{"id":9212,"date":"2020-02-22T19:02:00","date_gmt":"2020-02-22T18:02:00","guid":{"rendered":"https:\/\/paddys.de\/?p=9212"},"modified":"2023-10-07T02:13:00","modified_gmt":"2023-10-07T00:13:00","slug":"bundesrechtsanwaltskammer-gesteht-bea-nutzer-verwenden-raubkopien","status":"publish","type":"post","link":"https:\/\/paddys.de\/en\/bundesrechtsanwaltskammer-gesteht-bea-nutzer-verwenden-raubkopien\/","title":{"rendered":"Federal Bar Association admits: beA users use pirate copies"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading time<\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">Minutes<\/span><\/span>\n<p><em>This article was first published at <a href=\"https:\/\/www.itk-security.de\/bundesrechtsanwaltskammer-gesteht-bea-nutzer-verwenden-raubkopien\/\" target=\"_blank\" rel=\"noopener\" title=\"\">ITK SECURITY<\/a>.<\/em><\/p>\n\n\nLetzte Aktualisierung vor 3 years durch <a href=\"https:\/\/paddys.de\/en\/\" target=\"_blank\" class=\"last-modified-author\">Ruppelt Patrick<\/a>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Reading time: 6 minutes<\/p>\n\n\n\n<p><strong>Last year, we uncovered that the Federal Bar Association (BRAK) was getting its users to install illegal pirated copies of the software Oracle Java on their computers. The BRAK has now admitted this in its latest newsletter. It's about time.<\/strong><\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The instructions provided to users of the \"special electronic lawyer's mailbox\" (beA) requested the download and installation of the respective current JAVA software from Oracle. <strong>The BRAK was not at all interested in the fact that this software would be chargeable - even for every lawyer who installed it.<\/strong><\/p>\n\n\n\n<p>On the contrary, BRAK referred to licensing provisions on its website, <strong>although the BRAK had no licence at all<\/strong>. The manufacturer Oracle had confirmed this to us in writing at the time and referred to the fact that the BRAK had cited the wrong licence model as alleged legitimacy anyway<a><sup>1<\/sup><\/a><sup>).<\/sup><\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Since every lawyer, law firm and court is legally obliged to use the beA system, we have calculated that it is therefore a <strong>Licence fraud amounting to around USD 5 million annually<\/strong> traded<a><sup>2)<\/sup><\/a>.<\/p>\n\n\n\n<p>Added to this were safety concerns due to demonstrably <strong>Server software not updated for months at the Federal Bar Association<\/strong>. The software used had countless known security vulnerabilities<a><sup>3)<\/sup><\/a>.<\/p>\n\n\n\n<p>When asked, the BRAK was very unwilling to help us. No, they were not grateful for the information.<\/p>\n\n\n\n<p><strong>Several BRAK lawyers tried to silence us<\/strong>by generally denying everything, denying everything and trying to take refuge in more and more outrageous excuses.<a><sup>4)<\/sup><\/a>.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>For those who would like to read about the incidents in more detail, I recommend the following articles, which seem almost amusing in retrospect:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.itk-security.de\/haben-bea-nutzer-eigentlich-gueltige-java-lizenzen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Do beA users actually have valid JAVA licences? Thought experiment on the correct licensing of Oracle JAVA software by lawyers and law firms<\/a><a><sup>5)<\/sup><\/a> from 11 August 2019<\/li>\n\n\n\n<li><a href=\"https:\/\/www.itk-security.de\/offener-brief-an-die-bundesrechtsanwaltskammer-brak-bea\/\" target=\"_blank\" rel=\"noreferrer noopener\">Open letter to the Federal Bar Association (BRAK)<\/a><a><sup>6)<\/sup><\/a> from 23 September 2019<\/li>\n\n\n\n<li><a href=\"https:\/\/www.itk-security.de\/brak-verzichtet-bei-bea-auf-sicherheitsupdates\/\" target=\"_blank\" rel=\"noreferrer