[HN Gopher] Two UK Broadband ISPs Trial New Internet Snooping Sy...
___________________________________________________________________
Two UK Broadband ISPs Trial New Internet Snooping System
Author : offby37years
Score : 432 points
Date : 2021-03-11 23:15 UTC (23 hours ago)
(HTM) web link (www.ispreview.co.uk)
(TXT) w3m dump (www.ispreview.co.uk)
| he0001 wrote:
| How would things like Tor work against these things?
| sammy2244 wrote:
| I'd like to see them try to find the domain when ECH becomes
| standard
| swiley wrote:
| Don't like the environmental impact of monero and TOR? Stop
| making them something everyone needs.
| bennysonething wrote:
| I thought under previous government all isps keep logs of all
| internet history for two years?
| [deleted]
| nazbuck wrote:
| Just when you think Englandistan couldn't be anymore cucked by
| Zionists shit like this pops up lmao
| dfgdghdf wrote:
| What can an individual do to protect against this (excluding
| going off-grid)?
| cm2187 wrote:
| Is a datacentre considered an ISP in this respect? Between vpns
| and just remote desktoping into a VM, it seems trivial to
| circumvent to real criminals while being a privacy nightmare to
| the rest of the population. There is a probability 1.000 that
| this data will be abused.
| ajsnigrutin wrote:
| This is politics, who cares about a few people doing bad
| stuff...
|
| If the shit hits the fan, you want to know the political stance
| of all the citizens, and who the troublemakers will be, if
| something large is happening. ...and for that, it's enough to
| know which political sites they're visiting, even if you don't
| know the content itself.
| lupire wrote:
| The fan was hit Jan 6 and no one in power really cared.
| novok wrote:
| Anything any large organization does is not about absolutes but
| about increasing or reducing the probability of something in a
| population. The small few VPNers can be dealt with later.
|
| Also this is done in america for commercial reasons to sell to
| adtech, like t-mobile recently or comcast for quite a while and
| probably all the others.
| null0pointer wrote:
| 1. Trivial to bypass: Check
|
| 2. Further degrades the privacy of the general public: Check
|
| Just another day in internet legislation.
| mattowen_uk wrote:
| > _Trivial to bypass: Check_
|
| For you and me, yes. For Joe Public no. I think it's fair for
| people to expect a modicum of privacy _inside their own
| home._
|
| Is constant surveillance of a nation's citizens OK? I don't
| think so.
| brokenmachine wrote:
| This often makes me think, what would happen if the
| authorities suddenly instituted something that actually
| wasn't trivial to bypass?
|
| There are smart people working for them, why do they keep
| bringing in this stuff that doesn't actually have an effect
| against the baddies?
|
| Is it possible that they are self-sabotaging because they
| actually realize they don't want to live in the world they
| are rushing headlong towards? Or is that giving them too much
| credit?
| 14 wrote:
| I think it is supposed to be a slow erosion of our rights
| over time so that each generation that follows every thing
| seems par to the course.
| alephu5 wrote:
| Those trying to communicate will always have the advantage
| thanks to cryptography. It gives you many way to secure and
| obfuscate communications, even in plain view.
| ben_w wrote:
| I disagree. Surveillance isn't limited to breaking
| encryption -- the Stasi would put cameras in water cans
| to spy on funerals, drill holes in walls while you were
| out to spy on you in your own apartment, etc. -- and the
| tech for meatspace surveillance has only gotten smaller
| and cheaper since the fall of the Wall. Laser microphones
| in particular are something a high school student could
| reasonably make with a pocket-money budget.
| sodality2 wrote:
| https://f-droid.org/packages/hans.b.skewy1_0/ for the
| eavesdropping microphones :)
| ben_w wrote:
| > It works best with a small hardware extension (a small
| speaker/headphone) to focus the sound on the mic, making
| it silent its surroundings. An idea how to build it is
| found in the Menu.
|
| Great when you know where the microphone is but can't
| leave the area for a private chat; not so useful when the
| microphone is _any_ nearby substance that reflects some
| wavelength and which vibrates enough when exposed to
| sound that the reflected light can be decoded.
| dmitryminkovsky wrote:
| What I want to know is: what happened? I always think of this
| event 70 years ago [0]:
|
| > "police obtained the fingerprints of every male aged 16 and
| over who had been in the vicinity of Blackburn on the night of
| 14-15 May to compare their fingerprints to those left at the
| crime scene by the perpetrator. ... a milestone in the history
| of forensic science; this being the first time a mass
| fingerprinting exercise had been implemented to solve a murder
| in the United Kingdom."
|
| > Just weeks prior to the execution of Peter Griffiths, _all
| the fingerprint records obtained from individuals who had been
| in the vicinity of Blackburn between 14 and 15 May were
| publicly destroyed_ [emphasis my own] in a mass pulping
| exercise at a local papermill. Several local journalists were
| present to record the destruction of the records.
|
| Why was society so vigilant about giving data that might be
| abused to authorities, and now, when the data is so much more
| vast and powerful, no one seems to care?
|
| [0] https://en.wikipedia.org/wiki/Murder_of_June_Anne_Devaney
| bambataa wrote:
| People are apathetic and ill-informed.
|
| It is far easier and more enjoyable to believe that Britain
| is peace- and freedom-loving, which is the continual message
| from the tabloids, than to keep track of these developments
| and their implications.
| dmitryminkovsky wrote:
| If so, why were they not apathetic and ill-informed a mere
| then, not even 100 years ago? Certainly people of the time
| thought Britain was peace- and freedom- loving then, too.
| brokenmachine wrote:
| The average person doesn't understand all our nerd worries.
| zo1 wrote:
| Neither does this specific "nerd". I honestly have yet to
| be convinced; a lot of it seems very similar to fear
| mongering and illogical with the arguments being very
| nebulous. Maybe I have yet to sit down and flesh it out
| with a deep privacy advocate.
| bennysonething wrote:
| I understand the need for wire tapping and for the police
| to be able to do their job. What I don't understand is
| the no need for a warrant. Also the list of public bodies
| who can access this data includes the health and safety
| executive, the pensions regulator, the environment
| agency.
|
| I see no reason why bodies like this can have access to
| sensitive data about individuals without requiring a
| warrant.
|
| https://www.google.com/amp/s/amp.theguardian.com/world/20
| 20/...
| KMag wrote:
| The big problem is that our modern legal code is so
| convoluted that people regularly accidentally commit
| crimes[0][1] but aren't aware of it, leaving a big gap
| for inconsistent enforcement (mostly against those who
| dare challenge authority or the authorities are biased
| against). There's reasonable evidence that the FBI or
| rogue agents within the FBI tried blackmailing Dr. Martin
| Luther King, Jr. into committing suicide.[2] J. Edgar
| Hoover was collecting a stash of blackmail information on
| politicians.
|
| I'm very unlikely speak up enough to become a target, but
| the next Dr. King, the next Snowden, the opponents of the
| next Trump or next J. Edgar Hoover are going to have big
| problems if privacy continues on its present course.
|
| Privacy isn't currently a big problem for the average
| citizen in our society, but it's very important fat-tail
| event insurance to have in the future. By the time you
| realize you need to worry about privacy, it's probably
| already too late. History has shown liberal democracies
| are at best metastable (all governments tending toward
| authoritarianism if not actively maintained) and
| whistleblowers are an important stabilizing force.
|
| [0] https://www.insidermonkey.com/blog/7-easiest-
| felonies-to-com...
|
| [1] http://thinkaboutnow.com/2016/07/average-americans-
| commit-3-...
|
| [2] https://en.wikipedia.org/wiki/COINTELPRO
| yomly wrote:
| Not that long ago the most powerful and free country in
| the world was engulfed in chaos after the killing of
| George Floyd.
|
| The event was polarising and you had your anti-rioter
| camp and anti-police camp. It should not be hard to see
| how there would have been direct chains of command on
| either side which could facilitate data misuse.
|
| If you want a hard example, look at Hong Kong: protestors
| getting arrested via all manner of tracking, but also
| police's family being doxxed by protestors.
|
| Also see Belarus and now Myanmar.
