NL national security law to grant automatic permission for targeted surveillance
aboutintel.eu
aboutintel.eu
What is nice with this law is that they can look for things not related to the hack on target devices. If they see something incriminating against you not related to the case, they can still use it against you in a new procedure. Without warrant. How convenient.
In addition, I can easily guess that they don't have to prove that you were really hacked, but mere suspicion or being a potential victim of the hackers might be enough.
I also find puzzling, that I remember people being outraged if country X done something and now when something like this gets done in Western countries, there is very much indifference.
When I talked about this with a couple of friends, who are not interested in politics, they just shrugged it "why would anyone would be interested in spying on me. I don't do anything wrong, so they can follow me to their heart's content. That would be a waste of time." and so on.
Seems like indeed, the media are powerful in regulating emotions and turning the outrage up and down.
If that topic was on the front pages, using the same language as some other issues that governments are using to cover up their ineptitude (so called dead cats), then maybe people would be more aware and inclined to do something about it. But I can imagine anyone trying to run these kind of stories would be quickly shut down.
The media is owned by these same people that push these laws.
I don't remember it. Do you have some citations that would jog my memory?
This also works the other way around. For example, if some far right group in US uses Nazi symbolism, people get understandably outraged, and the system goes into overdrive to destroy the groups and people involved. On the other hand, when random photos of Ukrainian soldiers with Nazi patches sewed to their uniforms keep popping up, the New York Times talks about “complicated relationship with Nazi imagery”
https://www.nytimes.com/2023/06/05/world/europe/nazi-symbols...
The point is, all that matters is “who whom”, and there is little point in trying to parse and analyze the arguments made by powers on rational, objective level. These are always self-serving, and if take these at face value and respond to the content, you have been successfully fooled.
As technology makes individuals more powerful the state wishes to diminish this power.
"Dutch scandal serves as a warning for Europe over risks of using algorithms" - https://www.politico.eu/article/dutch-scandal-serves-as-a-wa...
"Dutch PM has been deleting text messages daily for years: report" - https://nltimes.nl/2022/05/18/dutch-pm-deleting-text-message...
/s
> kidnapped a few thousand kids from their families
What is this?"Dutch government resigns over child benefits scandal" - https://www.theguardian.com/world/2021/jan/15/dutch-governme...
I wonder, at what point does a government become and enemy of the people, and defending oneself is legitimate? is it when the storm troopers comes to take your children based on false premises? if no, what is is then?
im sure a "scandalized government" will say that its "never", but really, when as criminals ever agreed that going against them is okay?
This is absolutely what this is about.
Prosecuting cybercrime is a nightmare, especially if it crosses international borders. NL has historically had a bad CSA hosting reputation, though I get the impression LEO hands have been tied.
This legalizes fruit of the poisoned tree. Or at least, blurs the line until the fruit rolls into scope of plain-sight doctrine. Hire some Israelis to pop a machine and you won't have to deal with mapping Tor/VPN connections across all of the world's jurisdictions until it comes back to your own neighborhood.
The way it's phrased, they're positioned to take down entire networks of pedophiles. Compromise a host, then compromise anything connecting to it, etc.
It's ugly but makes a lot of sense, and there really isn't a better solution short of limiting networks to national borders. Anybody who leads a long enough wild goose chase across the world is more untouchable than Pedo Sandiego. This cuts through the shenanigans.
And unfortunately will be abused in time, but it solves the problems of today.
In the US, they'd do this stuff and make up an elaborate story about how they came to discover the evidence they illegally obtained.
And in order to address emerging threats, they should be able to apply their judgement based on threat indicators like known bad hashes, origin from known bad email addresses or IPs, etc. to call something malicious beyond that threshold...
Does that mean that if they know your account is under attack they can just read all of your emails?
I would give that a big "no" because unless your account has 999 malicious emails in it for every benign one, they have not met the criteria.
If they "suspect" it is more like it in practice, suspecting also meaning "when they want to target you".
They'll be the ones helping send others to the clink and being best buddies with those who do, so fat chance of that restraint or punishment getting to them.
They still need a judge to provide a warrant, there is still oversight.
In practice not much will change, except they only have to ask for 1 warrant instead of 10 like they do now.
An example of such a situation is the EncroChat hack.
No amount of hypothetical "it could also be used against criminals" balances out the bonkers overreach this represents.
NL has lots of problems, but lack of judicial oversight over both the police and the intelligence services isn't one of them, in fact you could make a pretty good argument that the degree of oversight actually hinders going after tech savvy criminals. But better too much than too little. This law won't change that by much as far as I can see.
Obviously the intelligence services would love to be able to tap phones the way they were able to in the past as well as to read all of your mail.
But in practice the network analysis is as much or even more efficient than reading the mail itself in the investigation phase of a case.
0: https://www.tweedekamer.nl/kamerstukken/detail?id=2023Z05165...
1: https://debatdirect.tweedekamer.nl/2023-03-30/binnenlandse-z...
Now they want free reign to spy on everyone.
My main worry would be journalists, those are at some danger from stuff like this especially when they are protecting their sources. If this ever gets abused that's where I would expect it to happen.
Btw, both lawyers and journalists have quite a few special protections under Dutch law and it isn't clear to me that this proposal would trump those protections, in fact if challenged I would expect the judiciary to affirm that those protections carry the most weight.
