How UK Spies Hacked a European Ally and Got Away with It
theintercept.com
theintercept.com
> However, Europol wanted nothing to do with the investigation and refused to assist, according to two sources familiar with the interaction. Europol asserted that it would not carry out investigations into other European Union member states – in this case, the U.K. The Belgians were frustrated and believed Europol had stonewalled them for political reasons; they noted with suspicion that the organization was led by Rob Wainwright, who is British.
I mean, what are we doing here? How can Europol so blatently refuse a case? Isn't that a clear violation of the trias politica?
[1] https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...
Furthermore, all large countries, like Britain, France and Germany, engage in this kind of espionage against "friendly" countries, and none of them want an agency like Europol getting involved, because then they would reduce their co-operation with it, and that would harm the fight against organised crime and terrorism.
Basically, when it comes to a supranational organisation like Europol, real separation of powers is impossible, because there's always a political calculus involved in a collaboration between sovereign countries with occasionally competing interests.
That may well be, but without having any inside knowledge I'm pretty sure that the extent to which such incidents damage relations depends on more than a yes/no question. How was this done and why? Were any non-public inter-agency agreements or silent understandings breached? Was the UK acting alone on this or with the US?
I think all of this could influence the mood in the negotiations now taking place over the future security collaboration between the EU and the UK.
This incident will certainly not be the most important consideration by far. That would be just crazy. But it could add to the potential distrust of a UK now desperately dependent on getting into the good graces of the US, which isn't exactly seen as a staunch defender of the rule of law outside US territory.
Countries don’t have friends, they have interests, and allies.
I'm not in a position to know, but I find that unlikely. Say GCHQ was using Belgacom to spy on some Belgium based terror suspects ignoring Belgian privacy laws. Would that really be the same as if they had been spying on the Belgian government or on EU institutions in Brussels? I think not.
Well, now see it from the point of view of the other side. How will Belgium now see their future cooperation with europol? You are not wrong, but it is a stance which causes supranational organisations to whither until nothing is left.
Why is this tolerated? Is it, perhaps that surveillance a country cannot legally conduct internally is conducted by its "friends", sometimes resulting in relevant information being shared with its own intelligence services?
See, for example, the Jonathan Pollard case, where Israel stole US intelligence on Iran. The spy was imprisoned for almost 30 years (considered a bit extreme by the Israeli system, though that may reflect different norms about incarceration in general). Similarly, an American spy (Yosef Amit) sent information about Israeli troop deployments to the US, and was in prison for 7 years. Both sides worked hard to get their respective spies released, and were stubborn about not releasing the ones they had in custody, but because the countries were allied no one was willing to go to the mat over the issue.
Knowing what motivates your neighbors allows you to navigate the relationships better
* Make a very public stink about it. Publicize exactly what was done, how and who was involved. Attempt to attract the interest of the media in the hope that the electorate of the country in question will find spying on allies objectionable.
* Raise the issue with the EU parliament or possibly the UN. This may not have hard consequences, but officials having to answer for the behavior of their spy agencies can put pressure on those spy agencies.
* Use any of the many cooperative agreements between the countries in question as leverage to demand action against the officials who authorized the spying, evidence that it won't happen again, or compensation.
Of course, all of these have potential downsides, and I've ordered them from what I think is low risk to higher risk. The fact that the usual result is a quiet diplomatic protest and sweeping the event under the rug suggests that governments think this kind of spying is acceptable, and the only problem is getting caught.
We know that this definitely happens. https://en.wikipedia.org/wiki/Five_Eyes#Domestic_espionage_s...
Whether that is the reason more isn't done against foreign intrusions is hard to say. It seems that in this case many people would have liked to punish the UK for it, but there weren't many reasonable options for doing so.
The UK seems well organized ;)
In theory any of these countries could surely just issue an arrest warrant for the head of GCHQ and order their extradition.
In view of that it seems there's some other aspect preventing such actions -- like blackmail by GCHQ. Or controlling powers in Belgian security being in part responsible.
Anyway, I wonder how much of this shit the Belgian public will put up with post Brexit.
It still seems illegal under UK law -- these things do show how the powers that be have no respect for the authority of the rule of law, that our democracy is only allowed inasmuch as it doesn't interfere with their plans.
