Tech firms anti-terrorism efforts criticised in Rigby report
bbc.co.uk
bbc.co.uk
According to various reports in the serious media today, the security services had these two in their sights seven times before the attack. Some commenters also seem to be suggesting that surveillance was undermined, possibly as late as the day before the attack, by numerous procedural errors by those security services, though I haven't yet seen a specific citation of anywhere the ISC report itself states this.
In any case, why do we still pretend that it is plausible to monitor everything said on-line, correctly identify every genuine threat needle in the hyperbole haystack, and anticipate and prevent every small-scale, isolated violent attack by bad people?
While I would never make light of the loss to Lee Rigby and his family and friends, objectively this appears to have been an isolated incident with a single victim, given coverage out of all proportion by the media because someone said "terrorism". There were hundreds of murders in the UK last year, and I doubt the others were any less tragic for those affected, but we don't see David Cameron, Theresa May and Malcolm Rifkind calling for draconian state surveillance powers to avoid repeats of all the other killings.
- There are many many young people on facebook. Every year a percentage of these innocents decide to kill themselves. I think facebook have a MORAL OBLIGATION to monitor all language used in facebook posts in order to ascertain potential suicide threats - which should then be reported to the appropriate authorities.
- Every year thousands of people die of hear attacks brought about by years of unhealthy living. It is facebooks MORAL RESPONSIBILITY to monitor the word density of posts, giving extra weight to words like 'pie', 'cake' and 'spachumnauzer' - These perpetrators should be reported to the relevant NHS department for immediate medically induced coma therapy[1]
- EVERY, SINGLE, YEAR, millions of illegal immigrants done come over to our country illegally, in order to steal our benefits. Facebooks continued lack of action in monitoring facebook photos for suspicious foreign looking persons in a job type role consists of MORAL CONSTIPATION on the part of Facebook. All foreign-ish photos should be vetted by the appropriate vets.
[1] study after study show people in comas are at a significantly lessenered risk of dying of heart attacks - I don't have the links right now, but believe me, they do!
> “It is not appropriate for internet services — who handle some of our most private and sensitive correspondence — to be snooping through that data for the police, anymore than it would be for the postman to snoop through peoples' letters.”
http://www.independent.co.uk/life-style/gadgets-and-tech/new...
I know BBC tries to remain neutral, but why is it that almost always when we see a post like this, that serves as a platform for UK government's propaganda, it seems to come from BBC?
> Isabella Sankey, director of policy for Liberty, said: "The ISC shamefully spins the facts seeking to blame the communications companies for not doing the agencies' work for them."
> Executive director of the Open Rights Group, Jim Killock, said: "To pass the blame to internet companies is to use Fusilier Rigby's murder to make cheap political points."
In that respect, it's actually more critical of the government position than the equivalent article from the newspaper that broke the Snowden story: http://www.theguardian.com/uk-news/2014/nov/25/lee-rigby-rep...
>Cameron, still speaking in the Commons, says he does not believe it is acceptable that there should be internet communications that authorities are not permitted to intercept. The government should legislate on this, he adds.
http://www.theguardian.com/uk-news/live/2014/nov/25/lee-rigb...
Authorities can in practice permit themselves to do anything they damn well want, I'm not under any illusions otherwise. But I want to do everything I can to try to make sure that neither they nor anyone else are able to perform mass surveillance - because I know damned well there is now no other way of stopping such grossly horrendous violations of everyone's inalienable rights to privacy. They lie routinely; they have no oversight, no accountability, no limits, no apologies, no truths, and absolutely no hope of reform inside a system that is not even prepared to acknowledge what it is doing is wrong, let alone stop it.
Talk is cheap, but I will state now that no legislation of any kind will stop me trying to develop, publish, advocate and deploy strong encryption and anti-surveillance techniques everywhere that I can: places where such techniques are illegal are uniformly the places that need it most. Maybe trying to bring a little more 'civil liberty through complex mathematics' is all I can do: but it's something.
a) get into hiring positions in the government and hire the stupidest, least qualified and incompetent people you can get then quit and leave the projects in the shit.
b) spend money galore so it cant be used on anything else
c) leak insider information on the sly.
d) use the tools you built against the people who paid for them.
e) manipulate and shame other staff out of positions of power.
f) play people off against each other and create new rivalry which consumes all money and time.
I worked for the defence industry. This is how to break it.
You mean just like it is hard to spot potential threats in physical mouth to ear communications?
