Live data from Hacker News

UK intelligence forced to reveal secret policy for mass surveillance

privacyinternational.org

1–10 of 148 posts

Re: UK intelligence forced to reveal secret policy for mass surveillance

#2
> GCHQ is intercepting all communications - emails, text messages, and communications sent via “platforms” such as Facebook and Google – before determining whether they fall into the “internal” or “external” categories

This should raise some interesting questions about the methods used considering all of that communication is going over TLS.

Re: UK intelligence forced to reveal secret policy for mass surveillance

#5
post #2

> GCHQ is intercepting all communications - emails, text messages, and communications sent via “platforms” such as Facebook and Google – before determining whether they fall into the “internal” or “external” categories This should raise some interesting questions about the methods used considering all of that communication is going over TLS.

Secure technology doesn't prevent governments from getting the "platforms" to co-operate with them, as we saw with PRISM. I could be wrong, but surely it seems far more likely that they are providing GCHQ with the data rather than that GCHQ is cracking encrypted traffic.

Re: UK intelligence forced to reveal secret policy for mass surveillance

#6
> The distinction between ‘internal’ and ‘external’ communications is crucial. Under the Regulation of Investigatory Powers Act (‘RIPA’), which regulates the surveillance powers of public bodies, ‘internal’ communications may only be intercepted under a warrant which relates to a specific individual or address. These warrants should only be granted where there is some suspicion of unlawful activity. However, an individual’s ‘external communications’ may be intercepted indiscriminately, even where there are no grounds to suspect any wrongdoing.

This is another reason to force companies to hold local datacenters in major countries...or, if they prefer, put everything under end-to-end encryption, so it doesn't matter where they hold it.

Only these 2 options should be given to the companies, otherwise no "foreigner" (in relation to where the data is kept) can trust them with their data. They decide which is less costly, but I'm hoping they choose the latter.

Re: UK intelligence forced to reveal secret policy for mass surveillance

#7
The political silence on this issue is indeed deafening. As was the press silence (other than the Guardian). The press in this country are far more interested in reality tv, political infighting, fanning flames about 'immigrants' and what the royals are up to.

And I suspect it's because most of the public don't care either. There are people who would like privacy, who think that GCHQ should be accountable and then there are other people who are perfectly happy that someone is watching everything, everywhere, because that makes them feel safe, and of course they aren't doing anything wrong, so why should they care?

And of course a large proportion of the population either aren't intelligent enough or aren't interested enough to understand what's going on.

It makes me angry, but that's the world we live in.

Re: UK intelligence forced to reveal secret policy for mass surveillance

#8
post #2

> GCHQ is intercepting all communications - emails, text messages, and communications sent via “platforms” such as Facebook and Google – before determining whether they fall into the “internal” or “external” categories This should raise some interesting questions about the methods used considering all of that communication is going over TLS.

We all talk about using SSL everywhere protects people from NSA/GCHQ/... It may prevent script kiddies to use Firesheep but as far as I understand if the NSA/GCHQ has access to any key from any Root CA (which I highly assume) then it doesn't matter at all to the NSA/GCHQ what kind of encryption we use as they can do easily MITM attacks (anyone checking SHA1 from the certificates from a reliable source, whatever this means?). The same is true that at several companies I worked for, people had to install (or per automatic software update) a fake certificate to allow the proxy to spy on all traffic. In one case I tried to fight against it, but I was the only developer of the 80 developer which cared. Their reasoning was totally flawed (which I demonstrated, e.g. that it protects against viruses, which it didn't, as the proxy only checked the first few MiB) but despite that, it was signed by management etc. Maybe I made I mistake in my reasoning and I hope someone explains my why, but in my opinion SSL (despite the script kiddie example) is broken as long as we have to trust companies which we shouldn't trust at all.

Re: UK intelligence forced to reveal secret policy for mass surveillance

#9
post #2

> GCHQ is intercepting all communications - emails, text messages, and communications sent via “platforms” such as Facebook and Google – before determining whether they fall into the “internal” or “external” categories This should raise some interesting questions about the methods used considering all of that communication is going over TLS.

Or, as has been in the case in many of these stories, the public policy vectors are reported roughly accurately, but the specifics and, most especially, the scope aren't. So you have thousands or tens of thousands of FISA directives for specific accounts sent to Google reported as "NSA has a shell on Google servers".

It's probably the case that GCHQ simply doesn't collect "all" communications, and can't do much about cert-pinned TLS to Google Mail. (You know, since they got caught fiber tapping Google's UK data centers.)

Re: UK intelligence forced to reveal secret policy for mass surveillance

#10
> The Government believes that, even when privacy violations happen, it is not an “active intrusion” because the analyst reading or listening to an individual’s communication will inevitably forget about it anyway.

unbelievable! What if they're building a searchable database of every user, so as to have 'dirt' on someone when he 'becomes a threat' to their interests? (Like becoming a spokesman against this sort of thing or whatever the bureaucrats wantto do next year).

Post reply on HN