UK police secretly downloading content from suspects’ phones (2018)
privacyinternational.org
privacyinternational.org
The whole documentation (redacted) is available at https://www.whatdotheyknow.com/request/mobile_phone_data_ext... (search "ACESO documents"; note that most of the page is correspondence relating to FOIA and the usual practice of being denied and having to complain repeatedly)
The rollout was halted in Scotland: https://www.scottishlegal.com/article/police-asked-to-stop-u...
> "“It appears that, in relation to the introduction cyber kiosks, only the benefits were presented by Police Scotland to the SPA, with the known risks not provided. The SPA, for its part, seems to have accepted the information provided with very little critical assessment.
> “Even the most fundamental questions, such as the legal basis for using this technology, appear to have been totally overlooked."
(Yes, that sounds like Police Scotland to me)
How ironic that despite the continued protests against picture ID cards based on privacy concerns, the UK is the most watched country based on the number of CCTV cameras per square mile, and now this.
It's because people have given up hope of winning the war against the surveillance state but they still feel like they can opportunistically win a few battles.
Let's just say that it wasn't just a picture ID card; it was the camel's nose under the tent flap for a massively intrusive national database system with huge potential for misuse, abuse, and creeping changes of scope.
Today the UK has a de-facto biometric authentication system in the shape of the Identity and Passport Office database and the DVLA driing license database: between these, there's roughly 90% coverage of the adult population. But because it's opt-in and voluntary, and the police can't at any moment challenge you to produce a card and arrest you instantly if you're not carrying it, it hasn't produced the same push-back.
(As for those CCTV cameras? Most of them are in private premises, subject to GDPR data sharing restrictions. It's actually illegal for a shop CCTV system to cover the pavement outside, for example. The police only have access to them when a crime has been reported and half of them aren't working, as my wife discovered when her bicycle was stolen from right under a cluster of them …)
There was a popular campaign against the government keeping around the hand written, cardboard ww2 National ID cards on civil liberties grounds. They didn't even all have photos, and were super easy to forge! Attlee had kept them around throughout the Labour administration and proposed using them, and this will sound oh so familiar to anyone who remembers the Blair attempts at an ID card and database, as a "a key that could be used to access all the benefits of the state, from rationing to voting to NHS services". The chief Law Lord in the final appeal said of requiring "all and sundry" to produce ID cards that it "inclines them to obstruct the police instead of to assist them".
It was ultimately Churchill's second term that repealed them in the early 50s. The same decade a Conservative politician and lawyer drafted the first European Convention on Human Rights.
Same old arguments, 70 years on. I'm not sure those Tories would recognise today's bunch though. :)
Do you have a source for that, please? I've been wondering about this kind of issue for a long time, as a lot of private premises now have cameras obviously overlooking public space outside or even more private areas like the gardens of neighbouring properties. Personally I find that quite intrusive in terms of the public spaces and rather inappropriate in terms of neighbouring private spaces, but given the many ambiguities in our data protection and privacy laws, it's not obvious to me what would make it illegal in black and white. Both the UK government web site and the ICO do have specific guidance about domestic CCTV systems that clearly allows the possibility of and provides guidance for systems that overlook areas outside the operator's own property.
All of the Windrush fiasco and other Home Office outrages show that the UK is pretty comfortable with bureaucratic authoritarianism so long as they think it only applies to immigrants.
Non-photo UK driving licenses are in fact still legal [0] although they are not now issued. If you need a replacement or update (e.g. on address change) the new license will be the photo version. They are still valid for hire car.
If I need photo ID I use my passport. I do not therefore have an official photo-based identity document on me when travelling routinely in the UK.
Neither do I - there's no requirement to carry your driving licence whilst driving.
As for the UK being the most watched CCTV density - well - have you seen the quality of most of those CCTV's, egads. Just look at some of the images the UK police release which have been pulled from CCTV. Very rare that their is ever anything that would stand up in court. Then most of these CCTV are private, mostly shops.
So yes, we may (not sure if still have) the most per square mile, but darn - the quality on so many is terrible. But then, older camera's and the rush to be first often does that. Beijing on the other hand, now that's a CCTV network I dare say who could tell you were you lost your house keys in the park if so inclined.
But we British do excel at irony. https://en.wikipedia.org/wiki/File:Situational_irony_-_Baker...
It's not like its all state surveillance.
The same in Germany with taxes, people discuss increasing taxes for the rich, who are happy to confront this, because the real deal in Germany is not paying taxes, not paying social security and health insurance by the rich.
