On the new Dutch intelligence and security law
berthub.eu
berthub.eu
If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
I lived next door to someone that was busted for growing weed. The neighbor on the other side was involved at the time and then continued to harrass him then me because I complained about it for the next 10 1/2 years. The law only allows use of a civilian for a year with a contract in advance and no committing crimes. Didn't stop them. They spent more than 1 million euros in harrassing someone who was already convicted and then their neighbor because they complained.
I was told by the police that my phone had been tapped already, though I had already guessed that.
I assume this is going on routinely already.
Governments think they are above their own laws. Warrants? Privacy rights? Due process? Why bother?
Not that I agree with it, no, but it's not like they're acting above it.
These are not hypothetical questions. I'm not Dutch but in my own (EU) country it's a very common occurrence that the higher courts significantly modify or entirely cancel a fully approved law - often retroactively. Sometimes the state has to pay out damages.
IMHO a parliament acting like they can just vote for anything and that's it is exactly the definition of acting above the law.
It should, it's the job of the first chamber (aka the 'senate') to validate this. Unfortunately they have been playing politics more than anything.
> I'm not Dutch but in my own (EU) country it's a very common occurrence that the higher courts significantly modify or entirely cancel a fully approved law - often retroactively.
This sounds more like the common law system (US, UK, Ireland). In Holland it's not like that. The senate is supposed to check that an in fact a local judge can't directly reference the constitution. In common law they can and they create precedents to scope out a law further after implementation.
The EU does overrule it of course. And yes perhaps they can get fined damages. That would be good IMO because it will stop them doing it. But they didn't do anything wrong technically in that sense.
The worst thing they did technically was that this law was inplemented by a cabinet that had already stepped down after the coalition fell apart. New votes were held and a new parliament was formed, but the old cabinet is still in place until a coalition is formed to create the new cabinet.
The biggest problem there was that 24% of people voted for the extreme-right fascist party and nobody except the neoliberals (the party they split out from) and the farmers want to form a government with them. So it will take a lot of time. But the old (neoliberal) cabinet is not supposed to push through any legislation that can be considered controversial. They are doing that all the time though.
Not sure about the exact legal theory in the Netherlands but where I am it's not really the job of upper chamber to validate it. Both chambers should have done that but both are bodies with political agendas and they interpret it to their own liking - and that often doesn't pass through the courts.
Assume, the Chinese, Russians, North Koreans, Iranians, Americans, and everybody else gets a copy of all the bytes you send and receive. That may or may not be true depending on who or where you are and how competent their people are. But you can't rely on that not being the case so you simply shouldn't. So make sure that whatever they intercept is gibberish.
Is there any unencrypted traffic over these cables at all at this point? It's all ssl and https at this point, I would hope. There's still some intelligence to be extracted from which IP addresses are talking to which other IP addresses. But beyond that? What's really there to be intercepted that we haven't fixed yet?
You can encrypt DNS with DoH if you want, but the DoH provider still sees its you. You can take it a step further with Oblivious DNS over HTTPS if you really want to conceal DNS activity[1]. Note: this technology is rather new and experimental.
[0] https://en.wikipedia.org/wiki/Server_Name_Indication
[1] https://research.cloudflare.com/projects/network-privacy/odn...
It keeps Mullvad from intercepting DNS traffic: if you send cleartext DNS requests on UDP/53 through their network, they intercept it. But DNSCrypt packets are encrypted and authenticated, so they can't.
Bonus: DNSCrypt is still packet-based like UDP, so none of the downsides of DoH: no 3-way handshake, no connection pooling, no stream correlation attacks.
> It's worth noting that all our VPN servers hijack calls to our public DNS server and that the DNS requests are processed on a local non-logging DNS server installed on that VPN server.
https://mullvad.net/en/help/all-about-dns-servers-and-privac...
https://old.reddit.com/r/mullvadvpn/comments/invjgp/how_and_...
Unless the resolvers share data with each other.
These public DNSCrypt resolvers will publish claims like "no logging" but how does one verify this is a true statement.
It may be better to use mutiple third party DNS resolvers, whether DoH or DNSCrypt, than to only use one, but the best course of action is not to use third party resolvers at all.
The question I have for DNSCrypt fans is _why_ AFAICT no authoritative DNS servers are using it, e.g., https://github.com/cofyc/dnscrypt-wrapper
Personally, instead of DNSCrypt, I prefer CurveDNS,
https://github.com/curvedns/curvedns
There is at least one DNS forwarding service that offers CurveDNS.
For those who might be confused:
From https://dnscurve.org
"Do you run a DNS server that sends out DNS data? For example, do you run an "authoritative DNS server" such as tinydns or PowerDNS Server or BIND or NSD or MaraDNS or Nominum ANS to publish the IP addresses of your web server and mail server?
This page explains the benefits of adding DNSCurve protection to your outgoing DNS data."
DNSCurve protects outgoing data from authoritative DNS servers.
I use CurveDNS experimentally in homelab in front of tinydns and nsd. It is easy to set up and it works great. Unfortunately not many authoritative DNS servers on the internet are using it even though it is easy to set up and works great (based on own experiments).