noopener\">BRAK waives security updates for beA<\/a><a><sup>7)<\/sup><\/a> from 3 October 2019<\/li>\n\n\n\n<li><a href=\"https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/\" target=\"_blank\" rel=\"noreferrer noopener\">Officially confirmed: beA users require paid JAVA licence<\/a><a><sup>8)<\/sup><\/a><a href=\"https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/\" target=\"_blank\" rel=\"noreferrer noopener\">\/<\/a> from 9 October 2019<\/li>\n<\/ol>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>With the change of operator away from Atos and towards the bidding consortium Westernacher\/rockenstein<a><sup>9)<\/sup><\/a> everything should get better, as always.<\/p>\n\n\n\n<p>And indeed, at least the Oracle Java licence problem has apparently been \"solved\". Solved insofar as this component has been abolished and now a free alternative is used that comes with other restrictions. For example, it no longer works on our Linux computers. According to the instructions, only Windows 7, Windows 10 and Mac OS X 10 are supported. Our practical test confirms that not much works with Linux:<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itk-security.de\/wp-content\/uploads\/2020\/02\/image-14-1024x738.png\" alt=\"\" style=\"width:850px;height:613px\" width=\"850\" height=\"613\"\/><figcaption class=\"wp-element-caption\">Source: Login window of the BNotK for PIN setup for beA cards under Linux \/ Chrome (screenshot created on 22.2.2020 at 11:14 a.m.)<a><sup>10)<\/sup><\/a><\/figcaption><\/figure>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>It's nice to see that it still works with Windows 7, which is ten years old and no longer supported by Microsoft at all - completely insecure - but not on a current and secure Linux PC.<\/p>\n\n\n\n<p>Well, as is well known, the Federal Bar Association has never thought much of up-to-date security software and since there are still at least 33,000 PCs with Windows 7 in the German administration<a><sup>11)<\/sup><\/a>that's the way it had to be. The next <a href=\"https:\/\/www.itk-security.de\/wort-zum-sonntag-berliner-kammergericht-von-altbekanntem-virus-bis-naechstes-jahr-lahm-gelegt\/\">Kammergericht-GAU<\/a><a><sup>12)<\/sup><\/a> is pre-programmed.<\/p>\n\n\n\n<p>End-to-end encryption of this supposedly so-secure messaging system also exists today. <em>to<\/em> the change of operator still does not<a><sup>13)<\/sup><\/a>. Because experts from the Bar and the courts agree on this: State-of-the-art security is not needed for court traffic (cf. AGH Berlin, judgement of 14 November 2019 - I AGH 6\/18<a><sup>14)<\/sup><\/a>.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Be that as it may, to our great astonishment, we read a sentence in the BRAK's latest newsletter which we assumed would simply be swept under the table, like everything else before it:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>The Federal Chamber of Notaries recently amended the SAK. <strong>Previously, a separate ORACLE Java installation was necessary for use. This is no longer necessary.<\/strong><\/p>\n<cite>Source: beA Newsletter Issue 4\/2020 v. 20.2.2020 <a><sup>15)<\/sup><\/a>, emphasis added by us<\/cite><\/blockquote>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let's pause for a moment. \"Until now, a separate ORACLE Java installation was necessary for use,\" writes BRAK.<\/p>\n\n\n\n<p>But up to now we have been assured time and again, like a prayer mill, that it is exactly <em>not<\/em> be necessary to install this chargeable piece of software and for - quote - \"which would not incur any separate costs from the beA system and from the beA application or client security (...)\" (cf. email from BRAK to me dated 29.08.2019).