Setting out plans to monitor all Internet use in the UK
bbc.co.uk
bbc.co.uk
http://www.amazon.co.uk/The-Dying-Light-Henry-Porter/dp/0752...
Although it's a novel, it's written by a well-known journalist with an interest in civil rights and liberty: http://en.wikipedia.org/wiki/Henry_Porter_(journalist)
Pointless and makes my life as a British citizen more awkward as I'll having to put all my network traffic off through something rather than leaving it as a nice, simple internet connection.
Totally retarded, but I bet they will look at your traffic harder if you did this, even though I have nothing to hide...
Interesting read from something that was posted on HN yesterday: http://news.ycombinator.com/item?id=4105485
So what you're suggesting means they'd need to look at your traffic without a warrant in order to determine if they need a warrant to look at your traffic.
[edit] Also, presumably they can already get a warrant to tap your traffic. All this new legislation means is that they can look at historic traffic too?
Don't get me wrong. I am British, and I do think it's fucking disgusting. But don't forget, it's just a proposal.
[edit2] I was wrong. It seems they wont need a warrant to see who you're talking to. Just a warrant to see what you're saying. So yes, I guess they'll be able to tell that you're using a VPN without getting a warrant first.
Problem is I don't trust our government with our data, they've shown sheer incompetence far too many times when it comes to IT systems. And it's always a case of do as we say, not as we do as the expenses scandal and the current Leveson enquiry is showing.
... this is the reason several people I know don't use PGP signed/encryted email.
1. It's trivial for you. Is it as trivial or convenient for the average Joe? Tor is slower and more restricted in terms of multimedia and VPNs and other proxy/routing services cost money and while not hard to implement, are still beyond the grasp of the average citizen. Of course this immediately prompts the question of whether this is intended as a security measure at all since only the average citizen will be affected.
2. I suspect that this is more about legislative precedence than it is about actual implementation. Governments are forever forcing new surveillance measures. The common people ignore them and the techies resolve to bypass them technically. But the politically harm is already done. Before we know it there will be hundreds of these laws and measures passed and when we finally realize it, it will be very hard to persuade the bureaucrats that implemented them in the first place to remove them.
I used to think like this until a recent conversation between 2 cousins on facebook concerning the nautically naughty bay.. I had a bit of a shock seeing one of my "knuckle dragging, mouth breathing" (my words) relatives spouting on about VPNs etc. and getting it mostly right. I suspect if it's a choice between not accessing certain sites and learning you'll be surprised at how quickly people will learn.
This does not matter one iota. People have been spied upon for ages with things that are even more trivial to work around.
Also, that it's trivial to some means nothing, if it's not trivial for others, or if they are not bothered. Can you guarantee that your grandmother or friend will also "work around" this --and other such measures? You don't really believe that they can get information about you only from YOUR system?
Lastly, even if its trivial to bypass and useless, it raises the Overton Window. Society accepts that --already an unthinkable level of surveillance 2-3 decades ago--, and they'll come up with something more intrusive next time.
Plus, they make the laws. If they can get away with that one, they could also get away with outlawing "working around it", and all related tools.
In that case, they don't even need to "break" Tor to get people. They can execute some warrant search to your house (for whatever reason), or even a routine laptop search at the airport, and arrest them if they see such a tool MERELY installed on it.
I think this sums it up, this data will be of little help for stopping crime, but it would be of great help for corrupt officials to do evil not to mention the risks involved with storing this data.
Announcing this during the McPherson inquiry (where various people (including police officers) have shown they're happy to break criminal law to obtain, buy, and sell information) means they're going to have a hard time getting it passed.
Unfortunately those who probably would care are too busy consuming the noise of the numerous wars, inquiries, showbiz, celebrity dross, royal banality, Olympic bleugh and regurgitating it all over Facebook.
It was only as time went on and the costs increased and the benefits decreased that more people started being against the card. The death knell came when the government announced that each card would cost > £100.
See also the number of people who think that everyone should be on the Police DNA database; the number of people who'd volunteer to have their DNA on that database. It's only relatively recently that people have started campaigning to have data removed for people who haven't been convicted or charged of a crime.
There isn't much fuss around cctv cameras; or around automatic number plate recognition cameras; or around laws enforcing specific fonts to allow anpr cameras to work.
Your last sentence sums up the problem nicely: most people care more about X Factor than about privacy.
It's sad that it's shocking for a politician to be able to actually list ways that this sort of system can be worked around.
Given that another Conservative minister claimed, under oath, that he doesn't know what "quasi-judicial" means (he was appointed that exact role), I don't have much hope that the home secretary will apply legal advice before handing out warrants.
It seems an awful lot like catching someone in a hurry to get them to sign something because you don't want them to read it.
I await more "the terrorists are coming" and "think of the children" legislation.
