Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

91–100 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#91
post #72
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

Do you think that browser makers could come under attack? Will Chrome and Firefox be required to add back doors to their "service".

I don't think that there's any public actor you can say is definitely not at risk of attack.

Edit: this is probably a good opportunity to remind people to donate to the Open Rights Group, who are the UK counterpart to the EFF and already actively opposing this and other bad laws.

Re: Tech firms seek to frustrate internet history log law

#92
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

There was a round of this fought in the US over the "clipper chip" technology in the 90s.

I've been wondering about the interaction of technologies like this with DRM technologies; what if I send HDCP-over-TCP? What if ISIS start using Macrovision on their jihadi videos?

Re: Tech firms seek to frustrate internet history log law

#93
post #72
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

Do you think that browser makers could come under attack? Will Chrome and Firefox be required to add back doors to their "service".

I'm sure they will, but it's too easily answerable - open source browsers without the back doors will be trivial for end users to build. So again, it'll come back to criminalising what end users do, because in the end only restrictions on the end user can stop them using their own resources to build things.

Re: Tech firms seek to frustrate internet history log law

#94
post #67
post #42

Earlier quoted context omitted.

> So although the government is a real threat to citizens privacy That's not privacy which is under threat any more. Say you visit a website of random content in January. Website goes out of business, someone else buys the domain and puts flagged content on it in September. Now... how do you prove you were visiting a different site? Trigger an archive.org call on each and every site I visit? Dig up domain name change…

Or what if someone, say on an innocent blog, places an invisible iframe pointing to a flagged website? Now every visitor has that website in their logs without ever willingly visiting the URL and seeing any of the content.

Which is why the measure used for criminal law is beyond reasonable doubt: if there is no other evidence than an historic visit to a domain that the police can't show contained criminal content then there's not going to be a conviction (indeed the CPS wouldn't even entertain carrying such a case). If on looking at your hard drive the police then find a cache of content supporting criminal activity you're certainly going to have a hard time if you're innocent.

Do you know of any UK caselaw covering situations where people were convicted on the basis of having visited a particular domain and no corroborating evidence was found? Would be interested in reading how that went down.

Re: Tech firms seek to frustrate internet history log law

#95
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

I don't believe enough people would care enough about it to start a civil war. I think what needs to happen is, instead of going into IT management at 40, where we do more harm than good anyway, we start running for office until the government is full of experienced tech people.

Re: Tech firms seek to frustrate internet history log law

#96
post #47

In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their hands on a free sample from a company that offers "website traffic analytics", and which uses browser extensions as well as mobile apps as their main surveillance tools. The data set contained the complete browsing history of almost 3 million German Internet…

Some portion of people who choose to install a browser extension being traceable is worlds different from the government mandating that ISPs track all internet activity of all U.K. citizens. That distinction should be plainly obvious.

>mandating that ISPs track all internet activity //

Isn't it 'just' domains visited? I don't know if that's web or internet or what though.

Re: Tech firms seek to frustrate internet history log law

#97

How is this surveillance system supposed to work? Logging DNS requests? How feasible would it be to get everyone to look up every domain on the Internet and DDOS this surveillance system?

The introductory presentation (linked from the article) suggests what should be logged:

- customer ID

- start and end times of the 'event'

- source IP address and port (the port is used to avoid a NAT at the ISP level)

- destination IP address and port

- volume of data transferred in each direction

- name of internet service connected to

- the URL

https://www.gov.uk/government/uploads/system/uploads/attachm...

There is a sample provided on the next page, which dumbs it down enough so that it sounds rather compelling.

Re: Tech firms seek to frustrate internet history log law

#98
post #72
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

Do you think that browser makers could come under attack? Will Chrome and Firefox be required to add back doors to their "service".

Historically browsers for distribution outside the USA were required to be limited to 40-bit crypto.

"(About Netscape) The "International Edition" had its effective key lengths reduced to 512 bits and 40 bits respectively (RSA_EXPORT with 40-bit RC2 or RC4 in SSL 3.0 and TLS 1.0). Acquiring the 'U.S. domestic' version turned out to be sufficient hassle that most computer users, even in the U.S., ended up with the 'International' version, whose weak 40-bit encryption could be broken in a matter of days using a single personal computer." (Wikipedia - https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...)

In fact, strong crypto was only allowed in 2000. Only 16 years ago!

Re: Tech firms seek to frustrate internet history log law

#99

How is this surveillance system supposed to work? Logging DNS requests? How feasible would it be to get everyone to look up every domain on the Internet and DDOS this surveillance system?

There doesn't seem to be a technical definition of an 'Internet Connection Record', but from the factsheet[1], they:

"are records of the internet services that have been accessed by a device. They would include, for example, a record of the fact that a smartphone had accessed a particular social media website at a particular time."

and:

"ICRs do not provide a full internet browsing history. The ICRs do not reveal every web page that a person visited or any action carried out on that web page."

How this will work in practice is anyones guess at the moment - every time I think of something short of logging every packet header sent/received in the UK (which leads to a staggering amount of data needing to be logged), I think of things that would slip though (and therefore wouldn't fulfil the first statement)...

[1] https://www.gov.uk/government/uploads/system/uploads/attachm...

Re: Tech firms seek to frustrate internet history log law

#100
post #66
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

> they will have to outlaw inability to decrypt. The UK's already done that - the Regulation of Investigatory Powers Act 2000 already made it an offence not to divulge encryption keys when asked. [1] 1 https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...

Yes, that's a step towards it. But at least the person has to be a "suspect" in another crime (however low the bar for that is) and an explicit demand has to be made for the key. Not that it does a lot of good since anybody can become a suspect and the demand for the key is retrospective to when you weren't a suspect.
Post reply on HN