Everyone who can now see your entire internet history, including the taxman
independent.co.uk
independent.co.uk
This is one of the things that is harmful to your privacy. Should the list of websites that you visit be available for government unless you are under active investigation? Its not just the list of websites but every packet data that your devices send out, which means government could see your messages, data sent to dropbox, online spreadsheet like google docs etc. This is mass surveillance. You should be proud that your government have a website were you can start petitions. Now please use this feature and sign the petition so that this surveillance law can be repealed.
The petition against this bill is at: https://petition.parliament.uk/petitions/173199
You sign the petition and ask your close friends and family to do the same. What you do not need is an intrusive government. I am voicing this because even though I am not a UK citizen, I do not want law makers in my country thinking "Oh those chaps has a fine surveillance law and their citizens are okay with it. Lets adopt that law".
Now get to action. Sign the petition at https://petition.parliament.uk/petitions/173199
Don't rely on that one, google for yourself any poll in the last 10 years. In fact, think about just about any issue that you care about but is not current government policy, and google an opinion poll on it. You'll begin to see that democracy functions very effectively indeed. There are exceptions, such as the death penalty in the UK, but mostly legislation follows the opinion of the public (the voting public actually) quite closely, as we see with gay marriage and drug decriminalisation.
The Guardian article says that "[records] will be made available to a wide range of government bodies", which sounds like politicians and civil servants to me.
Given that the government doesn't have a great track record of proportionate use of these powers, I think this isn't the same as the question asked in the poll. (For example, at a local level http://www.telegraph.co.uk/news/uknews/3333366/Half-of-counc...)
[Edit: grammar and clarity.]
Maybe we do need an intrusive government? Maybe we, as a populace, believe that the data will save lives? That the cost of it existing is worth it compared to the cost of not having access to information on ~insert bad person here~. Maybe you value your privacy differently to us?
That's ok, btw, and I respect your point of view. Please, however, consider that alternative viewpoints are valid before telling everyone else what they must do to ensure their country is governed in a way that suits you.
I'm not trying to be snarky; I'm genuinely confused. Are you saying that UK citizens support surveillance, by and for the UK government, because it might aid the welfare of American citizens?
Obviously we don't get to tell you how to run your country, but at the same time we can certainly be troubled by your country's actions.
I suspect that many of the people for whom this is a non-issue are demographically similar to those who voted for brexit. Their perspectives are different, and shouldn't be dismissed as merely ignorant.
Of course you can be troubled, and you're free to make arguments for why it may be considered a bad thing™ - influencing Brits to give a shit.
I'd wonder where you got that idea then (http://motherboard.vice.com/blog/youll-never-guess-how-many-...).
Can you give an example of "insert bad person here", where having more data made a difference?
> Maybe we do need an intrusive government?
We don't need intrusive government any more than intrusive neighbors. How do you even come to a personal preference for invasive government? Seems actively against self interest.
> Maybe we, as a populace, believe that the data will save lives?
Based on what evidence though? And what lives? How many British citizens were killed by terrorism in the last 5 years? You have far more people dying of smoking or car crashes.
As much as I'm strongly against this bill, that petition is so poorly worded that there's no way I'm going to sign it. I did sign a somewhat poorly worded petition before and, not unexpectedly, the condescending "response" merely addressed the more hyperbolic rantings it contained rather than any of the reasons over 100K people signed it.
There really needs to be some way to greenlight draft petitions before they start getting major traction, so that anything that makes it to parliament reads like it was written by either a lawyer or journalist and not some outraged and poorly-informed 14 year old.
I really seems like that site only serves to placate people that might otherwise write to their MP, go out and demonstrate, or take some other form of potentially effective action, while never actually achieving anything.
Write to your MP instead. And please try to present a cogent, well-informed argument that might actually persuade that MP to champion the cause. Rants like this petition might be effective when it comes to preaching to the choir, but it's never going to change anyone's mind.
A bill allowing UK intelligence agencies and police unprecedented levels of power regarding the surveillance of UK citizens has recently passed and is awaiting royal assent, making it law.
* geographically
https://en.wikipedia.org/wiki/Road_pricing_in_the_United_Kin...