|
| Things are all fine and dandy, until they aren't.
|
| This is why you need checks and balances.
| dmitryminkovsky wrote:
| If I understand correctly, fingerprints were quite the
| nerdy technology back then. They're not beep boops in a
| data center, but it takes a high degree of nuance to argue
| against "if you didn't commit a crime, you have nothing to
| worry about."
| noir_lord wrote:
| In part possibly because it was a few years after WW2 where
| millions of allied soldiers thought against Fascism which was
| enforced via secret police (Gestapo).
|
| It's easier to stand against something when there is
| something stand against - The end of the cold war meant the
| west didn't have a "At least we don't do <insert Stasi
| tactics">" to oppose itself to.
|
| Now we routinely do things that would have made the Stasi wet
| themselves in excitement.
| jjgreen wrote:
| The Allies did not fight against Fascism, they fought
| against Germany.
| tweetle_beetle wrote:
| I wonder if it's to do with the physicality of older data
| collection methods. In your example, the data collection
| method was very clear: getting your fingers black and ordered
| to perform an action with them by someone in uniform. The use
| of that data is even clearer: the potential for being
| executed.
|
| It is very different to the newer methods where you don't
| necessarily know what is being collected or what it is being
| used for.
|
| I saw discussed online the other day some alarmist comments
| about the government wanting to know "what your bedroom
| activities are" in response to receiving the census letter in
| the post and seeing a mention of sexuality. Putting aside the
| ignorance of conflating sex with sexuality, I thought it was
| interesting how hard this problem is for most people to deal
| with.
|
| That same person no doubt uses multiple mainstream social
| media sites, has browsers full of tracking cookies, uses
| loyalty cards and has their data collected, sold and used for
| all sorts of things. But it's the letter through the front
| door, for, of all things, a function of society that is over
| 200 years old, that causes alarm.
| [deleted]
| easytiger wrote:
| It's a good observation. Not unrelated I suspect io why
| society no longer cares about basic personal freedoms in the
| wake of covid panic. Basic private peaceful assembly with
| your family is now or recently has been a civil and in some
| places criminal offence.
|
| Few seem to care
| nkellenicki wrote:
| Because it's abstract. The people aren't _actively_ having to
| do anything, such as hand over their records - it's happening
| away from them. It's hard to connect with abstract.
|
| It's easier for people to connect with the reason _for_ doing
| it. Stop the terrorists, it may happen to you, etc. But the
| other way round is harder because it's invisible and you can
| live your life without caring. Even the warnings fall on deaf
| ears because "come on, you're being irrational" or "meh,
| doesn't affect me".
| hanniabu wrote:
| I think it's also a lot easier to dismiss with the use of
| media pundits on replay saying "if you have nothing to hide
| then there's no issue".
| [deleted]
| inglor_cz wrote:
| In a similar way, withholding of income tax feels much more
| painless than having to pay it in full backwards in April,
| or even several times a year.
|
| There is a good chance that if everyone had to pay their
| income tax manually, the tax burden would shift quite a
| bit.
| zimpenfish wrote:
| > if everyone had to pay their income tax manually
|
| Isn't this basically the US model though? And ...
|
| > the tax burden would shift quite a bit.
|
| Hasn't really happened for them (unless you're in the 1%,
| obvs.)
| Nailgun wrote:
| Is there anything I can do about this as a citizen to protect my
| privacy?
| techrat wrote:
| Use a VPN for everything.
| azalemeth wrote:
| This is what I have done since the original snooper's charter
| came out. It is not perfect -- I am sure that GCHQ etc have
| got pretty good at correlation attacks -- but by encrypting
| _everything_ BT, Virgin Media etc. will just get a list
| containing exactly one IP and a month-long connection time.
|
| Secondly, I really recommend Andrews & Arnolds [1] as an ISP
| if you can only get ADSL. I don't use them at home because I
| need the bandwidth afforded by cable -- for which there is
| one supplier in my town, Virgin (bah!) -- but AAISP supply my
| mother's home and are genuinely amazing. She had some issues
| due to BT and they let me raise an issue via IRC; the few
| times I have had to get in touch with them it's been an
| absolute pleasure; they disclose their support as "xkcd/806
| compliant". Their owner also is a strong campaigner for
| digital privacy.
|
| [1]
| Nailgun wrote:
| Do you have any recommendations for VPN providers?
| input_sh wrote:
| This one's frequently suggested: https://mullvad.net/en/
|
| You can pay by cash or cryptocurrencies, you don't need
| to provide them with your email address, headquartered in
| the EU, Mozilla's VPN is a partnership with them, open
| source clients with reproducible builds, WireGuard
| support.
| sodality2 wrote:
| Also, no logins, just a single string of numbers as your
| account number. So no one can go to mullvad and say
| "gimme the deets for criminal@gmail.com", which is nice.
| azalemeth wrote:
| I personally have used two: cryptostorm and mullvad. Both
| were good, mullvad was better (and has regular
| independent audits: see, e.g. https://cure53.de/pentest-
| report_mullvad_2020_v2.pdf)
| taneliv wrote:
| Just switch between different ones every few months or
| so. Try to select some, which are not obviously nefarious
| against you, and might be going bankrupt soon, with the
| hopes of them not keeping much logs or records
| afterwards.
| cutthegrass2 wrote:
| Thanks for mentioning AAISP, I will check them out.
|
| I'm currently with a BT reseller and am thoroughly
| disappointed with the service so looking to move.
| cesarosum wrote:
| +1 for Andrews & Arnolds.
| openfuture wrote:
| VPN solves absolutely nothing. You are just moving your root
| of trust around. Nym is a very promising mixnet that is built
| with a global passive adversary in mind. That may work.
| azalemeth wrote:
| Isn't this almost exactly the use-case for a VPN: one well-
| defined snooping adversary? If one _assumes_ that the VPN
| provider doesn't lie (or at the very least is independently
| audited) and has a server beyond your jurisdiction then
| isn't moving the root of trust away from your un-
| trustworthy ISP the right thing to do?
| justinclift wrote:
| If you have the right skills, it's not hard to set up Squid
| or your choice of other proxy software in the EU (eg
| outside the UK), and direct your browsing traffic over it.
|
| Latency from the UK to (say) Germany or the Netherlands
| isn't too bad either.
| outsomnia wrote:
| ... if you own and trust the VPN server and exit arrangements
| then this is true.
|
| But it would have to be outside the UK to avoid the same
| fate, since you are in the UK, this makes it harder to trust
| the service provider and their security services not to find
| your "foreign" traffic very interesting and not subject to
| their laws protecting their own citizens' data.
|
| A lot of "we don't keep logs" vpn providers were found to
| very much keep logs of all your traffic. Some of the people
| in the VPN business are the last ones you would want to see
| all your traffic.
|
| Tor might work, or at least change the threat model, but it
| cannot be used as a high bandwidth proxy.
| LatteLazy wrote:
| Aren't uk ISPs already required to keep logs of everything that
| happens on a connection? How is this different to that? I'm not
| trying to be snarky, I'm just confused what is being added when
| they already (I thought) collected everything on everyone...
| _jstreet wrote:
| Could I submit freedom of information request to my ISP and be
| provided with all the details they store about my internet
| browsing? Unfortunately BT are a private company so sounds
| unlikely..
| hkt wrote:
| Freedom of information is about the activities of public
| authorities, and that includes private sector bodies performing
| public functions. A person could access aggregate data and
| other non-personally identifying information this way but it
| would likely require a court to rule on the public activities
| of the company. This happened with privately run care homes
| which were deemed to have public functions.
|
| However, you don't want that: you want a subject access
| request. This covers data from private sector companies too.
| Not responding is illegal and you can take them to the
| Information Commissioner and eventually the Information
| Tribunal.
|
| This is the information commissioner's office's guide to making
| a request:
|
| https://ico.org.uk/your-data-matters/your-right-to-get-copie...
|
| Source: trained as a journalist and am quite good at media law
| stuff. Not a lawyer, but have had substantial training and
| think this is worth a punt.
