Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

FIPR Release : EMERGENCY POWERS ALLOW MASS-SURVEILLANCE FOR NON-TERRORIST INVESTIGATIONS

0 views
Skip to first unread message

Kronecker

unread,
Oct 16, 2001, 10:22:19 PM10/16/01
to
FIPR Press release: FOR IMMEDIATE USE : 16th October 2001, London

EMERGENCY POWERS ALLOW MASS-SURVEILLANCE FOR NON-TERRORIST INVESTIGATIONS
========================================================================

*) Home Office undecided whether ISP data retention to be voluntary or
compulsory

*) Data revealing who you talk to, what you read, where you are, collected
for "national security"

*) Data can be trawled for public order, minor crimes, tax, health and
safety

*) E-Commerce to bear open-ended storage and data-protection compliance
costs

========================================================================


As part of an emergency package of anti-terrorism measures, Home Secretary
David Blunkett announced yesterday (Note 3) that Internet Service Providers
would be "enabled" to retain logs detailing the online activity of their
customers (but NOT the contents of communications).

Data protection legislation (Note 4) currently protects electronic privacy
by prohibiting blanket storage by ISPs of logs recording such details as
websites browsed, To and From addresses of e-mails, and which 'newsgroup'
articles are read by a subscriber. Other "communications data", such as the
telephone number used to dial-up the Internet, may be kept so long as it is
relevant to billing or fraud control.

Although Mr.Blunkett's use of the word "enable" (rather than "require")
implied that compliance will be at the ISP's discretion, the lead official
told FIPR that retention may be made compulsory, enforced through civil law.
The same source said a ministerial certificate will assert "national
security" exemptions (Note 5) so that ISPs and telephone companies will not
be in breach of European Directives. The government will only specify later
exactly what data may be collected and for how long in a Code of Practice in
consultation with ISPs.

No new legislation is necessary for police and intelligence agencies to
collect the data once it is recorded by ISPs and telephone companies.
The Regulation of Investigatory Powers (RIP) Act 2000 (Note 6) allows
records to be obtained for broad purposes including tax, health and safety,
public order offences and minor crime. Although "communications data"
provides a complete map of private life, revealing who you talk to, what you
read, and where you go, the authorities can rubber-stamp compilation and
trawling of large and detailed databases. In contrast, inspection of the
contents of a single e-mail requires a warrant from a Secretary of State,
and a search for documents requires a court order.

Bulk requests can be made on groups or the history of an individual and kept
by police and intelligence agencies indefinitely under data protection
exemptions. This includes the exact co-ordinates of your geographic
location - which 3rd-generation mobiles produce continuously whilst the
phone is switched on.

Computerised 'traffic analysis' (tracing links between individuals) is a
powerful new form of mass-surveillance, but is only efficient at keeping
tabs on the law-abiding. Professional terrorists know how to cover their
tracks - for example throw-away use of pre-paid mobile phones. Reports of
the modus operandi of the September 11th terrorists indicate they used
Web-based e-mail from public terminals. Clearly it is not persuasive to
argue for privacy to be sacrificed in the name of fighting terrorism if the
measures would not in fact be effective.

A leaked report from the National Criminal Intelligence Service last year
revealed that police and security agencies are nevertheless pressing for a
mandatory data retention law to warehouse the traffic data of the entire
population for several years (http://cryptome.org/ncis-carnivore.htm).
Blunkett's proposals amount to blanket 'dataveillance' for non-terrorist
investigations, using the the tragic events of Sep 11 as justification.

Providers of e-commerce authentication services could be affected as well as
ISPs and telcos. Anyone offering "provision of access to, and of facilities
for making use of...the transmission of communications" [RIP S.22(4) & S.1
defs] could face extra costs of providing suitable storage devices and
media, and full compliance with data protection legislation.

Quotes
======

Caspar Bowden, director of Internet think-tank FIPR (Foundation for
Information Policy Research) commented:

"Sensitive data revealing what you read, where you are, and who you talk to
online could be collected in the name of national security. But Mr.Blunkett
intends to allow access to this data for purposes nothing to do with
fighting terrorism. Minor crimes, public order and tax offences, attendance
at demonstrations, even 'health and safety' will be legitimate reasons to
siphon sensitive details of private life into government databases to be
retained indefinitely. This would be in flagrant breach of the first and
second Data Protection Principles." (Note 7)

Contact for enquiries:

Caspar Bowden
Foundation for Information Policy Research
www.fipr.org
c...@fipr.org
+44(0)20 7354 2333


Notes for editors
-----------------

1. The Foundation for Information Policy Research (www.fipr.org), is a
non-profit think-tank for Internet policy, governed by an independent Board
of Trustees with an Advisory Council of experts.

