2015-01-23

Call for Apple to "do the right thing"

The EU are joining the madness now [here] asking "region's leaders to force technology companies into sharing encryption keys with national authorities". So not quite saying "ban encryption", but still missing the point.

We are doing all of this to protect our freedoms.

If we have to give up those freedoms, our right to privacy, in the name of terrorism then the terrorists have won. Draw the line here.

A system that is secure by design will not allow anyone else to read messages.

Not the government, nor criminals. But change that, and make a back door, whether keeping copies of messages or handing over keys or whatever, and you create a system that is not secure and is a target for criminals and terrorists to collect personal information and exploit it.

Asking technology companies to hand over keys makes no sense.
  • There are companies in countries that respect privacy. They have no reason to comply. (see below re Apple).
  • There are systems designed such that the "technology company" does not have the keys to hand over, so could not comply. You would have to ban their systems.
  • There are open source messaging systems where there is no "technology company".
  • There are ways to send messages without "technology" even [video]
  • Criminals and terrorists have no reason to use any of the systems where keys have been handed over, even if illegal to, as it means just breaking one more law - but non terrorists will have to comply with such laws - we lose, terrorists win!

So, where does Apple come in here?

iMessage is secure. Apple don't have the keys. They could change iMessage so that it is not secure. That would be a massive backwards step for them and lose them reputation. Obviously anyone concerned over privacy (including terrorists) could use secure open source messaging apps on an android, so Apple doing this would lose them business worldwide.

But if Apple say no? Will the UK government really ban iPhones in the UK, and take them off visitors at customs? Would they go that far? And if they did - would they ever win an election again? I really think Apple is big enough to stand their ground and JUST SAY NO!

2015-01-22

No way to run the country!

I am no expert on this, and to be honest, I seriously think they need to teach this in school a lot more. It matters, and affects us all.

It seems there is a bill, the Counter Terrorism and Security bill. This goes through a process to make it a law.

Like many bills, this goes through a load of stages, in this case starting in the commons with our elected officials considering it and proposing amendments. Several "readings" and a "committee" stage and a "report" stage and further reading.

Then the bill goes through the Lords, again, several "readings" and a "committee" stage.

But at this eighth stage in the process, after our elected representatives have had their say, and it has been considered twice by the house of Lords, we have an amendment.

The problem is that this amendment actually contains 18 pages of stuff which is identical in almost all respects to another bill, the Communications Data Bill (aka The Snoopers' Charter). This is a bill that failed, quite conclusively for a lot of reasons. These were not just the cost to the taxpayer (£1.8 billion) which was probably a massive underestimate, but significant human rights issues. It is not even the first time this type of bill has failed.

This is an attempt to "paperclip" this old, dead, and wrong, bill to the one going through, at the last minute. If it goes through it will not have had any of the normal stages of review by the commons (by those that we have elected) and very few of the stages of the Lords. It is just like The Simpsons episode with something paper clipped to another bill.

The people doing this should be ashamed,  LORD KING OF BRIDGWATER, LORD BLAIR OF BOUGHTON, LORD WEST OF SPITHEAD, LORD CARLILE OF BERRIEW. It is shameful and you should apologise publicly for this.

I hope this is quashed, and please - tweet a lord/lady in the house of Lords or write to your MP on this now.

This is acting like Bart Simpson, paper clipping something to a bill at the last second to push it through, and you know it is wrong else you would not be so underhand with it. You should resign, and renounce your peerage and leave as a Lord, and leave now. This is deceit and underhand in so many ways and you are unfit to be making laws for us.

The Open Right Group have more info [here].

This is no way to run the country and it will not be tolerated by real people.

2015-01-21

Please buy numbers in conservation areas

There are areas in the UK which have fewer telephone numbers available, and are called conservation areas. One could renumber, like so many areas for so many decades (I recall when Peopleton exchange renumbered from three digit numbers). But no, OFCOM have a new tack, and that is to charge for numbers in conservation areas. Some are challenging the legality of this, and we hope they win. We are having to pay, under duress.

The problem is the scheme they have created is cack-handed to such an extent that it is now in our interests to sell more numbers in these areas.

The scheme is that....
  • There is a minimum size block we can get allocated, 1000 numbers
  • We have to pay for all numbers allocated even if we do not have customers
  • If we have a number that is ported out to someone else, we get a discount, and that is more than we pay for the number, and the company that it is ported to pays nothing.
It would not be so bad if we only paid for numbers that are live and for which we have paying customers. But no, we pay for all numbers we have allocated less discount for those ported out.

So, what do we do (in the best interests of our shareholders, as required by the Companies Act)?

I created a separate company (not part of the same group of companies) and set up a porting agreement, and a commercial contract for VoIP.

All customers, for over a year now, buying or having numbers in these areas agree on sign-up to port the number to the new provider. We then have a commercial arrangement with the new provider to deliver the calls for that number. This means for live numbers we save more than the cost of a dormant number in these areas. We have done this for the first year and proved it meets OFCOM rules and received the discount.

So now we have to try and encourage as many customers as possible to get numbers live in these areas so that they can be ported out and save us money.

This is a trial of 30 areas codes. If it goes nationwide we may have to shut down doing VoIP at all, as it would not be commercial viable for any small VoIP provider. Let's hope the trial fails and they stop charging, or the legal challenges work and they have to refund.

So, for now, we ask people to take numbers in these conservation areas, please. We can "reserve" numbers for 10p/month now, and that counts. We may actually do some commercial incentives, perhaps even free numbers or some silly low price to get people to take large blocks in these areas. That is the way for us to save the most money.

The big issue is that, until now, there was no reason for any telco to hand back a number block to OFCOM as there were free. Even going bust, another telco would take over the blocks. But now there is a cost for such blocks, so it may not happen. If blocks are handed back, even ported-out numbers will stop working and consumers will suffer when their numbers stop even through no fault of the company from which they buy the (ported) number. Clever idea OFCOM to expose the problems with porting by doing this.

Clever scheme OFCOM, well done making it in our commercial interests to sell more numbers in areas that are short of numbers. Excellent work there.

Long term - let's talk OFCOM - about DNS based number allocation. Make it work per number. Happy to discuss and solve these problems, as ever. Really long terms, "numbers" are so 20th Century and obsolete.

Update: Just to be clear here - two key issues even if you accept that charging for numbers is a way to reduce take up (a) only charge for the numbers that are in use, and this is no less admin than asking how many ported out, and (b) Surely only charge for new blocks from now, as existing telcos with any live numbers can't really give back blocks, so you are not impacting take up any more by charging for blocks already allocated or just new blocks.

Update: Current conservation area codes 01202  01206 01223 01224 01253 01273 01274 01276 01332 01382 01384 01452 01482 01483 01582 01603 01604 01642 01702 01752 01753 01772 01782 01792 01793 01865 01902 01908 01924 01925

Passwords

Pondering best practice here. We have some of this in place on some systems, but I wonder what people think of this. We may try to work towards this for all systems in due course.

Basically, when someone new comes along and "signs up" for something we create an account ID of some sort, and a password. Traditionally the normal practice was to email the password.

There is a simple alternative which is to allow people to pick a password at signup, but, whilst this can be "secure" via https, it causes problems in that it allows people to pick passwords - and people are basically stupid when it comes to picking passwords. People pick easy ones, and the same one multiple sites. So you end up with stupid and annoying passwords "rules" which piss everyone off.

So, the plan is this...

On creating an account, we run the "reset password" process. The account has no password (i.e. cannot log in) at this point, but we email a link to an https page which is one time use and short lived. If apathy rules, then the link times out and the account will have no valid password, needing a "password reset" requiring the email address and some key data such as postcode.

The link offers a password visible on screen (which we warn about with the link). Now, this is a password we have picked, ideally using a TRNG and along the lines XKCD 936, i.e one that is really easy to remember. We have a button to get a new password if the first is offensive (a tad hard to avoid with random words) or was overlooked, etc. And we have some subtle means to allow manual entry of the password which you have to find by doing some research or asking staff (made hard deliberately). Again, relying on apathy to mean people get good passwords. However, the manual password does allow anything.

All of that is via https to avoid snooping, and we immediately store a hash of the password so we do not have a record of it. Obviously we log that the change took place, and the IP address, and we log if it was the first choice offered, a re-picked one, or a manually set one. If ever there is hacking we can say "you must have set a weak password" if it was manual. I am tempted to log how long it was too but not sure if that is sensible. I may allow posting of an SHA256 hash or some such so we don't, at that point, know the password at all (though we would know when you later log in, if we want, so maybe pointless).

A couple of extra tricks would be for the user to be able to load a public key at signup or any time later, and so for the password reset emails to be PGP encrypted as well.

The process relies on the fact that apathy rules. People will have no password (if they don't care) or will have one we picked sensibly, as a default. No password ever actually sent by plain text.

Have I missed anything obvious here, or is this the way things should be done?

