In 2016, Turkey experienced an attempted coup. The Turkish government became convinced that the plotters had coordinated through a messaging app called ByLock, and it ordered the arrest of all of the app's users. That app ruined the lives of thousands of people who never downloaded it, until the work of a lawyer and two forensic experts exposed the real culprit: a single line of code.

How a Single Line of Code Turned Thousands of Innocent People into Terrorists
ByLock

The Political Context

Turkey's president, Recep Tayyip Erdoğan, is one of the most controversial leaders currently in power. Beyond weathering a constant storm of criticism, he also managed to prevent a coup from removing him from office in 2016. The Turkish government attributes the coup to Fethullah Gülen, founder of the Gülen movement, who now lives in exile.

Turkish authorities are not known for having much sympathy for press freedom, and they have implemented strict internet regulations, blocking access to various services. This brings us to the instant messenger ByLock, which was widely used by members of the Gülen movement (classified as a terrorist organization). As a result, all of its users became targets of subsequent 'purges,' facing detentions, arrests, and loss of employment.

How a Single Line of Code Turned Thousands of Innocent People into Terrorists
Downloading and using ByLock is equivalent to terrorism in Turkey.

A Massive Conspiracy

The problem is that more than ten thousand people have been accused of downloading and/or using ByLock, when in fact they never did. Even a technician who was traveling on President Erdoğan's own helicopter during the coup was declared a suspect and removed from his position. Faced with the possibility of a gross error by the authorities or some kind of foul play, digital forensics experts Tuncay Beşikci and Koray Peksayar began working with legal representative Ali Aktaş. The result of their investigation is a massive conspiracy.

Beşikci and Peksayar describe ByLock as "a tool developed by Gülenists" to communicate with and monitor their members. However, there was something more: a simple line of code, which opens a hidden window (one pixel wide by one pixel high) with a direct link to ByLock's official portal. This "digital beacon" was introduced into other applications, including a music service similar to Spotify, and an app for precisely determining the direction to Mecca.

The forensic experts are convinced that the fake window acts as a smoke screen to hinder the search for movement members. Faced with the strength of the evidence (and the risk of mistakenly implicating officials), the Turkish government published a list of 11,480 phone numbers recognized as "falsely accused", but it was too late for some people. At least four victims committed suicide before they could be exonerated, the accusations have destroyed entire families, and others spent months in prison. The experts have more than 200 devices in their offices, waiting to be analyzed for any technical detail that could clear the names of their owners. A nightmare by any measure.

Source: