Skip to main content

Interception and Surveillance

GreenNet opposes plans to legalise mass surveillance and malware

Submitted by cedric on

It's been a while since GreenNet last updated our members on our legal case against the British Government and UK Government Communications Headquarters (GCHQ) in the Investigatory Powers Tribunal (IPT), but things have been proceeding at a typical speed for such detailed legal judgements.  Meanwhile, there have been three official reports into surveillance and interception by the secret services and police, several changes to the law, several admissions that extreme (and in many cases likely illegal) powers have been used by the secret services, and one huge proposed "draft Investigatory Powers bill" (DIPB), that by some reckoning includes the fifth attempt at a "Snooper's Charter", the zombie legislation that will not die, and looked at by four (inevitably underinformed) Parliamentary committees.

[[{"fid":"5579","view_mode":"default","fields":{"format":"default","field_file_image_alt_text[und][0][value]":"","field_file_image_title_text[und][0][value]":"","alignment":"right"},"type":"media","attributes":{"height":"175","width":"180","border":"2","style":"padding:5px;margin-left:5px;","class":"media-element file-default"},"link_text":null}]]GreenNet submitted evidence to two of these committees; you can see our attempt at a technical analysis below or with other submissions; we are far from the only specialist organisation concerned that the draft has not been thought through technically.  GreenNet is very concerned that the draft bill grants the executive almost unlimited powers to compel people to spy on others and, given the history of the way such powers have been used, regard it as a massive threat to individual freedom, freedom to associate and political progress.  There is still a chance to comment on human rights implications until 4 January, but so far there has been insufficient time to have the right questions answered.  We've also been working with other members of the Internet Service Providers' Association (ISPA) to try to help MPs understand some of the likely implications of the bill. Early next year any pressure on representatives may help, although we're concerned the secret services will not give up lightly the powers they have claimed, and maybe the best hope is proper judicial oversight and safeguards for journalists and activists.  Open Rights Group have produced a good briefing on draft IPB that could help engage media and politicians. The position of the Labour party in particular is crucial.

The structure of the new draft is a bit of a pot-pourri: roughly part 1 of RIPA, which prevents things like the newspaper phone hacking, is swapped in; followed by part 2 allowing interception by agencies and the police, and part 3 which allows law enforcement to request communications data without a warrant; and it's not until part 4 where we get effectively the whole "Snooper's Charter" draft bill from 2012, this time with Deep Packet Inspection (DPI) disguised as "Internet Connection Records" (there are no such things; we should know), and a massively powerful search of all individuals called the "Request Filter".  Then part 5 makes explicit how the Intelligence Services Act has been used for targeted hacking; part 6 and 7 explicitly permit even greater powers for mass cracking, interception and access to stored data; and part 8 includes the safeguards, one commissioner instead of the current three. It's been described as a list of Christmas presents for the police (and other investigating agencies such as Ofcom and the Department of Work and Pensions).

On 1-4 December 2015, there were public hearings of the main evidence in the IPT case (there are also "closed" hearings where the real facts can be discussed between the government and the panel of judges, but no one else is allowed to know what's happening.)  See Privacy International's update including the outline arguments put cogently on behalf of us and progressive ISPs outside the UK by Blackstone Chambers and Bhatt Murphy. The Government is making panicked moves, apparently realising the secret services have been doing things that are incompatible with human rights or even the terms of legislation establishing the intelligence services themselves.  As one example, if GCHQ interfered with GreenNet equipment off their own bat (rather than for MI5), it could be illegal because they are confined to signals intelligence outside the UK; the new draft bill contains a small amendment to legalise this.  The crucial amendment to the Computer Misuse Act this year that made an exception so that government agencies could hack passed without a word of debate in Parliament.

much of the debate for the last 15 years appears to have been a charade about data that the government very likely already held. It is also clear that the legislation that the government relied upon was being interpreted in ways that Parliament never imagined

David Davis MP in an article by Duncan Campbell about PRESTON

GCHQ, by a twisted and unforeseeable interpretation of the law, have claimed scary powers to interfere with any digital device in the UK or abroad.  We also know they spied on Amnesty International illegally, and if they are so opaque, we cannot know if they are interpreting 'national security' in a political way.  Now the police want access to these powers.  If they play fast and loose in this way with existing law, who knows what they'll make of the new Investigatory Powers bill? The right to privacy isn't something we can leave up to ministers and judges operating in secret - it's something necessary to us all as human beings and to society, and we should all be involved in the discussion.