Update: Thanks for all the feedback. We are instigating a system wide password library which provides password generation of defined sizes and entropy for users (XKCD style where possible), password hash generation and password hash checking. The checking can, and does, upgrade the hash checked to a later hash function if an old one is being used on next correct login. This allows existing hashes to be upgraded, and allows any future policy change on chosen salted hashing function to be applied in one place. We are also reviewing how we advise customer of passwords when creating accounts and logins.

2015-01-20

Is over blocking legal?

One of the concerns with ISP filtering (e.g. porn, etc) is the risk of over blocking. One question is whether that is legal. For example, if an ISP's porn filtering setting blocked access to this blog, could I do anything about it, legally?

The best candidate I can see for this appears to be the the Computer Misuse Act 1990 (as modified to include DoS attacks).

Section 3 appears to be the relevant part. The first part (1) says that someone is guilty of an offence if they do any unauthorised act in relation to a computer, knowing it is unauthorised, and part (2) or (3) apply. (2)(b) is to prevent or hinder access to any program or data held in any computer. Part (3) covers being reckless as to such things.

It seems to me that a block on a web site is clearly within (2)(b) as the whole objective is to prevent or hinder access to data on a web site (i.e. held in a computer). So that is pretty clear.

The issue seems to me to hinge on whether the action was unauthorised or not. Clearly, the person setting up the filters had authorisation to do so on the "computers" that run the filters. But the action was in relation to a different computer - it is in relation to the web site in question as that is the computer to which access has been hindered.

Thankfully section 17 comes to the rescue, and says An act done in relation to a computer is unauthorised if the person doing the act (or causing it to be done) is not himself a person who has responsibility for the computer and is entitled to determine whether the act may be done; and does not have consent to the act from any such person.

Now, this means that the person doing the filtering to stop access to a web site would have to have responsibility for that web site. Clearly, someone in an ISP somewhere setting filters up does not have responsibility for the computers hosting the web sites to which those filters relate.

Someone with proper legal training - tell me where my loop hole is in reading this?

Otherwise it seems that not only is over blocking illegal (reckless) but the blocking in the first place, and even pirate bay blocks, are criminal under section 3 of the Computer Misuse Act 1990.

Thinking about it - this legislation is trying to catch a DoS attack, where someone does something to hinder access to, say, a web site, by flooding traffic or some such. It is hard to see how a filter on access is not logically just the same as a DoS attack really, and how you would word a law to allow one and not the other. Essentially, in DoS or filtering, the computer to which you are hindering access is not one for which you are responsible - so the same! I suppose a carefully worded exception specifically covering this sort of web filtering at the request of the end user could work - but even so, that would possibly leave over blocking as illegal.

2015-01-19

What's in a name?

FaceBook are being a pain - they want my "authentic name".

Many people think this is simple, but it turns out that a "name" is far from a simple matter.
  • Some countries have the concept of an "official name" - one name that you have officially that the state recognises, and anything else is a nickname or false name of some sort.
  • Some countries even have a list of approved first names, one of which you must use when naming your child!
  • Some countries allow a name to be just one word.
  • But in England it is not so simple.
In England your name is simply what you are known as. There is no "official name". Indeed, a large proportion of the population use a different name than they had at birth, largely due to the common practice of women (and some men) changing surname on marriage.

Changing your name in England is also surprisingly simple - you make a deed poll - a simple declaration saying you will use a new name now. It is not an "official" document, as there is not a government office that issues it - you issue it yourself. You don't register the deed poll anywhere either, you just tell everyone that has your name and use it as evidence of that name change. Sadly, you typically need something that looks official to convince a bank, etc, as they don't understand how it works. There is a really good web site that will make an official looking deed poll for you for free www.freedeedpoll.org.uk

You can, of course, find all of this with a bit of googling. If you are thinking of changing your name, do not get ripped off - it is not something you have to pay for (though some bodies such as passport office may charge to issue a new document in your new name).

There are some caveats, but the main one is that your name change must not be to commit fraud. It is not a way to hide from your creditors. Interestingly that web site says you have to have at least two names (i.e. first name and surname), which disagrees with some people.

One thing I have failed to find while googling is whether there is any legal reason not to have more than one name. Even a passport can have also known as names on the observations page. Indeed, the passport guidelines reference the possibility of a woman that uses her husband's name and her maiden name rather than using one name for all purposes which seems to suggest that the concept of someone that does use more than one name is legally valid. It seems to me that some people are known by one name in some circles and another name in other circles and both are equally "valid". If anyone has any references, do let me know.

My issue is that I am known as "Thrall Horde" to thousands of people on FaceBook, and have been for years. I don't hide that I am known as Adrian Kennard in other circles, and there is no fraud. But FaceBook are now insisting that is not an "authentic name". I am probably known as "Thrall Horde" by more people than known me as "Adrian Kennard" as FaceBook has quite some reach.

So, I am pondering what to do. I am reluctant to just give in and put Adrian Kennard - not really my nature is it :-) FaceBook say they can accept some non-government ID documents, such two different documents from a list. Many of the items on that list I can get with any name I like with no fraud involved - i.e. I can declare that I am using that name to my employer and have business cards issued in that name (and if I like I can then declare that I am using Adrian Kennard again).

If it is legal to have more than one name concurrently if not fraudulently, I am happy to make a declaration that I am known as Thrall Horde as well as Adrian Kennard, but I think the usual wording on a deed poll is that I stop using the old name. Would be nice to know if there is case law on this. I could certainly apply to have Thrall Horde on the observations page of my passport with no problem (i.e. as a stage name).

I could, perhaps, do a deed poll, get a new driving licence, and then send to FaceBook. And then just do another deed poll changing my name back, get a new driving licence, and not tell FaceBook. Maybe I'll try a company ID card and some mail or something first...

By the way, before anyone says I agreed to these terms so why am I whinging - I did not actually make the FaceBook account. Someone else did, and gave me the login details. I never read or agreed FaceBook's terms anyway. Not that it is likely to make much difference. Indeed, the "real name" thing is something I only recently heard of when the same happened to a friend of mine.

I could just ditch FaceBook I guess, though I have spent nearly £2000 on advertising with them over the years, so I think it is their loss if I do.

But I wonder, can I legally have two different names?

Update: I may give in for now - I have to put a name in so I can cancel the paid promotion of my privacy post - not going to spend any more with FaceBook after this fiasco.

P.S. This is what a deed poll looks like

2015-01-15

z226etuo57q9m6brbblz6ztkpea5ct23rmex0vlv3ik*0m3rw

Please do watch the video [here]. Tweet #dontbanprivacy. I may have nothing to hide but I still expect to be allowed a private conversation.

Theresa May has said that there must not be a safe place for terrorists to communicate. David Cameron has gone further and said that we cannot allow any means of communications which cannot be read, [telegraph article] and so presumably means that the 64 million of us in the UK that are not in fact terrorists are not allowed to communicate privately either. Sadly Obama has joined in [here].

I was horrified, really, that our servants, the government, are really saying that we cannot talk privately any more. That is just police state gone mad.

I was also horrified at the heckling and stupid answer that Julian Huppert got when he asked Theresa May about this. It shows that the people in government, who run this country, really have no clue what these statements actually mean.

Obviously, the people I deal with immediately think of how stupid this is in light of the technology we use every day. We understand the usage of encryption (keeping secrets) done by computer systems in our daily lives. Each and every one of us use secret communications that the security services cannot see when we access FaceBook, or Google, or even The Conservative Party Website! We are doing exactly what David Cameron has stated, in no uncertain terms, must not be allowed for any of us (not just terrorists) to do. We also know that any attempts to achieve what they are saying, no matter how stupid, would not actually stop criminals and terrorists. It is like passing a law that says "If you are a terrorist, you must send a copy of all your plans and communications to secretsquirrel@gov.uk". It is stupid. It is us, the ones that are not terrorists, that stand to be impacted by this stupidity. Terrorists won't care.

But I want to try and take technology out of this debate and explain just how stupid this is in terms that anyone can understand. I have made a video [here], and I explain below, a means of communications that anyone (including terrorists) can easily use; a method of communication that cannot be read; something that is absolutely what Theresa May and David Cameron say must not be allowed. I am not being extremest here - every one of you does far more complex stuff every time you visit FaceBook, remember that!

The system is called a one time pad, and it is uncrackable. This may look like child's play, but I can assure you that if the NSA or GCHQ intercepted your communications using this then they could not crack it as long as you have done what I say and made sure the keys are secret and safe. I'd be surprised if this is not millennia old, but the concept was first published in 1882 relating to secure telegraph.

This is not difficult - and it is fun for all the family - why not try it with your kids? If could teach them important tools they may need if this government have their way.