[edit: How many signatures does it take before the debate has to be followed by an action?]
I think the best way of handling this is to have a private code of ethics in the IT industry in the UK. If you are involved in any collection infrastructure, do like a government IT project, and make a complete fucking mess of it I.e. make it cost a fortune and bring bad publicity for any sponsors. Use O(n!) algorithms, use IO heavy storage patterns, piss all over cache lines, spend the entire budget having meetings in Wagamamas, write yourself a new minivan, overestimate everything and play solitaire.
She ignored all my points and just said "we cannot let the terrorists and pedophiles communicate".
> I do not believe that it is reasonable to allow terrorists, paedophiles and criminals to be able to use these same services out of sight to perpetrate criminal acts which harm UK citizens.
Time is up for this attitude.
I sent it via one of those "contact your MP" forms so I don't have a direct email chain.
I suspect in cases like this it's probably a bit of both (and perhaps in the case of this particular MP, she might just be toeing the party line).
The time to stop encryption is gone. TOR & Signal have seen to that.
In any other circumstances this would be fraud and unethical, sure. But is it when you're preventing digital fascism?
Well you can just point at Capita and say "it works better than their shit did".
We're talking DPI here, applied as a dragnet on each and every connection. The bill explicitly states that every connection is to be tracked, which means it disallows the stochastic methods that normally are used for traffic instrumentation.
And even storing "just" the metadata, over the course of a year, that's quite a significant amount of data. Where the hell are ISPs supposed to store that? And store it securely in a way, that only "lawfull" access is possible.
That bill is stupid and ludicrous and the people who came up with it should be institutionalized, IMHO. Not just because of the privacy concerns.
Didn't Tempora¹ achieve something very similar? This law sounds eerily similar. Still stupid and ludicrous, though.
Transparent monitoring for your protection
In keeping with this spirit, here is a reminder of how we monitor (your) CERN activities. We monitor all network Traffic coming into and going out of CERN.
Our new analysis infrastructure will be able to cope with the automatic live analysis of about one terabyte of data every day. All this data is stored for one year.
http://cds.cern.ch/journal/CERNBulletin/2016/05/News%20Artic...
And what is stored at CERN is the analysis results of the data, not the data history itself. Also it's one TiB/day in total for the whole of CERN.
Which refers to the result of the analysis. If CERN would retain all the data that crosses their network, or just the metadata they'd have to roll in truckloads of HDDs each day.
DPI products have been doing that for years. No biggie.
The law is still stupid, but not for technical reasons, imo.
Of course your typical TCP stream is highly redundant and even simple RLE compression will cut that. But ISPs have to provision for the worst case. Currently there are about 60M internet users in the UK.
That would amount to about 536PiB/year of retention data to be provisioned for (worst case). And even if due to redundancies you can compress that down in practice that's still a lot of harddisks to keep around just to store the bare minimum (who with whom, but without context) of a whole country's internet traffic metadata (about 100k HDDs).
That's a significant investment that's expected from ISPs to be implemented in a very short timespan.
From reading related articles, I get the idea its requirements can be implemented in terms of a browsing history, which could point to a date in the internet archive for all the legislator cares. Hint: that's how you compress browsing habits for > quadrillions of requests.
I don't see why one would need complete packet traces of the whole thing.
Good luck doing that with a TLS secured connection. All you see is the TCP stream between the two peers. And thanks to PFS enforced on the server side you can't even go around and force people to escrow their keys.
> I don't see why one would need complete packet traces of the whole thing.
Because that's the only thing an ISP is able to see of a properly encrypted connection.
Source IP, mapped to customer. Timestamp. Target domain (from SNI or the certificate). Passive system identification (os, browser).
The only thing they're additionally interested in is the link and that's the only thing that encryption hides. I'm not sure they even care about cookies and headers in ICR
Also a few years ago DJB proposed to make a systems hostname the nonce of a key/signature and use secured DNS (DNSSEC or DNSCurve) as a means for establishing a web of trust; a CNAME would be used to for translating www.example.com into ${NONCE}.example.com.