| scott_w wrote:
| Unfortunately this won't tell you if the ISP is storing extra
| data in compliance with the Snooper's Charter because legal
| compliance can override the GDPR. Basically, the law saying
| "you're not allowed to tell anyone you hold this data"
| overrides an SAR and a legal case to force compliance would
| likely fail on these grounds.
| hkt wrote:
| Does the charter specifically forbid companies from
| reporting what they store? I'm not familiar with it in
| detail. I'd be surprised..
| bennyp101 wrote:
| Basically, If you are required to store the data under an
| order, then you are not legally allowed to disclose the
| fact you have received an order, or what you are storing.
|
| Same as getting a request from the NCA asking for details
| on an individual, can't disclose that you received one.
| hkt wrote:
| Ah. They're the same as the old RIPA requests then. In
| another life I worked for a company which processed them
| from time to time. It is a dreadful shame that stuff has
| survived.
| bennyp101 wrote:
| Yea, only from what I can see, worse. Rather than just
| "tell me who had this IP on this date" it will be "tell
| me everything they visited and looked at during this
| period"
| throwawayffffas wrote:
| I don't know about freedom of information, but I think you
| could under GDPR for as long that applies to the UK.
| linuxlizard wrote:
| Why didn't they just do what the US Gov did? Snoop but not tell
| anyone. Certainly would have saved them some grief.
| https://en.wikipedia.org/wiki/NSA_warrantless_surveillance_(...
| tokai wrote:
| If you want to bust people for petty crimes and not 'terror' it
| makes more sense with a publicly mandated system I guess.
| barbacoa wrote:
| The americans used warrantless wiretapping for petty crimes
| too. In fact i don't think they even used it for "terrorism".
|
| https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-
| intel...
| DanBC wrote:
| Because we, unlike the Americans, have article 8 protections.
| dylan604 wrote:
| You have a piece of paper, America has a piece of paper, but
| neither of them are worth anything if the protections to
| declare are not upheld. The repurcussions for violating those
| protections are more trivial than traffic violations.
| DanBC wrote:
| The protections are routinely upheld in UK courts.
| danShumway wrote:
| The US has laws that should have prevented people from lying
| to Congress about PRISM, but it happened anyway.
|
| Your Article 8 protections only matter as much as they're
| enforced and respected by the government. If Article 8 was
| the defense you imagine it to be, then the Investigatory
| Powers Bill wouldn't have passed in the first place.
|
| It's very hard for me to square the text of Article 8 with a
| bill that allows warrantless access of every single IP
| address you visit. If that's consistent with the government's
| interpretation of the text, then it doesn't sound to me like
| the text is doing its job.
| incompatible wrote:
| The article says they are trying: "The IPAct effectively
| prohibits ISPs from talking about much of this, which makes it
| difficult to verify the details"
|
| I'm not sure if the "URL" column in a table in the article is
| supposed to contain URLs. In the example it only has domain
| names. I don't think full URLs can be obtained from SSL/TLS
| connections.
| tialaramex wrote:
| I assume it's because to lay people don't distinguish a
| domain name, an FQDN, eTLD+1, URL, "web address", URI, etc.
| and I'm sure that it's just as frustrating in any other
| discipline with a complicated vocabulary.
|
| When your browser tries to display https://www.example.com/so
| me/directory?someParameter=Value#A... ::
|
| #Appendix isn't sent anywhere, your browser only needs that
| locally
|
| The path /some/directory and the query ?someParameter=Value
| are encrypted using keys which should be known only to the
| browser and server, today in most cases the keys are random
| and will be forgotten soon afterwards
|
| The scheme https is implied by your browser's connection to
| an HTTPS web server. Modern browsers also explicitly transmit
| ALPN requesting h2 (HTTP/2) if available in their
| ClientHello, this will not be encrypted today.
|
| The server name www.example.com is _somewhat_ implied by your
| browser 's connection to an IP address for this server. Any
| browser that still works in 2021 explicitly transmits the SNI
| requesting this name, so as to enable Virtual Hosting which
| offers multiple distinct web servers on a single IP address.
| SNI is also in the ClientHello and thus not encrypted.
|
| The full server name will also be looked up by the browser in
| DNS. In many cases this means an unencrypted UDP query for
| that name, and this may in turn trigger a query for
| example.com, and in theory at least, com itself because DNS
| is hierarchical and the hierarchy may need to be discovered.
|
| You can secure some of this last step by using any of the
| DPRIVE technologies, including DNS over HTTPS (DoH) or DNS
| over TLS (DoT) and some day DNS over QUIC (DoQ). Eventually
| DPRIVE might also secure the recursion, but even today if
| snoopers can see that Google's DNS service asked about
| example.com that does not pin down _who_ wanted them to do
| that, let alone why.
|
| If you've secured DNS, this will pave the way for ECH, a
| forthcoming standard to Encrypt the ClientHello. It is likely
| that popular browsers will begin just doing ECH (silently
| enabling it for at least some users) in the next year or so,
| but right now it isn't quite finished.
|
| Even with an Encrypted ClientHello, the IP gives away roughly
| who you connected to. The Internet Archive, the Fox News web
| site, and Wikipedia have no interest in sharing IP addresses
| with Porn Hub so as to throw off snoopers who are wondering
| roughly what you're doing. On the other hand, Encrypted
| ClientHello would hide whether you're looking at the German
| Wiktionary or the English Wikipedia page about the Hitler
| Youth, and it would mean there was no longer a privacy
| advantage to a site using directory prefixes to categorise
| things versus using server names.
| pabs3 wrote:
| The set of IP addresses you connect to correlates with the
| domain connected to and the amount of data transferred
| correlates with the exact URL being loaded.
|
| Here is a post about the IP address part:
|
| "What can you learn from an IP?"
| https://irtf.org/anrw/2019/slides-anrw19-final44.pdf
|
| https://blog.apnic.net/2019/08/23/what-can-you-learn-from-
| an...
| AZ-X wrote:
| You do NOT desire ECH, if a server echoes all certificates
| it carries with. https://github.com/AZ-X/pique
| nostromo wrote:
| And then lie about it to congress. Repeatedly.
|
| https://www.youtube.com/watch?v=QwiUVUJmGjs
|
| https://www.youtube.com/watch?v=oYNXVgYhPOc
|
| And then lying about lying about it.
|
| https://youtu.be/2d03yjXRPtI?t=262
| lettergram wrote:
| For as much as many dislike the guy, Trump actually fired all
| these people... course they now work at CNN and the like.
| ianlevesque wrote:
| Congress then really outdid themselves by focusing all
| legislation on telephone calls (as if anyone younger than 60
| even cares about that part) and leaving the internet snooping
| untouched. Really fantastic misdirection.
| gumby wrote:
| Ahh, but it's actually very clever: young terrorists use
| _phone calls_ to communicate figuring all the normal means
| are being spied upon whereas nobody uses the phone anyway
| so it won't be spied on.
|
| Diabolical!
| dylan604 wrote:
| right, so just put surveilance on anyone ordering _new_
| land line phone service. problem solved
| IAmGraydon wrote:
| People always ask me about misdirection, It's fantastic.
| Let me tell you about misdirection. I do very well with
| misdirection. I love misdirection. No one loves
| misdirection more than me, BELIEVE ME. Misdirection loves
| me. We're going to have so many misdirections you are going
| to get sick of misdirection. The misdirection just got 10
| feet higher. I have the best misdirection.
| amscanne wrote:
| (Relevant bit starts at ~6:00 in the first video)
| [deleted]
| thinkaboutits wrote:
| Tell the right you are looking for Islamic terrorists. Tell the
| left you are looking for white supremacists.
|
| Like shooting fish in a barrel; total surveillance state
| achieved.
| eranimo wrote:
| The actual left is generally against that sort of thing, and
| even significant factions on the right don't want the kind of
| government control, what you should be concerned about are
| liberal centrist people.
| maybelsyrup wrote:
| You're right[0], though you won't get much recognition on HN.
|
| [0] https://t.co/9UuceYD2Xj?amp=1
| yew wrote:
| I hate to break it to you, but Greenwald is just another "I
| was a teenage leftist" Republican getting ready for his
| book tour. He's been pandering to Trump supporters for a
| few years now...
