Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

61–70 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#61
post #5

The scariest line was this: "Terrorists and serious criminals will always seek to avoid detection." The fact that in the public eye they're going to be claiming they are doing this under terrorism, will give a lot of weight with non-technical people.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

> Any serious criminal/terrorist will use a VPN

Or just plain old stenography in very public forums.

Basically impossible to detect.

Re: Tech firms seek to frustrate internet history log law

#62

"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…

Surely self-incrimination laws make this a non-starter?

Re: Tech firms seek to frustrate internet history log law

#63

"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…

I wonder if we can mitigate this by rolling keys regularly. Daily perhaps? As far as I know there's no requirement to store encryption keys personally, only to give up the keys on request if available. Something that you can't do if you never store them on physical media.

Re: Tech firms seek to frustrate internet history log law

#64
post #14
post #5

Earlier quoted context omitted.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

Yeah the weird thing is, despite being easy to circumvent these sort of measures are often very effective! So long as using a VPN requires any baseline of knowledge, technical skill and effort, I expect 90%+ of criminals won't do it. I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about…

> When the Australian minister for communication introduced record keeping laws for ISPs he encouraged people to bypass it using VPNs. Said thats what he was doing.

Do you have a source for that? If true I find it very bizarre.

Re: Tech firms seek to frustrate internet history log law

#65
post #62

"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…

Surely self-incrimination laws make this a non-starter?

Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have:

http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat...

It is up to you to prove you don't have it anymore too.

Re: Tech firms seek to frustrate internet history log law

#66
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

> they will have to outlaw inability to decrypt.

The UK's already done that - the Regulation of Investigatory Powers Act 2000 already made it an offence not to divulge encryption keys when asked. [1]

1 https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...

Re: Tech firms seek to frustrate internet history log law

#67
post #42

In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their hands on a free sample from a company that offers "website traffic analytics", and which uses browser extensions as well as mobile apps as their main surveillance tools. The data set contained the complete browsing history of almost 3 million German Internet…

> So although the government is a real threat to citizens privacy That's not privacy which is under threat any more. Say you visit a website of random content in January. Website goes out of business, someone else buys the domain and puts flagged content on it in September. Now... how do you prove you were visiting a different site? Trigger an archive.org call on each and every site I visit? Dig up domain name change…

Or what if someone, say on an innocent blog, places an invisible iframe pointing to a flagged website? Now every visitor has that website in their logs without ever willingly visiting the URL and seeing any of the content.

Re: Tech firms seek to frustrate internet history log law

#68
post #64
post #14

Earlier quoted context omitted.

Yeah the weird thing is, despite being easy to circumvent these sort of measures are often very effective! So long as using a VPN requires any baseline of knowledge, technical skill and effort, I expect 90%+ of criminals won't do it. I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about…

> When the Australian minister for communication introduced record keeping laws for ISPs he encouraged people to bypass it using VPNs. Said thats what he was doing. Do you have a source for that? If true I find it very bizarre.

Re-reading articles about it it seems his comments aren't as cut-and-dry as I remembered:

http://www.businessinsider.com.au/malcolm-turnbulls-sky-news...

> “If on the other hand I communicate with you via Skype for a voice call or Viber, send you a message on WhatsApp or Wickr or Threema or Signal or Telegrammer — there’s a gazillion of them — or indeed if you make a FaceTime call, then all that the telco can see, insofar as it can see anything, is that my device has had a connection with the Skype server or the WhatsApp server; it doesn’t see anything happening with you.

> “There are always ways for people to get around things, but of course a lot of people don’t, and that’s why I’ve always said the data retention laws, the use of metadata, is not a silver bullet. It’s not a 100% guarantee. It is one tool in many tools.”

Re: Tech firms seek to frustrate internet history log law

#70
post #65
post #62

Earlier quoted context omitted.

Surely self-incrimination laws make this a non-starter?

Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have: http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat... It is up to you to prove you don't have it anymore too.

Are perfect forward security protocols then illegal? What if it's physically impossible for you to give them a key that doesn't exist anymore?
Post reply on HN