However, we have one thing on our side: government IT incompetence. They have managed to screw every major IT project up in the last 20 years, so this will go the same way :)
When opposing this it's important to understand the remits of the two organisations and that one is nominally accountable to the public, while one isn't.
(http://www.gchq.gov.uk/AboutUs/Pages/index.aspx)
I agree that's suboptimal.
I am much less worried about letting GCHQ trawl my traffic data than I am letting my local council noodle around in it. Mostly because GCHQ probably already do it - they certainly have the capability, but also because local councils have shown themselves to be corrupt and "data-leaky".
I'm not bothered about my traffic data being trawled. I oppose this bill because it's stupid - the people who have to keep data are not clearly defined; hiding some of that data is trivial for criminals; keeping that data is an unreasonable burden on some (but not all?) ISPs; etc etc.
It's frustrating that there are some really clueful politicians and advisors, yet governments keep pumping out really stupid laws about computers and networking.
These legislators seem to be regulating what they do no understand.
If UK people are interested in helping stop this then the Open Rights Group is running training days on this topic: http://www.openrightsgroup.org/events/2012/censorship-and-su...
I dont consider myself any form of hacker, I dont think i do anything illegal on the interweb. However i am very for privacy on the internet and against goverment monitoring.
When SOPA and CISPA etc all came about my first port of call was to get off gmail and on to my own webserver on a VPS. 2 weeks ago i deicded it was time to create my own elite anon proxy using squid. Took a few days of tinkering (sidenote did you know that google can get your IP via user_agent header? took me ages to work out why all the sites but google were getting my VPS IP and yet google could see right passed it and get my orignal IP)
now I am posting to this topic using said proxy. I can bet that once all these systems go live I will be one of the first pulled up as a terroist. I have VPNs to 2 countries, and 2 machines route out over those, i have very little standard traffic going via my ISP, and i use external DNS (currently in the process of setting up my own bind server).
I am even in the process of setting up my own jabber server (what did google rename it to xxmp?) and using that as a replacement for MSN/Skype interaction thing with my friends.
All of the above will classify me as a terroist under the UKs ever watchful eyes, I think now I am going to route my proxy in to tor for extra funz
[...] the government would be able to request any service
provider to keep data about internet usage, although
initially it will involve about a dozen firms including
BT, Virgin and Sky.
I guess that includes VPN services (like HMA, who are based in UK).http://www.theregister.co.uk/2012/05/26/eprivacy_cookie_comp...
As I understand it they backed away from the stronger restrictions at the last minute... but still, the very idea of a surveillance nation like the UK "protecting" people by blocking third party cookies would be hilarious if it wasn't also tragic. Very generously they've said they won't prosecute offenders... probably... unless they don't like you... or have a political axe to grind... or you're the wrong ethnicity...
You think that if a government decides that its citizens should be granted extra privacy protections from corporations and individuals, then it's only right that they grant the same protections from law enforcement?
I guess it's also ironic that my government prevents McDonalds from locking me up, but will lock me up themselves if I commit a crime?
Forgive my ignorance, I'm very curious about this as a UK citizen.
Here's the best talk I know of this subject: BlackHat USA 2011: SSL And The Future Of Authenticity: http://www.youtube.com/watch?v=Z7Wl2FW2TcA
"Businesses (and governments) can legitimately buy root keys that allow MITMing any SSL connection"
A business can buy their own SSL keys, but to MITM any SLL connection those keys would have to be trusted and installed at both ends of the connection and used to generate the SSL session key.
"any CA can MITM the whole internet"
Again, the CA's keys would have to be trusted and installed by the communicating parties.
Or have I misunderstood your point?
But this is far from "Businesses (and governments) can legitimately buy root keys that allow MITMing any SSL connection". Businesses can't invoke CALEA (or the UK RIPA[4] law, since we're talking about UK government surveillance) - only governments can do that. And the keys are not really being sold or bought. And I don't see how a government could compel a CA in a different legal jurisdiction anyway.
"any CA can MITM the whole internet"
No. A CA has access to keys that can be used to MITM a connection that is secured by keys issued by them. Thats not the "whole internet".
[1] http://blog.thoughtcrime.org/ssl-and-the-future-of-authentic... [2] http://files.cloudprivacy.net/ssl-mitm.pdf [3] http://www.schneier.com/blog/archives/2010/04/man-in-the-mid... [4] http://en.wikipedia.org/wiki/Key_disclosure_law#United_Kingd...
Think Black Hawks and men in black suits.
£2500 to bribe a young woman at a high-profile company to accuse their upper management of sexual harassment.
£2500 to bribe the cop for access to all of the company's data.
Sell to interested parties.
Repeat.
of course they do - because the terrorists and the criminals have the brains and the survival instinct of a peanutbutter sandwich!