<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>This is very interesting in so far as it is a complete 180 degree turnaround. Up to now, the BRAK has done everything to assure me that everything was licensed correctly. <strong>With this newsletter, the BRAK now admits exactly the opposite. Until now, all beA users would have had to buy an Oracle JAVA licence for each computer on which they used beA. Which brings us to the licence fraud sum of around 5 million US dollars at the time. Qed.<\/strong><\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Incidentally, the fact that the BRAK is now making the Oracle JAVA software obsolete does not mean that everything is now fine. This is by no means the case, because this software component was developed by the users or their administrators. <strong>probably installed on at least 85,000 computers, continues to run happily there and is of course still chargeable<\/strong>, without any doubt<a><sup>16)<\/sup><\/a><a href=\"https:\/\/shop.oracle.com\/apex\/f?p=DSTORE:PRODUCT:::NO:RP,6:P6_LPI,P6_PROD_HIER_ID:132208699270491131625576,123775488249871532594385\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a>. And that is until it is uninstalled again. As long as the user does not ensure that Oracle JAVA is removed from his computer, he will continue to use pirated copies and has been doing so since the beginning of 2019. However, the BRAK - who would have expected otherwise - does not say a single word about this.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 id=\"wp-block-themeisle-blocks-advanced-heading-275209d3\" class=\"wp-block-themeisle-blocks-advanced-heading wp-block-themeisle-blocks-advanced-heading-275209d3\">List of sources<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><th><a>\u21911<\/a><\/th><td><a href=\"https:\/\/www.itk-security.de\/offener-brief-an-die-bundesrechtsanwaltskammer-brak-bea\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.itk-security.de\/offener-brief-an-die-bundesrechtsanwaltskammer-brak-bea\/<\/a><\/td><\/tr><tr><th><a>\u21912<\/a><\/th><td><a href=\"https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/<\/a><\/td><\/tr><tr><th><a>\u21913<\/a><\/th><td><a href=\"https:\/\/www.itk-security.de\/brak-verzichtet-bei-bea-auf-sicherheitsupdates\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.itk-security.de\/brak-verzichtet-bei-bea-auf-sicherheitsupdates<\/a>\/<\/td><\/tr><tr><th><a>\u21914<\/a><\/th><td><a href=\"https:\/\/www.itk-security.de\/haben-bea-nutzer-eigentlich-gueltige-java-lizenzen\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.itk-security.de\/haben-bea-nutzer-eigentlich-gueltige-java-lizenzen\/<\/a><\/td><\/tr><tr><th><a>\u21915<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.itk-security.de\/haben-bea-nutzer-eigentlich-gueltige-java-lizenzen\/\" target=\"_blank\">https:\/\/www.itk-security.de\/haben-bea-nutzer-eigentlich-gueltige-java-lizenzen\/<\/a><\/td><\/tr><tr><th><a>\u21916<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.itk-security.de\/offener-brief-an-die-bundesrechtsanwaltskammer-brak-bea\/\" target=\"_blank\">https:\/\/www.itk-security.de\/offener-brief-an-die-bundesrechtsanwaltskammer-brak-bea\/<\/a><\/td><\/tr><tr><th><a>\u21917<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.itk-security.de\/brak-verzichtet-bei-bea-auf-sicherheitsupdates\/\" target=\"_blank\">https:\/\/www.itk-security.de\/brak-verzichtet-bei-bea-auf-sicherheitsupdates\/<\/a><\/td><\/tr><tr><th><a>\u21918<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/\" target=\"_blank\">https:\/\/www.itk-security.de\/offiziell-bestaetigt-bea-anwender-benoetigen-kostenpflichtige-java-lizenz\/<\/a><\/td><\/tr><tr><th><a>\u21919<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.lto.de\/recht\/juristen\/b\/bea-vergabeverfahren-neuer-dienstleister-westernacher-rockstein-folgt-atos\/\" target=\"_blank\">https:\/\/www.lto.de\/recht\/juristen\/b\/bea-vergabeverfahren-neuer-dienstleister-westernacher-rockstein-folgt-atos\/<\/a><\/td><\/tr><tr><th><a>\u219110<\/a><\/th><td><a