Let's take is step by step...
  1. Before you start you need keys. In my video I have made each key a separate sheet of paper and printed with blank boxes by each character. In the spirit of SMS I have made the keys 160 characters long. You will need a set of keys for future messages, with each key twice, one kept by the sender and one by the recipient. I made the keys using a computer program, and you could get from a web site [here] but that means the web site operator may have your key, so not safe (unless you are just doing this for a bit of fun). Running the software yourself is better, but you can just use a pair of dice! You do not need a computer. A couple of dice and some squared paper and a pencil, that is all.
  2. You need to make sure the sender has a set of keys and the recipient has the same set of keys, and that nobody else has seen the keys or has a copy or has access. Each of you should keep them safe, perhaps in an actual safe even. This does mean meeting up face to face at some point, but this can set up secure communications for the future. You may want to agree a way to tell each other that your keys have been accessed, some suitable message like "my keys have been seen by someone else" in a text! NEVER LET ANYONE ELSE SEE THE KEYS!
  3. When you want to send some critical message, such as the date and time of an attack you are planning (don't attack people, that is not legal), you pick one of the key sheets. You can pick it at random, as it happens, and I'll explain how the recipient knows which you used.
  4. You write your message over the key letters on the sheet, but start with say 4 spaces. (We didn't do this on the video) Make sure you don't have other paper below as it could leave an impression when you write (a mistake we make on the video)
  5. For each letter in your message you also have a key letter. Using a simple addition table or wheel you add the two letters together. You look up the message letter on one side, and the key letter on the other, and find where the lines cross to get the output (coded) letter and write that down.
  6. For this purpose I have created a sheet with an alphabet of 36 characters in total, being A-Z, 1-9 and a space. To avoid misreading multiple spaces we are treating a space as a * in the final message sent, and to avoid confusion as well as making it a nice number to use with two dice, we have made O and 0 the same. A simple addition sheet can be found here. You could make different decisions on the alphabet to use and so on.
  7. For convenience, in my addition sheet, the space (or *) is added as a zero value, and so does not change the other letter (unlike the video). That means any spaces in your message you just write the key letter down unchanged - this saves time, but it also means your final message starts with 4 key letters as per the sheet. You should also have spaces on the end, so also writing the key letters again, either a random extra number of spaces, or perhaps all the way to the end of the 160 characters every time. This hides the length of your true message.
  8. You send the code letters to the recipient. This could be by text, but remember, this coded message is not secret - so you could just tweet it, or write it on a post-it note, or graffiti it on the side of a building (don't do that, it is not legal either). As long as the recipient knows where to look for the message that is fine.
  9. The sender now destroys the sheet, destroying your message and the key. NEVER EVER USE THE SAME KEY SHEET TWICE.
  10. The recipient can use the first 4 letters to work out which key sheet applies as they were coded as spaces. When making the key sheets you may want to avoid duplicates in the first 4 letters.
  11. The recipient writes the coded message on the sheet, and then works through the characters. This time, you find the key letter row, and follow it along to the coded letter, then go up/down to the letter at the end of the column and that will be the original message letter. Write that down on the sheet. You will see spaces easily as they have the coded letter the same as the key letter and so the padding spaces at the end are simple to spot and ignore.
  12. At the end you will see the original message on the sheet. Read it and understand it.
  13. The the recipient destroys the sheet, destroying the message and the key.
If, later, the police or security services, having seen this coded message, come to you and demand the key you used to decode the message (as allowed by law), you can honestly tell them that it was destroyed, and so not handing over the key would not be illegal. We think you have no legal obligation to hand over the keys that are not yet used and you can keep them in the safe, but if you do have to, just tweet that your keys are taken so no more message are sent or you indicate in some more subtle way if ordered not to, or if you are a terrorist and don't care about following the law!

The one time pad does have some issues. The main benefit is the simplicity and total security it offers, but the down sides are that you have to pre-exchange some keys, you have to be sure the keys really are random, and you have to be sure to keep the keys totally safe. If you can do that, then you have a means to safely communicate privately (even if you are not a terrorist).

Now, computers can do a lot more, and have ways to avoid the sharing of keys like this, but authenticity of sender and recipient are always issues in any system. Using computers it is even possible to actually hide the fact that the message is coded in some way, so you are not looking suspicious by sending gibberish texts. However, I hope this shows how simple it is to do what David Cameron and Theresa May actually want to ban, and how pointless any such ban would be. The damaging effects of any sort of measures they take could be massive though, and that is why we have to stop this proposal at the start and make them understand that:-
  • we have a right to communicate privately,
  • we have the technology (pen and paper) to communicate privately, and
  • we will communicate privately (and so might terrorists).
Please do watch the video [here]. And share our A&A FaceBook post and tweet under #dontbanprivacy. I want this to get back to David Cameron and Theresa May and everyone else that heckled Julian in parliament. He seems the only one with clue and I'd even move to his constituency if I could.

Dodecahedron

I was shown a dodecahedron with LEDs inside. Looked great, so decided to have a go. The principle is not that hard - a PCB strip on the insi...