2. FIPR's analysis of the RIP Act (www.fipr.org/rip) stimulated media
debate, and led to amendments ensuring that people who lose decryption keys
or forget passwords are presumed innocent until proven guilty, and
prohibiting detailed surveillance of web browsing without a full warrant.

3. Home Office Press Release 15/10/2001: "BLUNKETT OUTLINES FURTHER
ANTI-TERRORIST MEASURES"
(http://wood.ccta.gov.uk/homeoffice/hopress.nsf/50e2456405b67f7d802566b30068
19dc/2a5fc6811dec4c7180256ae6004fa4d3?OpenDocument)

4. The Telecommunications Data Protection Directive 1996, implemented in UK
law as SI 2093 (1999). The Office of the Information Commissioner (contact
Iain Bourne) has stated that ISP blanket (i.e. for all subscribers) logging
and retention of online Internet activity is prohibited. Logging of
telephone numbers is permitted whilst relevant for billing or fraud control.

5. Section 32. of SI 2093 allows a certificate signed by a Minister of the
Crown to over-ride for National Security purposes the prohibition on blanket
data retention (http://www.hmso.gov.uk/si/si1999/19992093.htm)

6. Regulation of Investigatory Powers Act 2000, Part.1 Chapter.2, Section 22
(http://www.hmso.gov.uk/acts/acts2000/00023--c.htm#22). This Part is not yet
in force and the relevant Code of Practice is open for consultation until
November 2nd (http://www.homeoffice.gov.uk/ripa/consultintro.htm)

7. Data Protection Act 1998, Schedule 1,
(http://www.hmso.gov.uk/acts/acts1998/80029--l.htm#sch1)

Bob

unread,
Oct 19, 2001, 11:40:54 PM10/19/01
to
On Wed, 17 Oct 2001 03:22:19 +0100, "Kronecker" <anal...@shock.com>
wrote:

>FIPR Press release: FOR IMMEDIATE USE : 16th October 2001, London
>
>EMERGENCY POWERS ALLOW MASS-SURVEILLANCE FOR NON-TERRORIST INVESTIGATIONS
>========================================================================

-- big snip --

Whilst this is undoubtedly A Very Bad Thing, I would imagine you can
at least protect your privacy to a large extent by simple means of
proxies and shell accounts in other countries. Sure the ISP can log
what groups you read off it's newsserver easily enough, but other
peoples? Will they log every packet to see that you've bounced a
telnet session through a proxy to a remote shell account, and did tin
-qr alt.ph.uk? How about if you ssh'd in? I don't think so. And of
course you could make it much more convoluted than that quite
easilly, e.g. with triangle boy.

The only problem being that the shell account will most likely be in
the US, which will soon have equally bad laws (USA act.)

Bob

Dave J

unread,
Oct 19, 2001, 7:42:17 PM10/19/01
to
robert....@BUTIDONTLIKESPAMukgateway.net (Bob) wrote :

> Will they log every packet to see that you've bounced a
> telnet session through a proxy to a remote shell account, and did tin
> -qr alt.ph.uk? How about if you ssh'd in? I don't think so. And of
> course you could make it much more convoluted than that quite
> easilly, e.g. with triangle boy.

I don't know enough about the mechanics to comment but I wonder how
difficult it would be to set up a vpn style linkup to a proxy in a
safe place, proxy set up to allow any sort of communication on any
port, with a dns at it's end?

There would then be no unencrypted traffic and no IP's for their
'known associates' style map. - I once had it explained to me that the
known associates database is the most important element of
surveillance and I think I agree, you don't need huge storage and it
provides very easily accesible/correlatable data.

So, how difficult and how come no one's done it yet?

The cross post list here is huge, uk.legal and uk.politics.misc
snipped from followups, please feel free to replace if you wish to
comment on the legality or otherwise of this method.

