Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

121–130 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#121

How is this surveillance system supposed to work? Logging DNS requests? How feasible would it be to get everyone to look up every domain on the Internet and DDOS this surveillance system?

The introductory presentation (linked from the article) suggests what should be logged: - customer ID - start and end times of the 'event' - source IP address and port (the port is used to avoid a NAT at the ISP level) - destination IP address and port - volume of data transferred in each direction - name of internet service connected to - the URL https://www.gov.uk/government/uploads/system/uploads/attachm... There…

Looking at the document (ANNEX C for example) one could guess they are going to log entire request body...

Re: Tech firms seek to frustrate internet history log law

#122

Assuming you can't block a VPN connection since business use them, how would this work? I assume at some point you simply ban HTTPS or non-public connections, or require government certs to be the only ones used (I think Turkey or some similar country is looking at this) so MITM can be done. Of course once you stick your foot into security, all the bad folks out there will take advantage, and their goes your financia…

Ironically I access my VPN to the UK so I can access geo-restriced UK websites while I am out of the country.

Blocking it would indeed mandate blocking HTTPS, my OpenVPN piggybacks on port 143 on my UK server (though I guess DPI could spot it too).

Re: Tech firms seek to frustrate internet history log law

#123

The problem with these systems is regardless of the efficacy, they are incredibly difficult to dismantle and easy to re-purpose with the stroke of a pen. And these "tech-savvy" people are dreaming if they think that access to VPN services from the UK will remain legal in the UK, esp. after a naughty person or two is shown to have used one to commission a crime. It won't happen quickly, but #include frog_boiling.h.

Even frogs get out of the water when it starts to get hot.

Re: Tech firms seek to frustrate internet history log law

#124
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

> Transmission of undecryptable data will be a crime, in and of itself.

I agree with you, but I am a bit afraid you are giving them ideas.

>.>

Re: Tech firms seek to frustrate internet history log law

#125
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

The first amendment itself won't be overturned, but they very well may try to exclude cryptography as a form of protected speech. The federal government never wanted to allow it in the first place, they just realized how difficult it would be to put the genie back in the bottle. A Trump-chosen Supreme Court could very well make rulings that weaken or even entirely do away with this protection.

Re: Tech firms seek to frustrate internet history log law

#126

The most scary thing for me is that both political left and political right is nowadays for increasing surveillance - and there is no one in opposition. Except probably for Pirate parties, which are mostly irrelevant.

The Liberal Democrats are against surveillance, and are the third biggest party in the UK.

They didn't exactly cover themselves in glory during the coalition.

As a side comment, did you know Hillary Clinton we getting leaks from behind the scenes at the coalition negotiations (see the PDFs)

https://wikileaks.org/clinton-emails/emailid/2850

https://wikileaks.org/clinton-emails/emailid/2817

and some other interesting stuff

https://wikileaks.org/clinton-emails/emailid/6988

https://wikileaks.org/clinton-emails/emailid/7377

Re: Tech firms seek to frustrate internet history log law

#127
post #70
post #65

Earlier quoted context omitted.

Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have: http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat... It is up to you to prove you don't have it anymore too.

Are perfect forward security protocols then illegal? What if it's physically impossible for you to give them a key that doesn't exist anymore?

If this was currently being developed in the UK, my money would be on illegal.

Thankfully it's a well-known concept now, and a foreign-invented technology you need to interoperate with the rest of the world.

Nothing stops them from throwing the law at you though, even if they know if won't work. You literally can't be punished as a prosecutor for anything less than deliberately throwing the trial for money. If they feel they won't win they'll intentionally ruin your life anyways.

Re: Tech firms seek to frustrate internet history log law

#128
post #109

Earlier quoted context omitted.

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

> the first amendment It took great effort to get crypto even recognized under the first amendment -- the USGov kept insisting that source code was not speech. In the 1990s it was against the law to let foreign nationals have access to the source code to DES. If you had folks from overseas in your organization, technically you couldn't let them see the source for crypto in your product (e.g., you had to wall off piec…

This can be partially fixed by printing the code on a tshirt.

https://www.wired.com/2000/08/court-to-address-decss-t-shirt...

Re: Tech firms seek to frustrate internet history log law

#130
post #81

Is it too late to return 2016? It's clearly defective. How long until... "Anexprogrammer was clearly a suspect individual. He used A&A, a UK ISP, widely considered sympathetic to terrorism under the thin guise of blogging about preserving privacy. The ISP has even provided information on how their users may circumvent the law and expressed the opinion it was a bad idea! It gets steadily worse, Anexprogrammer often us…

The MPs themselves are exempted from the IP bill. (Although it's safe to assume GCHQ is still collecting everything on them.)

Please tell me you're joking?!
Post reply on HN