Since DNSSEC (and DNSCurve) allow for signature verfication against a small number of root keys (ATM a single digit number) it'd be trivial to ensure an unbroken chain of trust for name resolution, which essentially completely mitigates a state level MitM attack on DNS.
So by combination of securing DNS and nonceing the hostname into TLS certificates you can throw quite a log into state level crypto circumvention. Of course the critical problem is rolling out all the necessary protocol changes and implementation. And of course DNSSEC is used only homeopathically ATM (and yes, I'm guilty of not having implemented for my stuff as well).
Like I said, nothing technically absurd about this law. It is its profound disregard for privacy that we should be discussing, instead of spending our time on technical issues which are solved.
If they don't terminate SSL a la NSA/google, then all they know is that you're talking to a lot CDNs and cloud provider.
I guess they can try to cross-match that with your DNS queries, but that still is fairly generic.
The domain (hostname) you request is inside the encrypted communications between you and the remote server. Only the TCP information is visible (IP, source port, destination IP, and destination port.)
It's the DNS request which reveals the domain you requested.
Then, the matching certificate is sent (again in plaintext) from the server so that you can verify it and extract the keys. It will contain the domain again, although it may be a partial one like *.example.com
So no, the domain is public. The full URL path is encrypted though.
I suppose, with IPv6, we could do away with shared-IP virtual hosting, and hence SNI at least; and perhaps we could even devise a system whereby the domain is omitted from the cleartext-transmitted handshake, say by using the IPv6 address as the cert's DN instead... but then that numeric address would serve as a surveillable site identifier, and you can still be tracked.
Is there any active research in this area? Is it provably impossible? Anyone know?
They are retrospectively making legal things which have been going on for years.
https://www.theguardian.com/uk-news/2014/jan/28/gchq-mass-su...
This allows a massive expansion in the scope of capture and use of that information to more agencies in a "legitimate" manner. At least when it was illegal they had to contain the "conspiracy" lest it get out.
It doesn't make any sense. We spent trillions of dollars every year making intelligence and the military war machine one of the largest shadow economies in the world... We could pretty much solve every other form of death and illness with that money in less time, we could raise everyone in the country out of poverty with that money so they could stand on their own two feet. We could educate those that need education so they could get jobs and stand on their own without the need for Government handouts. So what the fuck.
Some days though, all you can do is throw your hands in the air in resignation and say "Fuck it, you're all crazy! You cause problems and you spend billions of dollars to band-aid the symptoms, just like you do with your medical system."
The underlying cancer is this mentality. We'll do what the fuck we want and treat people the way we fucking want because it makes us rich and then we'll spend billions to deal with the symptoms of this dumbass behaviour.
I hope the riches are worth it because the behaviour is (and I don't treat this word lightly, nor do I mean it with any disrespect whatsoever to those that unfairly get labeled with it) retarded.
Programmers might help by making better tools for thinking and coordinating. Perhaps with a collective IQ boost for enough of us we can avoid the worst.
People worry about flying when stastically they are far more likely to die on the drive to the airport.
They worry about terroism when they are 50lbs overweight.
...and on and on, You'd rather hope the government would be better at assessing these risks in terms of a policy framework but they aren't they appeal to whatever the papers are focussing on and subscribe to the "we must do something, this is something ergo we must do it" school of thought.
It's worrying how far we haven't come.
It concerns me that in approximately 195,000 years of human history (arguably), this is as far as we've managed to come in terms of intra-planetary travel.
It boggles the mind that with the combined ingenuity of the human race, over a period of 195,000 years, we haven't come up with anything more efficient than airplanes. I find it quite pathetic honestly. I expected better of us. It's quite disappointing really.
We wage pointless wars to extract resources from countries we don't want to negotiate fairly with in the name of riches and greed and frankly we've got better things we could and should be doing.
So it's more like 194,700 years of stumbling around tripping over our feet and 300 years of actually making progress.
We went from steam engines to the moon in <300 years.
Yes I'm aware ancient civilizations had made progress and fell back but nothing like the civilizations we have now in an absolute sense, it's really fair to compare a Xeon processor to anything that went before.