As stated above, the best course of action is to avoid using third party DNS resolvers, i.e., public, shared caches. Instead one can run a local cache that sends DNSCurve-encrypted queries to remote authoritative DNS servers. For example,
https://github.com/janmojzis/dq
When using dq or dqcache, packets are _not_ sent "in the clear" for an ISP to sniff.
But, as above, the number of authoritative DNS servers using CurveDNS is unfortunately small.
The problem I see with DNSCrypt is it encourages use of third party DNS resolvers, i.e., shared caches.
I use locally-stored DNS data. When I retrieve DNS data from the interet I retrieve it in bulk using a variety of methods and sources. An unconventional approach perhaps but it works great for me.
Encrypted DNS is arguably pointless if one is using a popular browser that always sends SNI, even when SNI is not required, e.g., websites not using a CDN, or when visiting websites that do not support encrypted SNI, e.g., websites not using a CDN that supports encrypted SNI (ECH). Glad to see that the grandparent comment mentioned SNI.
For me it runs bound to a loopback address, as do the nsd and tinydns servers. None of this traffic uses the network, there are no remote queries. There is nothing for the ISP to sniff.
When placed in front of a remote authoritative DNS server, that server can be queried using DNSCurve, e.g., with dq or dqcache. The packets are encrypted. ISPs cannot read them.
For example,
dq -s -k dns2sdrnxskf5lqt46v34cdlfqb9q2lvvmpr95g3l1qh0148sf6 ianix.com 104.207.143.9
1 ianix.com - streamlined DNSCurve:
229 bytes, 1+2+2+2 records, response, authoritative, noerror
query: 1 ianix.com
answer: ianix.com 3600 A 104.248.15.206
answer: ianix.com 3600 A 104.207.143.9
authority: ianix.com 259200 NS uz5dns1bx64zu3pgn9nm4zfvmh2vy4hpjy7nkjz6qjcu325bg9hzcx.ianix.com
authority: ianix.com 259200 NS uz5dns2sdrnxskf5lqt46v34cdlfqb9q2lvvmpr95g3l1qh0148sf6.ianix.com
additional: uz5dns1bx64zu3pgn9nm4zfvmh2vy4hpjy7nkjz6qjcu325bg9hzcx.ianix.com 259200 A 104.248.15.206
additional: uz5dns2sdrnxskf5lqt46v34cdlfqb9q2lvvmpr95g3l1qh0148sf6.ianix.com 259200 A 104.207.143.9
The IP address of the ianix.com name servers, 104.207.143.9, and the DNSCurve key, dns2sdrnxskf5lqt46v34cdlfqb9q2lvvmpr95g3l1qh0148sf6, can be obtained from the com.zone file, which is available for free from https://czds.icann.org/homeNo recursive resolver is used. No packets are sent "in the clear". There is nothing for the ISP to sniff. Unlike public DoH or DNSCrypt servers, there is no third party DNS provider involved. No middleman.
Neither is a replacement for the other; they're orthogonal. They solve different problems.
You should use both of them.
From the CurveDNS link you posted:
> CurveDNS supports:
> Forwarding of regular (non-protected) DNS packets
These are being sent in the clear, and your ISP is most certainly logging them. You should tell your CurveDNS resolver to use a (local) dnscrypt-proxy instance for resolving "regular (non-protected)" queries that don't have DNSCurve entries. Then you have the best of both worlds!
> The question I have for DNSCrypt fans is _why_ AFAICT no authoritative DNS servers are using it
Because DNSCrypt is only for querying recursive resolvers!
... and DNSCurve is only for querying authoritative resolvers.
DNSCrypt is link-level encryption between you and your recursive resolver (the thing you put in /etc/resolv.conf).
DNSCurve is link-level encryption between your recursive resolver (or you) and the authoritative resolver (like this one, which is authoritative for cr.yp.to):
$ dig -t NS yp.to
yp.to. 3600 IN NS uz5jmyqz3gz2bhnuzg0rr0cml9u8pntyhn2jhtqn04yt3sm5h235c1.yp.to.
It is a shame that the two names (DNSCurve and DNSCrypt) are so similar.Even without looking into the encrypted payload there is so much you can learn from graphs connecting and the metadata.
I am decently sure that some state agencies help design routers.... if you know what I mean :)
How does that work in practice (under Dutch law)?
Nothing ever wins against "we need to keep the country safe".
So it's a noble cause then? Or does it have privacy implications for innocent netizens? I thought these exchanges would have been tapped in some form way before this announcement?
Surely no law enforcement would overreach when given tools like these, right? Right?
https://nos.nl/artikel/2432715-inlichtingendiensten-moeten-g...
https://www.rtlnieuws.nl/tech/artikel/5294998/aftappen-aivd-...
If you consider "to play its part in the trade war between US-China which is extending into real WW 3" as noble, then yes, it's noble.
You want to listen to what they want to do before they do something to your country. This is what this thing allows you to do: every internet packet transiting through the Dutch internet exchanges will be "scanned" (largely read-only).
