UK government to monitor email and web use under new laws
bbc.co.uk
bbc.co.uk
A lot of people don't even mind the absence of privacy, the key point is that that is a decision they can make for themselves. Even if everybody would gladly give away everything on facebook the moment you force them to do so you cross the line.
I'd even be willing to argue it with respect simply to communication performed as part of their work. More and more "governance" seems to be too sensitive to allow people being governed to be aware of it.
Its awful that an institution of questionable democratic legitimation (EU commission) is forcing a democratic government to implement laws, that are against their constitution. The worst thing is, that the big political parties dont see anything wrong in this.
You used the word "democratic" twice. But I don't see what democracy has to do with it. The whole point of a democracy is to allow the majority to bully the minority. The protections you need are Constitutional limitations.
The first question is too subjective in general to have a useful debate. I'll just say that complaints about interference in local affairs have been a mainstay of all political unions ever formed, including The United Kingdom of Great Britain and Northern Ireland. Just ask the Scottish. And it's completely natural because "interference" is just another word for "governing".
However, the parent post was about the democratic legitimacy of the EU commission. The commission is not directly elected just as most other governments are not directly elected. In most countries cabinet ministers are not even elected MPs. Parliaments are elected and sometimes heads of states but rarely governments. The closest thing to an elected government are probably the presidential systems in the US and France.
Most critics of the EU do not want an elected EU president or a directly elected EU commission as that would obviously take away more powers from the nation states. That's a legitimate position, but it's incompatible with criticising the EU for not being democratic enough.
Please link or state the directive before claiming such.
http://en.wikipedia.org/wiki/Data_Retention_Directive
Also check the german wikipedia article, for more references.
The EU says:
Article 4 Access to data Member States shall adopt measures to ensure that data retained in accordance with this Directive are provided only to the competent national authorities in specific cases and in accordance with national law. The procedures to be followed and the conditions to be fulfilled in order to gain access to retained data in accordance with necessity and proportionality requirements shall be defined by each Member State in its national law, subject to the relevant provisions of European Union law or public international law, and in particular the ECHR as interpreted by the European Court of Human Rights.
That would leave the UK quite within its rights to require a court order or warrant before access was granted. But Oh no.
The EU Directive makes no mention of logging Web URLs either.
Citation please. As far as I know, it isn't.
I like that. I been saying to hippy mates of mine for a while that while they have been trying to change the world through the application of drum circles and yurt building classes, the geeks have quietly been building in the open source movement, the only successful communist (with a very small c) system to successfully compete with capital on its own terms, and many are now setting their sights on using it for actual manufacture.
If you don't like the world you see around you, at this point in history one of your best chances for empowerment is to learn some form of engineering and then apply it.
The word communism can also describe systems that are mutual with consent, and most of the states that claim to be communist appear to be run by totalitarians who use the word and associated dogma to seize and hold power under the promise of equity in the future, so I am not sure there has ever been an actual communist state, by the terms of the philosophy.
Personally, I'm a Groucho Marxist, so my main tenet is that I wouldn't want to join a club that would have someone like me as a member. ;)
Look, a four year old child could understand this. Quick, someone fetch me a four year old child. I can't make head nor tail of any of it.
[edit] I wonder how it would go if I tried to work Groucho Marx quotes into all of my posts. Something tells me it might not go too well.
Unless a good majority of people get radical and stamp this out properly, and for every one world wide, this will creep and creep until the internet becomes nothing more than a sales portal.
i alway wonder what makers of james bond can do with these facts clearly some people are no more comfortable with the power of the web
The ultimate example is drug policy.
http://en.wikipedia.org/wiki/United_Nations_Commission_on_In...
http://en.wikipedia.org/wiki/Harmonisation_of_law
The US federal government does the same thing to the states:
Under the Federal Aid Highway Act, a state with a minimum drinking age below 21 would be subjected to a ten percent decrease in its annual federal highway apportionment.
http://en.wikipedia.org/wiki/National_Minimum_Drinking_Age_A...
Again, this really isn't controversial. It's the essence of international politics...
