Live data from Hacker News

Britain passed the “most extreme surveillance law ever passed in a democracy”

zdnet.com

281–290 of 302 posts

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#282
What a sensationalist title, I was expecting a comparison with other surveillance law in others countries and the result to be something outrageous. Turns out it's just sensationalism and it ends up being the kind of surveillance that has been enacted around the world in the last few years, mandatory ISP data retention has been active for 10 years in France[1].

It was even a European directive, directive 2006/24/EC or data retention directive[2], for all members of the European Union from 2006 to 2014 when it was invalidated through the Court of Justice of European Union. Interestingly this directive came into existence while the Uk had the presidency of EU in 2005. >According to the directive, member states will have to store citizens' telecommunications data for a minimum of 6 months and at most 24 months.

Why is zdnet trying to put this UK law as if it was something out of the ordinary ? Switzerland[3], Canada's bill C-51[4], Germany[5], Australia[6], Italy[7], and more [8] (Estonia, Greece, Spain, Hungary, Latvia, Lithuania, Luxembourg, Malta, Portugal, Ireland) all have mandatory data retention law.

Then again none of those are actual democracies (the closest being switzerland) and that's pretty much the reason these laws made to spy on citizens are possible.

[1]:https://en.wikipedia.org/wiki/Law_on_the_fight_against_terro... [2]: https://en.wikipedia.org/wiki/Data_Retention_Directive [3]: http://www.bbc.com/news/world-europe-37465853 [4]: https://en.wikipedia.org/wiki/Anti-terrorism_Act,_2015 [5]: https://www.huntonprivacyblog.com/2015/10/16/german-parliame... [6]: https://en.wikipedia.org/wiki/Telecommunications_(Intercepti... [7]: https://edri.org/edrigramnumber3-16italy/ [8]: https://www.purevpn.com/blog/data-retention-laws-by-countrie...

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#283
post #260
post #16

Earlier quoted context omitted.

The value of the £ has been the official opposition since Brexit.

"The value of the £ has been the official opposition since Brexit." I wonder if you realize that a declining value of the pound is likely to be positive for the British economy ? It's not certain, but very likely ... In fact, it might even be considered a feature of BREXIT.

The reduction of the exchange rate is unlikely to actually help the UK. Have a look at some of the academic research, while business leaders and politicians believe that a reduced exchange rate helps exporters there's not that much evidence for it. Also, even if it does help exporters from the perspective of average voters costs and inflation will go up - which they may not have thought through.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#284
post #113

As a UK resident: I know that I can only avoid logging traffic by using a vpn. But the domain logging part bothers me the most. Does anyone here know how they will do it? Could I just use another dns server? Or will they intercept http header? If I'm not mistaken, they could still extract the domain names from https traffic but no exact history? Anyway, a reason more to use https everywhere, reduces sharply what they…

>I know that I can ... avoid logging traffic by using a vpn. Are you sure? I'd expect you be hard pressed to explain how that would be the case. Hint: how do you facilitate secure key exchange with an untrusted man in the middle? I know public key exchange is a thing, but I don't know much about it, just that I wouldn't trust it. Do you? Check this link, for example: https://www.ietf.org/mail-archive/web/ietf/current…

We have to remember that this law still forces ISPs to do something that costs them money. They won't do more than requested in the law, especially if it means buying more servers just for that.

Agencies can of course do that, but that's independent of the law.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#285
post #113

As a UK resident: I know that I can only avoid logging traffic by using a vpn. But the domain logging part bothers me the most. Does anyone here know how they will do it? Could I just use another dns server? Or will they intercept http header? If I'm not mistaken, they could still extract the domain names from https traffic but no exact history? Anyway, a reason more to use https everywhere, reduces sharply what they…

Most of the negative comments on this story are in the context of stopping a state actor whose specifically targeting you. The rest of this comment is covering the "drag net" effect of this legislation - any one individual is not being targeted, it's a situation where everything is caught up.

If you change nothing then your provider will be able to track your DNS traffic (site you're going to) and unprotected traffic (non-HTTPS). You can't use another DNS server because the protocol is in the clear so they could just track that even if it's not on their network - though it would be real work and they might not bother to do so.

Using a VPN will protect all your network traffic which means both DNS looking up the domain and traffic to/from the sites you're going to. Note that the VPN provider should be outside the UK jurisdiction - from there decide on your level of paranoia.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#286

What a sensationalist title, I was expecting a comparison with other surveillance law in others countries and the result to be something outrageous. Turns out it's just sensationalism and it ends up being the kind of surveillance that has been enacted around the world in the last few years, mandatory ISP data retention has been active for 10 years in France[1]. It was even a European directive, directive 2006/24/EC o…

> Why is zdnet trying to put this UK law as if it was something out of the ordinary ?

Because the 2006/24/EC data retention directive [1] didn't say anything about browsing history and even then was invalidated by the Court of Justice of European Union. The new UK law however:

"The law will force internet providers to record every internet customer's top-level web history in real-time for up to a year, which can be accessed by numerous government departments; force companies to decrypt data on demand -- though the government has never been that clear on exactly how it forces foreign firms to do that; and even disclose any new security features in products before they launch."

[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2... (read "Article 5" "Categories of data to be retained")

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#287
post #284

Earlier quoted context omitted.

>I know that I can ... avoid logging traffic by using a vpn. Are you sure? I'd expect you be hard pressed to explain how that would be the case. Hint: how do you facilitate secure key exchange with an untrusted man in the middle? I know public key exchange is a thing, but I don't know much about it, just that I wouldn't trust it. Do you? Check this link, for example: https://www.ietf.org/mail-archive/web/ietf/current…

We have to remember that this law still forces ISPs to do something that costs them money. They won't do more than requested in the law, especially if it means buying more servers just for that. Agencies can of course do that, but that's independent of the law.

Why would it cost them money, when the tax payer can afford it?

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#288

Earlier quoted context omitted.

> most of the VPN standards What VPN standards are you talking about?

IPSEC, IKE.

From the (excellent list of) papers you listed, it seems the weaknesses are not so much that the encryption can be broken, but that you can do all kinds of man in the middle and timing attacks. Does this mean, that as long as you are not being actively attacked, the security is acceptable? That is, if you are only trying to avoid passive logging?

I guess in either case, it would be better to just go with openvpn. I really don't understand why it isn't natively supported in Android, OSX etc.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#289
post #7

Oddly I can't find any other sources reporting this. I'd have expected it to show up in at least one other place else (e.g. BBC news for example). I'm not trying to imply that it's not accurate, I'm just confused by the lack of info. And the article doesn't really reference anything other than other zdnet articles, so it's really hard to tell exactly what form of the act got passed - did all the really controversial…

The BBC is dodgy. That might sound like blasphemy, but year after year I'm increasingly aware of blatant bias, omissions, misrepresentations. The BBC is not to be trusted.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#290
post #150

So the British government is just rubber stamping what they had already been doing in secret and technically illegally for the last twenty years. I can't wait till they get hacked and someone dumps every parliamentary minister and lord's dubious Google searches for the public to see.

[deleted]
Post reply on HN