Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

21–30 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#21
post #18

Earlier quoted context omitted.

I disagree. The headline is reasonable because you can be put in a position in which you're not forced to do something, but it's extremely unreasonable not to do that thing. They weren't forced to close down per se, but their other options were extremely infeasible or reprehensible.

Arguably it is a problem they created by the architecture they chose, in which this is a fatal flaw of design that was almost certainly something that could be anticipated.

I do agree, but historically we've been able to write software in an environment we didn't foresee being hostile. We've been too trusting and blasé when it comes to privacy and security. For example, look at the original SMTP implementation: the designers didn't take into account there might be governments or other bad actors that would snoop wholesale on such messages as they bounced around the infrastructure. If the original designers had known, the specification would have undoubtedly been different.

It's also hard to create a system that's private and secure, and it's vastly less convenient to use which increases friction and drives down adoption. PGP, for example, is very good but extremely inconvenient to use all the time.

As an outsider, I think I understand the rationale behind their design decisions. Just saying it should have been more carefully created with privacy in mind glosses over the many complexities and difficulties that design goal entails.

We, as creators of software, have problems that are more political than technical, no matter where we are in the world.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#22
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

RIPA was strongly opposed by the IT and communications community during its 'consultation' period, but was passed largely intact. It was so intrusive a proposal that even people like me who often say 'I'll write and complain' actually did write a letter. Predictions of its misuse have been borne out, particularly as the authorized users of communication data were never enumerated or restricted. So we have the situati…

> ..local Councils use RIPA to obtain communication data...

It's worth noting that legislation introduced during 2012 limited the circumstances under which councils could use RIPA powers [1] and required judicial approval for the exercise of those powers [2].

[1]: http://www.legislation.gov.uk/uksi/2012/1500/article/2/made

[2]: http://www.legislation.gov.uk/ukpga/2012/9/part/2/chapter/2/...

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#23
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

RIPA was strongly opposed by the IT and communications community during its 'consultation' period, but was passed largely intact. It was so intrusive a proposal that even people like me who often say 'I'll write and complain' actually did write a letter. Predictions of its misuse have been borne out, particularly as the authorized users of communication data were never enumerated or restricted. So we have the situati…

Spot on. I wrote to my MP about RIPA. Not a sausage back.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#24

Earlier quoted context omitted.

RIPA was strongly opposed by the IT and communications community during its 'consultation' period, but was passed largely intact. It was so intrusive a proposal that even people like me who often say 'I'll write and complain' actually did write a letter. Predictions of its misuse have been borne out, particularly as the authorized users of communication data were never enumerated or restricted. So we have the situati…

> ..local Councils use RIPA to obtain communication data... It's worth noting that legislation introduced during 2012 limited the circumstances under which councils could use RIPA powers [1] and required judicial approval for the exercise of those powers [2]. [1]: http://www.legislation.gov.uk/uksi/2012/1500/article/2/made [2]: http://www.legislation.gov.uk/ukpga/2012/9/part/2/chapter/2/...

This only happened after various scandals about privacy invasion by councils.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#25
post #19

The headline attached to this submission is sensationalist and misleading. GCHQ did not force CertiVox to shut down PrivateSky. CertiVox decided to close PrivateSky after they were served with a notice issued under section 49 of the Regulation of Investigatory Powers Act (RIPA) which required that they hand over the key(s) required to decrypt one (or more) of their customer's data. The underlying legislation can be f…

That doesn't appear to be the whole story. The claim to have needed to re-engineer their system to have access to keys, effectively making it a different service than it had been. And that means that a demand for keys can effectively make services where users' key are not accessible impermissible.

Again, that's the silver lining in this story. For details on how trust is split to assure no single point of failure, have a look at https://certivox.org/pages/viewpage.action?pageId=10420248 "Distributed Trust Authority"

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#26

The headline attached to this submission is sensationalist and misleading. GCHQ did not force CertiVox to shut down PrivateSky. CertiVox decided to close PrivateSky after they were served with a notice issued under section 49 of the Regulation of Investigatory Powers Act (RIPA) which required that they hand over the key(s) required to decrypt one (or more) of their customer's data. The underlying legislation can be f…

I disagree. The headline is reasonable because you can be put in a position in which you're not forced to do something, but it's extremely unreasonable not to do that thing. They weren't forced to close down per se, but their other options were extremely infeasible or reprehensible.

> They weren't forced to close down per se...

That's the crux of the issue. They weren't forced to close down, they chose to.

End of discussion.

EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter?

"The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash."

Source: https://news.ycombinator.com/item?id=6894316

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#27
post #24

Earlier quoted context omitted.

> ..local Councils use RIPA to obtain communication data... It's worth noting that legislation introduced during 2012 limited the circumstances under which councils could use RIPA powers [1] and required judicial approval for the exercise of those powers [2]. [1]: http://www.legislation.gov.uk/uksi/2012/1500/article/2/made [2]: http://www.legislation.gov.uk/ukpga/2012/9/part/2/chapter/2/...

This only happened after various scandals about privacy invasion by councils.

And after a Tory-led government came to power...

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#28
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

From https://wiki.openrightsgroup.org/wiki/In_the_interests_of_th... -

"The House will notice that the Bill restricts the activities of the SIS and GCHQ for safeguarding the economic well-being of the country to the acts or intentions of persons outside the United Kingdom. The agencies may not and do not get involved in domestic economic, commercial or financial affairs."

So it's not quite as broad reaching as it reads on first glance. It is generally a problem though that laws need to be written so they're broad enough to cover circumstances which might not have been considered at the time of the laws' writing so that new laws don't need to be written all the time yet they can't be so overly broad as to be unworkable - which is why the judiciary has it's role in deciding how to interpret the laws and decide whether or not they ought to apply in a given circumstance.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#29
post #24

Earlier quoted context omitted.

This only happened after various scandals about privacy invasion by councils.

And after a Tory-led government came to power...

What's that got to do with it? (genuinely interested).

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#30
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

A warrant could imply that they are unable to attack the provider This is the institution which allowed U-boats to sink British ships so not to even hint that the ENIGMA cipher was cracked. I'm sure they're utterly incompetent at keeping secrets, and anyone on the internet can deduce their most critical SIGINT capabilities simply by observing how they deal with civil warrants in minor cases.

Well the Snowden revelations suggest that yes this kind of capability will become public. We exist in a space that is bounded by technological opportunities and limitations which agencies are just as subject to as everyone else.
Post reply on HN