[[{"fid":"5580","view_mode":"default","fields":{"format":"default","field_file_image_alt_text[und][0][value]":"","field_file_image_title_text[und][0][value]":"","alignment":"right"},"type":"media","attributes":{"height":"163","width":"322","border":"2","style":"padding:5px;margin-left:5px;","class":"media-element file-default"},"link_text":null}]]While some have worried that we're putting our head above the parapet, GreenNet would not be party to the complaint if we did not believe that it is likely to improve transparency, privacy and security for the internet as a whole as well as for our users.  The new draft bill, if passed without thorough amendments, would create additional "disclosure" and "tipping-off" offences by those given notice to spy on others.   In the next year or two, that probably applies mostly to mobile operators (and maybe broadband wholesalers), but the authorities would have no limit on whom they can give notice to.  As of December 2015, GreenNet can categorically state that we have not been asked to retain or hand over information on our users or their communications.  If you ask, we won't lie to you about having received a notice.

Encryption alone is unlikely to completely remove the threat of mass surveillance, although Ed Snowden and other whistleblowers have made us all more paranoid about security in general, and rightly so.  There are lots of good tools for routine encryption and anonymisation: for instance we're now using Tox as an instant messenger, and Enigmail to apply OpenPGP encryption to email.  One thing we would like to organise in the new year is a "cryptobuffet" to demonstrate and discuss some of these tools.  For more advanced users, including those working in hostile regimes, the Centre for Investigative Journalism produces an up-to-date guide to computer security.  Another possible response is activists networking offline and locally, as described in a fascinating piece by Paul Mobbs in the Ecologist.

Among other related policy things we've been up to in 2015, we've been at a conference on Digital Citizenship and Surveillance organised by Cardiff University's school of journalism and media, and contributed to their report on online policing of "Domestic Extremism" (a term that has included journalists and comedians as well as ordinary activists, such as "non-violent extremists" who are a bit extreme in their non-violence.)  If you're confused about the various post-Snowden cases, there's a list here.

We look forward to the IPT's judgement in the new year, and hope for some moves towards transparency and accountability at the very least.  Please do contact us if you have any questions.

Snoopers' charter: report on "Scrambling for Safety", 19 April 2012

Submitted by Anonymous (not verified) on

"What does the UK Home Office think they want to do, and why do they think they want to do it?"  The question was a recurring theme at Scrambling for Safety 2012, a conference to discuss the mooted new powers for the "Surveillance State", swiftly arranged in the wake of April's media furore. Academics, MPs, lawyers, journalists, civil libertarians, ex-police officers, a smattering of technologists and industry representatives plus a few people who seemed to know RIPA like the back of their hand, gathered at the LSE to piece together what was known about the inchoate legislation often referred to as CCDP (Communications Capability Development Programme). 

Although several common themes emerged, there was a general worry that the people in the room understood the issues far better than any permanent staff in the Home Office.  We can only hope that there were some civil servants paying attention in the room as well as politicians.  Conference video and other blogs are already available via the SfS link, and Ross Anderson provided a blow-by-blow account, so I'll just add my reflections to some of the points of agreement about what we think they think they want and why, and various legal, ethical, technical and economic objections to it.

Gus Hosein of Privacy International kicked off with a historical overview of interception and surveillance in the UK.  (Under RIPA, the Regulation of Investigatory Powers Act, interception is about content of messages, and surveillance is about "communications data" such as sender, recipient and time of a message and subscriber data, also known as metadata.  Interception requires a warrant and the evidence is not admissible in court, while surveillance merely requires the judgement of a senior police officer.)  It's clear that despite ministers' protestations that they propose merely "maintaining" the status quo in the face of new technology and "preserving" and "updating" capabilities, these are whole new classes of data that may be subject to snooping and "deep-packet inspection" (DPI) without a warrant.  Gus reiterated that the "central database" idea had already been dropped under Jacqui Smith.  Of course that's true, but you wouldn't think so to hear coalition ministers desperately trying to find something placatory to say.  And as the powers are extended further and further, justifications have gone from saying it's "only" access to data that's stored by ISPs/CSPs anyway, to storing it for longer; to retaining data that wouldn't be retained; to whole new areas of data that ISPs wouldn't otherwise generate; and now possibly to collecting, correlating and processing it (in "real time" even).