|
| He's a terrible example to cite if you want to support the
| actual left.
| maybelsyrup wrote:
| "People's Front of Judea"
| yew wrote:
| I mean, he has started spreading TERF propaganda on
| Twitter (because those particular brainworms always
| infect the new converts, for _whatever_ reason). That and
| the Trump thing aren 't minor ideological differences -
| they're fundamental, irreconcilable conflicts. There's no
| future for them.
| SilverRed wrote:
| I think what you mean by "actual" left is probably more
| accurately described as libertarian left as apposed to
| authoritarian left. Both are real.
| delecti wrote:
| Probably more like "actual left" in contrast to the
| milquetoast kind that passes for the left wing of
| mainstream US politics, which are center-right by global
| standards.
| lupire wrote:
| "left" and "right" are nearly devoid of meaning once you go
| beyond "the bickering between two most popular teams in a
| country"
| AZ-X wrote:
| Tell the above you are looking for Aliens, who cares right,
| left or flipping middle :D
| peterkelly wrote:
| Has everyone forgotten about Tempora [1], XKEYSCORE [2], PRISM,
| [3] and the other Snowden revelations [4]? This kind of shit has
| been going on for at least a decade in various forms.
|
| [1] https://en.wikipedia.org/wiki/Tempora
|
| [2] https://en.wikipedia.org/wiki/XKeyscore
|
| [3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
|
| [4]
| https://en.wikipedia.org/wiki/Global_surveillance_disclosure...
| morrbo wrote:
| As a person from the UK, no I've not forgotten. The difference
| here (and this is NOT excusing them) is that you've gone from a
| series of systems which didn't officially exist, accessible
| from the select few of intelligence agencies and no doubt
| secure as hell into private ones which are controlled by people
| like BT. Yep, BT. The same BT who are laying off 10k staff this
| year because they need to cut costs. This isn't something
| they're putting effort into, this is some mandated program
| which will mean they're going to come up with the cheapest
| solution to store all your data. That's obviously bad.
|
| What was disappointing about this was that I remember the day
| this bill got passed. I remember refreshing BBC news
| repeatedly. Not one article was written about the snoopers
| charter within the days leading up to it (or the day itself).
| Now, back to the "bad" again... The list of people who can
| access these records, without a warrant is just utterly insane.
| It starts off legit-ish but honestly some of these are pretty
| hard to justify:
|
| * Metropolitan police force
|
| * City of London police force
|
| * Police forces maintained under section 2 of the Police Act
| 1996
|
| * Police Service of Scotland
|
| * Police Service of Northern Ireland
|
| * British Transport Police
|
| * Ministry of Defence Police
|
| * Royal Navy Police
|
| * Royal Military Police
|
| * Royal Air Force Police
|
| * Security Service
|
| * Secret Intelligence Service
|
| * GCHQ
|
| * Ministry of Defence
|
| * Department of Health
|
| * Home Office
|
| * Ministry of Justice
|
| * National Crime Agency
|
| * HM Revenue & Customs
|
| * Department for Transport
|
| * Department for Work and Pensions
|
| * NHS trusts and foundation trusts in England that provide
| ambulance services
|
| * Common Services Agency for the Scottish Health Service
|
| * Competition and Markets Authority
|
| * Criminal Cases Review Commission
|
| * Department for Communities in Northern Ireland
|
| * Department for the Economy in Northern Ireland
|
| * Department of Justice in Northern Ireland
|
| * Financial Conduct Authority
|
| * Fire and rescue authorities under the Fire and Rescue
| Services Act 2004
|
| * Food Standards Agency
|
| * Food Standards Scotland
|
| * Gambling Commission
|
| * Gangmasters and Labour Abuse Authority
|
| * Health and Safety Executive
|
| * Independent Police Complaints Commissioner
|
| * Information Commissioner
|
| * NHS Business Services Authority
|
| * Northern Ireland Ambulance Service Health and Social Care
| Trust
|
| * Northern Ireland Fire and Rescue Service Board
|
| * Northern Ireland Health and Social Care Regional Business
| Services Organisation
|
| * Office of Communications
|
| * Office of the Police Ombudsman for Northern Ireland
|
| * Police Investigations and Review Commissioner
|
| * Scottish Ambulance Service Board
|
| * Scottish Criminal Cases Review Commission
|
| * Serious Fraud Office
|
| * Welsh Ambulance Services National Health Service Trust
| varispeed wrote:
| I was amazed that I also couldn't find any prominent mention
| about this when it passed, but that only cemented my view
| that our media are not free. They will not publish something
| that could outrage public against an agenda that has got a
| green light and has to go through no matter what. Even so
| called outlets that praise themselves as being "anti-tories"
| have not published anything. There is plenty of stories like
| that and it is extremely worrying. I think there is
| corruption going on at a scale not seen before and there is
| media embargo. One striking story I remember when it was
| discovered that husband of drugs minister (that minister had
| anti-cannabis stance) was running medical cannabis crops
| making the UK biggest exporter of cannabis in the world. When
| this was discovered only RT wrote about that and weeks later
| they where threatened their license will be pulled (on a
| "unrelated" matter, to not bring attention). Only few months
| later, when everyone was talking about it online, BBC dared
| to publish the story and drugs minister promised to withdraw
| herself from anything cannabis related and she kept the
| office. Can you imagine that in a civilised country?!
| AndyMcConachie wrote:
| Not saying this is a cure all. But we should support British
| independent media.
|
| https://www.dailymaverick.co.za/declassified-uk/
|
| https://www.thecanary.co/
| mathw wrote:
| Why does anybody other than policing and security agencies
| need access to this stuff? NHS? Fire and rescue? WHAT? They
| don't have a role in investigating crime. Okay the fire
| brigade do post-fire analysis of possible arson etc. but
| that's not something you need access to somebody's internet
| history for.
| knorker wrote:
| Because the UK is only borderline a free society.
|
| It's like asking why does the king of Saudi Arabia need to
| have the power to jail his subjects for no reason? Why does
| Putin need to have the right to jail or kill political
| opponents?
|
| The UK doesn't give you right to remain silent (your
| silence will be used against you), you are compelled to
| bear witness against yourself (you must surrender
| passwords), and there are super-injunctions where you are
| gagged and not even allowed to discuss the legal issue with
| your lawyer.
|
| This is the country that sent government thugs to force
| journalists to physically destroy their own laptops and
| hard drives.
|
| With religious clergy overtly and explicitly being part of
| government power (in house of lords).
|
| Hell, it's super recent that government power in house of
| lords stopped being _inherited_.
|
| Imagine if the US senate was staffed solely by inherited
| power. Not just in the style of Bust Sr/GWB, but _actually_
| inherited. It 's not the same, since the US senate is more
| powerful than the house of lords, but "it's complicated".
|
| So your confusion here may come from the fact that you look
| at the UK as "like the US, but they talk weird", where it's
| a couple of step closer to "Like Saudi Arabia, but part of
| political power is elected".
|
| Obviously Saudi Arabia is much further away along this
| spectrum, but I hope you see my point anyway. You seem to
| be saying "how can a free society do this?", where the
| answer is "because it's not that free, your assumption is
| flawed".
| knorker wrote:
| ... and this is what you get: A lifetime appointee to the
| house of lords has proposed a curfew for men after 6pm.
|
| https://news.sky.com/story/sarah-everard-baroness-who-
| sugges...
|
| This idiot (who is clearly making a completely idiotic
| contraproductive and divisive point, since I'm charitable
| enough to not take her at face value) is there for life.
| She can't even be voted out. She's there for life.
|
| But what can you expect from the Green Party? Are they
| actually competent at what they do in any country?
| bananapub wrote:
| The Greens in Australia are by and large the most
| rational party in the country, from the future of energy
| to drug policy to social policy.
| bananapub wrote:
| well, yes, the UK has many problems including some of the
| above, but most Western countries are deeply flawed in
| terms of real freedoms - e.g. US governments routinely
| murder people (both official "judicial" executions and
| extra-judicial killings by police), the "patriot" act
| abridges all sorts of freedoms in the name of terrorism,
| routine civil forfeiture of random property by police,
| denial of basic healthcare for many people, abridgement
| of basic bodily autonomy for women with many states ready
| to end it entirely if the Supreme Court ever changes it's
| mind, secret unappealable no-fly lists, everything to do
| with guantanamo bay or CIA "black sites".