A typical scenario is that a hacker is using a series of nested accesses to compromised systems, if the original warrant allows for tracking the hacker on the first system then there is no time to obtain warrants for the systems that are uncloaked as the result of the investigation, this happens pretty much in real time. So this provision allows the investigation to proceed and will have a reasonable time allowed to 'catch up'.
It definitely is possible that it will be abused, but that will lead to this provision being disbanded, as has happened in the past when dutch LE overstepped their authority. I'm fairly sure that those lessons - and the cases thrown out as a result - have been learned, but of course it is very well possible that we'll see a re-run.
I'm on the fence on this one, I'd say let's see where it leads because it is clear to me that the digital world is moving much faster than law enforcement can normally speaking keep up with and a lot of crime is perpetrated because of that. The risk of abuse of such methods is always present, and 'protections in theory' that are abused tend to find very unsympathetic judges in this country. It's fairly clear that something will have to change if LE is to keep up with the increase in online crime, whether this overshoots the mark or not remains - in my view - to be seen. It definitely has that risk, but then again, so would every other proposal short of the status quo and that clearly isn't effective enough.
Did it? If anything the history is riffe with cases that oversight was totally lost...
And of course, if it comes to "trusting oversight" the Overton window has already moved to accepting such kind of surveillance.
I am sure you are right, harmful laws have been passed, and then on the basis of their harm, repealed.
But if we are to be reassured that since the law is harmful it will be repealed, that is an illusionary reassurance. Clearly not all harmful laws are repealed, even if some are.
And even repealed harmful laws are likely not repealed until the harm they cause is very evident. Meaning great harm has been done.
It basically reads like this - translation/interpretation errors are mine: Any machine that is compromised by a hacker and that leads to other machines that are also compromised by this hacker are fair game in the process of an investigation.
This ensures that the typical chain of wrapped connections can be pierced, even if some of those systems may well be compromised outside of the owners knowledge. Yes, they are also victims, but their unsecured systems and accounts that are currently under the control of the hacker makes them a part of the investigation.
It's no secret that hackers tend to use many layers of obfuscation in order to reach their ultimate target and this attempts to put a stop to that, with the nice side benefit that if one of the machines en-route is a communications server that other accounts found there are fair game (such as what happened with EncroChat, but there are also other examples).
From what I can see this is all relatively straightforward, and as long as the usual safeguards are in place I do not see a problem with it. Investigators are often laughed at for their lack of digital chops, this doesn't match my own experience, the thing I do see is that they are almost always outmatched because of the constraints placed on their ability to investigate when it comes to digital crime. Some balance should be found here and given a relatively careful weighing of the interests of society and law enforcement I think this proposal really does its best to achieve such a balance. If and when it is abused I fully expect that abuse to be smacked down, as has happened numerous times.
There always will be a tension between LE on the one side and society on the other, LE only has as much power as we collectively grant them and oversight is the ultimate arbiter of what is and what isn't permissible.
As for the context: this is NL we're talking about where such oversight really seems to work well, in other countries that may be a completely different story.
The history of good behavior of NL law enforcement took place, itself, under legal safeguards!
What would have been abuses today, will no longer be abuses. So LE can now act in good faith in a far more pervasive manner.
Unless you think the previous safeguards were superfluous, because of LE good sense, there should still be legal safeguards. More nuanced safeguards of course, that take into account the new LE freedoms. But still explicit legal safeguards.
Otherwise, we are not just depending on LE to act in good faith, but to define good faith. Which is not a good system, or the system before, when safeguards were explicit.
Those 'huge legal safeguards' in practice work out to a fairly loosely specified set of laws that are then interpreted as widely as possible by LE and subsequently tested in court whenever a party feels that they have overstepped the line. This method seems to work well enough that it has become standard procedure and of course new laws will be tested in a similar way. The current investigative process is often very dynamic, far more dynamic than the usual warrant process provides for and in that sense I can see the frustration about seeing a crime in progress and not being able to something about it as something that would need addressing. The international nature of the net and the speed with which these situations develop would mean that the online equivalent of 'skipping state lines' would be enough for a perp to always get away with it. This is an undesirable situation. It is also undesirable that law enforcement would be handed tools that give them too much leeway. Whether this tool is one of those or not will depend very much on how it plays out, given what I know about how the oversight system here works I have very good confidence that if there is abuse that it will be stopped. Dutch LE has learned a lot from various incidents in the past, which led to various backlashes. So they stand to lose as much as they stand to gain here.
(The fallback purpose for safeguards is for when bad faith occurs, to provide a documentable reason for taking corrective action.)
"Good faith" with legally defined safeguards is a much clearer and safer situation than "good faith" without a clear definition of what standards, if any, impact what "good faith" could possibly mean.
They'll use this to hound poor people and anyone who isn't white.
That said, I fail to see how this particular law could be abused in that way, after all, the typical hacking investigation doesn't really know much about the perp until the moment of apprehension. It's after that moment that most of the concern for minorities should kick in, because most of the real life trouble has to do with abusive treatment by the authorities once someone became an identified target. Racial profiling and all kinds of other abuses have been heaped upon minorities time and again, but in the context of hacking suspects prior to apprehension I have no evidence that this has happened.
Usually the problem that this phase of an investigation focuses on (the access to systems that are compromised) is when the hacker is still unknown other than that the authorities are aware they exist.
But I don't doubt that if someone does get arrested and they happen to be a minority that the system will not treat them equally compared to someone who is not a minority. This is a systemic problem that needs addressing, but it isn't directly connected to this law.
Like uninstall Windows without permission?