Belgium was designed to be a toothless and spineless state by the UK, France & Germany, and it's playing its part wonderfully.
Belgium is in its own way more often than not, which is a pity because with Brussels the de-facto capital of Europe the potential to become a regional power-house is definitely there. But Belgian politics, the language divide and a surprisingly large amount of corruption (a bit better than France but substantially worse than Germany and NL) do not help.
Maybe there are more interesting hacks to do ? What about https://www.ehealth.fgov.be/ or https://www.smals.be or nuclear plants networks (these are isolated I think, so extra bonus if one hacks into them)?
Also, anyone has data about the last failure @ Belgacom ( http://www.lesoir.be/125094/article/2017-11-19/le-reseau-pro... )
I'm not saying ehealth is broken by design, but I won't be surprised if it turns out to be broken into a couple of years from now.
Under what law?
The reasons not to have them indicted are "we don't want to keep the rule of law" and "we don't care about costs to our citizens" and "screw democracy, we want to play with the pawns too".
Yes, there is zero chance of extradition because such people give less than two shits about rule of law and democracy ... but that's exactly why one should care. They should evict all our UK government personnel from Belgium.
Low-life criminals.
Edit:
See also: French industrial espionage: http://www.france24.com/en/20110104-france-industrial-espion...
You'd have to toss out France too.
CMA doesn't apply: https://www.legislation.gov.uk/ukpga/1990/18/section/10
The powers of GCHQ are basically unconstrained by the law: "[GCHQ shall] monitor or interfere with electromagnetic, acoustic and other emissions and any equipment producing such emissions and to obtain and provide information derived from or related to such emissions or equipment and from encrypted material [...] in the interests of national security, [...] in the interests of the economic well-being of the United Kingdom [... or] in support of the prevention or detection of serious crime." per http://www.legislation.gov.uk/ukpga/1994/13/crossheading/gch...
But if the laws are written so that they don't apply to the king in the first place of course the law is just.
additionally the queen is the head of the judiciary, so she would be being tried in her own court 'queen (R) vs. xyz'
http://www.royal.uk/queen-and-law
of course the last time the King behaved like this it didn't end too well for him
What rubbish. In the UK, Parliament is sovereign. The British monarchy can be entirely removed by an Act of Parliament. Not only is it sovereign, but it cannot be bound by any previous Parliament.
Your fake facts portray the UK as an absolute dictatorship.
The emphasis on OP's quoted line should be on _technically_.
A bill has to proceed through Royal Assent by the Queen before it becomes law [1]. It just happens that she is always timely with this duty and always agrees with Parliament.
Also the government's executive power is primarily through Royal prerogative [2]. _technically_ the Queen could exercise these powers herself for her own benefit.
The "checks and balances" that keep the Monarch from abusing these powers are a combination of tradition, facing the wrath of the British people and precedent set by what happened last time a monarch attempted to abuse royal prerogative [3]
[1] http://www.parliament.uk/about/how/laws/passage-bill/lords/l... [2] https://en.wikipedia.org/wiki/Royal_prerogative_in_the_Unite... [3] https://en.wikipedia.org/wiki/Charles_I_of_England
> Parliament means, in the mouth of a lawyer (though the word has often a different sense in conversation) The King, the House of Lords, and the House of Commons: these three bodies acting together may be aptly described as the "King in Parliament", and constitute Parliament. The principle of Parliamentary sovereignty means neither more nor less than this, namely that Parliament thus defined has, under the English constitution, the right to make or unmake any law whatever: and, further, that no person or body is recognised by the law of England as having a right to override or set aside the legislation of Parliament.
Note the use of the phrase "King in Parliament" - all law making authority derives from the historical powers of the Monarch, whereas the Lords and Commons guide and use that power. This can be seen in how UK Acts of Parliament begin "BE IT ENACTED by the Queen's most Excellent Majesty, by and with the advice and consent of the Lords Spiritual and Temporal, and Commons" - the Act is _enacted_ by the Queen, with the two Houses advising and consenting to the use of that ability.
Now it's possible that the role of the Monarch could be removed from the process, but it would arguably by one of the biggest fundamental _technical_ (not practical) changes to the British constitution in hundreds of years.
