Researcher buys US military device containing sensitive biometric data for $68 from eBay

midian182

Posts: 9,746   +121
Staff member
WTF?! Stories of people selling electronic items on eBay without first wiping their storage aren't unusual. However, one would not expect to buy a military device from the auction site and find it contains sensitive biometric data on thousands of individuals. Yet that's what a German security researcher discovered after he paid just $68 for one of the machines.

The New York Times reports that Matthias Marx, head of a group of European researchers called the Chaos Computer Club, bought six biometric capture devices on eBay, most of them for under $200. The group intended to analyze the machines to search for vulnerabilities following a 2021 report from The Intercept on the Taliban seizing similar equipment. One of the items, a hand-held machine designed to capture fingerprints and perform iris scans, Marx managed to secure for just $68, much less than the listed $149.95 price.

The researchers were shocked to find the device, called a Secure Electronic Enrollment Kit, or SEEK II, contained a memory card that stored the names, nationalities, photographs, fingerprints, and iris scans of 2,632 people, most of whom were individuals from Afghanistan and Iraq. Many were known terrorists and wanted individuals, and there were also details of people who had worked with the US government and everyday citizens who had simply been stopped at checkpoints.

Another device contained the fingerprints and iris scans of US military personnel. It had last been used in Jordan in 2013.

The data also included detailed descriptions of individuals alongside their photographs and biometric information, which could have placed members of the military and those who aided them at risk of being identified and tracked down by the Taliban.

Exactly how the device ended up on eBay is unclear, as is the number of times it had passed between owners since last being used in 2012 near Kandahar, Afghanistan. Why the military never removed/destroyed the memory card is also a mystery. One of the sellers said they were not aware it contained sensitive information, adding that they acquired the SEEK II at an auction of government equipment. Another refused to say where they obtained the device.

"The irresponsible handling of this high-risk technology is unbelievable," the researcher told the Times. "It is incomprehensible to us that the manufacturer and former military users do not care that used devices with sensitive data are being hawked online," he added.

Defense Department press secretary Brig. Gen. Patrick S. Ryder told the Times, "Because we have not reviewed the information contained on the devices, the department is not able to confirm the authenticity of the alleged data or otherwise comment on it. The department requests that any devices thought to contain personally identifiable information be returned for further analysis."

Masthead: Marine Corps photo by Cpl. Briauna Birl

Permalink to story.

 
"Why the military never removed/destroyed the memory card is also a mystery."

Its no mystery. Nothing about the gift to terrorists that was the Afghanistan pullout was an accident. The Biden administration knew EXACTLY what it was doing, as evidenced by the inexplicable orders to leave behind tons of sensitive equipment that could have easily been either destroyed or removed. Leaving hostile dictatorships in charge of nations gives the US oligarchs a perfect pretext for anything that serves their interests.
 
I have always wondered about that particular fiasco myself. And why US allies had only last minute warning of the sudden pullout and were left to deal with the friendlies desperate to escape.
 
"Why the military never removed/destroyed the memory card is also a mystery."

Its no mystery. Nothing about the gift to terrorists that was the Afghanistan pullout was an accident. The Biden administration knew EXACTLY what it was doing, as evidenced by the inexplicable orders to leave behind tons of sensitive equipment that could have easily been either destroyed or removed. Leaving hostile dictatorships in charge of nations gives the US oligarchs a perfect pretext for anything that serves their interests.

I thought you couldn't shout on TS - ignoring that - if there was evidence like you say - it would be in main media and on conspiracy sites & fake media.

It wasn't malice it was incompetence's and panic at suicide boomers and speed of Taliban advance .
Americans and Allies were also left behind.

It's actually very hard to do a good evacuation in a rapidly changing war zone
Planning wasn't great - wrong assumptions
Withdrawal has to be kept secret for a long time to stop panic and enemy actions.

You know the USA army was probably still meant to supply the Afghani Army - so wasn't like Vietnam etc ??

This is on the ground stuff - basis ops - you sell your fishing boat - you wipe your gps - Police don't leave notes at scene. hospital staff don't leave private info laying around.

Military stuff should have kill codes or something as well

 
"Why the military never removed/destroyed the memory card is also a mystery."

Its no mystery. Nothing about the gift to terrorists that was the Afghanistan pullout was an accident. The Biden administration knew EXACTLY what it was doing, as evidenced by the inexplicable orders to leave behind tons of sensitive equipment that could have easily been either destroyed or removed. Leaving hostile dictatorships in charge of nations gives the US oligarchs a perfect pretext for anything that serves their interests.

Same here. Well said.
 
Hope he sold off the info before he told the government of their screw up unlike the case of M16's that were accidently sold to that couple
 
Similar to Iraq. When ISIS attacked a warehouse in Iraq and stole all kinds of vehicles, including tanks, hummers, cannons, etc...... what did the US military do?

1. Sent ground forces to stop the convoy at the border?
2. Scrambled fighter jets to intercept the convoy heading towards Syria?
3. Launched satellite-guided missiles to destroy the stolen vehicles?
4. Sent armed drones to bomb the convoy and prevent ISIL from getting advanced weaponry?

None of the above. They just let them take everything and leave. There wasn't even a single attempt made to stop or destroy them. That says everything.
 
"Why the military never removed/destroyed the memory card is also a mystery."

Its no mystery. Nothing about the gift to terrorists that was the Afghanistan pullout was an accident. The Biden administration knew EXACTLY what it was doing, as evidenced by the inexplicable orders to leave behind tons of sensitive equipment that could have easily been either destroyed or removed. Leaving hostile dictatorships in charge of nations gives the US oligarchs a perfect pretext for anything that serves their interests.

You mean following the Withdrawl agreement that Trump made with the Taliban, the one he always brags about when he says he talked to "Abdul and showed him a picture of his house"

Biden followed Trumps plan. I guess he could have ripped it up but that would lower US credibility even further.
 
Back