I'm reading in uk.net.reg

--
Dave Johnson :- req...@freeuk.com

Percy Picacity

unread,
Oct 20, 2001, 5:33:04 PM10/20/01
to
Dave J <req...@freeuk.com> wrote in
news:aod1ttc6a99uhpr4g...@4ax.com:

> robert....@BUTIDONTLIKESPAMukgateway.net (Bob) wrote :
>
>> Will they log every packet to see that you've bounced a
>> telnet session through a proxy to a remote shell account, and did tin
>> -qr alt.ph.uk? How about if you ssh'd in? I don't think so. And of
>> course you could make it much more convoluted than that quite easilly,
>> e.g. with triangle boy.
>
> I don't know enough about the mechanics to comment but I wonder how
> difficult it would be to set up a vpn style linkup to a proxy in a
> safe place, proxy set up to allow any sort of communication on any
> port, with a dns at it's end?
>

The difficulty would seem to be to find a 'safe place', now privacy has
been abolished in the USA. No place has ever been safe if you are of
positive interest to the security services. In the past, I don't think
evidence obtained by illegal surveillance could be used in a US court.
However, now the USA seems to have brought in UK-style legislation,
directed against 'terrorism'. Even more unfortunately, stealing dvd
movies, software and audio CDs seems to be regarded as a major form of
terrorism by the people running the USA. Other countries which have privacy
laws may well have little resistance to corruption. If anyone knows of a
'safe place' for such a proxy I should be interested to see the suggestion
subjected to peer review.

--
Percy Picacity

Wm...

unread,
Oct 20, 2001, 8:49:54 PM10/20/01
to
Sat, 20 Oct 2001 21:33:04 <Xns9140E5673A3...@207.14.113.10>
Percy Picacity <k...@under.the.invalid> wrote...

>The difficulty would seem to be to find a 'safe place', now privacy has
>been abolished in the USA. No place has ever been safe if you are of
>positive interest to the security services. In the past, I don't think
>evidence obtained by illegal surveillance could be used in a US court.
>However, now the USA seems to have brought in UK-style legislation,
>directed against 'terrorism'. Even more unfortunately, stealing dvd
>movies, software and audio CDs seems to be regarded as a major form of
>terrorism by the people running the USA. Other countries which have privacy
>laws may well have little resistance to corruption. If anyone knows of a
>'safe place' for such a proxy I should be interested to see the suggestion
>subjected to peer review.

Errm, isn't the issue whether or not FIPR issued the purported press
release?

--
Wm...
address valid for at least 31 days from date of posting

11 September 2001, 07 October 2001 - ?

Percy Picacity

unread,
Oct 21, 2001, 6:25:28 AM10/21/01
to
"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
news:6pbh3OFy...@tarrcity.demon.co.uk:


> Errm, isn't the issue whether or not FIPR issued the purported press
> release?
>

That's one issue, there are others.


--
Percy Picacity

Wm...

unread,
Oct 21, 2001, 9:15:24 AM10/21/01
to
Sun, 21 Oct 2001 10:25:28 <Xns91417436C3...@207.14.113.10>
Percy Picacity <k...@under.the.invalid> wrote...

I know what you mean.

I'd like to raise another issue: one of my neighbours doesn't do their
bit when it comes to putting the bins back in place after they've been
emptied.

Percy Picacity

unread,
Oct 21, 2001, 10:59:21 AM10/21/01
to
"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
news:1EsyMvFs...@tarrcity.demon.co.uk:

> Sun, 21 Oct 2001 10:25:28 <Xns91417436C3...@207.14.113.10>
> Percy Picacity <k...@under.the.invalid> wrote...
>
>>"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
>>news:6pbh3OFy...@tarrcity.demon.co.uk:
>>
>>
>>> Errm, isn't the issue whether or not FIPR issued the purported press
>>> release?
>>>
>>
>>That's one issue, there are others.
>
> I know what you mean.
>
> I'd like to raise another issue: one of my neighbours doesn't do their
> bit when it comes to putting the bins back in place after they've been
> emptied.
>

Someone wondered whether it would be easy to make an Internet connection
which could not be eavesdropped on successfully by this country's
authorities. I doubt if it would be easy. This seems a perfectly sensible
issue to discuss, even if you do not believe that the collection of
information is as extensive as the posted anouncement suggested. Why be so
silly? (On second thoughts, please regard this question as rhetorical.)

--
Percy Picacity

Sam Simpson

unread,
Oct 21, 2001, 11:09:23 AM10/21/01
to
Hi Dave,

Anonymiser.com already offer this service for HTTP, NNTP and POP/SMTP
mail services. It's a little primitive (they use SSH w/port forwarding
rather than IPSec) but works very well. Effectively this means your
traffic can't be snooped by your TelCo, your ISP or anywhere else "local".

Of course, the problem is that Anonymiser.com is based in the US and
will soon likely be covered by some very strong "anti-terrorism" laws.