Any technologically advanced civilization would have disturbed the earth in ways that would still have shown today (mining, top soil removal, vast irrigation works etc) as well as used at least some of the natural resources, We'd find strangely high concentrations of materials even if it was spoil.
Advanced technologies don't just spring out the ground full formed, you have to bootstrap up the tech tree, something as 'simple' as an iPhone requires vast industrial capabilities backing it from mining and refining the metals, the oils for the plastics, the silicon for the processors, the copper for the traces, each piece of technology is the center of a massive web of interconnected industries and finally people, for advanced technologies you need thousands/tens of thousands of specialists in every single part of the production chain.
As for your Pyramids thing, https://en.wikipedia.org/wiki/11th_century_in_architecture ... yes?
The pyramids while wonders of the world required nothing we'd remotely consider advanced technology to build, ingenuity and a crap load of labour.
From this: David Davis: British 'intellectually lazy' about defending liberty
https://www.theguardian.com/politics/2015/nov/08/david-davis...
To this:
David Davis: Most public opponent of Theresa May’s snooping laws stops opposing them as soon as he enters cabinet
http://www.independent.co.uk/news/uk/politics/david-davis-mo...
"All ministers, whether senior and in the cabinet or junior ministers, must publicly support the policy of the government, regardless of any private reservations."
Although, I would concentrate on Theresa May herself (I considered doing this at the last election when all this was mooted but blocked by the lib dems, but I stood where I live instead.)
We don't know his private position any more, and it may have changed. But I think it's quite likely that his opinion hasn't changed; he just isn't allowed to state it publicly any more. In this case, it would be better for supporters of this position to keep him in the cabinet, where he can at least have a private influence. Consider this: if we could get everyone in the cabinet to share his opinion, we wouldn't have a problem any more. We need more David Davises in cabinet, not fewer.
The MPs to vote out are all the ones who are publicly in favour of the Snoopers' Charter. We can be far more confident in having an influence in our favour this way.
In a sense, UK actually has too much democracy, and too few [formal] checks and balances on the power of the elected legislature.
If you're not going to see what people did on a site, what's the point? Presumably nefarious stuff like pedo rings and dark markets will not stay in the same place very long.
At the same time, people can see what kind of politics you're into. Or porn. Or dating. Which is not terribly useful for the public interest, but you can see a cop abusing this for personal gain. I think Snowden mentioned his colleagues used to stalk their exes.
Also, anyone who's accidentally left WireShark open will know how much data you're sucking up. It's not actually a small amount, and it compounds if you're an ISP. And it sure isn't easy to filter huge pcap files, which you'll have to do if you want to find something specific. And then you have to glue the clues together, totally non trivial.
Last, how will this be used in court? Knowing what sites someone visited is not evidence they did something. Some guy visits an ISIS homepage, is that because he's curious or he's getting bomb manuals? At best you can use it to suggest some guy is a sympathiser, when he might well not be.
It's a matter of public record that MI5 staff have been abusing their powers and had to be disciplined:
http://www.thetimes.co.uk/article/mi5-misuse-of-surveillance...
That's before some idiot walks out the door with the entire database for an ISP and leaves it on a train.
Because you are not a unique and special snowflake. If you regularly go to /r/The_Donald, it says something specific about your politics (probably). Same for /r/LateStageCapitalism or /r/trees. It might not say much, but it adds up to a profile of who you are and what you think about.
If you are emailing certain people, or tweeting them or whatever, GCHQ can build a social graph of people you know, who they know, etc. If you are the friend (or friend of a friend) of a person of interest, you're more likely to be of interest yourself. There are not many criminals like the una-bomber working entirely on their own - most of us need encouragement and/or provocation, and nowadays much of that happens online.
If your search phrases include things like "how to make a bomb", you're probably going to be on a database somewhere. There have been numerous serious court cases (e.g. murder trials) where the prosecution have presented evidence that the accused's search history included phrases like "how to dispose of a body" or "how to poison someone". In other cases, jurors have been dismissed for using Google to research the background to the case they are serving on. I wonder where the information about these searches came from?