We are going to miss the open internet, but there will always be "ham radios" like Tor or other technologies in the future.
I'm glad I don't live in the UK but pissed since they set an example others might be tempted to follow.
Looking through your comments it looks like you're in Sweden: Sweden already has similar legislation via the FRA law, which authorises the Swedish government to wiretap all traffic entering the country. A lot of countries have similar arrangements: not all arrangements are backed by legislation.
In many ways it is better to have this thing legislated: at least then it's out in the open. It's naive to think that large ISPs in countries without active legislation aren't linking intelligence agencies into their networks.
The legislation in the UK is presumably intended to speed up the time from getting a warrant to putting the tap in place: I would imagine most large ISPs (BT, Virgin, etc) are already plugged into GCHQ, in the same way the NSA intercepts all AT&T traffic.
Why is it better to have this thing legislated? The argument that it is better to have laws like this because otherwise they will just do it anyway (illegally) just blows my mind. There are many advantages to having stuff like this unlegislated, without support from the law they can't actively act on the data, something that is far better than having the FRA-law. Especially when the intent of the law isn't to act on it but rather to observe.
In other words that argument is of the lines that "since they already have the information (which they illegally intercepted), why wouldn't we want to give them the legal right to intercept that information so that they act on it as well?". How does that make any sense?
Even with a warrant the data collected by FRA wouldn't be legal to use in a court if both parties (sender and receiver of a message/whatever) was in Sweden (regardless of whether the traffic took a detour across the border or not (too/from gmails servers for instance)).
Whether or not this interception is currently legal / illegal, this has been happening on a massive, global scale. The UK is just catching up to France / USA / Canada in this regard. The EU legislation on the books for Saas, ISPs to log all their traffic for an indeterminate time is also a huge cause for concern.
Shameless plug: Use PrivateSky.
Oh, and we have a law in the UK which makes it a criminal offence, punishable by 2-5 years in prison, to refuse to hand over the private key so that your data can be decrypted. :(
That does not make me fell much safer. In Sweden there is nothing preventing illegally obtained evidence to be used in court. The idea is that the one obtaining the evidence will also be punished for his crimes, but I can easily see that case not even reaching court.
How about the other option: we make it strictly illegal for ISPs to cooperate with intelligence agencies (or anyone else asking for data) unless there's a warrant involved (and even then only to the extent of the warrant).
Note that this talks about the content of emails, calls or messages. The police will still be able to see the metadata without a warrant.
I think in the UK the public accept that the security service (MI5) and SIS (MI6) have greater leway but that the police should be much more restricted.
The problem is when you let "uncle tom cobley and all have access" is where people get worried.
This effectively the position the Stella Rimington ex head or Mi5 said in the house of lords a while back.
No, it's actually worse having it legislated.
Having it happen covertly (and in shame) by the agencies, would be much preferred.
By legislating it, you enable it to be more widespread, used in court, etc. But the worst thing is, that by legislating, you make it normal, and that pushes the boundaries of what is acceptable. Since now, this monitoring is acceptable, then even worse things can take its place in the "secret" surveillance domain.
This line of thinking, is similar to what (philosopher) Zizek describes when talking against legalizing torture in the US:
"*Why not go further still and legalise the torture of prisoners of war who may have information which could save the lives of hundreds of our soldiers? If the choice is between Dershowitz’s liberal ‘honesty’ and old-fashioned ‘hypocrisy’, we’d be better off sticking with ‘hypocrisy’.
I can well imagine that, in a particular situation, confronted with the proverbial ‘prisoner who knows’, whose words can save thousands, I might decide in favour of torture; however, even (or, rather, precisely) in a case such as this, it is absolutely crucial that one does not elevate this desperate choice into a universal principle: given the unavoidable and brutal urgency of the moment, one should simply do it. Only in this way, in the very prohibition against elevating what we have done into a universal principle, do we retain a sense of guilt, an awareness of the inadmissibility of what we have done.
