Magistrates’ Software: Security Breach & Investigation

A technical experiment, some television and journalistic interviews, and now a criminal investigation. There Milan Prosecutor’s Office opened a file for unauthorized access to a computer system towards a ministerial technician of the Turin districtafter a statement from the Ministry of Justice presented on January 24th. The initiative was launched the day after an episode of the show was previewed Reportbut before the official broadcast, which took place the following Sunday.

At the center of the story is the software Ecmprogram of Microsoft used by the Ministry of Justice for the remote management and maintenance of magistrates’ computers, in particular for the installation of updates, software and security features on networks made up of thousands of stations. According to what was reported by Corriere della Serathe technician had said, maintaining anonymity, before Report and then to Il Fatto Quotidianoto have concretely demonstrated one alleged fragility of the system.

The technician’s story spoke of a experiment carried out with the consent of the judgein particular of investigating judge of the Court of Alessandria Aldo Tirone. The operation, carried out on the magistrate’s office computer, would have shown that the Ecm program can be used at a distancewithout leaving traces visible to the Ministry’s system administrators, for observe the magistrate’s PC screen and interact with it as if you were physically at the keyboardwithout the user’s knowledge.

In interviews, the same Aldo Tirone had explicitly confirmed that the technician’s access had occurred with his consent. A point which, however, did not convince the Ministry of Justice. In the complaint sent to the Prosecutor’s Office, accompanied by correspondence with the Turin offices relating to the years 2024 and 2025the Ministry indicated investigating judge Tirone as “offended party”considering consent to be irrelevant if access occurred in ways other than those permitted.

The legal and technical issue is all here. According to the ministerial reconstruction, the contested access could not be justified by the simple use of ordinary credentials of the technician, as he publicly supported. The hypothesis, which remains to be verified, is that they were used technical “forcings”. of the Ministry’s network, because – according to the administration – some functions attributed to the software they could not function without prior approval from the magistrates interested.

Precisely to clarify this aspect, the Milanese investigation entrusted the Postal police the task of ascertaining thereliability of the Ecm system and to establish whether what the technician said is technically possible in the ways described. The investigations will have to clarify whether the software really allows remote access invisible to administrators or whether, on the contrary, the system provides controls and tracking such as to exclude hidden surveillance scenarios.

The choice of territorial jurisdiction on Milano arises precisely from the ministerial complaint, which identified the case of the investigating judge Tirone as the central episode on which to base the hypothesis of a crime. The investigation is still in one initial phaseand at the moment there are no precautionary measures. The principle of presumption of innocence for the technician under investigation.

The affair, however, has already opened a delicate front: that of the relationship between IT security, autonomy of the judiciary e control of digital infrastructures of the Ministry. A slippery slope, in which a test presented as a technical demonstration risks turning into a judicial case capable of raising broader questions about the management of justice IT systems and the boundaries between maintenance, control and access to magistrates’ data.

Related Posts

Leave a Comment