Regards,

Sam

--
Regards,

Sam Simpson
s...@samsimpson.com
http://www.samsimpson.com/
http://www.scramdisk.clara.net/

Dave J

unread,
Oct 21, 2001, 12:11:50 PM10/21/01
to
Percy Picacity <k...@under.the.invalid> wrote :

> However, now the USA seems to have brought in UK-style legislation,
> directed against 'terrorism'. Even more unfortunately, stealing dvd
> movies, software and audio CDs seems to be regarded as a major form of
> terrorism by the people running the USA. Other countries which have privacy
> laws may well have little resistance to corruption. If anyone knows of a
> 'safe place' for such a proxy I should be interested to see the suggestion
> subjected to peer review.

I think that to set up a publically accesible system to provide
absolute anonynimity is an impossibility. [1] That is not my 'intent',
what I want to do is render the RIP act a waste of paper. If anyone
who wants to can use an encrypted public proxy then many who have
absolutely nothing to hide but resent the loss of privacy will use it.
Impossible to detect anything at all with that amount of background
noise.

Provided it is illegal inside the country to into tap the data, they
are back where they started, they can still find stuff out but they
have to break laws to do it. Not much protection I know but it puts
them back where they started. It all then rests on the security of the
proxy machine. This could only be acheived by an open source design,
in this sort of game no individual is trustworthy.

[1] actually, on thinking about that, with sufficient throughput and
small random delays between reception and transmission of any packet I
think it could be set up to be unmonitorable from outside the proxy
machine. [Anyone?]

Eric Lee Green

unread,
Oct 21, 2001, 8:35:51 PM10/21/01
to
On 21 Oct 2001 14:59:21 GMT, Percy Picacity <k...@under.the.invalid> wrote:
>"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
>Someone wondered whether it would be easy to make an Internet connection
>which could not be eavesdropped on successfully by this country's
>authorities. I doubt if it would be easy. This seems a perfectly sensible
>issue to discuss, even if you do not believe that the collection of
>information is as extensive as the posted anouncement suggested. Why be so
>silly? (On second thoughts, please regard this question as rhetorical.)

http://freenet.sourceforge.net

You're welcome.

Eric Lee Green er...@badtux.org http://www.badtux.org
GnuPG public key at http://badtux.org/eric/eric.gpg
*** You do not preserve freedom by destroying freedom ***

Bob

unread,
Oct 22, 2001, 6:57:35 AM10/22/01
to
ac...@207.14.113.10> <1EsyMvFs...@tarrcity.demon.co.uk> <Xns9141A2A6A58...@207.14.113.10> <slrn9t6oo...@ehome.inhouse>
Distribution:

Eric Lee Green (er...@badtux.org) wrote:

: http://freenet.sourceforge.net

: You're welcome.

Freenet is a very good concept, but last time I checked it was still
pretty much unusable because it lacked any sort of "DNS" system to map
documents to keys, i.e. you had to know the key you were looking for,
you couldn't just search for a filename. When that's fixed, I'll give
it another go.

Bob

Percy Picacity

unread,
Oct 22, 2001, 7:43:55 AM10/22/01
to
er...@badtux.org (Eric Lee Green) wrote in
news:slrn9t6oo...@ehome.inhouse:

> On 21 Oct 2001 14:59:21 GMT, Percy Picacity <k...@under.the.invalid>
> wrote:
>>"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
>>Someone wondered whether it would be easy to make an Internet
>>connection which could not be eavesdropped on successfully by this
>>country's authorities. I doubt if it would be easy. This seems a
>>perfectly sensible issue to discuss, even if you do not believe that
>>the collection of information is as extensive as the posted anouncement
>>suggested. Why be so silly? (On second thoughts, please regard this
>>question as rhetorical.)
>
> http://freenet.sourceforge.net
>
> You're welcome.
>

I suppose this could perform the functions of email (if there is another
route for telling the recipient the name of the message) or news (given a
public 'identity' for such messages). Is this envisaged, or is it still at
an early stage? Is it designed for handling lots of small files rapidly?
Can you trace who placed a message by looking at traffic or asking for a
message and seeing who supplies it, or does this only apply when there is
not much traffic?

--
Percy Picacity

Eric Lee Green

unread,
Oct 22, 2001, 11:16:49 AM10/22/01
to
On Mon, 22 Oct 2001 10:57:35 GMT, Bob <kwy...@h14me.yi.org> wrote:
>: On 21 Oct 2001 14:59:21 GMT, Percy Picacity <k...@under.the.invalid> wrote:
>: >"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
>: >Someone wondered whether it would be easy to make an Internet connection
>: >which could not be eavesdropped on successfully by this country's
>: >authorities. I doubt if it would be easy. This seems a perfectly sensible
>: >issue to discuss, even if you do not believe that the collection of
>: >information is as extensive as the posted anouncement suggested. Why be so
>: >silly? (On second thoughts, please regard this question as rhetorical.)
>
>: http://freenet.sourceforge.net
>
>: You're welcome.
>
>Freenet is a very good concept, but last time I checked it was still
>pretty much unusable because it lacked any sort of "DNS" system to map
>documents to keys, i.e. you had to know the key you were looking for,
>you couldn't just search for a filename. When that's fixed, I'll give
>it another go.