| knorker wrote:
| I'm not saying other countries are perfect, including the
| US.
|
| But there's a difference. The US is not living up to its
| ideals of equality and democracy, or even equal
| treatement under the law (e.g. lying to congress about
| not "collecting" data about US citizens). The UK is not
| even aspiriting to living up to those standards.
|
| For example take torture. The best way to paint this is
| to "do horrible things for the protection of freedom and
| democracy". It's Realpolitik.
|
| I'm still absolutely against torture, but it's a
| difference in _kind_ to the UK putting religious clergy
| into positions of government power.
|
| It's possible to defend torture as an instrumental goal
| to the ultimate goal of freedom & democracy. But the UK
| is not aiming for the same ultimate goal.
|
| Similarly it's a difference in _kind_ when Trump or
| Bolsanaro practice nepotism, compared to when some asshat
| gets a peerage in the UK.
|
| We can list flaws all day, but the difference between the
| US and the UK here is that the US really does have an
| ideal of equality, freedom, and democracy, and the UK
| does not. The UK has not outgrown the Monarchy. And I'm
| not just talking about the royal family, but the whole
| aristocracy.
|
| Another way to explain this: If you tell the story of
| Plebgate to an American, they won't fully get it. It's an
| insult, yes, but merely saying it's an insult is missing
| the point. It's bad because the class society is still
| there. People owning their homes often still literally
| pay a land tax to someone with a lord title. A land Lord.
|
| It's a step on the spectrum to Saudi Arabia, where within
| its borders every grain of sand, and every person, is the
| personal property of the king.
|
| If you take the US and add a permanent unelected head of
| state, add 20 dedicated priest posts to the senate,
| remove the first, second, fourth, and fifth amendment,
| and on top of that have a society that generally feels
| like this is a good idea, then you have a completely
| different country.
|
| And it's not a country that even aspires to be as free or
| democratic as the US. And since the UK doesn't try, it
| also isn't.
|
| Under Trump we saw that the US institutions were (mostly)
| holding. What's being "held" in the UK is not even a goal
| on the level of the US.
|
| You point out many things. And probably those kinds of
| things the US has done more than Saudi Arabia has done.
| But nobody would therefore conclude that Saudi Arabia is
| more freedom&democracy than the US, would they?
| cs02rm0 wrote:
| I don't even think the Police should have access.
|
| If it's that serious, have them ask an intelligence agency
| to investigate and report - as they do anyway today. They
| don't need direct access.
|
| But yes, crazy that the Food Standards Agency always end up
| on this list. Must be someone who knows someone.
| morrbo wrote:
| Yep, food standards Scotland could call up TalkTalk and ask
| for a copy of my browsing history. This is assuming its not
| been leaked because they got hacked by a 16 year old script
| kiddy *again*.
| outsomnia wrote:
| The probability of the Chav Network being able to convert
| bungs into your private data, more or less at will, must
| be about 100% with that list.
| emayljames wrote:
| I'll call Dave at the Food Standards Agency, he'll get
| your internet history. Crimes against food.
| jozvolskyef wrote:
| The NHS investigate people for abusing their authority as
| medical professionals. I don't know how they divide the
| work with the police, but they do have their own people for
| investigations.
| adwww wrote:
| Also for fraudulent malpractice cases. An investigation
| made the news recently where a lady was suing a hospital.
|
| She claimed some massive disability following an
| operation, and the hospital's own investigations team
| followed her and filmed her jogging, drinking, etc.
|
| It would have been using these same powers to do the
| surveillance work.
| HPsquared wrote:
| Observing someone in public isn't really in the same
| league as this.
| nvarsj wrote:
| Let's not forget who brought us the wonderful law: Theresa
| May, as home secretary. Architect of the Windrush scandal,
| for which she took 0 responsibility.
|
| She probably envisioned the Home office doing mass denial of
| visas based on a lookup of applicant names with IP addresses
| deemed to be related to terrorist activity.
| doggodaddo78 wrote:
| TM is a plutokleptocratic fascist Tory who sticks it to
| "the little people" at every opportunity.
| disgruntledphd2 wrote:
| And yet she's still not as bad as the current PM.
| noir_lord wrote:
| Only because the current PM is all of that _and_ inept in
| every dimension except his own political survival.
| [deleted]
| oji0hub wrote:
| The BBC is state media, so unfortunately not surprising.
| dijit wrote:
| Doesn't really make it ok though.
|
| We should absolutely keep it in the public eye lest it be
| relegated to acceptance.
| buran77 wrote:
| It doesn't make it ok at all. But this is a double edged
| sword. Just keeping this in the public eye but without hard
| action against it simply normalizes the situation as "problem
| that's only big enough to complain about". People need to see
| action being taken, like right to repair initiatives that
| bore fruit.
|
| Unfortunately unlike right to repair, this is a fight against
| a government which already has too much leverage on anyone
| and gaining more, making the fight progressively more
| difficult. It's clear that the gov't _will_ use any power at
| it 's disposal to fight against any such citizen initiative.
| feralimal wrote:
| It was relegated to acceptance about 10 years ago.
| thraxil wrote:
| I find it a bit amusing that we are now at the point where we
| can say "has everyone forgotten about" about Snowden
| revelations. When those came out, my reaction at the time was
| "has everyone forgotten about ECHELON?"
| https://en.wikipedia.org/wiki/ECHELON
| squarefoot wrote:
| Back in ...huh maybe late 2002, we were testing embedded
| machines for surveillance video streaming through the then
| new UMTS 3G system. So we had this very compact (there were
| no Raspberry PIs back then) Linux machine with its PCMCIA 3G
| card which would use ffmpeg to stream the video taken by a
| camera, to a nearby broadband connected PC having a fixed IP.
| Everything worked, but we were literally struggling to
| achieve low latencies because the application would have been
| in potentially life threatening scenarios; the customer had
| been very clear about the numbers: half a second maximum
| latency, not more. We were almost getting there, with some
| quality tradeoffs, still something was slowing us down, so we
| fired a traceroute to see the path traveled by our precious
| video packets, and the shock when we found that to reach a
| machine on the same bench they went through not one but two
| countries to get to London, and back. We filed a detailed
| request to the carrier, which was our partner, to ask if
| there was something wrong with routing. We got no reply,
| other than realizing the following days that they had blocked
| ICMP and other things so that we couldn't use traceroute
| anymore.
| secfirstmd wrote:
| Hahaha yeh same here. People thinking I was mad talking about
| it until Snowden came around
| [deleted]
| doggodaddo78 wrote:
| Mass, warrantless surveillance in the US has be going on for
| 30+ years, I can assure you.
| Havoc wrote:
| >The IPAct effectively prohibits ISPs from talking about much of
| this
|
| How very democratic and transparent of them
|
| Kinda in two minds about this...tempted to implement a VPN to a
| VPS but not super keen on killing my gbps speeds.
| M2Ys4U wrote:
| VPNs just move the problem around, they don't solve it.
|
| You've gone from your ISP being the point at which interception
| can happen to your VPS provider and/or _their_ ISP being the
| point at which interception can happen.
| [deleted]
| gorgoiler wrote:
| If you have the budget for gigabit connectivity then you have
| the budget for hardware-offloaded VPN.
|
| Cryptography is fast and cheap enough to handle SSD encryption
| -- it's plenty fast enough to handle your network traffic too.
|
| The only downside is the packet overhead. Can you survive going
| from 1500 down to 1420 bytes per packet? (Yes.)
| hansel_der wrote:
| while i technically agree, i think it's worth noting that
| gbps internet connections are available for cheap (<40$/mon)
| in many countries and on the other side a gbps-vpn is far
| from a trivial task especially if it leaves your country to
| terminate in another jurisdiction.