Why is it okay to look at internet data for threats but not okay to put listening devices on every person? Seems like it's the same flow of data coming in either way.
If an employee at a coffee shop overheard patrons at a table detailing a terrorist plot. What exactly do you think would happen right now?
I mean, I'm all for thought experiments, but you haven't carried out step 1.
Why?
The report seems surprised that Facebook failed to hand the guy over to the authorities because he said he wanted to kill a soldier online. They'd be reporting half the teenagers in the world if they were forced to do so
The way things stand, I agree that there's currently a big rush in the UK to approve wider snooping laws
> The report seems surprised that Facebook failed to hand the guy over to the authorities because he said he wanted to kill a soldier online.
Facebook had already taken down several of his accounts because they were deemed offensive and used to spread terror stuff (videos/hate speech). The ISC report says Facebook took the content offline and didn't forward the matter to the authorities.
These laws have been fully rejected once and will not pass in the current government. What the heck news are you even reading if you don't know this?
Or so this is what I gather based on the ISC report describing the MI6's monitoring of the two terrorists who killed the soldier.
> The ISC describes the internet firm’s policy of not policing its own website as “unacceptable” and accuses the firm of “providing a safe haven for terrorists”.
http://www.telegraph.co.uk/news/uknews/terrorism-in-the-uk/1...
It's clear that if the UK have evidence of someone breaking the law then there are options available. What they're complaining about are suspects who are just being monitored as "suspicious".
But even if they'd wanted to ask e.g. Yahoo to monitor the suspects, I can't see how that would have operated. Obviously UK ISPs can identify and monitor specific people (or at least their home/mobile internet). But remote services can't tie things back to an individual[2].
Really they seem to be suggesting that anyone running a large internet service proactively monitor everything for "terrorism" and notify the relevant international authorities when this happens. From the report:
We note that several of the companies ascribed their failure to review suspicious content to the volume of material on their systems. Whilst there may be practical difficulties involved, the companies should accept they have a responsibility to notify the relevant authorities when an automatic trigger indicating terrorism is activated and allow the authorities, whether US or UK, to take the next step. We further note that several of the companies attributed the lack of monitoring to the need to protect their users’ privacy. However, where there is a possibility that a terrorist atrocity is being planned, that argument should not be allowed to prevail.
I find it hard to believe that anyone technical is suggesting this!
The MPs on the committee might not understand how impractical it is but what about the people from GCHQ who were suggesting this? Either they seriously think this is a good ide, or they're just trying to get more ammunition for increased monitoring powers within the UK.
[1] https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/indep...
[2] I suppose they could use the IP address, if GCHQ did the cross referencing for changing NAT etc. But that would be impractical for some ISPs where the IP changes regularly.
Some of the statements it makes are much more modest than the politicised responses; others a fair bit more dubious.... either way I think the below are more interesting talking points than the original article...
(i) They believe multiple accounts were closed by the service providers themselves due to "terrorist content", so they believe the service providers are failing in an assumed duty to share information with UK intelligence services more than an assumed duty to scan the content.
(ii) Some [likely US] providers did share details directly with UK intelligence after the fact whilst others were achieved indirectly via a [presumably US] "partner agency".
(iii) The "partner agency" didn't share everything that was possible to share either, which [unlike the computer service providers] GCHQ apparently considers normal and acceptable given their "resource constraints".
(iv) The report claim that Adebowale "obviously" had a "number of accounts" with the service provider the media are claiming to be Facebook, some of which were closed down "because they hit triggers which we believe were related to their criteria for closing things down on the basis of terrorist content". Which suggests either the provider in question wasn't Facebook, or that the report authors have a serious lack of understanding either of what a Facebook account is or what Facebook's policy on an individual having several accounts is.
(v) GCHQ suggests that an account with the text "let's kill a soldier" should have triggered algorithms detecting potential terrorist content, which implies they believe that [allegedly] Facebook could or should have algorithms that can parse sentences containing trigger words that happen to be extremely common, rather than simple blacklists and flagging functionality.
Don't worry, they've got that one covered:
http://www.ispreview.co.uk/index.php/2014/11/uk-counter-terr...
https://www.scribd.com/doc/248153458/25th-November-2014-ISC-...
source: http://www.parliament.uk/business/news/2014/november/stateme...
This[1] would happen multiple times a day because nobody can tell the different between a joke & a real threat... except teenagers and people who "get it".
1. http://www.cbsnews.com/news/long-island-high-school-student-...