However:
> The powers granted to the services are broad, but also largely ‘read-only’.
Largely `read-only`, the way I read it, means that in some cases they can actually replace whatever is going through the cable.
I imagine something like:
- terrorist A and B are texting each others, and you replace some of the text that they are sending each other (before this is received over the phone, because you own the "hop"), so that you can maybe redirect them straight into the police hands.
If done properly, I believe this can prevent quite some bad damage - not the simple example above, but probably also major things like serious attacks (e.g., ransom attacks on public institutions, etc). That's my guess - how easy or realistic this is, I can't tell you.
"Nobody who speaks German can ever be evil"
- The Simpsons
The CTIVD will have supervision during and after the tab (good).
Private data can be held much longer without government approval (why?).
There is no permission needed to tap another server when a party, that is under surveillance, is moving there.
---
I have mixed feelings about this. We know Russia is trying to disrupt the Netherlands because of previous taps. So on one hand it is good that the government can quickly react to such threads. On the other hand it has huge privacy implications.
Some people in this thread think that TLS will keep us private but that is not how it works when they can listen to all traffic. For example they can see I posted a request to Hacker News on a specific time. Then it is a matter of finding all posts that were made around that timestamp to see what I wrote and what my username is.
I think this is a lot of work to do. Just ask some 3 letters agencies for some help on some malware or on some "router firmware bugs" to be exploited etc. They don't care about hacker news readers or posting comments (because this implies you must know the DNS first, etc). They care about botnets DDoS-ing your railway infrastructure, ransomware on hospitals, serious stuff that can lead the country to chaos.
Websites in the range 54.239.0.0/8 often host problematic content. My opponent visited several addresses in this range overnight and hid his traffic with military-grade message scrambling functionality.
Of course that's just AWS and you can't even do HTTP/2 or HTTP/3 without encryption. But do the voters know that? Will they be educated on it? Probably not. And you're not saying anything untrue, you have facts and logs to back up your assertions!
Of course this is only relevant for targeted surveillance, not mass surveillance.
Happy to be corrected though, I've been wondering about this.
Some web browsers have pinned certificates for certain services, Google Chrome/Chromium being one of those. Subsequently, the browser refuses to perform any more actions towards the server that serves an invalid (according to the browser) certificate. That browser is also one of the reasons the DigiNotar case in 2011 emerged to the surface.
In my opinion, it's less about the amount of cleartext traffic, but also about what parties terminate your so preciously encrypted connections/requests, the percentage of internet traffic they handle, and what they exactly store about those requests.
Encryption on the internet doesn't mean it's suddenly safe.
Metadata analysis on netflow, source and destination traffic, etc.
Most people still don't use VPNs for everything, and some services outright block or degrade VPN connectivity. Two notable examples are most banks, and 4chan.
I firmly believe 4ch is a Honeypot.
Is there specific intelligence leading to this? It seems very to the point about being related to Russia.
Biden, on the other hand, renews them promptly, to bipartisan satisfaction.
Funny how that works. :p
Twenty years ago, the excuse was "we are restricting your freedom because of what happened in 11/9."
Then in the internet age, the excuse became "we are restricting your freedom to save the children from online abuse."
Now, Europe has unlocked the option to restrict its citizens' freedom because of the "war."
I ask my fellow computer engineers what the hell are we waiting for to pool our minds and resources towards a truly decentralised, encrypted and anonymous overnet. Something a little more practical than I2P, Tor, Freenet, etc. "Oh bad people will use it to do crime" is not a serious enough excuse to just passively accept the government tightening the noose around our digital presence, for total control by the State, all in name of safety and security. Was Bitcoin (2009) the last hurrah of the crypto-anarchist ideals of freedom of thought, freedom from the Big Brother and freedom from the ever-looming State?
https://groups.csail.mit.edu/mac/classes/6.805/articles/cryp...
I often hear this somewhat loose idea and have to say that I also have such reoccurring thoughts myself. We currently enjoy pretty great freedoms to do stuff, we have the chance to set something up, and those freedoms might be severely restricted in the future. It may be easier to develop something like that now than it will ever be in the future. The problem seems to be that there is no coordinated plan. Stuff like Tor exists, but it hasn't really caught on as much as one would hope. Also it is built upon a rather specific architecture (the internet) from what I understand, which could basically be shutdown by authorities at any moment.
For example, I can't currently safely communicate with people in my geographic area independently of the internet, even though my devices theoretically have the hardware to do so (think of radio capabilities, for example). There might be some lose projects out there capable of some of it that 99.9999% never heard about, but nothing that could actually be considered general-purpose. Why is that?
It isn't an easy problem to solve. And it isn't enough of a problem for people to actually apply themselves nearly enough. Once it is needed in a way that more people would devote their time to it, it might be too late.
I can't wait to pay ESG tax because I am breathing.
Now I look at this and all that comes to mind is that actions like this would provide a basis for tapping people closer to source.
All the p2p and e2e encryption in the world won't help if someone is reading every key you type, or in the near future, every thought that crosses your mind.
Still, I applaud your spirit.
– Milton Friedman