| marshmallow_12 wrote:
| i'm not as concerned as i might be. My rather meager
| understanding, which may be entirely baseless, is, that unlike
| the NSA which is obsessive about collecting every single scrap of
| data (and many large chunks), the UK intelligence services are
| rather more discerning. Again, i would be happy for someone to
| correct me, that's just the general impression i get.
| pdkl95 wrote:
| I recommend reading this article, which includes leaked
| documents from GCHQ's Joint Threat Research Intelligence Group
| (JTRIG).
|
| https://theintercept.com/2014/02/24/jtrig-manipulation/
| marshmallow_12 wrote:
| That is truly nasty stuff. Stuff like this is part of the
| reason i try not invest too much of myself on the 'net and
| obfuscate as much as possible (i'm not really a marshmallow).
| mattowen_uk wrote:
| Are you also marshmallows 0 to 11? If so, that your whole
| internet profile right there.
| marshmallow_12 wrote:
| no. As far as i can tell, those are real.
| Camas wrote:
| https://en.wikipedia.org/wiki/Tempora
| Enginerrrd wrote:
| I mean, the NSA famously uses the UK as a loophole to spy on
| American citizens. That suggests that they probably aren't
| particularly discerning to me.
| marshmallow_12 wrote:
| All it suggests is that the UK is happy to curry favour with
| the US government and doesn't give a hoot about the perceived
| rights of American citizens. Harsh, but true.
|
| Their own citizens are an entirely different ballpark, as you
| might say.
| mhh__ wrote:
| The UK government is also even more lax than the US one
| with regard to its own citizens privacy.
| marshmallow_12 wrote:
| I don't know, i think the mentality here is that the
| government is spying _for_ you, not at you. Is it
| different in the us? And is that because all revelations
| revolve around the fact that citizens are being spied on?
| lupire wrote:
| Then why do people light british spy cameras on fire so
| often?
| Spare_account wrote:
| Do they? I'd like to read about that
| tomatocracy wrote:
| As someone who lives on the UK, I've never once seen a
| vandalised CCTV camera or even a vandalised road speed
| camera (which I'm given to understand is more common).
| _puk wrote:
| I've seen many of the early "Gatso[0]" cameras
| vandalised.
|
| My understanding is that they originally used film, which
| had to be retrieved, so trying to burn it down with a
| well placed tyre had a chance of avoiding a fine.
|
| [0] https://www.speedcamerasuk.com/gatso.htm
| chiefalchemist wrote:
| Isn't there a fairly solid connection (read: partnership)
| between US and UK intelligence? Isn't such a chain only as
| strong as the weakest link? It's hard to imagine any of our
| European allies to be too far off the NSA's pace.
| known wrote:
| "If you want total security, go to prison. There you're fed,
| clothed, given medical care and so on. The only thing lacking is
| freedom" --Eisenhower (b. 1890)
| PaulAJ wrote:
| Because in prison the likelihood of being raped, beaten or
| having your property stolen is so much less than it is outside.
| CaptArmchair wrote:
| As recently as october 2020, the Court of Justice of the European
| Union ruled that data retention laws in the UK, Belgium and
| France are illegal as they aren't in accordance with EU
| directives:
|
| > Today 6 October 2020, the Court of Justice of the European
| Union (CJEU) delivered its verdict on four data retention cases
| in France, Belgium and the UK, in the context of these countries
| surveillance programmes. The European Court of Justice ruled that
| the surveillance laws of France, Belgium, and the United Kingdom
| fail to safeguard fundamental rights and freedoms. The CJEU rules
| that general and indiscriminate data retention is allowed under
| EU law when the State faces a "serious threat to national
| security" that is present or foreseeable, but only under the
| scrutiny of courts or independent administrative bodies and when
| this is done only temporarily. Finally, the CJEU specifies that
| national courts cannot use information obtained from bulk
| retention regimes against suspects in criminal proceedings.
|
| > "Today's judgement is a massive blow to existing laws in
| France, UK and Belgium and to other current data retention
| practices by Member States", said Diego Naranjo, Head of Policy
| at European Digital Rights (EDRi). "With this judgement, the CJEU
| essentially rules that, States can only engage in general and
| indiscriminate data retention when they face a "serious threat to
| national security" that is present or foreseeable, when subject
| to a court or administrative body review. The CJEU has put a stop
| to current illegal practices and disregards practices that are
| not under a national court's scrutiny in the name of national
| security or in the fight against "terrorism"", he added.
|
| > Data retention practices entail the storage of traffic and
| location data (metadata) by telecommunications companies for an
| extended period of time in order to ensure the availability of
| such data for law enforcement purposes. As electronic
| communications technologies are increasingly used in the course
| of criminal activity, electronic communications data can play an
| important role in criminal investigations. Mandating the bulk
| retention of this data, however, poses serious risks to the right
| to privacy and communications freedoms.
|
| https://edri.org/our-work/press-release-the-data-retention-r...
|
| This was October 2020. The CJEU still held jurisdiction over the
| U.K court during the transition period after brexit (31 jan 2020
| - 1 jan 2021) per the withdrawal agreement.
|
| > The Court of Justice of the European Union continues to have
| jurisdiction over the United Kingdom during the transition
| period. This also applies to the interpretation and
| implementation of the Withdrawal Agreement.
|
| https://ec.europa.eu/commission/presscorner/detail/en/qanda_...
|
| The U.K. is free to do whatever with little to no recourse for
| U.K. citizens beyond appeal to their own Supreme Court to
| challenge the constitutionality of data retention / surveillance
| laws.
|
| That said, the EU is not without it's own particular faults and
| shortcomings, but there are times when it does pay off to be able
| to challenge national legislation and policy making when it
| threatens human rights and freedoms such as they are purported to
| be upheld on the West-European continent.
|
| As far as "governments" go, across the EU, the separation of
| powers is a thing. If data retention laws are enacted, that's a
| reflection of the prevailing winds / power balances between the
| legislative, executive and judicial bodies.
| chiefalchemist wrote:
| Snooping? Now doesn't that reek of newspeak? If anyone of us did
| that to someone else it would (at very the least) be stalking.
|
| When you track and log everything - for up to a year - that's not
| snooping.
|
| That's surveillance.
|
| Using candy-coated language for such things is as (almost as)
| harmful as the acts themselves.
| jimbob45 wrote:
| I don't want to derail a very interesting thread but IMHO
| snooping has a darker connotation than surveilling.
| londons_explore wrote:
| The night security guard surveills the premisis.
|
| Your school nemesis snoops on what you're up to to try to
| embarrass or one-up you in some way.
|
| Surveillance can be good or bad. Snooping is always bad.
| chiefalchemist wrote:
| You've left the context out of your position.
|
| This is a couple ISPs in bed with the government. Under
| what conditions is that good surveillance?
| NeutronStar wrote:
| No, he was explaining it out of context. Not every
| comment HAS to take context into account.
| novok wrote:
| No it's just the word that the british tend to use for spying.
| Much like lavatory vs restroom. Ex: Snooper's charter
| chrisseaton wrote:
| > Using candy-coated language for such things is as (almost as)
| harmful as the acts themselves.
|
| 'Snooping' isn't candy-coated language in British English, and
| this is a British article. It's just another way to say
| surveillance. You're imagining a meaning that isn't there.
| bartread wrote:
| Brit here: can concur. 'Snooping' is pejorative in British
| English. It implies that (at the very least) you are sticking
| your nose where it doesn't belong, and always carries a hint
| of sinister overtone.
| kitd wrote:
| More than that: the IPA, the legislation that allowed this
| surveillance, is very well known in the UK as "The
| Snooper's Charter".
|
| Snooping describes this perfectly.
| chiefalchemist wrote:
| Snooping is what your neighbor does.
|
| Surveillance is a whole other level.
|
| When your ISP is logging your every move for a year. And
| making it available to the government. Regardless of
| country, that's not snooping. It's surveillance.
|
| The fact that some of you accept snooping as being
| legitimate description simply proves my point about candy-
| coating it.
| chrisseaton wrote:
| > When your ISP is logging your every move for a year.
| And making it available to the government. Regardless of
| country, that's not snooping.
|
| But that's just not true in British English.
