Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

51–60 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#51

In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their hands on a free sample from a company that offers "website traffic analytics", and which uses browser extensions as well as mobile apps as their main surveillance tools. The data set contained the complete browsing history of almost 3 million German Internet…

So although the government is a real threat to citizens privacy, unregulated private actors are much more dangerous in my opinion.

Companies don't have a monopoly on violence and complete control over you life as governments do, also, they are not unregulated or above the law - this company for example is probably breaking several laws. Spy agencies on the other hand, regularly break laws with impunity or have the laws rewritten to allow unlimited storage (as recently in the UK).

Governments are a much bigger worry when it comes to saving internet history as they have greater capabilities for capture and storage, and a simple policy change in 20 years could make everyone who visited a certain site a criminal liable to deportation or imprisonment.

Re: Tech firms seek to frustrate internet history log law

#52

The problem with these systems is regardless of the efficacy, they are incredibly difficult to dismantle and easy to re-purpose with the stroke of a pen. And these "tech-savvy" people are dreaming if they think that access to VPN services from the UK will remain legal in the UK, esp. after a naughty person or two is shown to have used one to commission a crime. It won't happen quickly, but #include frog_boiling.h.

So I guess using opera as your browser with its free vpn will be a problem

http://www.opera.com/computer/features/free-vpn

Re: Tech firms seek to frustrate internet history log law

#53
The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it just gets worse.

But this doesn't mean that technology wins. Rather, it makes the loss even worse, because it means the laws will ultimately have to be defined in reverse - rather than outlawing encryption, they will have to outlaw inability to decrypt. That is, it will be the end user's responsibility to ensure that authorities can decode data you transmit. Transmission of undecryptable data will be a crime, in and of itself.

Apart from the obvious dystopian consequences, this will impact progress in technology tremendously - suddenly it won't be possible to just invent a new data format or protocol any more. Doing so will put you at extreme risk of being interpreted as sending unauthorised encrypted data. So data formats will have to be registered - to send data in a new format you will first have to register a codec with the government and probably yourself have to be licensed. This will have a severe chilling effect on innovation. Software development, already dominated by tech behemoths, will become completely out of reach of small development teams simply because the regulatory burden is so high.

It's a depressing picture but given the trends of late I don't really see it going any other way. Only some extreme swing back towards individual rights over rights of the state will change its direction. But terrorism seems to have set in as a permanent tool for governments to grind away at individual rights.

Re: Tech firms seek to frustrate internet history log law

#54
post #47

In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their hands on a free sample from a company that offers "website traffic analytics", and which uses browser extensions as well as mobile apps as their main surveillance tools. The data set contained the complete browsing history of almost 3 million German Internet…

Some portion of people who choose to install a browser extension being traceable is worlds different from the government mandating that ISPs track all internet activity of all U.K. citizens. That distinction should be plainly obvious.

But most people don't know what happens to their data, and many don't even know that they're being tracked when the opt in to provide "anonymized usage statistics".

Of course it's a completely different if the government forces total surveillance, but the impact on people's privacy can be just as bad or even worse.

Re: Tech firms seek to frustrate internet history log law

#55

Brian K. Vaughan's comic Private Eye [1] foreshadows what might happen if this dataset is breached. The premise is the digital cloud "bursts" - all private data is suddenly dumped and searchable - forcing people to completely abandon their identities and assume new ones - changing their name, appearance, re-starting their careers, etc. When you consider this in the context of technologies like Voco [2] and Face2Face…

> How do you cryptographically sign yourself?

Now that's a problem whose solution deserves a unicorn valuation

Re: Tech firms seek to frustrate internet history log law

#56
Is it too late to return 2016? It's clearly defective.

How long until...

"Anexprogrammer was clearly a suspect individual. He used A&A, a UK ISP, widely considered sympathetic to terrorism under the thin guise of blogging about preserving privacy. The ISP has even provided information on how their users may circumvent the law and expressed the opinion it was a bad idea!

It gets steadily worse, Anexprogrammer often used a VPN, from an overseas company who made a feature of logging nothing, another technique widely used by terrorists to evade our beloved leader's protections. He even admitted to viewing online pornography, illegal in the UK, where performers appeared to be actually enjoying themselves.

He was also suspected of being a believer in climate change and is known to have signed a petition against fracking. The 20 year maximum security sentence for illegal circumvention of logging is considered lenient."

May the "one bad actor" that goes in there and gets the entire database please dump the histories of the politicians asap?

Re: Tech firms seek to frustrate internet history log law

#57
post #14
post #5

Earlier quoted context omitted.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

Yeah the weird thing is, despite being easy to circumvent these sort of measures are often very effective! So long as using a VPN requires any baseline of knowledge, technical skill and effort, I expect 90%+ of criminals won't do it. I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about…

Alternatively, if you're competent, there are so many better and safer crimes to commit.

Re: Tech firms seek to frustrate internet history log law

#58
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected.

I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

Re: Tech firms seek to frustrate internet history log law

#59

"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…

> All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it.

If the VPN connection uses ephemeral keys (IIRC, at least IPSEC, SSH, and TLS 1.3 always use ephemeral keys, while older TLS uses them when possible), by then it's too late: the keys are gone.

Re: Tech firms seek to frustrate internet history log law

#60

The thing I don't get about the UK is that they have very pervasive surveillance set up both online and in the real world, yet anyone can buy a mobile phone and a prepaid SIM at some random Tesco's and pay with cash without giving their name or ID. Why do they keep allowing this? Other countries have always required presenting ID to buy a SIM. It's a surveillance measure that's presumably quite effective, but also fa…

The UK rejected requiring identity to purchase a phone since that just means criminals steal a phone, when they know they'll need good anonymity.
Post reply on HN