UK Government is breaking the law by collecting everyone's internet data
liberty-human-rights.org.uk
liberty-human-rights.org.uk
I want you to go through
a visualization exercise
with me. Really imagine
it.
Nixon's in your datacenter.
He's got his laptop open.
He's logged in! He's got
root! What does he find?
If you didn't break into a
cold sweat at the thought,
congratulations. You are a
good steward of data.
But if Tricky Dick in your
data center scares you,
then consider what you're
doing.
Slides: http://idlewords.com/talks/haunted_by_data.htmNo matter how many examples we get of far better funded companies getting hacked.
https://www.google.com/search?num=100&client=firefox-b&q=tot...
s/nixon/goebbels/
and there's no need to imagine it
That doesn't mean its good for anyone not working for the government, explicitly (as an employee or contractor) or implicitly (as a data collecting company which can be forced to share).
IMO a) collecting data on users and b) doing it in a way that does not preserve user privacy makes you complicit to mass surveillance.
Edit: directly -> explicitly
I totally agree. I'd argue that it's objectively bad for anyone not working for the government. But I'm talking about from the company's point of view.
It just doesn't matter that much, because the inconvenience is minimal for the average person, so the backlash is minimal. I mean, most people cannot even be bothered to use different passwords (!). That's how low the bar is. Say something gets hacked, unless you experience identity theft, nothing happens. Banks will reverse any fraudulent charges. Not even a minor inconvenience. So people won't learn and won't care. Brand damage is minimal. Not worth spending on infosec if the maximum fine is less than your CEO earns in a month. Meh.
I think the masses are not scared enough to encrypt their communications and that's why such an apparatus has crept in so brashly and abruptly, sort of a 'surveillance creep'.
The moment the masses are conscious of the fact we are going through our second 'crypto war' is also the moment they might encrypt. Not that crypto is some munition they can use, as is wrongly spouted by the cypherpunks (IMHO), but that crypto can provide viable amounts of privacy for their needs and it doesn't need to be absolute privacy as spouted by the 'go dark' movement. Just enough that I can surf the web without my eyeball hours being monetized or that the pressure cooker I am interested in buying is not a potential tool to be used in a terrorist attack several weeks later.
Also, if there were a proponent of this kind of collection, wouldn't it be fine for a company like Google, Facebook, Microsoft, etc... if someone with the position of US President wanted to "sit in the datacenter with an open laptop"? Because then they'd be using data as a currency, which they are already very comfortable and capable of doing to meet their own and the "gov" agendas.
~2010 due to a number of factors a third party (the lib dems) gained a significant increase in votes on campaign promises centred around free university courses for UK citizens.
As no party had a majority, a coalition was formed between the conservative party & the liberal democrats.
The Lib Dems went back on every single thing they had promised and essentially forced a new generation of voters to either pick conservative of labour.
Also the libdems actually did manage to achieve quite a few of their campaign pledges: https://www.theguardian.com/politics/2015/apr/15/how-much-of...
What they did is go back on tuition fees which the press then merrily highlighted at every opportunity. Meanwhile New Labour & now the Cons are free to break promises every day of the week with barely a whisper from their mates in the press.
Other parties got around 30% of the vote at the last General Election, but won only 13% of seats.
(It is also worth noting that the Liberal Democrats did not gain a "significant increase in votes" in 2010 (23%) vs. 2005 (22%), and that they won fewer seats in 2010 than in 2005.).
Everyone trashes them for supposedly just bandwagoning on student loans and not backing it up, but they were the junior partner in a coalition - right now we are seeing the proof that their involvement held the conservative government back from a huge range of terrible policy, which they are now pushing through given their full government.
It's a travesty the Lib Dems got slaughtered, right after proving their value.
Secondly, their popularity was built in large measure on their reputation for honesty - for not being the same two-faced shits as other politicians. Signing an ironclad pledge on tuition fees before the election and then reneging didn't just piss off students and their parents, it cannibalised their own political brand.
As to the second part, this often stated thing about the pledge on tuition fees - they were the junior partner in a coalition - expecting them to somehow be able to uphold all their policies in that situation is insane.
They took the sane route and compromised to make sure that the situation was better, apparently people will only accept zealous idealism and pragmatism is wrong. They held a louder voice in the role they had, and used it to ensure better policies from the government in that period.
They made the best play, results-wise. That apparently doesn't matter to the voting public.
I'll agree so far as saying that Conservative/LibDem governance produces better policies than solely Conservative governance (as least as far as civil liberties etc. are concerned), but I'm unconvinced it was the right move to make.
Firstly, it may have enabled them to keep the Conservatives in check to some degree, but, by providing an effective government majority, it may have resulted in some of the Conservative proposals passing at all, rather than being rejected in the House of Commons if the Conservatives formed a minority government.
Secondly, I suspect that the LibDem support of the Conservatives, and the years of stable government that followed, may have contributed to Conservative gains in future elections (the Conservatives being the senior party, it is easier for them to claim the credit, deserved or otherwise).
> As to the second part, this often stated thing about the pledge on tuition fees - they were the junior partner in a coalition - expecting them to somehow be able to uphold all their policies in that situation is insane.
Again, I'll agree so far as them to uphold all of their policies in coalition is something that could never happen, but the pledge on tuition fees was rather different from the traditional manifesto pledges. It was signed by individual candidates/MPs, rather than as a party, and stated:
"I pledge to vote against any increase in fees in the next parliament and to pressure the government to introduce a fairer alternative"
Expecting MPs to follow through on something so plainly stated, and importantly something that is not contingent on the LibDems being in government, is not unreasonable IMO. It should have been obvious that reneging on that pledge would cause a huge loss of trust in the LibDems, regardless of what they were able to achieve in government, especially in a year when one of their election broadcasts was titled "Say goodbye to broken promises".