Metadata is important for identifying "interesting" people. When you have found them, you "zoom in" and start hoovering up all the information you can find, not just the metadata. It's the greatest spying tool ever, and a way to implement highly repressive government too - just start monitoring people with different lifestyles or "way out" opinions.
http://ghanadailies.com/2016/11/22/uk-government-plans-porn-...
https://www.theguardian.com/commentisfree/2016/nov/23/niche-...
It's about profiling, how that profile is determined, and who accesses it under what circumstances.
I suppose they already have that power, otherwise we wouldn't have what you describe.
But the article says they're only gathering connection metadata, this law anyway. I guess they're already doing even more intrusive things, at least as a way to know who to get "legit" evidence on.
They won't be collecting that information though. They'll only see that you visited reddit.com in all those cases.
For https sites (green lock icon) they only know domain name, for example reddit.com
And from another site on the same issue: "When you visit a website you usually start at the websites homepage such as www.bigbrotherwatch.org.uk/ the Government define this part of a website address (the part before the first forward slash) as communications data which they consider to be non-intrusive information." (https://www.bigbrotherwatch.org.uk/wp-content/uploads/2016/0...)
Given that the ISP's have now been given cart blanche to collect data that is very commercially valuable I can see some of them doing it with the hope they can sell it later.
I've also wondered about that. Presumably it could simply be from the browser history of a seized computer. But now, who knows?
Will it become standard practice to look up the internet history of anyone accused of any crime? Who decides whether this stuff is admissible as evidence?
Or even better start using it to monitor opponents and discover their weak points and alliances. If you wanted a recipe for tyranny when a vindictive leader comes to power, this is it.
This is really a legalisation of the law-breaking that has been going on for decades from GCHQ, and the expansion of their data out to a huge number of government departments. There will be abuse of this system at all levels.
Google tracks it.
It's amazing how bad some people are with computers, like astoundingly bad, It's easy to forget as techies/developers that not everyone even understands crudely how a computer works.
I would urge everyone who can to sign the petition against it.
This, in my mind is a problem, not because of the obvious costs (ISPs storing _literally all_ metadata for a year), and the insidous privacy concerns, but how bad Govts are at keeping information secure. Below are 3 recent and well known examples of Government Mass Data leaks- this information will be compromised at some point, for profit or espionage.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
http://news.bbc.co.uk/1/hi/uk/7449927.stm
https://www.troyhunt.com/when-nation-is-hacked-understanding...
IMHO, trotting out "If you've got nothing to hide, you've got nothing to fear" BS doesn't mean that at some point, that data will be misused, even if the UK (My) Government doesn't suddenly turn dictatorial.
Even if, for whatever reason, you agree with governments being able to access this data in extreme cases (suspected terrorism, whatever) and even if we put aside concerns about governments misusing this power, this bill also relies on ISPs keeping data safe. That is a huge risk in itself.
Not to mention the number of government agencies and departments that can access your data [0]. Does the Department for Transport, Food Standards Scotland or the Welsh Ambulance Services NHS Trust really need access to my browsing history?
[0]: http://yiu.co.uk/blog/who-can-view-my-internet-history/
I'm not so sure that many portions of this law will stand up to legal scrutiny.
This has already been debated extensively in parliament, and got voted through.
This, in my mind is a problem, not because of the obvious costs (ISPs storing _literally all_ metadata for a year), and the insidous privacy concerns, but how bad Govts are at keeping information secure. Below are 3 recent and well known examples of Government Mass Data leaks- this information will be compromised at some point, for profit or espionage.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
http://news.bbc.co.uk/1/hi/uk/7449927.stm
https://www.troyhunt.com/when-nation-is-hacked-understanding...
IMHO, trotting out "If you've got nothing to hide, you've got nothing to fear" BS doesn't mean that at some point, that data will be misused, even if the UK (My) Government doesn't suddenly turn dictatorial.
What concerns me is the sheer number of groups that are being given access from the start, not because of who is on it, but because somebody has compiled that list in the first place. It suggests that there is already a longer term plan in place for the use of this data, and these are the entities who will need access to achieve that end. Otherwise, surely the approach would be a lot more cautious - "We'll limit it to GCHQ and the Secretary of State for now, and all requestss can go through the SoS. That will give us an idea of who actually needs this data on a case by case basis, and we can tweak the legislation as necessary based on that."
