Live data from Hacker News

Two UK Broadband ISPs Trial New Internet Snooping System

ispreview.co.uk

121–130 of 241 posts

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#121

Earlier quoted context omitted.

Because it's abstract. The people aren't _actively_ having to do anything, such as hand over their records - it's happening away from them. It's hard to connect with abstract. It's easier for people to connect with the reason _for_ doing it. Stop the terrorists, it may happen to you, etc. But the other way round is harder because it's invisible and you can live your life without caring. Even the warnings fall on deaf…

In a similar way, withholding of income tax feels much more painless than having to pay it in full backwards in April, or even several times a year. There is a good chance that if everyone had to pay their income tax manually, the tax burden would shift quite a bit.

> if everyone had to pay their income tax manually

Isn't this basically the US model though? And ...

> the tax burden would shift quite a bit.

Hasn't really happened for them (unless you're in the 1%, obvs.)

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#122

Has everyone forgotten about Tempora [1], XKEYSCORE [2], PRISM, [3] and the other Snowden revelations [4]? This kind of shit has been going on for at least a decade in various forms. [1] https://en.wikipedia.org/wiki/Tempora [2] https://en.wikipedia.org/wiki/XKeyscore [3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program) [4] https://en.wikipedia.org/wiki/Global_surveillance_disclosure...

As a person from the UK, no I've not forgotten. The difference here (and this is NOT excusing them) is that you've gone from a series of systems which didn't officially exist, accessible from the select few of intelligence agencies and no doubt secure as hell into private ones which are controlled by people like BT. Yep, BT. The same BT who are laying off 10k staff this year because they need to cut costs. This isn't something they're putting effort into, this is some mandated program which will mean they're going to come up with the cheapest solution to store all your data. That's obviously bad.

What was disappointing about this was that I remember the day this bill got passed. I remember refreshing BBC news repeatedly. Not one article was written about the snoopers charter within the days leading up to it (or the day itself). Now, back to the "bad" again... The list of people who can access these records, without a warrant is just utterly insane. It starts off legit-ish but honestly some of these are pretty hard to justify:

* Metropolitan police force

* City of London police force

* Police forces maintained under section 2 of the Police Act 1996

* Police Service of Scotland

* Police Service of Northern Ireland

* British Transport Police

* Ministry of Defence Police

* Royal Navy Police

* Royal Military Police

* Royal Air Force Police

* Security Service

* Secret Intelligence Service

* GCHQ

* Ministry of Defence

* Department of Health

* Home Office

* Ministry of Justice

* National Crime Agency

* HM Revenue & Customs

* Department for Transport

* Department for Work and Pensions

* NHS trusts and foundation trusts in England that provide ambulance services

* Common Services Agency for the Scottish Health Service

* Competition and Markets Authority

* Criminal Cases Review Commission

* Department for Communities in Northern Ireland

* Department for the Economy in Northern Ireland

* Department of Justice in Northern Ireland

* Financial Conduct Authority

* Fire and rescue authorities under the Fire and Rescue Services Act 2004

* Food Standards Agency

* Food Standards Scotland

* Gambling Commission

* Gangmasters and Labour Abuse Authority

* Health and Safety Executive

* Independent Police Complaints Commissioner

* Information Commissioner

* NHS Business Services Authority

* Northern Ireland Ambulance Service Health and Social Care Trust

* Northern Ireland Fire and Rescue Service Board

* Northern Ireland Health and Social Care Regional Business Services Organisation

* Office of Communications

* Office of the Police Ombudsman for Northern Ireland

* Police Investigations and Review Commissioner

* Scottish Ambulance Service Board

* Scottish Criminal Cases Review Commission

* Serious Fraud Office

* Welsh Ambulance Services National Health Service Trust

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#123
post #111

Earlier quoted context omitted.

Freedom of information is about the activities of public authorities, and that includes private sector bodies performing public functions. A person could access aggregate data and other non-personally identifying information this way but it would likely require a court to rule on the public activities of the company. This happened with privately run care homes which were deemed to have public functions. However, you…

Unfortunately this won’t tell you if the ISP is storing extra data in compliance with the Snooper’s Charter because legal compliance can override the GDPR. Basically, the law saying “you’re not allowed to tell anyone you hold this data” overrides an SAR and a legal case to force compliance would likely fail on these grounds.

Does the charter specifically forbid companies from reporting what they store? I'm not familiar with it in detail. I'd be surprised..

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#124
post #93

Earlier quoted context omitted.

You're right[0], though you won't get much recognition on HN. [0] https://t.co/9UuceYD2Xj?amp=1

I hate to break it to you, but Greenwald is just another "I was a teenage leftist" Republican getting ready for his book tour. He's been pandering to Trump supporters for a few years now... He's a terrible example to cite if you want to support the actual left.

"People's Front of Judea"

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#125
As recently as october 2020, the Court of Justice of the European Union ruled that data retention laws in the UK, Belgium and France are illegal as they aren't in accordance with EU directives:

> Today 6 October 2020, the Court of Justice of the European Union (CJEU) delivered its verdict on four data retention cases in France, Belgium and the UK, in the context of these countries surveillance programmes. The European Court of Justice ruled that the surveillance laws of France, Belgium, and the United Kingdom fail to safeguard fundamental rights and freedoms. The CJEU rules that general and indiscriminate data retention is allowed under EU law when the State faces a “serious threat to national security” that is present or foreseeable, but only under the scrutiny of courts or independent administrative bodies and when this is done only temporarily. Finally, the CJEU specifies that national courts cannot use information obtained from bulk retention regimes against suspects in criminal proceedings.

> “Today’s judgement is a massive blow to existing laws in France, UK and Belgium and to other current data retention practices by Member States”, said Diego Naranjo, Head of Policy at European Digital Rights (EDRi). “With this judgement, the CJEU essentially rules that, States can only engage in general and indiscriminate data retention when they face a “serious threat to national security” that is present or foreseeable, when subject to a court or administrative body review. The CJEU has put a stop to current illegal practices and disregards practices that are not under a national court’s scrutiny in the name of national security or in the fight against “terrorism””, he added.

> Data retention practices entail the storage of traffic and location data (metadata) by telecommunications companies for an extended period of time in order to ensure the availability of such data for law enforcement purposes. As electronic communications technologies are increasingly used in the course of criminal activity, electronic communications data can play an important role in criminal investigations. Mandating the bulk retention of this data, however, poses serious risks to the right to privacy and communications freedoms.

https://edri.org/our-work/press-release-the-data-retention-r...

This was October 2020. The CJEU still held jurisdiction over the U.K court during the transition period after brexit (31 jan 2020 - 1 jan 2021) per the withdrawal agreement.

> The Court of Justice of the European Union continues to have jurisdiction over the United Kingdom during the transition period. This also applies to the interpretation and implementation of the Withdrawal Agreement.

https://ec.europa.eu/commission/presscorner/detail/en/qanda_...

The U.K. is free to do whatever with little to no recourse for U.K. citizens beyond appeal to their own Supreme Court to challenge the constitutionality of data retention / surveillance laws.

That said, the EU is not without it's own particular faults and shortcomings, but there are times when it does pay off to be able to challenge national legislation and policy making when it threatens human rights and freedoms such as they are purported to be upheld on the West-European continent.

As far as "governments" go, across the EU, the separation of powers is a thing. If data retention laws are enacted, that's a reflection of the prevailing winds / power balances between the legislative, executive and judicial bodies.

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#126
post #113

What I don’t get is this: our governments - “ours” being the group of parliamentary democracies - routinely diss authoritarian ones such as China - and rightfully so - for their violations against human rights, among which that to habeas corpus, privacy, and reasonable suspicion. To the point that we agonized over and sabotaged contact tracing apps, which could have helped a lot in fighting COVID, over claims to priv…

In my view privacy has more layers. It has layers of personal data (name, social security, medical records), user-produced data (your family photos), communication (chat) and metadata (ad tracking). Lately I have seen ad tracking put in the same group as personal data. I don't think they deserve the same level of protection. I think total privacy is fools' gold.

We always ask for total transparency from our governments, yet if they ask even a little of it from us, it's bad. Why? Also, in our society, wanting too much of anything makes you a weirdo and an outcast. Why has advocating for total privacy become normal(ized)?

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#127
This seems simultaneously too intrusive, and yet not intrusive enough to actually benefit law enforcement. They are logging source and destination IPs. But to what end? What can that possibly prove? Surely the vast majority of crime occurs at the application level.

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#128
post #122

Has everyone forgotten about Tempora [1], XKEYSCORE [2], PRISM, [3] and the other Snowden revelations [4]? This kind of shit has been going on for at least a decade in various forms. [1] https://en.wikipedia.org/wiki/Tempora [2] https://en.wikipedia.org/wiki/XKeyscore [3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program) [4] https://en.wikipedia.org/wiki/Global_surveillance_disclosure...

As a person from the UK, no I've not forgotten. The difference here (and this is NOT excusing them) is that you've gone from a series of systems which didn't officially exist, accessible from the select few of intelligence agencies and no doubt secure as hell into private ones which are controlled by people like BT. Yep, BT. The same BT who are laying off 10k staff this year because they need to cut costs. This isn't…

Why does anybody other than policing and security agencies need access to this stuff? NHS? Fire and rescue? WHAT? They don't have a role in investigating crime. Okay the fire brigade do post-fire analysis of possible arson etc. but that's not something you need access to somebody's internet history for.

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#129

Another step closer for a families web history to affect their life insurance policies. How long until this information is repackaged and sold on?

That seems like a weak slippery-slope argument. The exemptions to the usual rules that require ISPs to comply with government security policy here and keep quiet about it only cover those things.

So for one thing, using the data collected for anything else or providing it to anyone else would be an immediate and severe breach of both data protection and security laws. That would have serious consequences for the ISP doing it.

For another, it would bring that monitoring system into disrepute and damage the credibility of a government that wants to be seen as strong on security. As a previous government learned to its cost when it tried to introduce personal ID cards here, even voters in the UK (who traditionally have a majority in favour of tough policing and security measures) still have lines they aren't willing to cross.

In short, while there is plenty of scope to debate whether a system like this is necessary or justified as a security measure, it's highly unlikely that it will also be turned into the kind of sell-all-your-data exercise that might be a concern in some other parts of the world.

Re: Two UK Broadband ISPs Trial New Internet Snooping System

#130
post #113

What I don’t get is this: our governments - “ours” being the group of parliamentary democracies - routinely diss authoritarian ones such as China - and rightfully so - for their violations against human rights, among which that to habeas corpus, privacy, and reasonable suspicion. To the point that we agonized over and sabotaged contact tracing apps, which could have helped a lot in fighting COVID, over claims to priv…

[deleted]
Post reply on HN