So any claims that this is in principle nothing new, because we've had RIPA for 12 years, are simply wrong.  The state, or law enforcement, is always demanding more intrusive data, and the fact we're conducting more of our lives online makes that data more sensitive, not less. 

(Some in the audience, however, felt that invasion of privacy was not as good an objection as economic and practical arguments, given the general public's propensity to give away private data to Facebook and Google.  My view is that while it's true that the world has moved on since wiretaps, such that technology including encryption and onion routing may make it near-impossible to intercept everything going down a wire even for national security, just as you can't bug every possible location, you can't compensate by paying ISPs to turn the internet from communication services provided for their users, to a mass surveillance system for spying on them.)

Shami Chakrabarti of Liberty was on the first panel.  I can't help but be a bit critical of her organisation since it stopped being NCCL nearly 20 years ago, because it seems to have been so unsuccessful in defending our liberties and rights (for example, right to peaceful protest inside a private building); because of suspicions of it becoming closer to the powers-that-be than to those at the sharp end; and because of a lawyerly concentration on human rights rather than civil liberties (my example of this nicety is that a right to education as in Article 26 of the UDHR is an enabling right, while being able to drink alcohol on a bus is a liberty but not a right, and freedom of expression is both). 

However, I can forgive them for doing little for freedom in the electronic sphere since we effectively now have a specialist group for that, and Shami made her impassioned case.  This time the emphasis was that privacy is essential to fundamental principles like the secret ballot, consultation with lawyers and representatives and protection from discrimination, but also to basic human intimacy and trust.  One point of shared concern was how "the Home Secretary" whoever it was seemed to be rather irrelevant, as policy was driven by advisers and civil servants like Charles Farr (head of counter-terrorism and reputed former MI6 agent) regardless of who were the elected representatives.  In fact "civil servant" and "adviser" seem inappropriate terms when policy and legislation seems to be dictated by the security services rather than anything remotely democratic.  Blanket surveillance is disproportionate, unnecessary, unethical and illegal.  There is already too much data retention, and the EU data retention directive is being challenged as a violation of rights for instance in Germany.  Does Theresa May believe "there should be no unwatched space, online or offline"?  The logic would lead to putting a monitoring device behind a wardrobe in every bedroom in the UK.

Perhaps, I suggest, the panopticon (the prison with universal visibility) is not just a campaigning metaphor, and comparisons with George Orwell's 1984 are not overstatements after all.  In 1984 the state (embodied as everyone's Big Brother) monitored every citizen through the "telescreen", a television and camera combination that doubled for propaganda and surveillance.  Now televisions never had cameras fitted, but increasingly internet-enabled devices do, and our political and personal actions happen networks that are being asked to look out for "thoughtcrime".

Next up, with some actual legal and technical facts, was Professor Ross Anderson of University of Cambridge Computer Laboratory and chair of FIPR.  He recalled the pressure in the 1990s over key escrow, the evolution of the supposed distinction between sensitive content which was a privacy issue, and surveillance of traffic data in which the police wanted to include every web search.  In reality much traffic data such as who you're talking to on Facebook are now often specially sensitive.  Ross made the point that senior civil servants are technically clueless. (From hearsay, their statements do give a strong impression of ignorance of the basic principles of electronic communications.)  The Home Office doesn't have significant expertise of its own and so buys it in from outside including those who are in the business of selling surveillance hardware.  He didn't need to say how dangerous this situation was, worse than a typical "revolving door" problem of government consultants.  His conclusions agree closely with the research of Eric King at PI, who monitors the way the vendors of hardware espionage "solutions" sell their products (including at DSEi) to places like Syria and Iran.  Unfortunately, these manufacturers are looking to expand that market.

