Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

101–110 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#101
post #14

Earlier quoted context omitted.

Yeah the weird thing is, despite being easy to circumvent these sort of measures are often very effective! So long as using a VPN requires any baseline of knowledge, technical skill and effort, I expect 90%+ of criminals won't do it. I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about…

I would argue that the notion of "crime" is typically biased by the observed criminal acts. For example, criminal theft is usually thought to be some form of robbery, including everything from bank robberies to residential break-ins. However, wage theft, consisting of employers illegally withholding wages, is more than 2.5 times larger than all robberies combined [1]. It isn't that smart criminals don't exist. Rather…

> Rather, smart criminals don't fit our mental image of "criminals", which makes it harder to target laws against it

I would argue that it has nothing to do with the laws; they're breaking the same laws as everybody else. It's that our justice system, at least in the US, incentivizes law enforcement to focus on easier prey. Smart criminals will probably defend themselves in court and be more likely to be privy to the tricks that police use. It's much easier for them to just arrest a poor person and threaten to throw them in jail for months behind bail that they can't afford unless they plead guilty to something they obviously didn't do. Most poor people will just take the plea, because they can't afford to miss work and lose their job while they wait for their day in court. NYPD in particular are notorious for this.

Re: Tech firms seek to frustrate internet history log law

#102
post #70
post #65

Earlier quoted context omitted.

Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have: http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat... It is up to you to prove you don't have it anymore too.

Are perfect forward security protocols then illegal? What if it's physically impossible for you to give them a key that doesn't exist anymore?

If you can prove (on the balance of probabilities) that you don't have the key - because it doesn't exist or otherwise - then you are not guilty of the offence. Of course, that's not entirely straightforward.

Re: Tech firms seek to frustrate internet history log law

#103
Features like "You are currently logged in from 5 different devices" are event log-driven.

Unfortunately, this level of security and consumer protection is only found in top-tier online services.

Service providers can spin this "compliance" measure into a "benefit" for their customers/users. The net result, more users will disable or report rogue sessions.

Re: Tech firms seek to frustrate internet history log law

#104
post #67

Earlier quoted context omitted.

Or what if someone, say on an innocent blog, places an invisible iframe pointing to a flagged website? Now every visitor has that website in their logs without ever willingly visiting the URL and seeing any of the content.

Which is why the measure used for criminal law is beyond reasonable doubt: if there is no other evidence than an historic visit to a domain that the police can't show contained criminal content then there's not going to be a conviction (indeed the CPS wouldn't even entertain carrying such a case). If on looking at your hard drive the police then find a cache of content supporting criminal activity you're certainly go…

I was trying to point out that:

1. It wouldn't be hard to pollute the logs with noise, and

2. At the ISP level there's no distinction between "browsing a website" and accessing the URL unknowingly.

So let's assume no one will monitor these logs to fight thoughtcrime in real time, and it'll only be analyzed once someone becomes a suspect in a criminal investigation. Would it present as valuable evidence considering the points above?

As to your question: no I don't, but it isn't unheard of for law enforcement around the globe to set up honeypots. But then again there's no need to look into ISP logs because they control the server.

Re: Tech firms seek to frustrate internet history log law

#105

The most scary thing for me is that both political left and political right is nowadays for increasing surveillance - and there is no one in opposition. Except probably for Pirate parties, which are mostly irrelevant.

The Liberal Democrats are against surveillance, and are the third biggest party in the UK.

I used to think that. They say they are against it. When given an opportunity to actually fight it in the past they rolled over and did very little (essentially asking for minor tweaks).

Re: Tech firms seek to frustrate internet history log law

#106

Pardon my extreme language but Fuck! How on earth do bills like this come to pass without uproar widespread enough to quash it. Shit like this seriously makes me want to give up on the internet and walk away from it despite it having been my lifeline and the foundation of my income since I was in my teens almost 30 years ago.

The reason such bills get proposed and passed is because, broadly speaking, they are popular with the electorate or at least not unpopular.

The reason they are not unpopular, the root problem, is because the downsides are perceived as theoretical and in the future whereas the upsides are seen as real and in the present. Put simply the arguments against look like this:

Oppose this bill because the government COULD abuse it and PROBABLY will abuse it in future

i.e. it's all vague arguments about probabilities, and the arguments for it look like this:

Support this bill because it WILL help the fight against terrorists and paedos right now

For better or worse the British government has a relatively high level of trust amongst the British people. There is no British constitution and we can now see how a minority of the population is trying to convince Parliament to override the results of an actual referendum on the grounds that people are too stupid to rule themselves, so must be dictated to by small enclaves of their betters. That attitude is widespread, even if it is kind of dumb - MPs are just ordinary people too, after all, it's not like there's any filter on them beyond voting. But given that the governmental "elite" imposing its own morality and wisdom on the majority is practically a sexual turn-on for non-trivial numbers of voters, this kind of thing shouldn't surprise us.

We can and probably should argue that this trust is misplaced. There's plenty of evidence of that, along with the fact that surveillance is invariably paired with secrecy so it's hard for people to judge whether the government can be trusted to begin with. But that's why such bills happen.

The solution is probably not VPNs. Ultimately in a fight between internet technologists and lawmakers, sufficiently determined lawmakers will always win: China proves this. The UK's lawmakers may not be sufficiently determined but if they are the only solution is to continue making the argument to the electorate that the government cannot be trusted with such powers, and that they won't help fight terrorists and paedos anyway.

Pointing out that Trump now controls the NSA might be a good start.

Re: Tech firms seek to frustrate internet history log law

#107
post #99

How is this surveillance system supposed to work? Logging DNS requests? How feasible would it be to get everyone to look up every domain on the Internet and DDOS this surveillance system?

There doesn't seem to be a technical definition of an 'Internet Connection Record', but from the factsheet[1], they: "are records of the internet services that have been accessed by a device. They would include, for example, a record of the fact that a smartphone had accessed a particular social media website at a particular time." and: "ICRs do not provide a full internet browsing history. The ICRs do not reveal eve…

HTTP Host headers, IP addresses and HTTPS hostname negotiation headers are sufficient to meet that requirement without a doubt.

Re: Tech firms seek to frustrate internet history log law

#108

Earlier quoted context omitted.

There's stuff there about cryptography too, but the logging is about metadata. For metadata things are the opposite of your logic. It is always accessible. Whatever protocol you create to hide it, will have holes; Math dictates it.

Is that true though? I thought the point of protocols like Tor was that it makes gathering the metadata very very expensive.

Yes, expensive. That means it's perfectly doable (and was already done a few times).

Re: Tech firms seek to frustrate internet history log law

#109
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

> the first amendment

It took great effort to get crypto even recognized under the first amendment -- the USGov kept insisting that source code was not speech. In the 1990s it was against the law to let foreign nationals have access to the source code to DES. If you had folks from overseas in your organization, technically you couldn't let them see the source for crypto in your product (e.g., you had to wall off pieces of your repositories, and many companies did).

We could see a return to this. Don't take it for granted.

Re: Tech firms seek to frustrate internet history log law

#110
Assuming you can't block a VPN connection since business use them, how would this work? I assume at some point you simply ban HTTPS or non-public connections, or require government certs to be the only ones used (I think Turkey or some similar country is looking at this) so MITM can be done. Of course once you stick your foot into security, all the bad folks out there will take advantage, and their goes your financial industry and more. It's a stupid idea all around but the dolts in charge seem to either not care or don't understand. Also calling all of your citizens terrorists is a nice touch.
Post reply on HN