Do you disagree that pervasive surveillance would make it easier for an oppressive government to collect data on their opponents and imprison or harass them? The East German Stasi didn’t have the advantage of universal surveillance and they did a great job of suppressing political opposition. Do you think their job would have been easier or harder with pervasive logging of all conversations conducted electronically or in public or private spaces?
Good god, reading that was horrifying. What a bunch of thugs on that police force. Absolutely disgraceful.
Just the presence of surveillance alone discourages criminals from acting in the first place. Without any surveillance, I don't think criminal activity will increase by just .000001%.
When it comes to cyberspace, digital surveillance, I fled Windows for Linux and read /r/StallmanWasRight. Bad stuff happens in cyberspace, but none of it is meaningful enough to me to warrant the limitations to privacy that we endure IRL.
Does anyone else have this arbitrary configuration of opinions?
What's this based on?
From a quick google, it seems there isn't a clear consensus that this is the case.
I lost one of my ex-school mates in an market-place explosion (2005 Delhi bombing). While the London Bombing suspects were identified, all suspects in the Delhi bombing that same year were released due to "lack of evidence".
I am completely in favor of surveillance of public property.
They were identified. After they’d blown themselves up on trains and a bus. The one person ‘identified’ as it was happening was in fact mistakenly identified and killed by the police.
Surveillance only helps in situations like this where the authorities have intelligence upfront. Even then you can argue that regular on-foot surveillance is a more proportionate approach over serveilling the entire nation ‘just in case’.
I was in London when the bombs went off (I worked on Russel Square along from the bus bomb - I would walk past the site, every day, to and from work; and have a friend who was on the train going from Liverpool St that was blown up). And, I remember being nearby (and hearing) the IRA bomb in Bishopsgate. I still believe very strongly that governments should not have carte blanche rights to spy on all citizens. Privacy is more valuable
Binney had the answer.
Below I have linked real posters and not satire - unless their graphic designers are covertly revolting in protest.
https://p10.secure.hostingprod.com/@spyblog.org.uk/ssl/spook...
https://www.tandfonline.com/doi/full/10.1080/10242694.2011.6...
But it didn't prevent the bombing
I am very sure, inspecting phones has, or will at some point in future be used to stop some crime or terrorist attack, but that's not the point here.
Oh Gosh. It's been years since I owned a car, but I've been merrily hiring them here and abroad two or three times a year. I'm a bit surprised that no one has denied me a vehicle as a result :\
Thanks for the heads up - I guess I need to get mine updated!
- ed
OH. PHEW. @KineticLensman states this isn't quite the case in another response here. I did wodner why none of the hire companies had said anything!
Obviously the NIR was the big deal but nobody cared about that.
Forensic devices were installed in patrol cars and officers could download phone contents during a traffic stop. I’m sure these devices are a lot more advanced now.
https://abcnews.go.com/Technology/michigan-police-cellphone-...
That's a euphemism if I've ever heard one ;)
There may be places where this is routine, but it really shouldn't be - anywhere.
If you'd like to educate yourself on some of the transgressions of UK police in the past, and the extent to which subsequent cover ups have gone, I'd suggest reading some recent Irish history.
Even today it seems like there are many apps available that claim to keep photos, docs, etc., safe from prying eyes. But this seems to be accomplished just by putting the files into a location that's hidden from the standard apps, and requiring a password to run the one app that knows where to look. So, useless against something that captures the whole filesystem.
Highlighting the potential value of data from mobile apps, a recent murder investigation in Germany utilized metrics from the apps on individuals’ phone. In that case, Apple’s iPhone health app activity record stated that the suspect was “‘climbing stairs,’ which authorities were able to correlate with the time he would have dragged his victim down the river embankment, and then climbed back up.
I'm not sure if the data comes from physical access to the phone or from asking service providers.
Home data
Health data (iOS 12+)
iCloud Keychain
Messages in iCloud
Payment information
Quicktype Keyboard learned vocabulary (iOS 11+)
Screen Time
Siri information
Wi-Fi network information
One odd and notable exclusion though is iCloud Backups. If you use that feature, at least from what I can tell it can actually compromises the E2E of some of the others since keys are stored as part of the backups. I guess Apple considers backups to be more important to the general population to have fallbacks for, but it's also a big privacy hole and I still consider it a bummer that they don't at least have an option to not store keys with Apple there and just have it be an encrypted blob (with UI for printing out recovery keys and such of course, but they've long had that for FileVault already).Also worth noting that Apple's overall scheme for multi-factor and general Apple ID auth and management remains an irritating worrying clusterfuck, but at least there have been some ongoing improvements I guess.