Ross talked about what they are trying to sell, perhaps the 10,000 "black boxes" (probes in the network) that had been rumoured, which would give access to content not just metadata, since an internet packet is generally a mixture of both and it would have to pick up all of them.  If you filter out broadcast content like iPlayer, increasing hard drive capacities mean it is possible to store everything going over the net, as India already does (they also have probes at the national boundary allowing people to see email as it goes past).  BT already has capacity to do DPI (deep-packet inspection) of 100,000 circuits; this would mean about five extra data centres and paying BT about £2bn to rebuild their network, and a £200m hardware contract to Chinese manufacturer Huawei (who annoyingly call one of their filtering systems "GreenNet").  £2bn is really just initial outlay; a later expert speaker has written of extensive maintenance and administration and a total cost over time of £12bn.  Among other things, this means a competition issue giving near-monopoly providers more control and making small and medium-sized ISPs unable to compete; "undoing Thatcher's good work" was a line that appealed to Conservative MP David Davis on the same panel.  In any case, traffic is getting harder to monitor because of encryption (TLS/SSL/HTTPS), and the way such a system would only trap those people who think they have nothing to hide is likely to mean that it will be abandoned on practical grounds.  However, there may be a later threat of private or secret arrangements with some companies like Facebook (others might refuse), and a question over how these could conceivably be regulated.  (Note that later speaker Prof Korff points out that voluntary arrangements and codes cannot override human rights.)

Dr Julian Huppert, LibDem MP from Cambridge, comes over as concerned at these issues and worried that the majority of civil servants and his fellow politicians wave stuff through with no understanding.  They conceive of a Skype call as equivalent to a phone call without stopping to think whether there are technological differences that mean that quite distinct principles might apply.  Both understanding of civil liberties and technical issues are important, but MPs were offered basic training in scientific issues and fewer than a dozen turned up.  Dr Huppert echoed that an additional problem was that every Home Secretary was "captured" by the security services in time, which and the home affairs select committee is calling Theresa May on Tuesday 24th at 12.30 to find out what is happening.  (In the event, May refused to answer Dr Huppert's question about the "technical detail" of whether plans include decryption and black boxes, made precisely the same errors over Skype and "maintaining capability" again, and is probably going to be invited back for another session.)  Liberal Democrat policy includes "ensuring that service providers are not mandated by law to collect third-party communications data for non-business purposes by any method", and the coalition agreement promised to end data retention without good reason: we'd seen no good reason.  There was also a commitment to scale back the scope of the EU Data Retention Directive towards privacy.  Dr Huppert observed that current safeguards on traffic data are too weak, and agreed access should require some kind of warrant from a magistrate. (Some RIPA cases like dog fouling hit the headlines and have been addressed in a rather narrow way.)  He was more reassured than I would be by his leader's promise that legislation would be presented as a draft before being introduced in Parliament (just keep that promise, please).

Trefor Davies, CEO of wholesale/business internet provider Timico, the only "industry" figure on the panel, owned up to not being told anything about the practical project specifications yet (it sounds like the Home Office has spoken in very vague and modest terms to only 3 or 4 big ISPs, yet somehow the Home Secretary later claims there had been "considerable discussions with the industry").  He pointed out that larger providers did some automated inspection for traffic management, but the costs for smaller providers were prohibitive.  Can it be done for £2bn?  It is possible in China, but there is an undefined hidden cost not in the hardware, but in the implementation, such as in trying to make the data meaningful.  He pointed out that there were many, many ways to circumvent interference in the network, and doubts the black boxes could effectively defeat encryption, thus driving more and more people to anonymity.

David Davis, former shadow Home Sec, was the second MP to speak, and felt waiting for 600 or more MPs to understand the issues was futile - a favourite quote of politicians is Adlai Stevenson's supposed response to a supporter's shout "all intelligent people will vote for you": "That's not enough, I need a majority."  This is an issue of poor government, ignorance and fear, and one problem is that ministers have no experience of terrorists and in the absence of other advice, believe whatever the security services tell them.  His additional reason for privacy, transparency, cited 16 anonymous whistleblowers in the Damien Green case, all of whom would have been sacked if their communication data were accessible.  There were also data-mining "experts" keen to see what they could do with huge amounts of personal data; this would generate enormous numbers of false positives (i.e. miscarriages of justice) and a "hoovering up" of ordinary people, while missing sophisticated attacks.  He laid claim to getting CCDP dubbed "snoopers' charter" (in my opinion, pretty accurate), and made a good point that in the past surveillance has been self-limiting by requiring manual tapping of wires and so restricted to areas of genuine suspicion.

The Register's coverage of the event.

 

Less than three years ago, David Cameron said

Faced with any problem, any crisis – given any excuse – Labour grasp for more information, pulling more and more people into the clutches of state data capture…  And the Government doesn’t want to stop with the basic information. They want the most complex, important, personal information there is… Scare tactics to herd more disempowered citizens into the clutches of officialdom, as people surrender more and more information about their lives, giving the state more and more power over their lives. If we want to stop the state controlling us, we must confront this surveillance state.