Then you look a little closer at some of the entries. Why would the Fire Service need access? Nothing in their job involves anything to do with individuals, at least not to the degree that they have any requirement for access to any data about them. Well, it doesn't say Fire Service. It says "Fire and Rescue Authorities under the Fire and Rescue Services Act 2004". Take a look at that act. Unless you're in Greater London, your fire and rescue authority is your local council. Why did they feel the need to slip your council in through the back door like that? Granted, access is limited to "Watch Manager (Control)", which sort of sounds like a Fire Service position, but it's vague enough that you could legitimately assign that job title to a Traffic Warden's supervisor without anybody batting an eye.
Why do the Food Standards Agency need access? Access for them is restricted to Grade 6, which doesn't seem to have any job title definitions, only a pay range - as of August 2015 it was £54,000 to £69,500. So any person who commands that salary, regardless of whether they need it for that job, will have this access? That doesn't seem a particularly clever way to manage data access.
FFS, are they deliberately choosing the creepiest sounding job titles to give access to?! Sure, it sounds fine when it's linked to the Fire Service, but it sounds dodgy as hell when applied to the Internet Snooper Service.
Step One: Maliciously cause the target to click on a link or open a url (Phishing, Exploit, RFE, XSS etc)
Step Two: With JS, one can easy introduce HTTP connections to any number of websites, such as maybe the Taliban's official website (They have one!), Google Searches for (to think of a few) "Gaziantep Places to Stay", "Turkey Flights", "Opposition to the Kuffar at home", "Dabiq Magazine", "how to join the Khalifah" etc
This could easily be done in a realisic appearing manner, especially to ISP/GCHQ filters and alerts.
Step Three: If any of this tallies with any physical activity (Let's say the target wanted to go Clay Pigeon Shooting, or Visited a Gun Club because he has in interest in .22 target shooting), then they have a case.
Sure, it's defendable, and this is a really simplistic example. But it's basically ruined the target's life.
Remember, it's probably not the "Government" doing this, as this info will be leaked.
EDIT: heck, I'll be stuffed- I tend to actively visit /r/combatfootage...
Here's a nasty example of where this is going. Agencies will be able to compile "watches" on searches across the UK.
The Food Standards Agency will have a trigger for anyone that searches for "Salmonella" for example. They then cross reference the source IP address to any restaurants. Then they march in there and close it down.
For example, they tried to bring in censorship in Australia and failed. Change is possible. Don't be a pushover. You must fight.
Which makes the point about how ridiculous recording an IP address is.
Tons of developer/security websites are blocked on O2 "hacking tools"....
They are using the same nonsensical lists that some web gateways use, anything that is even remotely objectionable is blocked.
https://www.linuxjournal.com/content/nsa-linux-journal-extre...
Meanwhile, you better setup your VPN on DO or one of the cheap ARM-based cloud hosting companies. That's what I did and it works flawlessly for as cheap as $5 a month - or the price of a cup of coffee.
This setup is fine for all types of activities except downloading larger data files, which can be offloaded elsewhere with some clever routing or just jumping on a different box.
I do understand that this might be too much for the average Joe but if you care about your privacy, that exactly what it takes.
So running search engine crawlers like yacy or using browser link prefetchers, could cause sites to appear on this list, you haven't even visited?
Even if you don't use that, you have to investigate every link and external site resource, if it points to a domain/site that also hosts illegal stuff? And how do I do that? Using VPN?
Also content and owner of sites change. I can't imagine such "prove" holding up against a good lawyer in a fair court.
What exactly are they logging? IP addresses, reverse domain names, dns lookups?
They just should provide a white list of sites the lawful citizens are allowed to visit. That would make things much easier and safer for everyone. And the government exists to keep the citizen safe, isn't it?
"The first duty of any government is to keep our country and our people safe." - David Cameron
The TLDR is it's netflow data eg: Source IP, Destination IP, FQDN, Date, Amount of Data
<iframe src=http://www.isis.com style="visibility:hidden">
Welcome to the watch list.
I don't have anything to hide- but a malicious attacker could easily cause me to.
