Live data from Hacker News

Independent review of UK national security law warns of overreach

techradar.com

251–260 of 299 posts

Re: Independent review of UK national security law warns of overreach

#251
post #230

There are quite a few comments below complaining about the headline - happy to change it, but I'm in a meeting trying to figure out more about https://news.ycombinator.com/item?id=46301921 for the next bit. Can someone suggest a better title? Better here means "accurate and neutral, and preferably using representative language from the article".

Broadly-defined "hostile acts" in UK national security law

Reasoning:

* Original report behind the article: "State Threats Legislation in 2024" [0], i.e., UK national security law

* Article focuses on an example from section 6.17 where developing an encrypted messenger app is given to show how broad the definition of "hostile act" is

* Snippets from the article:

> In his independent review of the Counter-Terrorism and Border Security Act and the newly implemented National Security Act, Hall KC highlights the incredibly broad scope of powers granted to authorities. > > He warns that developers of apps like Signal and WhatsApp could technically fall within the legal definition of "hostile activity" simply because their technology "make[s] it more difficult for UK security and intelligence agencies to monitor communications."

[0] Original report: https://assets.publishing.service.gov.uk/media/69411a3eadb57...

Re: Independent review of UK national security law warns of overreach

#252
post #147

Earlier quoted context omitted.

Do you understand what transit encryption is? The point of TLS is the ISP can't inspect the traffic. They can of course refuse to carry all encrypted traffic, but 1) stenography exists, so have fun writing DPI filters to detect suspicious noise in the note velocities of MIDI data; 2) turns out the free market didn't adopt HTTPS just to hide drug dealers -- I don't know if you heard, but there's this itty bitty thing…

I know very well and I absolutely am not advocating for removing TLS. I am only saying that there is no need for them to remove it as IsP's can already access your traffic if needed through a lawful intercept. These are part of ISP certification. You're very naive if you believe there is no way for the ISP to view your traffic just because you're over an Https connection. The ISP has "Intercept Access Points" withing…

> You're very naive if you believe there is no way for the ISP to view your traffic just because you're over an https connection.

You seem to be under an impression an ISP's "Intercept Access Point" is somehow different from any downstream MitM. An ISP is certainly has more area than a coffee shop network, but the threat model stays mostly the same. Both I and Comcast can run tcpdump or mess with your packets to the extent cryptography permits.

There are only some realistic ways you could intercept a TLS connection, and that would be

1) For you to use TOFU, and the ISP to tamper with the initial key exchange. To stay undetected, you would have to ensure every vantage point after provides your compromised keys, expanding to potentially every cellular provider, home/business connections, and data-centers, potentially even outside your jurisdiction. This would be easiest if you could meddle near the backbone, until you realize the cost of deeply inspecting every packet, detecting the protocol, and transparently re-encrypting _all_ the internet. As soon as you verify out-of-band, even over a VoIP call, or the target crosses into a network you didn't compromise, your cover is blown. And you've only got shot at intercepting the key exchange, so you can't afford to be picky about who to target.

2) In practice, most traffic uses Certificate Authority roots from the browser's default set. As I've said before you can either plead with the citizens to install your intercept CA, or you can find one trusted by browsers without cross-jurisdictional threshold signatures and try to apply rubber hose cryptoanalysis until the rights certs get signed. A transparency log will mandate you publish your MitM cert onto an immutable global ledger, letting everyone know something fishy is going on. Your attack has succeeded, but at the cost of blowing your cover.

What an ISP, as well as me as a network admin, do see is the domain and IP, timing, and packet size. That does allow me to deduce a lot about you--large packets sent to whatsapp.com are probably images, many small ones may be a call. But that's about it unless you can get the keys.

Re: Independent review of UK national security law warns of overreach

#253

Earlier quoted context omitted.

Don't worry, WiFi sensing will eventually remove our walls and curtains for free in that respect.

Aluminum siding will make a comeback.

Unlikely after Grenfell.

Re: Independent review of UK national security law warns of overreach

#255
post #111

> He warns that developers of apps like Signal and WhatsApp could technically fall within the legal definition of "hostile activity" simply because their technology "make[s] it more difficult for UK security and intelligence agencies to monitor communications. Sounds like Let's Encrypt would also fall under that. This has got to stop. If you want to stop criminals, then focus on their illegal activites, not the stree…

> I see why governments think they are doing this to protect the people. they're not doing this to protect people, they're doing this to ensure there cannot be rebellion against unpopular policies. Organization is harder if all communications is monitored. But this is how gov't get to be kept in check - the risk of "rebellion". If this risk is removed, you get authoritarian states - see north korea.