href=\"https:\/\/secure.bnotk.de\/idp\/Authn\/Smartcard\/\">https:\/\/secure.bnotk.de\/idp\/Authn\/Smartcard\/<\/a><\/td><\/tr><tr><th><a>\u219111<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/www.handelsblatt.com\/politik\/deutschland\/windows-7-bundesregierung-zahlt-fast-eine-million-euro-fuer-veraltetes-microsoft-betriebssystem\/25452158.html?ticket=ST-7494672-79NK0UVPqdwhvPmgZf2K-ap1\" target=\"_blank\">https:\/\/www.handelsblatt.com\/politik\/deutschland\/windows-7-bundesregierung-zahlt-fast-eine-million-euro-fuer-veraltetes-microsoft-betriebssystem\/25452158.html?ticket=ST-7494672-79NK0UVPqdwhvPmgZf2K-ap1<\/a><\/td><\/tr><tr><th><a>\u219112<\/a><\/th><td><a href=\"https:\/\/www.itk-security.de\/wort-zum-sonntag-berliner-kammergericht-von-altbekanntem-virus-bis-naechstes-jahr-lahm-gelegt\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.itk-security.de\/wort-zum-sonntag-berliner-kammergericht-von-altbekanntem-virus-bis-naechstes-jahr-lahm-gelegt\/<\/a><\/td><\/tr><tr><th><a>\u219113<\/a><\/th><td><a href=\"https:\/\/anwaltsblatt.anwaltverein.de\/de\/news\/agh-berlin-bea-ist-sicher-keine-ende-zu-ende-verschluesselung-noetig\">https:\/\/anwaltsblatt.anwaltverein.de\/de\/news\/agh-berlin-bea-ist-sicher-keine-ende-zu-<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/anwaltsblatt.anwaltverein.de\/de\/news\/agh-berlin-bea-ist-sicher-keine-ende-zu-ende-verschluesselung-noetig\" target=\"_blank\">end<\/a><a href=\"https:\/\/anwaltsblatt.anwaltverein.de\/de\/news\/agh-berlin-bea-ist-sicher-keine-ende-zu-ende-verschluesselung-noetig\">-verschluesselung-noetig<\/a><\/td><\/tr><tr><th><a>\u219114<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/anwaltsblatt.anwaltverein.de\/files\/anwaltsblatt.de\/anwaltsblatt-online\/2020-003.pdf\" target=\"_blank\">https:\/\/anwaltsblatt.anwaltverein.de\/files\/anwaltsblatt.de\/anwaltsblatt-online\/2020-003.pdf<\/a><\/td><\/tr><tr><th><a>\u219115<\/a><\/th><td><a href=\"https:\/\/mailcluster.wegewerk.com\/mailing\/36\/2620027\/7696415\/3951\/c90ce8ac25\/index.html\">https:\/\/mailcluster.wegewerk.com\/mailing\/36\/2620027\/7696415\/3951\/c90ce8ac25\/index.html<\/a><\/td><\/tr><tr><th><a>\u219116<\/a><\/th><td><a rel=\"noreferrer noopener\" href=\"https:\/\/shop.oracle.com\/apex\/f?p=DSTORE:PRODUCT:::NO:RP,6:P6_LPI,P6_PROD_HIER_ID:132208699270491131625576,123775488249871532594385\" target=\"_blank\">https:\/\/shop.oracle.com\/apex\/f?p=DSTORE:PRODUCT:::NO:RP,6:P6_LPI,P6_PROD_HIER_ID:132208699270491131625576,123775488249871532594385<\/a><\/td><\/tr><\/tbody><\/table><\/figure>","protected":false},"excerpt":{"rendered":"<p>Since every lawyer, every law firm and every court is legally obliged to use the beA system, we have calculated that this represents licence fraud amounting to around USD 5 million per year.<\/p>","protected":false},"author":1,"featured_media":9213,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_lmt_disableupdate":"","_lmt_disable":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9212","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-posts"],"acf":[],"modified_by":"Ruppelt Patrick","wps_subtitle":"","_links":{"self":[{"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/posts\/9212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/comments?post=9212"}],"version-history":[{"count":2,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/posts\/9212\/revisions"}],"predecessor-version":[{"id":9511,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/posts\/9212\/revisions\/9511"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/media\/9213"}],"wp:attachment":[{"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/media?parent=9212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/categories?post=9212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/paddys.de\/en\/wp-json\/wp\/v2\/tags?post=9212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}