Clearly they could still go significantly further, as the lack of end-to-end encryption for things like iCloud backups of photos demonstrates.
Another black mark against them for now is their persistence in walling off their ecosystem so much that iCloud (or maybe iTunes running on additional Apple equipment) is the only reasonably usable and future-proof method of transferring data between devices. It really should be possible to import and export common types of data like calendars, photos, contacts and notes in standard formats using standard protocols, and it's clearly a deliberate policy not to support this.
Even so, the world of iOS now appears to be in an entirely different class to the Android ecosystem in terms of privacy and data protection. At least with Apple devices, you can (if you're willing to spend an hour or so toggling settings) basically turn off all of the data sharing and remote services if you just want a modern phone with standard communications tools like web and email available. And at least Apple doesn't have an obvious commercial interest in undermining its own devices' privacy safeguards.
Though those truly paranoid - there are many ways to curtail such actions, re-wire the USB lines demanding you use a equally rewired USB cable and many other avenues.
But back to the police - what irks me is that whilst they can pull all this data - it is futile unless they use it. Alas the level of data-mining is very much lacking here - unless however it is related to a headline case and then the full PR budgets kick in and the real policing happens (cynical I know, but based upon decades of observations, that are equally shared amongst people in the force I know).
The real thing many overlook is that UK laws are already in place that telco providers have to keep copies of all calls made and text messages for many years (3 iirc at least).
However, things change and it is how long they retain such images of phones content that makes things concerning. After all, laws change and what was legal yesterday, probably won't be tomorrow. But more so - perception and interpretation. As an example the fad of planking could be classed foul of many a law in most situations if zealously applied it could be classed as a performance and as that fun planking video in the local park needed a performance license from the local authority. Then lottoiring laws and many others that came in to curtail real issues but.....if social perception changes could render innocent and well mannered acts foul of legal redress down the line due to cultural change. But been many a innocent fad, all harmless and an edge-case accident happens so that fad then becomes demonised. That happens. But with social media and other snapshots of your life moments via your phone immortalized. Whilst the spirit of the law is more important than the letter of the law, that spirit over time can change and yet facts do not and afford reinterpretation at a later time of the event. That end up recontextualizing it all and some innocent, totally harmless and socially acceptable action of the time could become antisocial tomorrow. Cigerrettes - classic upon that, and who knows, maybe in a few hundred years time, pictures of this era of people smoking will garner cries of murderer in future minds and classed as terrorist poisoners murdering the innocent around them with their polluting weapons of mass destruction.
So yes, how long they retain it - would be the real concern about all this.
Do zip bombs still work in 2019? I'd expect most antivirus and unzip programs can detect this easily, no?
Might prove that they are the perfect way to store your sensitive data - buried deep inside a zip-bomb, knowing AV will filter it away. Food for thought.
Most police forces in the UK are using digital forensic "self service kiosks", which allow ordinary officers to create images of the storage of mobile devices seized during criminal investigations. Privacy International are concerned that policies and procedures surrounding the use of this technology may be inadequate. In particular, they are concerned that the Police and Criminal Evidence Act gives the police relatively broad powers to image devices without a warrant. The report does not identify any specific evidence that these powers are being abused.
PACE:
https://www.legislation.gov.uk/ukpga/1984/60/contents
https://en.wikipedia.org/wiki/Police_and_Criminal_Evidence_A...
RIPA:
https://www.legislation.gov.uk/ukpga/2000/23/contents
https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...
This game was over the moment that law passed.
The problem the article is highlighting is that police are gathering data from phones outside the powers granted by RIPA. Police are potentially acting unlawfully, and so now we have RIPA we can stop them doing so.
The UK government has passed quite a few laws and government departments have taken their own interpretations of these – for instance, the home office has been using tax filing corrections (fairly routine practice in the UK) as evidence of dishonesty – in some cases the amounts owed didn't change – and using these to write the your-immigration-status-has-changed-go-home-before-we-deport-you letter. [0]
A lot of interpretations of legislation fall under the "there is no case law – it is probably unlawful but plenty of others are doing it and the worst that can happen is..." category.
[0] https://www.theguardian.com/uk-news/2018/nov/23/home-office-...
A running, unlocked phone may be hacked by zero days. Encryption at rest... currently no.
Any body have more details on these technical aspects ?
Source: https://arstechnica.com/information-technology/2018/02/celle...