|
| I don't know anything about you but your comments imply
| you're not British? If so, you'll just have to accept you
| don't know the meaning of these words in written British
| English.
|
| You're mistaken. I don't know what else to tell you?
| [deleted]
| [deleted]
| smashah wrote:
| 10 years from now cyberterrorism companies with government
| clearance will be selling machine learning models trained on
| these logs of previous criminals. Sad.
| brokenmachine wrote:
| Maybe then we will have finally got them all and declare the
| war on terrorism officially over!!
| abraxas wrote:
| Yes, yes that is exactly what they will do. Shareholders and
| lobbyists be damned.
| smashah wrote:
| Big Oil will be replaced with Big ML. The lobbyists will
| erode our liberties after rinsing our planet. They will
| make cutesy ads tricking the masses into trusting the
| models and anyone using protection online will be branded a
| terrorist.
| jl6 wrote:
| This seems simultaneously too intrusive, and yet not intrusive
| enough to actually benefit law enforcement. They are logging
| source and destination IPs. But to what end? What can that
| possibly prove? Surely the vast majority of crime occurs at the
| application level.
| intricatedetail wrote:
| Connected to Tor or VPN? You must be up to something...
| Sophira wrote:
| It wouldn't be too difficult to work out which app/site you're
| using given profiling data on which hosts are contacted during
| typical runs, and that data can be generalised in cases where
| the services use multiple names.
| csunbird wrote:
| They are slowly boiling the frog (the citizens). This surely
| will be extended to more data in the future.
| breakingcups wrote:
| "Fun" fact, that only works on lobotomized frogs.
|
| Regular healthy frogs just jump out of the pan when it gets
| uncomfortable.
| upofadown wrote:
| How? For TLS connections that is all the information
| available.
| noir_lord wrote:
| https://www.cryptomuseum.com/crypto/usa/clipper.htm
|
| It's not like governments haven't tried to backdoor
| computing devices via the legal route before.
| megous wrote:
| You can ask one end (typically the service end) for timestamp
| and local and remote port and IP address.
|
| Then you ask ISP to lookup subscriber info (via account id)
| based on that.
|
| You can do that already in some EU countries, just by lodging a
| complaint with police as a service provider (say you have an
| e-shop) for example. ISPs have to store these logs for some
| months.
| asix66 wrote:
| https://web.archive.org/web/20210311232132/https://www.ispre...
|
| Because the real link has too many redirects behind my pihole.
| ;-)
| JdeBP wrote:
| You could read the original article in _Wired_ instead. (-:
|
| * https://www.wired.co.uk/article/internet-connection-
| records-...
| ketamine__ wrote:
| Would constantly opening and closing connections use an insane
| amount of storage?
| JdeBP wrote:
| My educated guess would be no. There are some fairly obvious
| compression and junk filtering techniques, and the size of the
| record presented as an example is a lot smaller than a cat
| video file. (-:
|
| Of course, a computer trying to hide like that would also raise
| a red flag.
| hansel_der wrote:
| surely depends on the scale, but generally: no
| afturkrull wrote:
| Old news, ISPs have been using Deep Packet Inspection (DPI) for
| ages. Purely in the interests of "prioritise latency" for video
| or voice that "don't tolerate dropped packets" ;]
| collsni wrote:
| So essentially they're collecting net flow data on every citizen.
| It may be kind of fun to overload their storage by creating a ton
| of short connections, probably wouldn't be feasible.
| citrin_ru wrote:
| This system likely will be paid by the state, so the more
| traffic flows internet users will generate, the more taxpayers
| will pay.
| chrisacky wrote:
| Your the first comment and I had exactly the same idea. What do
| you want to bet we've all had the same thinking. As a community
| we sure like to bend things for sure.
| curiousgal wrote:
| I mean if they could get the act to pass I am sure they get
| storage funding too.
| edrxty wrote:
| So what you're saying is if some people banded together, they
| could manipulate the storage tech market with the force of a
| nation state behind them?
| marshmallow_12 wrote:
| But for how long will they manage to hang on to it? Here's a
| laugh if you want https://www.silicon.co.uk/data-
| storage/database/police-delet...
| tgragnato wrote:
| Rest sure things like masscan and file sharing will be singled
| out and excluded from long term storage. If I recall correctly
| there is a process called massive volume reduction by which you
| filter out "uninteresting stuff".
|
| It's not a bad idea, but you'll need something more
| sophisticated.
| gruez wrote:
| >If I recall correctly there is a process called massive
| volume reduction by which you filter out "uninteresting
| stuff".
|
| So all you have to do to avoid surveillance is to make a
| bunch of connections so the system gets overwhelmed and
| ignores you?
| lupire wrote:
| No. It drops the junk and tags you as an person of
| interest.
| jjbinx007 wrote:
| Then criminals should focus on what that non interesting
| stuff is likely to be and exploit that.
|
| Terrorists (as well as a CIA director) have for years
| used a simple trick to communicate without leaving
| suspicious looking metadata: https://www.washingtonpost.c
| om/news/worldviews/wp/2012/11/12...
|
| I find this type of legislation works like DVD copy
| protection: the innocent and non tech savvy will be
| disproportionately affected and it won't do anything to
| deter those with sufficient knowledge.
| worldofmatthew wrote:
| A python script to visit random scraped form directory websites
| or just having it request invaild pages if you want the logging
| to be least compressable.
| darkport wrote:
| I created a tool awhile back that pretty much does this
| https://github.com/eth0izzle/Needl - it's gone stale so
| looking for new contributors
| jimmygrapes wrote:
| Do want ISPs to charge by the minute again? Because that's
| how we get there.
| worldofmatthew wrote:
| If ISPs tried than the public would pressure the government
| to drop the law.
|
| I calculate with 50% reduction from compression (After the
| required back-ups to comply with the law the number will be
| much worse for the ISP). That somone on VM 500Mbits using
| less than 10% of their connection for this could increase
| their log size by 200GB per day or 73TB over the 12 months.
| lupire wrote:
| Then you get throttled by your ISP
| phendrenad2 wrote:
| Then people move to Germany for the good internet.
| brokenmachine wrote:
| As a side effect, then those people will be living in a
| country that already has laws against this kind of
| thing...
|
| You know, because of the... unpleasantness.
|
| But no worries, you go ahead with what you're doing, UK.
| Good job. Maybe IBM can offer some technical experience
| in this area.
| riknox wrote:
| I'm not sure if this is referring to the privacy laws or
| the internet itself, but the internet connectivity in
| Germany is dreadful in my experience. Capacity is at its
| limits, to the point that some flats don't have access to
| the internet.
| hanniabu wrote:
| > the public would pressure the government to drop the
| law
|
| And the government would just ignore them because of
| lobbying
| ClumsyPilot wrote:
| The level of spying instituted by 'free countries' would make
| Stalin roll in his grave.
| londons_explore wrote:
| I would like to see this data collected _and published_.
|
| Data you send out over the internet unencrypted doesn't have an
| expectation of privacy. Yet lots of people assume stuff like this
| is private.
|
| The only way to close the gap is to publish the data so everyone
| can see exactly what they and others are inadvertently telling
| the world.
| Silhouette wrote:
| This monitoring is primarily about metadata, which is
| necessarily not encrypted anyway. The concern that most people
| aren't aware of how much data they're leaking may be justified,
| but unless you're planning to redesign the Internet, exposing
| it isn't going to help much.
| SilverRed wrote:
| Someone did this for torrents, they built a website that
| scrapes the DHT data and creates a record of every torrent
| downloaded by each IP address, publicly searchable. This data
| is technically public and anyone could have got it including
| governments, making a site to access it just helps awareness.
| brokenmachine wrote:
| https://iknowwhatyoudownload.com/
|
| It listed a bunch of stuff that I never downloaded though...
| anaganisk wrote:
| You could be using a dynamic IP, this site links downloads
| to IP
| floatboth wrote:
| Or cgNAT, when many many clients of an ISP _share_ a
| public v4 address simultaneously.
| KnobbleMcKnees wrote:
| doesn't that make the information essentially useless?
