On TV.com: LOST Season 6. Premiere Date. Announced.
BNET Business Network:
BNET
TechRepublic
ZDNet

September 25th, 2009

How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi

Posted by Larry Dignan @ 5:39 am

Categories: General, Government, IT Management, Infrastructure, Search, Web Technology

Tags: Agent, Information Technology, Pakistan, Laptop Computer, Internet, E-mail, Notebooks, Online Communications, Hardware, Notebooks & Tablets

Source: CBS News video

The indictment of suspected terrorist Najibullah Zazi, who is charged with acquiring and preparing bombs similar to the ones deployed in the 2005 London subway attacks, rides substantially on Zazi’s Internet surfing habits.

Federal prosecutors say that Zazi was trained in Pakistan and shuttled between Queens, N.Y. and Denver in an attempt to prepare bombs. The Feds allege that Zazi was involved in an Al Qaeda conspiracy to attack the U.S.

As you read the indictment and order for permanent detention (also see FBI statement, CBS News) you can almost picture the various connected databases and monitoring techniques at work. Simply put, Internet surveillance and information technology sleuthing played a big role in the Zazi case. FBI agents arrested Zazi in Colorado.

Jeffrey Knox, an assistant U.S. attorney, tells the tale in the permanent detention document. Here’s a look at the key linchpins where IT crossed paths with detective work.

The Customs databases…

Zazi flew from Newark Liberty International Airport to Peshawar, Pakistan on Aug. 28, 2008.   Something triggered in a database, given that Zazi, 24, was going to Peshawar, known as a terrorism hotbed.

Pakistan email accounts…

Here’s where the surveillance kicked in. Knox notes in the order for detention:

Zazi is associated with three email accounts (”Email Account 1,” “Email Account 2″ and “Email Account 3″) that were active during his time in Pakistan. One of the accounts is directly subscribed to Zazi, and all three accounts contain slight variations of the same password. The government will establish at trial that these accounts were used in furtherance of Zazi’s efforts to manufacture explosive devices. Among other things, during a consent search of two of the three accounts, agents found jpeg images of nine pages of handwritten notes containing formulations and instructions regarding the manufacture and handling of different kinds of explosives. Based on email header information, these images had been emailed to Email Accounts 2 and 3 in early December 2008, while Zazi was in Pakistan. As discussed below, the same notes were transferred onto Zazi’s laptop computer in June 2009.

Customs databases again…

Zazi flew back to the U.S. via JFK International Airport in Queens on Jan. 15, 2009.

You are your Internet search history…

Knox continues:

A lawfully-authorized search of Zazi’s laptop computer reflects that Zazi transferred the bomb-making instruction notes onto his laptop and/or accessed the notes on his laptop in June and July 2009. The FBI’s search of the laptop also reflects that Zazi conducted several internet searches for hydrochloric acid during the summer of 2009, and “bookmarked” a site on two different browsers for “Lab Safety for Hydrochloric Acid.” Zazi also searched a beauty salon website for hydrocide and peroxide.

Turns out Zazi and cohorts went shopping at various beauty supply stores for these ingredients. The Feds say that Zazi rented an Aurora, Colo. hotel room on Sept. 6 and 7 and tried to put the ingredients together.

The cell phone tap…

According to the permanent detention request:

Also on September 6 and 7, Zazi attempted to communicate on multiple occasions with another individual - each communication more urgent in tone than the last - seeking to correct mixtures of ingredients to make explosives. Included in the communications were requests related to flour and ghee oil, which are two ingredients listed in the bomb-making instructions. Zazi repeatedly emphasized in the communications that he needed the answers right away.

Internet search history take 2…

Knox writes:

A lawfully-authorized search of Zazi’s laptop computer reflects that the next day, September 8, Zazi searched the internet for locations of a home improvement store within zip code 11354, the zip code for the Flushing neighborhood of Queens, New York. He then searched the home improvement store’s website for muriatic acid, which is a diluted version of hydrochloric acid and, as discussed, could constitute the third component of TATP, which is comprised of hydrogen peroxide, acetone and a strong acid like hydrochloric acid. Zazi viewed four different types of muriatic acid. He viewed one particular type - Klean Strip Green Safer Muriatic Acid - multiple times. This product claims to have lower fumes and is safer to handle than standard muriatic acid.

