Jump to content

Recommended Posts

Posted
Your second link is about updating Data Protection law from 1995 and is nothing to do with Data Retention, except of course they clash... the proposed regulation likely says retention is permitted where it's required by law e.g. Data Retention.

 

Would you mind going and reading The Register's take on this and then explain how that fits with your EU-wot-dunnit case. Note how that and lots of other folk, including the briefing paper that's supposed to be calm the lib dem masses, keep invoking the magic acronym RIPA in relation to *this* story and RIPA is not Data Rentention.

 

What's this I see?

 

A press release about the launch of the new EU cybercrime centre? http://ec.europa.eu/home-affairs/doc_centre/crime/docs/Communication%20-%20European%20Cybercrime%20Centre.pdf

 

The Register, although it is mostly right, is wrong on this one. This is an EU programme, and an EU directive. Why else would it be that two political parties who had explicitly committed to dismantling Labour's surveillance state in the GE manifestos should suddenly jump on board the whole scheme? I'm prepared to believe many things of the incompetents who run our country in to the ground, but that two political parties with the same policy would both jack it in at the same time?

 

Come on.

Posted (edited)

No, the whole point is to provide real time access without a warrent.

Similar to a bobby/spook turning up on your doorstep and demanding entry to view your book/cd/dvd collection without a warrent, just to see if there is any seditious material there.

 

Fine if you have nothing to hide since you dont have to answer the door, someone else gives them all the info. Bad if they decide that the political satire site you visited via stumbleupon means you end up on a no-fly list without any recourse/reason/suspicion.

 

On top of which, look at how wrong the RIAA got things taking little old ladies to court for downloading rap songs they had never heard of. You think the governement can do it with less errors and no oversight?

Edited by peterp
  • Thanks 1
Posted

May I suggest that we all include the word 'bomb' in all our emails, tweets and texts and Facebook posts. Should make life interesting for those doing the monitoring.....

 

''Hello Granny, I'll be bringing your shopping tomorrow. Bomb. Love, your Grandson xxxx''

Posted
May I suggest that we all include the word 'bomb' in all our emails, tweets and texts and Facebook posts. Should make life interesting for those doing the monitoring.....

 

''Hello Granny, I'll be bringing your shopping tomorrow. Bomb. Love, your Grandson xxxx''

 

Well hello to anybody at GCHQ who now might be picking this up! lol

Posted (edited)

Here is a FAQ written by folk who are in the (non-profit) business of knowing what they're talking about. Coz some folk don't click links, some choice excerpts:

 

What do we know? Very little. The Communication Capabilities Development Programme (CCDP) is going to be included in the Queen's Speech next month and we still haven't had public confirmation of the details. What we do know is that there have been secret briefings to MPs designed to scare them into compliance, and secret briefings to industry that were originally designed to calm their fears (but in fact have only served to increase their outrage).

 

Why is this happening now? In the days of the old internet, when we used email addresses provided by ISPs like BT, who tended to have servers in the UK, government authorities were able to grab information on who we were emailing and when with ease. Growth in interactivity and international services has meant that new 'third party providers' are enabling our email. Simply put, we now use Gmail and Hotmail to communicate with other people, not a BT address. Gmail and Hotmail are run by companies outside of the UK (Google and Microsoft respectively) and so don't have to automatically comply with UK government requests....

 

What about security? There are two security nightmares involved here. Firstly, the security of the black boxes at ISPs is suspect. Analagous capabilities have been abused before

the use of SSL generates significant problems for these black boxes - they know which service provider you are connecting to, but are unable to access your transactional information. This can be circumvented, but such a step on the government's part would be difficult, controversial and potentially illegal.[1]

 

Will this help prevent terrorism? No. In a terrorism investigation, the police will already have access to all the data they could want. This is about other investigations - it is about the millions of requests made every year by local law enforcement and other authorities in the investigation of serious - and less serious - crime.

 

What’s the big deal? Once the government is allowed to install these black boxes at ISPs, there’s basically no limit on future actions. Could this data be used to track file-sharing and monitor who is visiting specific websites? Absolutely. Could this system be used to restrict access to services? Absolutely. Once this line is crossed, the government will have enormous scope to monitor and control the internet.

 

[1] If they don't address the "significant problem" then these boxes clearly won't be able to fulfil their raison d'etre. Addressing the obvious means SSL MITM type stuff as implemented by Smoothwall and others. In order to get away with the latter they need a sub-CA from a widely recognised CA to spoof normal site certs so they can then grope around in the content to figure out who you put in a To field in a new mail web page etc. "Controversial" is an understatement: PKI has always had woes, but given whats gone on recently it's reputation is in tatters and given some of the subsequent militancy I suspect key browser makers might not find this acceptable i.e. could kick any CA that makes a sub-CA for the gov to do this out of the default set they ship with the browser. Another factor is that there are two parties in an SSL "conversation" - on the server-side some sites may resent UK state interception and refuse to talk to UK clients. See also: Projects like Sovereign Keys which is intended to help fix some of PKI's woes and would drop all MITM'd connections, then there's the rise of several browser add-ons for detecting certificate fiddling etc.

Edited by PiqueABoo

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...