Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

111–120 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#111

Pardon my extreme language but Fuck! How on earth do bills like this come to pass without uproar widespread enough to quash it. Shit like this seriously makes me want to give up on the internet and walk away from it despite it having been my lifeline and the foundation of my income since I was in my teens almost 30 years ago.

> Shit like this seriously makes me want to give up on the internet and walk away from it

You echo my thoughts exactly - I've recently been thinking about moving to a small town north of where I currently live, where land prices are cheap, and you can get 10 acres for nothing. Bad part - little to no internet access.

Part of me thinks that's a good thing.

Re: Tech firms seek to frustrate internet history log law

#112
post #86

Earlier quoted context omitted.

The SNP are the third biggest UK party.

Or UKIP, if you consider the popular vote (to echo the current US situation) edit: The Lib Dems are probably the 3rd largest party if you include local council seats

Yeah, one and two are obviously tory/labour, after that it gets confusing.

Re: Tech firms seek to frustrate internet history log law

#113
post #87
post #61

Earlier quoted context omitted.

> Any serious criminal/terrorist will use a VPN Or just plain old stenography in very public forums. Basically impossible to detect.

This is correct. Every serious criminal won't use a VPN or other obvious crypto, because this paints a big target on your back signalling you want to hide something. A serious adversary will, as you say, use a pre-arranged innocent vocabulary that is virtually impossible to detect, or just communicate face-to-face or via written notes delivered by a messenger. Oh and by the way, remember to buy lettuce today ;) ;)

> Oh and by the way, remember to buy lettuce today ;)

Raymond Shaw is the kindest, bravest, warmest, most wonderful human being I' ve ever known...

Re: Tech firms seek to frustrate internet history log law

#114
post #100
post #66

Earlier quoted context omitted.

> they will have to outlaw inability to decrypt. The UK's already done that - the Regulation of Investigatory Powers Act 2000 already made it an offence not to divulge encryption keys when asked. [1] 1 https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...

Yes, that's a step towards it. But at least the person has to be a "suspect" in another crime (however low the bar for that is) and an explicit demand has to be made for the key. Not that it does a lot of good since anybody can become a suspect and the demand for the key is retrospective to when you weren't a suspect.

I really don't think that having to be a suspect is in ANY way meaningful, since there is absolutely no bar to being a suspect. It is perfectly reasonable to state "we have no idea who did this so every UK resident is a possible suspect".

Re: Tech firms seek to frustrate internet history log law

#115
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

This may be a stupid question but I've got to ask because I'm not 100% sure. Is there no practical way data can be sent and received anonymously? If no one, except the people trying to communicate, knows who encrypted or decrypted anything, how could they enforce such a law? Since a well encrypted message should be safe to broadcast, it can be sent to the whole world with only the intended recipients being able to de…

Once upon a time, we imagined a cypherpunk future, where speech was free and the internet was the great frontier of autonomous anonymity.

It turns out, though, that we leave fingerprints on everything we touch. And many of the conveniences and indeed basic user experience we've come to expect leave plenty of markers of who we are for anyone who might be listening. This makes it easy for hacker news to remember who I am, and easy for advertisers to target ads, and governments to track individuals.

So yeah, tools exist, sort of, but require a lot of inconvenience. We've seen instances of ISPs inserting their own cookies on headers of outgoing customer traffic, meaning there are still times when your precautions don't matter at all. When I've thought about totally anonymous internet usage, my guess is that you need to go buy a fresh laptop with cash, and then only use it on large public networks, with good encryption...

Re: Tech firms seek to frustrate internet history log law

#116
post #14
post #5

Earlier quoted context omitted.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

Yeah the weird thing is, despite being easy to circumvent these sort of measures are often very effective! So long as using a VPN requires any baseline of knowledge, technical skill and effort, I expect 90%+ of criminals won't do it. I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about…

> I've been nursing a theory for a long time that modern society has an accidental saving grace. And that is, if you're competent, its usually better to just not commit crime. Think about it - any criminal can learn lockpicking today via the internet, but few do. Why?

Because it's easier to crack open a window someone left unlocked.

Re: Tech firms seek to frustrate internet history log law

#117

Is it too late to return 2016? It's clearly defective. How long until... "Anexprogrammer was clearly a suspect individual. He used A&A, a UK ISP, widely considered sympathetic to terrorism under the thin guise of blogging about preserving privacy. The ISP has even provided information on how their users may circumvent the law and expressed the opinion it was a bad idea! It gets steadily worse, Anexprogrammer often us…

You're just missing Tor for the "suspicious character" trifecta.

Re: Tech firms seek to frustrate internet history log law

#118

The most scary thing for me is that both political left and political right is nowadays for increasing surveillance - and there is no one in opposition. Except probably for Pirate parties, which are mostly irrelevant.

The Liberal Democrats are against surveillance, and are the third biggest party in the UK.

Liberal Democrats are bench warmers and when they are moved into play they can't execute anything - for example their drugs minister Norman Baker did nothing along the lines what Liberal Democrats preach. They are a political laughing stock and nobody takes them seriously.

Re: Tech firms seek to frustrate internet history log law

#119
post #5

The scariest line was this: "Terrorists and serious criminals will always seek to avoid detection." The fact that in the public eye they're going to be claiming they are doing this under terrorism, will give a lot of weight with non-technical people.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

I guess that is true to a first approximation but exceptions perhaps prove the rule

https://magazine.atavist.com/the-mastermind

Re: Tech firms seek to frustrate internet history log law

#120
post #25
post #5

Earlier quoted context omitted.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones. The technical difficulties law enforcement faces with terrorism and crime isn't that crimin…

> Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones.

We have no way of knowing. There hasn't been a repeat attack at the scale of 9/11 to date in the US, which either means that people aren't trying or the security services are very effective. Since terrorist organization have been encouraging crazy lone-wolf type people to commit random attacks, that suggests to me that the security services are effective.

All security/law enforcement operations are about managing risk. Criminals and other "opponents" find weaknesses quickly -- remember the early 2000s popularity of Nextel and Boost Mobile devices among drug dealers. Even something as ridiculous and expensive as TSA serves a function... getting contraband on an airplane is a riskier proposition now. You don't need 100% effectiveness -- in a 9/11 type scenario a 40% effective screening process would have likely discovered some conspirators.

IMO, attacking the law enforcement surveillance creep is the wrong approach. That's a symptom of a larger problem, which is this global instability kicked off by Bin Laden and his ilk. That's the disease, and the only way to address surveillance is to attack those political problems and get back to a more balanced system.

Post reply on HN