I think the saying “the road to hell is paved with good intentions” is more apt.

I think what’s happening isn’t some evil plot to quell opposing voices, but more likely the UK government thinking they’re actually passing laws to reduce rioting and online abuse. And the censorship effects are a side effect of these laws.

Some might consider this opinion naive but take this counterpoint: laws require a majority to pass. So if these censorship laws were written to squash opposing voices, then we’d be dealing with a literal conspiracy involving hundreds of people. I don’t believe all politicians are only in it for themselves (though I do believe many are), so you’d expect at least 1 MP to speak out if such a conspiracy existed.

Re: Independent review of UK national security law warns of overreach

#256
post #163

Earlier quoted context omitted.

> So say if my UK friend connected directly to my PC with SSH/RDP, both uses end-to-end encrypted link, to chat with me using `wall`, `write` or Windows Task Manager, then all of sudden this is a hostile and Mr Big Ben will just launch laser at me to burn me to death. Wow, this is just messed up. No, because nobody is using those systems to communicate at scale to try to destabilize a government. Quantity has a quali…

> destabilize a government Governments often equate any opposition to "destabilizing"; don't let them. Yes, there are real information-warfare efforts in the world to destabilize governments and societies. There are also far more people who are trying to organize, and rally, and communicate about issues they care about.

At the same time, intentional government destabilization - usually by governments of rival countries - is real and shouldn't be ignored.

Two conflicting problems can be true at once, and require careful balancing.

Re: Independent review of UK national security law warns of overreach

#257
post #9

I wonder how the public in the UK feels about their country quickly devolving into an oversurveilled state.

One of the original motivations for the First Amendment was the UK's surveillance and censorship of American mail; the UK has been a surveillance state for a very long time.

I also can't help thinking people living in the UK now are descended from people who didn't leave for the colonies, or were too rich to need to. Far too many of us just can't be bothered.

Re: Independent review of UK national security law warns of overreach

#258
post #81

Earlier quoted context omitted.

Curtains should also fall under the same category because they do make it more difficult for UK security and intelligence agencies to monitor suspect activities. Then of course you also have walls... The argument is so fundamentally stupid that they should be embarrassed just putting it down in writing!

This cuts to one of the critical issues with governance globally in this era. For a really long time, we relied on social norms and mores to keep governments in check - and astonishingly it worked at least a little. Embarrassment was a good proxy for well constituted rules of representation. What right-wing institutions have noticed all around the world is that you can just kind of ignore all that shit now. Centrists…

It boggles my mind that you think this stuff is being pushed by the right. Expansion of government and surveillance is a hallmark of the left, and indeed this latest wave of surveillance is being pushed by progressive governments in Western Europe and Australia.

Governments of both flavours are ignoring the voting public, for various reasons, e.g. they are signatory to agreements that no longer work for the public but are difficult to break, the public is increasingly economically irrelevant compared to businesses, and, of course, the greedy self-interest of the politicians themselves.

I agree with you on the third paragraph, but it's also the reason that I believe the US will be okay compared to other Western democracies (an opinion I'm not sure you would share, judging by your post). The Constitution is already a thing, and is on its own a declaration that certain rights derive from a higher authority than government. The second amendment in particular is under siege (again, by the left), but does equalize things in a way that many of its opponents are reluctant to admit.

Re: Independent review of UK national security law warns of overreach

#259
post #81

Earlier quoted context omitted.

Curtains should also fall under the same category because they do make it more difficult for UK security and intelligence agencies to monitor suspect activities. Then of course you also have walls... The argument is so fundamentally stupid that they should be embarrassed just putting it down in writing!

This cuts to one of the critical issues with governance globally in this era. For a really long time, we relied on social norms and mores to keep governments in check - and astonishingly it worked at least a little. Embarrassment was a good proxy for well constituted rules of representation. What right-wing institutions have noticed all around the world is that you can just kind of ignore all that shit now. Centrists…

Right-wing institutions like the Labour regime.

Re: Independent review of UK national security law warns of overreach

#260
post #81

Earlier quoted context omitted.

Curtains should also fall under the same category because they do make it more difficult for UK security and intelligence agencies to monitor suspect activities. Then of course you also have walls... The argument is so fundamentally stupid that they should be embarrassed just putting it down in writing!

This cuts to one of the critical issues with governance globally in this era. For a really long time, we relied on social norms and mores to keep governments in check - and astonishingly it worked at least a little. Embarrassment was a good proxy for well constituted rules of representation. What right-wing institutions have noticed all around the world is that you can just kind of ignore all that shit now. Centrists…

Pretty incredible ability to make something so clearly about government overreach into some pet cause about “corporations” or whatever
Post reply on HN