They were all so blinded by actually being asked on TV most never seemed to think it would be a problem that they were being asked to defend things completely opposite to their views.
Why the beep they didn't say "Your policy, you defend it" I'll probably never know.
On Topic: I was worried this would be a "we're leaving the EU so we don't care" thing. But turns out they already lost in the UK courts and it was the government trying to use the EU to overrule the British legal system. Which is the first good thing I've heard the British legal has done in ages.
Tom Watson, the MP who brought the case, is deputy leader of Labour.
Davis, the Tory, didn't vote.
That'll be an interesting Cabinet meeting.
http://www.independent.co.uk/news/uk/politics/jeremy-corbyn-...
http://www.independent.co.uk/news/uk/politics/jeremy-corbyn-...
[1] https://www.theguardian.com/uk/shami-chakrabarti Just look at her history before and after Labour peerage (Aug '16).
[2] http://www.huffingtonpost.co.uk/entry/shami-chakrabarti-has-...
[3] https://www.theguardian.com/uk-news/video/2016/sep/04/shami-...
The ECJ has agreed with the British High Court's previous ruling on DRIPA, so should still carry weight regardless of Britain's status within the EU (unless further legal amendments are made post departure, such as the replacement of the Human Rights Act).
In Sweden Telenor immediately seized saving traffic data: http://press.telenor.se/pressreleases/telenor-upphoer-med-la...
I don't think his position makes it any more interesting though, this issue has little to do with the EU - other than it being the location of the appropriate court for as long as we remain in the Union.
As long as he is part of the cabinet, we can assume Theresa May will at least be faced with internal opposition. And as long as the Tories have as slim a majority as they do, he will be one of the people guaranteeing that e.g. her ambition to abolish the Human Rights Act won't happen, as he's virtually certain to leave cabinet and stage a rebellion in the commons if she goes that far.
There's plenty of stuff he won't be able to stop, though, especially in cases where May can rely on Labour to prop her up.
"App used"? How? I understand that "website visited" is clearly 'public' even if not recorded by ISPs for the state, but I don't understand how, technically, "app used" is known - unless it means "web application visited", which is of course exactly the same as "website visited".
I saw a very interesting hearing when the Bill was still at committee stage, discussing concerns raised by small and community-run ISPs that although they of course have every intention of complying with the law, it's so non-technical and under-specified that it's not at all clear to them what they need to actually do: precisely what to record, how to store it, what guarantees they need to be able to make (e.g. are they liable if data is corrupted? If they're hacked?) etc.
They probably mean for instance the Gov would know when you use Instagram, Facebook etc on your phone.
As the iOS or Android app will be sending requests to Instagram, Facebook etc IP and the Gov will log this.
But how?
> As the iOS or Android app will be sending requests to Instagram, Facebook etc IP and the Gov will log this.
That says that I "visited" (in a sense) Instagram, Facebook, etc. - not that I used the Instagram or Facebook app to do it.
I don't think that's a meaningless distinction.
However, the use of the term app is probably more to do with vast usage of apps to now consume the internet. So if you now just use the term "website", many of the general populace (who aren't technical) will think that's fine they won't know because I use apps for Facebook etc.
It's important people know that this covers access through apps. So they simplify the usage of that term.
Technically incorrect yes, but probably a proper description for general readers.
They could have made the law more general by talking about 'messages' or 'accesses a server'.
They said app used. That genuinely could compel Google or Apple to hand over your usage metrics.
At the very least, they could make a law that would focus most of the energy in hacking those who do try to conceal and protect their privacy. They blindly believe the time trotted motto of "if you're doing nothing wrong, you have nothing to hide."
I Googled some info on Sudafed dosages (specifically interested in pseudoephedrine, even though they changed that to phenylephrine apparently) and half of the links were blocked because they were "adult content".
Well fuckers, if you're blocking information like that, good fucking job. It will not affect anyone but the general population, so it's all good. The Brits are pretty complacent with what the government tells them, compared to many other countries.
Now the problem is that the current government is desperate to get rid of the HRA, because of a mixture of authoritarianism and ridiculous and often plain false tabloid stories about criminals supposedly getting away with crimes because of "human rights".
There's a large part of the population that is very vocal against things like "basic human rights", and it's happening all over the world.
Doesn't matter if it is by ignorance or by political preference. I think we need to acknowledge that and take action before it's too late.
So far, politicians have taken the sane path, but I fear this is going away.
Now, if he's booted from or leaves cabinet, we should be worried as in that case it's a good sign May is about to take her authoritarianism one step further.
The ECHR is quite problematic in a lot of ways. It would not be hard to do better.
Pulling out of it tells every tinpot wannabe dictator that it's perfectly fine not to sign up to basic human rights.
Seeking a technological solution to a political problem is not going to end well.
:(
I guess for now EU members can still use VPNs and the like.
I believe some of it has already come into effect. According to s. 272[1] several sections come into effect on the day the Act is passed and another few after a period of two months.
[1] http://www.legislation.gov.uk/ukpga/2016/25/section/272/enac...
We've got a second chance to fight this. Give em both barrels everyone!
And they've put it through whilst most people are busy being annoyed over the Brexit and you've got a situation where people just have bigger (in their minds) things to worry about.
In addition to laziness, there is democracy and patience. Threatening your society with violence and anarchy shouldn't be taken lightly.