How is this surveillance system supposed to work? Logging DNS requests? How feasible would it be to get everyone to look up every domain on the Internet and DDOS this surveillance system?
The introductory presentation (linked from the article) suggests what should be logged: - customer ID - start and end times of the 'event' - source IP address and port (the port is used to avoid a NAT at the ISP level) - destination IP address and port - volume of data transferred in each direction - name of internet service connected to - the URL https://www.gov.uk/government/uploads/system/uploads/attachm... There…
Tech firms seek to frustrate internet history log law
121–130 of 170 posts
Re: Tech firms seek to frustrate internet history log law
#122Assuming you can't block a VPN connection since business use them, how would this work? I assume at some point you simply ban HTTPS or non-public connections, or require government certs to be the only ones used (I think Turkey or some similar country is looking at this) so MITM can be done. Of course once you stick your foot into security, all the bad folks out there will take advantage, and their goes your financia…
Blocking it would indeed mandate blocking HTTPS, my OpenVPN piggybacks on port 143 on my UK server (though I guess DPI could spot it too).
Re: Tech firms seek to frustrate internet history log law
#123The problem with these systems is regardless of the efficacy, they are incredibly difficult to dismantle and easy to re-purpose with the stroke of a pen. And these "tech-savvy" people are dreaming if they think that access to VPN services from the UK will remain legal in the UK, esp. after a naughty person or two is shown to have used one to commission a crime. It won't happen quickly, but #include frog_boiling.h.
Re: Tech firms seek to frustrate internet history log law
#124The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…
I agree with you, but I am a bit afraid you are giving them ideas.
>.>
Re: Tech firms seek to frustrate internet history log law
#125The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…
The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.
Re: Tech firms seek to frustrate internet history log law
#126The most scary thing for me is that both political left and political right is nowadays for increasing surveillance - and there is no one in opposition. Except probably for Pirate parties, which are mostly irrelevant.
The Liberal Democrats are against surveillance, and are the third biggest party in the UK.
As a side comment, did you know Hillary Clinton we getting leaks from behind the scenes at the coalition negotiations (see the PDFs)
https://wikileaks.org/clinton-emails/emailid/2850
https://wikileaks.org/clinton-emails/emailid/2817
and some other interesting stuff
Re: Tech firms seek to frustrate internet history log law
#127Earlier quoted context omitted.
Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have: http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat... It is up to you to prove you don't have it anymore too.
Are perfect forward security protocols then illegal? What if it's physically impossible for you to give them a key that doesn't exist anymore?
Thankfully it's a well-known concept now, and a foreign-invented technology you need to interoperate with the rest of the world.
Nothing stops them from throwing the law at you though, even if they know if won't work. You literally can't be punished as a prosecutor for anything less than deliberately throwing the trial for money. If they feel they won't win they'll intentionally ruin your life anyways.
Re: Tech firms seek to frustrate internet history log law
#128Earlier quoted context omitted.
The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.
> the first amendment It took great effort to get crypto even recognized under the first amendment -- the USGov kept insisting that source code was not speech. In the 1990s it was against the law to let foreign nationals have access to the source code to DES. If you had folks from overseas in your organization, technically you couldn't let them see the source for crypto in your product (e.g., you had to wall off piec…
https://www.wired.com/2000/08/court-to-address-decss-t-shirt...
Re: Tech firms seek to frustrate internet history log law
#129So, if you don't want the government to see your thoughts, you're a criminal.
Re: Tech firms seek to frustrate internet history log law
#130Is it too late to return 2016? It's clearly defective. How long until... "Anexprogrammer was clearly a suspect individual. He used A&A, a UK ISP, widely considered sympathetic to terrorism under the thin guise of blogging about preserving privacy. The ISP has even provided information on how their users may circumvent the law and expressed the opinion it was a bad idea! It gets steadily worse, Anexprogrammer often us…
The MPs themselves are exempted from the IP bill. (Although it's safe to assume GCHQ is still collecting everything on them.)