| iknowwhatyoubutpossiblysomeotherblokedownload.com
| cmeacham98 wrote:
| Other people scraping this data like ISPs or governments
| could presumably do a better job of mapping IP+time to
| person.
| typenil wrote:
| Yes. The more control centralized authority has the more they can
| control hate speech. Please babysit us apathetic cynical
| regulatory capture mechanisms - I mean politicians.
| eecc wrote:
| What I don't get is this: our governments - "ours" being the
| group of parliamentary democracies - routinely diss authoritarian
| ones such as China - and rightfully so - for their violations
| against human rights, among which that to habeas corpus, privacy,
| and reasonable suspicion.
|
| To the point that we agonized over and sabotaged contact tracing
| apps, which could have helped a lot in fighting COVID, over
| claims to privacy and government control.
|
| Now this shit. Fuck it.
|
| You either are or you're not. So if my privacy is to be made
| sausages, chopped and sold at the market for FB, ad-tech and
| spooks, then give me at least some upside! As it is, we're just
| bovines with ear tags...
| cambalache wrote:
| Because you are taking the government criticism of other
| countries at face value. This is not a case of a well intended
| but barely self-aware organization or even some ideological
| zealots not giving pause to its enemies. This is just
| propaganda, pure and simple, they dont give a damn about the
| Uighurs, freedom of the press or democracy in general, they
| have an economical and geopolitical adversary who is getting
| stronger year after year so they will attack it. That boogeyman
| role has been played by Spain by France by Nazi Germany by the
| USSR by Japan,by Lybia,by Iraq,by Iran and now by China,For the
| powerful a foreign enemy is perfect:
|
| - It gives justification to obscene spending on the military
|
| - It justifies imperialist actions which violates international
| law
|
| - It blinds the local populacy with "patriotism"
|
| - It allows to create draconian local policies which would not
| be accepted in "peaceful times"
|
| - It protects the government because any local or foreign
| criticism can be discarded by using _whataboutism_ about the
| enemy du jour.
|
| Oldest trick in the book.
| intricatedetail wrote:
| Western governments project. They accuse enemy of something
| while doing the very thing. In the end humans in power develop
| the same desires and aim to fulfil them regardless of political
| framework.
| pjc50 wrote:
| The UK has never been especially supportive of human rights; it
| has a tradition of a sort of live-and-let-live native
| libertarianism, which is why we don't have ID cards (+), but it
| also has the tradition of imperialist repression techniques
| which means that the public are broadly supportive of the
| military shooting people in the street if they think they might
| be terrorists.
|
| https://www.independent.co.uk/news/uk/politics/conservative-...
|
| (+) however, you need an ID card if you're an immigrant, or
| want to open a bank account, rent or buy a house, or have a
| job.
| ClumsyPilot wrote:
| Honestly this 'we dont have an Id card' business just gets
| you the same result, but more chaotic and disorganised
| ben_w wrote:
| Also means you need multiple different forms of identity,
| at least based on my previous experiences with the UK
| banking and real estate systems.
|
| It's not even amazingly secure. A few years ago a TV news
| investigator managed to get a provisional driving license
| in the name of the blind then-Home Secretary, David
| Blunkett.
| ricardobayes wrote:
| In my view privacy has more layers. It has layers of personal
| data (name, social security, medical records), user-produced
| data (your family photos), communication (chat) and metadata
| (ad tracking). Lately I have seen ad tracking put in the same
| group as personal data. I don't think they deserve the same
| level of protection. I think total privacy is fools' gold.
|
| We always ask for total transparency from our governments, yet
| if they ask even a little of it from us, it's bad. Why? Also,
| in our society, wanting too much of anything makes you a weirdo
| and an outcast. Why has advocating for total privacy become
| normal(ized)?
| ClumsyPilot wrote:
| "We always ask for total transparency from our governments"
|
| Since time immemorial governments have used the seal of
| secrecy to hide their daily embarrasments, failures, and
| corruption.
|
| UK government has ordered a report into whether Sauidi is
| promoting Jihadism in Uk, and then decraled it secret. Same
| for Russia report. Recently the government has been sued for
| handing out multi-billion contracts to pals without
| challenge, and obviously they immediately reached out for the
| secrets act.
|
| We are sensitive about private data, because if you believe
| in a right to remain silent, well, now you can't stay silent.
|
| Evem if you are innocent, spurrious charges can ruin you
| financially.
| yrgulation wrote:
| But who are "they" to "ask even a little of it from us". With
| all due respect but this sounds as if "they" are not the
| people we send there to manage _our_ countries, but rather a
| cast of all loving all watching overloads that we should feed
| a bit of our freedoms now and then to keep us fed, safe and
| well. And we all know how that worked in history.
| ricardobayes wrote:
| Well we just saw with covid how it works out if everyone
| gets to do what they want. Too much freedom is just as
| harmful as too little. I would argue the only working model
| was the ancient Romans', having two leaders, a wartime
| leader and a 'fair-weather one'. It also requires the
| population to be grown-up enough to know their freedoms can
| and should be limited at times for their own good. No
| wonder why 'full citizenship' was rather limited in Rome.
| logicchains wrote:
| >Too much freedom is just as harmful as too little.
|
| Covid killed what, 0.1% of the population at most, and
| the average age of death was over 80. Stalin, Mao and Pol
| Pot killed well over an order of magnitude more than
| that.
| ben_w wrote:
| It killed 0.185% of the UK _with restrictions in place
| that limited the infections to 6.28% of the population_.
|
| Unconstrained spread would've been a bit over one order
| of magnitude worse, even if that hypothetical somehow
| managed to avoid overwhelming the NHS with exponential
| growth making half of all cases happen in the final
| doubling period.
| [deleted]
| [deleted]
| feralimal wrote:
| What helps, I find, is to think of governments as
| administrations. The civil service does implements whatever it
| has been told. Politicians are voted in - this is a slight of
| hand to distract the public. (I think of politics as a soap
| opera for the middle classes.) All the while the real governors
| operate through global undemocratic organisations, such as the
| UN and the WHO.
| bregma wrote:
| The UN and the WHO are not covert control operations but
| simply troughs where the friends of the rich can feed.
|
| The real governors operate from their country clubs and
| banquettes. No proper kingmaker would be so obvious as to
| grab headlines or make public announcements. Where is the
| personal enrichment in that?
|
| A simple rule of thumb: if you know who they are, they're not
| the people in control.
| tomcooks wrote:
| The Chinese model works, and it's what every government wants.
| The rest is marketing.
| KoftaBob wrote:
| It "works" if your priority is getting things done, but it
| absolutely does not work if you value liberty and personal
| freedom.
|
| Ask minority groups in China like Christians wanting to build
| a church or Uyghurs how well the model works.
| StavrosK wrote:
| Seems to me that the GP meant "it works for the government
| and politicians".
| pacifika wrote:
| Another step closer for a families web history to affect their
| life insurance policies. How long until this information is
| repackaged and sold on?
| Silhouette wrote:
| That seems like a weak slippery-slope argument. The exemptions
| to the usual rules that require ISPs to comply with government
| security policy here and keep quiet about it _only_ cover those
| things.
|
| So for one thing, using the data collected for anything else or
| providing it to anyone else would be an immediate and severe
| breach of both data protection and security laws. That would
| have serious consequences for the ISP doing it.
|
| For another, it would bring that monitoring system into
| disrepute and damage the credibility of a government that wants
| to be seen as strong on security. As a previous government
| learned to its cost when it tried to introduce personal ID
| cards here, even voters in the UK (who traditionally have a
| majority in favour of tough policing and security measures)
| still have lines they aren't willing to cross.
|
| In short, while there is plenty of scope to debate whether a
| system like this is necessary or justified as a security
| measure, it's highly unlikely that it will also be turned into
| the kind of sell-all-your-data exercise that might be a concern
| in some other parts of the world.
| londons_explore wrote:
| Now is time to remind people the benefits of having a free and
| open WiFi network...
| oji0hub wrote:
| The UK is getting less and less attractive all the time...
| gvd wrote:
| Turning into one big fat Vicky Pollard
___________________________________________________________________
(page generated 2021-03-12 23:02 UTC)