump" and "Conspiracy Theory" Territory
Time to get back to paper? Or read an old paper?
Links 07/11/2024: Online Manipulation in Social Control Media, Election Deniers, and More
Links for the day
Gemini Links 07/11/2024: emacs-guix and File Hoarding
Links for the day
[Meme] Election Day at the European Patent Office
Less than 60 minutes left to cast your vote
Staff Union of the European Patent Office (SUEPO) Election Ending Today
In one hour
[Meme] When the Patent Office Does Illegal Things and Staff Speaks Out
many leaks received today
Today We Got an Early Birthday Gift
Exciting times
[Meme] Going Too Far to the Left Can Breed Militant Ideology
Some people can never be appeased because they prefer not to be appeased
Apple's Debt Has Skyrocketed While Gimmicks Like Vision Pro Failed
In Apple's case, the debt is almost double the "Cash on Hand", which isn't even cash
FSF Expressed No Preference Regarding Presidential Candidates (Its Founder Did)
Because he is a principled person, he does not prioritise loyalty to customers or employers (money)
A President Trump is Excellent News to Microsoft
His racist policies gave lots of contracts to Microsoft
Who Next on the Linux Foundation's 'Kill List'?
Remember that only about 2% of the "Linux" Foundation's budget goes to Linux
Links 07/11/2024: Facebook Scams, Journalists on Strike
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 06, 2024
IRC logs for Wednesday, November 06, 2024
Microsoft-Connected Publishers Want Us to Think That Linux is Some Sort of a Virus and a "Backdoor"
"The problem is with windows and the attack vector is via Windows"
We've Made it to 18! Here's to Another 18!
Going on for another 18 years means until some time at the end of 2042
Links 07/11/2024: Political Angst and Laptop Issues
Links for the day
Even LKML Subjected to Slop/SPAM by Guardian Digital, Inc (linuxsecurity.com)
They're really awful
Links 06/11/2024: BPF in RFC 9669, More Facebook Fines for Privacy Abuses
Links for the day
Gemini Links 06/11/2024: Political Shock and Hermaic Encouragement
Links for the day
Planet Debian Allows Politics (But It Depends on Your Opinions and Debian's Big Sponsors)
Planet Debian is OK with politics... as long as all your political opinions are the "correct" ones and you add cute animals
What Makes RMS Such an Attractive Target ('Discreditisation' Campaigns)
Don't be so easily fooled
The Biggest OEMs or Vendors of GNU/Linux Stopped Competing With Microsoft (Which Pays Them to Promote Windows, Too)
Where are the competition authorities (or regulators for that matter)?
Let's Encrypt Falls to a New Low of Only 0.6% of Gemini Capsules Known to Lupa
In Gemini Protocol, certificates for encryption are required, but centralised Certificate Authorities (CAs) aren't needed
Computer-Generator Crap Flooding the Web, the Latest Example About "Linux"
Here's today's example
Links 06/11/2024: Election Disinformation and Legal Actions
Links for the day
Gemini Links 06/11/2024: Stargazing and Death on Hallowe'en
Links for the day
Would You Trust a Liar?
Why lie about the authorship?
Mass Layoffs at Mozilla Announced During US Elections
Maybe nobody will notice?
[Meme] Announcing "Results" Before Everyone Even "Played"
There is a "tech" angle to otherwise political news
US Polls Close in One Minute (Social Control Media Does Not Care, Will Not Wait)
US election results will be known in about 2 days
Concentration and Centralisation Versus Aggregation or Syndication
KDE has a history of burying old sites
Social Control Media, Even Hours Before Polls Have Closed
Has social control media controlled by CPC (TikTok) and the Trumpmobile guy (Musk's "X") done enough to convince people not to even vote (based on presumptive "results", presented a long time before all polls have closed)?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 05, 2024
IRC logs for Tuesday, November 05, 2024
Wayland Pains in Community-Led Distros of GNU/Linux
Few people and companies use Wayland; there's hardly any technical or practical reason to choose it
IBM Still Conflating Microsoft With 'Security'
As a meme
Sanctions Cause Fragmentation in Software
some Chinese Linux developers are already subjected to restrictions similar to Russians'
Web Failing With Slop, Even in 'Linux' Sites (LLM Spam)
Add SEO prompting to the mix and the Web becomes a pool of slop, not knowledge
[Meme] State of the World Wide Web and Online Journalism
Technically a failure (DRM) and cannot even get basic things right
Trump's signature policy, building a wall, copied from Irish-Australian student politician
Reprinted with permission from Daniel Pocock
Linus Torvalds' self-deprecating LKML CoC mail linked to Hitler's first writing: Gemlich letter
Reprinted with permission from Daniel Pocock
[Meme] Turning 18 in One Day
just one more day