Step One: Maliciously cause the target to click on a link or open a url (Phishing, Exploit, RFE, XSS etc)
Step Two: With JS, one can easy introduce HTTP connections to any number of websites, such as maybe the Talibans official website (They have one!), Google Searches for (to think of a few) "Gaziantep Places to Stay", "Turkey Flights", "Opposition to the Kuffar at home", "Dabiq Magazine", "how to join the Khalifah" etc
This could easily be done in a realisic appearing manner, especially to ISP/GCHQ filters and alerts.
Step Three: If any of this tallies with any physical activity (Let's say the target wanted to go Clay Pigeon Shooting, or Visited a Gun Club because he has in interest in .22 target shooting), then they have a case.
Sure, it's defendable, and this is a really simplistic example. But it's basically ruined the target's life.
Remember, it's probably not the "Government" doing this, as this info will be leaked.
However, May has stated her desire to also leave the European convention on human rights (and replace it with a UK owned Bill of Rights). This is not something that's happening as part of Brexit, and no bills have been presented before Parliament with this as a component or purpose.
I would assume that the government would take the pragmatic approach that it's better to focus on Brexit for now, and deal with the ECHR once Brexit is over with. However, I have no inside knowledge of this, and that's just my wild and unsubstantiated assumption.
So voting for Remain was also a vote to keep the UK locked in to the ECHR. Voting for Leave was also a vote to release that lock.
Also, the UK is signed up to the ECHR which theoretically guarantees a right to privacy. It's sort of like the US Bill of Rights except useless, because it was drafted by Europeans so every right has a giant get-out clause. In this case the so-called "right" to privacy exists only as long as it doesn't conflict with the "needs of a democratic society". That sort of thing crops up all the time in this document.
It's not sufficient to have a constitution. It must have teeth as well.
Unfortunately privacy is not being taught and propagated to the general public in order to prevent this from harming you either you want it or not.
Sell a pre-loaded rpi with an automated "average user" browser that you install on your network, while you keep using VPN for everything else.
wget -r http://wikipedia.org
This is a joke.That way I'll have a "plane jane" traffic log and some VPN data which is a profile that anyone who works for a large company from home would have.
Lose lose all round now.
I'm concerned that information gathered from this will be used in court prematurely to perform "character assassination". And as we know, UK courts have a public gallery full of news reporters searching for juicy stories.
What we are seeing with implementing such laws is a more larger trend. Mental world is being taken under control by Mr. Smiths, agents of the matrix. Our thoughts and self-expressions more than ever are under the surveillance.
What I don't know is whether it is a good or bad thing in general for the mankind, but they way our technology worshipping civilizations develops it seems to be unavoidable. It seems we are way too far in this to go back.
When we do it, we announce it in the Queen's speech then have a law be published, read and voted through both Houses.
As much as I don't like it, an awful lot of other people either don't care or are fine with it. I wish the result was different but this is what you can get when you have a democracy. I absolutely would not want to swap the systems.
The excuse of "if you have nothing to hide, you have nothing to fear" is not only intellectually feeble; it permits a gradual erosion of civil liberties that can easily find the average citizen on the wrong side of the law should any agency casually find it convenient for them to be so. It is a snowball.
On that note. What VPN services are recommended and has anyone got some good guides to this?
Another option is to rent a VPS/dedicated server somewhere outside the UK, with decent bandwidth and data cap, and configure your own VPN between your systems, using the rented server as the internet gateway.
"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him".
I find this all very disturbing, but, having grown up without the Internet, perhaps I'm just a relic from a bygone area. Still, I can't shake the uneasy feeling that this all will lead to a very bad place...
I wonder why that is, just really good SEO on their part?
Yes, within NI a 'southern' paper now achieves about the same circulation as one from Belfast and a considerably better reputation for journalism. Quite a remarkable failure on the BT's part.
As a result the BT has been trying to adapt by widening its news remit and shifting into the tabloid space, as a visit to one of its web pages will quickly show. But most of its 'world news' stories are just AP feed, nothing special.
My neighbour's fiance is a night-club photographer who sells to the BT; 20 years ago such a thing would have been unthinkable in that paper.