In short, every authentic liberal should see these debates, these calls to ‘keep an open mind’, as a sign that the terrorists are winning. And, in a way, essays like Alter’s, which do not openly advocate torture, but just introduce it as a legitimate topic of debate, are even more dangerous than explicit endorsements. At this moment at least, explicitly endorsing it would be rejected as too shocking, but the mere introduction of torture as a legitimate topic allows us to court the idea while retaining a clear conscience. (‘Of course I am against torture, but who is hurt if we just discuss it?’).
Admitting torture as a topic of debate changes the entire field, while outright advocacy remains merely idiosyncratic. The idea that, once we let the genie out of the bottle, torture can be kept within ‘reasonable’ bounds, is the worst liberal illusion, if only because the ‘ticking clock’ example is deceptive: in the vast majority of cases torture is not done in order to resolve a ‘ticking clock’ situation, but for quite different reasons (to punish an enemy or to break him down psychologically, to terrorise a population etc). Any consistent ethical stance has to reject such pragmatic-utilitarian reasoning."
http://www.lrb.co.uk/v24/n10/slavoj-zizek/are-we-in-a-war-do...
"At any given moment, the “window” includes a range of policies considered to be politically acceptable in the current climate of public opinion, which a politician can recommend without being considered too “extreme” or outside the mainstream to gain or keep public office. Overton arranged the spectrum on a vertical axis of “more free” and “less free” in regard to government intervention. When the window moves or expands, ideas can accordingly become more or less politically acceptable."
In the US this is covered under the Pen Register Act: https://en.wikipedia.org/wiki/Pen_register. Essentially the fact that two people have communicated is not protected under our Constitution; only the content of that communication is protected. In that context, Congress passed the Pen Register Act, which requires law enforcement to get a warrant to monitor who calls who; the bar for these particular types of warrant is particularly low.
The Patriot Act extends the concept of pen register and their required warrants to internet communication. The government specifically is required to get a warrant before it can ask an ISP, for example, to reveal who someone emails or what web sites they visit. For now, they need a warrant to know that you visited Amazon or your library's site, but they need a harder to get different warrant to know what books you've bought or checked out, or what you thought about those books when you emailed your friend.
The fundamental problem with pen registers and the internet equivalents is that it brings people under government scrutiny that otherwise would have escaped notice. If person A is a person of interest, and the government is pen registering his communication, then that makes everyone on person A's communication list a person of interest. Now the government gets a warrant to pen register person B, someone who person A communicates with. That means that everyone that person B communicates with is now known to and watched by the government, even though they are not specifically the target of any investigation or warrant.
Person A may be a drug dealer, person B may buy from person A, and I, person XYZ, may be a friend of person B, don't buy or use drugs, and don't know a thing about the relationship between person A and B. But now the Eye of the government has swung its gaze over to me. I could become collateral damage in, for example, a plea bargain negotiation. My house might be violently raided by law enforcement, merely because Person B visits me a lot; my child might have a gun pointed at his head, and my dog might be routinely killed merely for getting in the face of one of the law enforcement home invaders.
This (the pen register) is a violation of my desire to not be scrutinized by the government, whether I've done nothing wrong or not, whether I have anything to hide or not. I in fact have done nothing wrong and have nothing to hide, and I still do not want the scrutiny of the government to fall on me. The government is in theory my servant, not my master. That relationship naturally gives me the right to expect the government to leave me alone.
Cynical enough to think GCHQ do this already & the legislation allows for more favourable results.
True, but wouldn't the sources be covered under OSA and hence not disclosed?
Excellent point.
For more info about the security theater revolving around SSL in the context of HTTP see this great talk: http://www.youtube.com/watch?v=Z7Wl2FW2TcA
This can be spoofed only if the nation state buys the master root keys (i.e. not just a key allowed to sign any domain, but the root key the provider uses to sign everything, so that the chain is exactly the same) from every certificate provider... At which point you're screwed whatever you do.
This is just a first step in making encryption illegal. Not like that's not the case already in some parts of the world, and it's not regulated heavily in other parts of the world.