There now exist several Freenet "links engines", to which you can submit
a link either by injecting a file of a specific sort into Freenet or by
using their web page (for less controversial files where you aren't worried
about who knows who posted it). Alas, these do present single points of
failure, since their existence must, of necessity, be public in order to
do their job. The next step is to distribute the links engines.

Research is ongoing in how to use Freenet as a remailer substitute. I do not
claim any current knowledge in what success has been encountered in the
Freenet 0.4 development (last version of Freenet that I tried was the latest
Freenet 0.3 version).

Freenet is still a ways away from being usable by mere mortals, but is
getting closer. The web interface was a good start, as was the links
engine. Some kind of EMAIL system is the next step. Once that happens,
Freenet becomes much more useful (EMAIL is the "killer app" of the
Internet, and there's no reason to believe this will be less true of
Freenet).

Eric Lee Green

unread,
Oct 22, 2001, 11:25:07 AM10/22/01
to
On 22 Oct 2001 11:43:55 GMT, Percy Picacity <k...@under.the.invalid> wrote:
>er...@badtux.org (Eric Lee Green) wrote in
>news:slrn9t6oo...@ehome.inhouse:
>
>> On 21 Oct 2001 14:59:21 GMT, Percy Picacity <k...@under.the.invalid>
>> wrote:
>>>"Wm..." <tcn...@tarrcity.demon.co.uk> wrote in
>>>Someone wondered whether it would be easy to make an Internet
>>>connection which could not be eavesdropped on successfully by this
>>>country's authorities. I doubt if it would be easy. This seems a
>>
>> http://freenet.sourceforge.net

>
>I suppose this could perform the functions of email (if there is another
>route for telling the recipient the name of the message) or news (given a
>public 'identity' for such messages). Is this envisaged, or is it still at
>an early stage?

There are in fact news publications already on the Freenet. The
Freenet guys have basically figured out how to use Freenet as a web
server. EMAIL is still under development, and will probably require
index servers of some sort to allow for looking up ID's to inject
EMAIL with, as well as a better front end, much like the web server stuff
requires index servers to be useful.

> Is it designed for handling lots of small files rapidly?

Well, as rapidly as Java does anything :-}.

>Can you trace who placed a message by looking at traffic or asking for a
>message and seeing who supplies it, or does this only apply when there is
>not much traffic?

You can tell from whom a message was requested, but that does not mean
that the message was injected there. Modus operandi for anonymous
EMAIL would be to inject, then bounce it around the Freenet by
requesting it from various servers. When the eventual recipient
receives the EMAIL, he will get it from one of the "bounce" systems at
some time in the future. Unfortunately, it's unclear that Freenet
traffic is currently large enough to defeat traffic analysis.

Note that I am by no means an expert on Freenet. Because of the transition
from Freenet 0.3 to Freenet 0.4 I'm nowhere near up-to-date. Going to the
above URL is the best bet for figuring out Freenet's current state.

Hugh Watkins

unread,
Oct 26, 2001, 10:08:07 PM10/26/01
to

"Kronecker" <anal...@shock.com> wrote in message news:FX5z7.43894$uM2.7...@monolith.news.easynet.net...

> FIPR Press release: FOR IMMEDIATE USE : 16th October 2001, London
>
> EMERGENCY POWERS ALLOW MASS-SURVEILLANCE FOR NON-TERRORIST INVESTIGATIONS

seems to be fiction or badly organised "open government"

Your search - site:www.fipr.org "EMERGENCY POWERS" - did not match any documents.


Your search - site:www.fipr.org "october 2001" - did not match any documents.

Searched Groups for author:Kronecker Results 1 - 9 of about 15. Search took 0.24 seconds


a one off with that moniker
rest tw. or hk.

Hugh W

Your search - "EMERGENCY POWERS" MASS-SURVEILLANCE "october 2001" - did not match any documents.
Searched the web for "EMERGENCY POWERS" "home office" "october 2001". Results 1 - 6 of 6. Search took 0.33 seconds.


surely the Guardian or what ever would have picked it up ??


0 new messages