I am not from UK, but listen to me if any folks from UK are reading this.
This is one of the things that is harmful to your privacy. Should the list of websites that you visit be available for government unless you are under active investigation? Its not just the list of websites but every packet data that your devices send out, which means government could see your messages, data sent to dropbox, online spreadsheet like google docs etc. This is mass surveillance. You should be proud that your government have a website were you can start petitions. Now please use this feature and sign the petition so that this surveillance law can be repealed.
The petition against this bill is at: https://petition.parliament.uk/petitions/173199
You sign the petition and ask your close friends and family to do the same. What you do not need is an intrusive government. I am voicing this because even though I am not a UK citizen, I do not want law makers in my country thinking "Oh those chaps has a fine surveillance law and their citizens are okay with it. Lets adopt that law".
Now get to action. Sign the petition at https://petition.parliament.uk/petitions/173199
NordVPN is one I keep seeing talked about, so I'll be looking into them this weekend :)
Advantages of a service seem to be location switching, good apps, cheap, and IP mixing.
Disadvantages are that you have to trust them not to keep logs, and lots of Cloudflare captchas, and they would seem like a good target for being compromised by the government.
Also important is to setup outbound firewall (or other mechanism) so that if the VPN goes down, you don't spew your traffic over the open connection [1].
I don't notice any speed difference from daily usage over the last year. Large file downloads I task my NAS to download outside the VPN.
My purpose is only to prevent the ISP from collecting logs about usage, I don't expect it to have much effect if I'm targeted for surveillance and I'm fine with that. Who knows how ISPs will handle the data (we've seen targeted advertising and content injection in the past) let alone all the agencies with less than stellar security practices.
[0]: https://github.com/thomascannon/scripts/tree/master/vpn [1]: https://github.com/thomascannon/scripts/tree/master/vpn/vpn-...
Large downloads is a concern of mine. I downloaded 1TB over PIA this month and it was never a problem. I can probably do these outside the VPN though.
It's not that the UK GOV "doesn't understand how the Internet works" as claimed by many on this topic, but that the citizenry don't care enough to encrypt. The citizenry aren't scared enough to encrypt.
Education is the key here, and it needs to be bashed into a citizen's skull that The Internet is not a black box, and that traffic moving en clair is fair game by Governments, even criminal threat actors in Starbucks with their fake Free Wifi.
We need to keep building abstractions on top of The Internet to make it expensive for spying to take place. The usual solutions apply; TOR, VPNs, TLS/SSL, PGP, et al.
https://www.digitalocean.com/community/tutorials/how-to-setu...
From what I gather, the ISP has to record the sites you visit—but not the specific pages. Does VPN stop my ISP from seeing the loaded sites? Or do I need Tor for that? I’m not too concerned about complete privacy, I just don’t want every website I just don’t want my browsing history to be leaked.
Also if you are visiting https site your ISP only see domain name, not pages.
It neatly circumvents this bullshit, some suspect doing so will put you on a list for a closer look but if your traffic is innocuous who cares, I'm more worried about my useless ISP leaking/losing such data than I am about state intelligence.
Just the existence of these databases held by ISP's built under lowest cost bids will make them a massive target.
I only ask, because routing everything over a VPN provides the illusion of privacy while flipping contracts every month provides some element of real privacy. It is easy enough to check on the activity of people pretending to hide their activity (assuming GCHQ has access to the same access that the NSA do), but real resources have to be spent tracking down people who actually hide their activity.
I have no idea how they allocate their budget for tracking potential threats, but somebody flipping prepaid sims would warrant a closer look if I was analysing the logs.
[1] https://security.stackexchange.com/questions/45509/are-there...
It is not safe, that is true, but it's better than nothing for this specific purpose.
Not saying that's a correct interpretation, but that's likely the conclusion they'll come to.
Still, though, disgusting.
The ISPs will not be compelled to store and share the full URL you visited.
It's akin to the phone companies logging each number called. This isn't as intrusive as people are making it out to be.
When it does, it will make Ashley Madison look like a small thing, and be a good argument against future surveillance.
Are we sure of that? they might require that for UK customers
Also what stops them selling access to this?