My point, admittedly facetiously expressed before, was an aside, and it is that hey, we know the government's screwed up, and it's not likely to get much better soon (especially on this particular issue) without a fundamental shift away from Big Government (and more debatable, a Massarchy implementation of government). In the meantime, there are technical solutions around it which we could implement en-masse today for the benefit of the masses instead of the localized solutions like GnuPG that us privileged nerds have--and it's worth reminding/letting be known by budding smarty-pantses that they too can communicate with other smarties securely if they want to. (I suspect any dangerous terrorists already do communicate securely and don't need reminding, but most terrorists are dumb and ineffectual in whatever their particular goals are so most probably don't.)
If only Joe Public was educated about it and motivated to care and demand... Does a gmail-to-gmail message stay on Google's network alone? If not, they should encrypt everything behind the scenes before it leaves their network, just like how they've now been using https by default. It limits gov. snooping to subpoenaing the specific email provider to get the data off their servers rather than catching it in real-time as it passes through some network node. Also, I think that most probably gmail-to-hotmail or gmail-to-yahoo goes outside, so you can expand. Why can't Google, Microsoft, and Yahoo each agree to roll out an auto-PGP system where when an email is sent to one of the others, a handshake occurs first where a one-time public key is swapped from receiver to sender that's used to encrypt before sending, and the receiver will decrypt before presenting the decrypted email to the receiver user? (And to the receiving user's provider's content-scanners to display targeted ads.) With similar legal implications, the public could always demand regulations that require an auto-PGP protocol alongside a requirement of https (even though https isn't as secure as it could be). But that would be an instance of the government looking out for its people when the private companies aren't doing so, therefore it's not going to happen.
It's hard to enforce any anti-encryption laws beyond monitoring for distribution of specific software and monitoring for users who encrypt almost everything. Basically you can only catch someone using encryption for almost everything by noticing that none of their data is understood by any of your software. If you only encrypt important things, well, a steg'd image once in a while isn't going to be detected (and there are other things you can do too).
Of course, we can go further down the rabbit hole of schemes, we don't have to stick with just PGP. As one of your sibling-comments noticed, anyone who wants to get around any State Spying can do so as long as the State leaves room for some reasonable assumptions. (As for outlawing encryption, that's a problem on its own, both in enforcement and in definition. You'd likely just get particular encryption software outlawed rather than the concept. (I'm aware of the US classifying certain algorithms as munitions.) Funnily enough, telegraph operators tried to outlaw simple ciphers and encodings (like 'u' for 'you' and even anagrams) used back in the day because they were losing money, since they charged a fee for a message length.)
I like the '89 paper entitled The Dining Cryptographers in the Disco: Unconditional Sender and Recipient Untraceability with Computationally Secure Serviceability. Here's part of the abstract:
We present a protocol which guarantees unconditional untraceability, the original goal of the DC-net, on the inseparability assumption (i.e. the attacker must be unable to prevent honest participants from communicating, which is considerably less than reliable broadcast), and computationally secure serviceability: Computationally restricted disrupters can be identified and removed from the DC-net.
An important part of public key cryptography is the "web of trust" - you must know that you're sending stuff to the right person. A person's identity is tied to their PGP key.
> You tell me how useful it is to know that I sent a message to cornflakesrule12345@emailprovider.ext without knowing what the message says.
They build up big databases and then mine that for information. Most people are not disciplined enough to use cryptographic technology properly; and that holds for "not doing stuff that leaks data". Associating username@example.com with a set of data is an important step in getting the identities of both username and the people username is communicating with. Don't forget that even if username is careful the people that username emails might be idiots.
Fundamentally, it only takes one matching join on your citizen-data against any other collected assortment of data to implicate you. Human stupidity will continue being the weakest link. But there's still a lot that can be done to guard against it.
Even if the government manages to figure out that user@example is an Al-Qaeda member, and they know I sent them an email, they have no idea what I sent without resorting to, depending on how secure I was, torture, bargaining, private key compromises of the receiver, further insecure communications from the receiver's end, or hard drive sniffing for the original message from my computer. Increased carefulness can guarantee the message only exists within the minds of the sender/receiver, but with the advent of the "forgetting pill" even that vulnerability can be accounted for when plotting world domination. Of course as you note, human stupidity can undo it, but that's no reason to give up adding more layers of security.