Too little too late: Ditching the hard drive…

According to cell phone taps, Zazi started to realize he was being tracked after renting a car to New York. Zazi purchased an airline ticket and returned to Denver on September 12. After laptop searches revealed scans of handwritten bomb making instructions, Zazi removed the hard drive. According to Knox:

After Zazi’s laptop was searched in New York, and after Zazi returned to Colorado with his laptop, agents executed a search warrant at his Aurora residence. Agents recovered the same laptop that had previously been searched and found that the hard drive had since been removed.

There are still gaps in the account and specifics about how the Feds followed Zazi’s Internet habits. But it’s safe to say that the case would be a lot harder to prove if it weren’t for Zazi’s search habits and digital fingerprints.


Watch CBS Videos Online

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 59 Talkback(s)
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi
How much do "they" knowe about you? Who are "they"? Who controls the controllers? It seems you can get sentenced for a crime you never committed and could not possibly commit. How can you prove your i... (Read the rest)
Posted by: theoikos Posted on: 10/08/09 You are currently: a Guest | | Terms of Use
Kinda eerie  bigsibling | 09/25/09
Kinda eerie  gertruded | 09/25/09
Don't commit any crimes and you'll be fine. nt  T1Oracle | 09/25/09
There are 2 Issues Here  davagain | 09/25/09
Also Conflicted  sboverie@... | 09/25/09
if he's cooking chemicals  bearlyworking | 09/25/09
Yes, but guilty of what?  zackers | 09/28/09
I agree  T1Oracle | 09/25/09
There is systematic abuse  HollywoodDog | 09/25/09
like they have enough personnel to follow activists  bearlyworking | 09/25/09
That's exactly who they do follow  HollywoodDog | 09/25/09
that's the whole point  bearlyworking | 09/25/09
HMMM  sboverie@... | 09/25/09
actually it does matter  steeleblue_cactus | 09/26/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  Capt_Sparky | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  Try2Ketchup | 09/25/09
Great thing he was caught  stefan.metzeler@... | 09/25/09
A little old fashioned here  Bill4 | 09/25/09
Prison will always be torture.  T1Oracle | 09/25/09
A decent catch  Dr_Zinj | 09/25/09
Fair exchange of privacy for safety  kellycarter | 09/25/09
not an issue of "personal privacy" to me  steeleblue_cactus | 09/26/09
You made some good points, but your conclusion was, frankly, stupid  adornoe@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  tom@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  norm@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terro  mondaka@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  bearlyworking | 09/25/09
Not likely to work  Geedavey | 09/25/09
What I learned  Geedavey | 09/25/09
Re: What I've learned  nevthaman | 09/25/09
RE: ...and how the nation so easly traded it rights for "secuity."  mario@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terro  lazerousz | 09/25/09
Probably they did not catch this guy via IT  HollywoodDog | 09/25/09
gee... I often wonder how they treat **peaceful demonstrators**  BlueBerry Pick'n | 09/25/09
"we don't need RIGHTS, we need Protections!"  BlueBerry Pick'n | 09/25/09
Foreigners should not teach us about liberty  Linux Geek | 09/25/09
Guess what... I'm a brown dude and...  adornoe@... | 09/25/09
can you SAY WARRANTLESS WIRETAPPING??  BlueBerry Pick'n | 09/25/09
Message has been deleted.  MSFTWorshipper | 09/25/09
we should not apologize to anybody  Linux Geek | 09/25/09
concious, actions and laws define a nation  mario@... | 09/25/09
Helping Terrorists 101  FiOS-Dave | 09/25/09
Story doesn't help terrorists  HollywoodDog | 09/25/09
Posted in wrong place... so content removed  adornoe@... | 09/25/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  PeterPac | 09/25/09
Agree with discretion in journalism  james_houston@... | 09/25/09
It's not about the enemy's experience in warfare and subversion  adornoe@... | 09/26/09
Peterpac, you're wrong - govt can assert guilt  HollywoodDog | 09/27/09
What a load of BS!  adornoe@... | 09/27/09
Agree  sboverie@... | 09/28/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terro  chiefpace | 09/26/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terro  jlutgring | 09/26/09
These criminals were captured and charged according to law.  HollywoodDog | 09/27/09
Reality runs completely counter to your views and beliefs  adornoe@... | 09/29/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  Mr Piston | 09/28/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  LazyMom | 09/29/09
Lessons  homant@... | 10/02/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  gwreg4fge | 10/08/09
RE: How Internet surveillance, IT sleuth work helped indict suspected terrorist Zazi  theoikos | 10/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here