Also, strictly speaking, the King is above the law - the Monarch is the source of all law, and even Parliament acts through that power in its activities: https://en.wikipedia.org/wiki/Queen-in-Parliament
The rules are different for states. Arresting a foreign security official for the actions they carried out in their official capacity is an inherently political/diplomatic decision, and not a normal criminal one.
There are some carve-outs for war crimes, but there's a reason those were so difficult to push through even for countries that haven't committed war crimes lately and aren't even liable to get into any wars any time soon - the whole concept goes against a lot of the assumptions of state sovereignty.
No senior GCHQ officer is going to sign off in a cyber hack of an ally unless they had a really good reason and had covered their own ass.
But if they’d really been freewheeling then it amazes me just how much impunity state apparatus can act with - what hope has an ordinary individual or private company got of protecting themselves and seeking redress through the courts?
good reason: much more information
Covering: was very good, only because of Snowden it got linked to the UK
So even though it might be possible, that Belgium was in it on high level (you hack, but we get data conveniently without legal issues), it is also very possible, that they went for it without saying anything.
This and browsers should really just execute in their own externally managed sandbox
Want to try it now? You can try it with Steam, which is otherwise notoriously annoying to install on Linux:
flatpak install --user --from https://flathub.org/repo/appstream/com.valvesoftware.Steam.flatpakref
flatpak override com.valvesoftware.Steam --filesystem=$HOME
# run it with this command:
flatpak run com.valvesoftware.Steam
Unfortunately, if you're running X11, Steam can still spy on everything you're doing in X11. But Wayland is coming/is here, and fixes that too.:sigh: year of the linux desktop, ...
The only issue is that QubesOS rely on paravirtualization (it's a Xen hypervisor underneath) for process isolation.
(By the way Windows is taking the same path with ApplicationGuard)
At the same time you can run your password manager in a VM with no network access.
However, Qubes can't protect against malicious hardware. I see no way around it, we must have hardware with completely open sources.
« The British spies appear to have targeted Belgacom due to its role as one of Europe’s most important telecommunications hubs. Through a subsidiary company called Belgacom International Carrier Services, it maintains data links across the continent and also processes phone calls and emails passing to and from the Middle East, North Africa, and South America. But tapping into a broad range of global communications is only one possible motive. GCHQ may also have sought access to Belgacom’s networks to snoop on NATO and key European institutions, such as the European Commission, the European Parliament, and the European Council. All of those organizations have large offices and thousands of employees in Belgium. And all were Belgacom customers at the time of the intrusion. »
And the second motivation is that they can. The pre-Snowden speculation was that all major European carriers are targets for NSA and friends, and the Snowden files basically reinforced that view. The question is not “why should they spy on their allies”, everyone has always done that; the question is the degree of success that any given player achieves and what they do with the info they gather. In this case, it looks like the operation was a great success, followed by huge failure (it was burnt to the ground).
FFS.
Despite this, devs are still generally very cavalier about running code from the internet on their machines. Often times they have no choice of security mitigations because their package manager is compromised by flaws in its design.
There are also plenty of companies such as Lench/Gamma who overtly advertise their ability to penetrate any system. You can only buy or lease their software as a state actor, though.
there is a wide spectrum of actors in this space and besides the well known (Gamma/HackingTeam) also include many smaller firms that do not shy from working in a gray area and cater to both criminal enterprises, unstable regimes, warlords. Especially smaller fish fill the niche (AREA[¹], Negg[²], ...)
Though any of these providers they don't just give you a software because "solutions* would (due to their nature) rarely work out of the box. Instead they come with a consulting service contract to ensure the system is correctly used (to facilitate breaching the target). So "state actors" isn't restricted to spy-agencies but low-level law-enforcement who lack the budget and technical know-how for maintaining or creating these tools. So these systems are kind of a poor-mans TAO.
¹ https://www.linkedin.com/feed/update/urn:li:activity:6367357...
² https://twitter.com/ValbonneConsult/status/95357449457630412...
When that story first came to light, what they didn't tell you is that the NSA was also in Deutsche bank and several other financial institutions. Perhaps they still are.