US examining whether UK's encryption demand on Apple broke data treaty
reuters.com
reuters.com
The Online Safety Act is about internet systems that are akin to traditional publishing, and so it holds the operators of those systems to the same standards to which we hold traditional publishers, but the Investigatory Powers Act relates to individuals' private use of computer systems. It represents a serious breach of individuals' privacy, which is a foundation stone in the culture of a country as densely populated as the United Kingdom. The extraterritorial aspect of the legislation is not only uncouth in the twenty-first century, but presently unenforcible given the United Kingdom's diminished Armed Forces. Finally, choosing to pick this fight now was a poor choice given the current state of international politics.
Do you defend the aims of the Act, the Act itself, or both?
I'm having to figure out compliance for a volunteer run, donation funded forum, and I think the Act itself could (and should) have been better written. I don't think Ofcom can handle it better than they are, because until it's tested in court they haven't the ability to say what the vague and undefined terms mean.
If you're looking for advice on how to comply with the act, the go-to person is Heather Burns[0].
And that awful purpose is something you see fit to defend?
(realistically the OSA kills the possibility of UK social media startups, which I'm sure everyone is fine with, right?)
I won't consider myself an expert on this, but from what I've read, that's just not true. Perhaps that's the intent, but the vague wording makes it possible that all sorts of websites could be subject to it, even, for example, a small forum run by a hobbyist that has a few hundred members.
Even if the intent behind the Act is good (debatable!), the implementation of it seems designed to scare everyone and allow for selective enforcement, while people get pushed to the big social media platforms as smaller niche communities feel pressured to shut down.
This is not really true though, is it? Involving OFCOM holds the internet to broadcaster standards, which is very different from print standards. We ditched print censorship and "think of the children" in the Lady Chatterly case, long ago.
> I think the Investigatory Powers Act (which allows for this spat with Apple) is a terrible piece of legislation.
It is. Long ago I was briefly involved with the UK Campaign for Digital Rights campaigning against it. Nowadays that work is being done by the Open Rights Group (UK HN readers check it out!)
The deeper problem is the UK security services got stuck in counterinsurgency mode during the Troubles, and then the War on Terror, and that infects everything with paranoia. There's no way to tell these people "you are fighting yesterday's threats".
OK, I can see that, though even then I could imagine this sometimes being the case.
"...nor is it authorized to demand the data of persons located inside the United States."
Really, even if in the case of individual UK citizens, under all circumstances ?
For any U.S Person you may not say anything about it at all. I mean that is totally reasonable, if they want that data it's basically a diplomatic matter not a demand you issue.
With your clarification.
What they've reportedly demanded is that systems be changed, so that later a demand for data may be be effective. As to if any hypothetical later demand for later would contravene the agreement would seem to simply be speculation for the moment.
Surely the UK could just be careful not make a contravening demand at that time? Which would then make this whole "review" a case of PR on the part of the US politician.
Now it is quite bad that the UK has apparently triggered this bit of the snoopers charter, but it would seem to be othogonal to that agreement.*
* Unless someone bothers to review the agreement, and finds that such meta-demand are covered.
But, you know, there must be legal proceedings, the court must be satisfied that the information is necessary, etc. The guy at the border can't do that, on their own initiative. But of course, they can just not let you in.
Edit: does it apply to border guards too?
There are cases of people being prosecuted under it [1], [2], [3]
[1] https://www.independent.co.uk/tech/cage-muhammad-rabbani-ant...
[2] https://www.birminghammail.co.uk/news/midlands-news/drug-sus...
[3] https://www.independent.co.uk/news/uk/crime/facebook-passwor...
Also if encryption itself is not illegal, but it is illegal to not decrypt something when asked, then encryption is effectively illegal, since you only need to convince a part of the state that you have suspicion to get it decrypted for you, a task which is really not that difficult in the modern day.
The abuse of power means they could detain him indefinitely etc (as it happens in countries where abuse of power is common). But in this case he had the right to defend himself in the court and he used it.
This is very far from the situation where encryption is illegal, all communications are transparent to the state and it can search for incriminating data without asking.
Scotland, Wales and Northern Ireland retain the term country or nation for historical identity reasons, not contemporary practical or relevant reasons.
Apple chose to partially comply with the order, by disabling ADP for UK users, instead of inserting a backdoor.
Apple is making the distinction here between UK and non-UK, so they can define a "UK user" however they want. A foreign citizen travelling in the UK almost certainly won't be affected.
In other words, they aren't handling this case legally, or at least that is a matter that may be resolved in court if the UK is unsatisfied with Apple's method of compliance. Apple would seek to challenge the UK's jurisdiction in that case.
That the country is STILL able to spy is the result of huge amounts of spending and insecure applications. It's pretty well known that most US law enforcement cannot get into a locked iPhone, for example.
But sure, countries can sign trade treaties that give each other mutually-beneficial things. Some of those things could be what is and isn't allowed to require companies to do in order to operate within the other country's borders.
But in absence of something like that... that's just life. I guess the US could act like a baby and slap tariffs on goods from the UK, but I'm not sure what the upside would be for the US here.
So this is a charade while status is quo, I guess.
Why would France, Germany, or any other country should allow their citizens in their sovereign country to be treated like that? And what’s next? “If you want to do business in country X then give us all the user data for country Y?
Countries are free to set whatever conditions they like for allowing a company access to its market.