Antibiotics are great - they kill almost all bacteria, and this means that they have saved a lot of lives that would have been lost to serious illnesses.
However, as most people know, not all bacteria are killed off. Some strains are resistant to the antibiotics. This is because of random mutations, but the resistant strains did not originally have any sort of competitive advantage in their environment so there were not many of them.
The problem is that when you use antibiotics a lot you find that all you are left with is resistant strains. These now have a competitive advantage in their new antibiotic rich environment.
In many ways anti-terror laws are the same - there will be people in society that want to commit some serious crime or terrorist act - they are the bacteria of our society.
Now, suppose you make laws that make it easy to track communications and spot terrorist plots. There will be some terrorists that are not so dumb as to just make normal mobile phone calls to their conspirators to plot something. A few will be smarter. The new laws will, of course, catch the dumb ones, and everyone will get a pat on the back for thwarting another terrorist plot, but that leaves you with the smart ones.
There have been examples of this. I have read that those plotting 11th Sep bombings put messages in draft on a dummy mail account, and someone else logs in, reads and deletes the draft. When I heard this I was impressed at how simple and clever it was - because draft messages are not the sort of thing that we monitored - only actually sent messages. Oddly the new Counter Terrorism bill going through now does not address that flaw even 13 years later - why? But what it does show is that there will be some that are smart enough to bypass the anti-terror laws.
Unfortunately, just like antibiotic resistant bacteria, it only takes one new strain to cause an epidemic.
This means that apart from all of the other collateral damage caused by anti-terror laws, and the progressive stripping away of freedoms from law abiding citizens, you also breed a new generation of smarter terrorists that are even harder to track down - and as I say - it only takes one.
Ultimately we have to be a lot more cautious and targeted with our anti-terror laws and surveillance powers or we risk making it really impossible to track what anyone does even when that is fair and proportionate.
2015-01-28
2015-01-27
SnoopersCharter is already out of date
Watching the debate yesterday did raise a few interesting points. One is that it is taking a long time to get in to place something to fill a supposed "gap" in logging of communications data (hence the proposed amendment to re-introduce the Data Communications Bill). Another is that a key problem with the snoopers charter is that it tries to be far too broad in order to allow for new technology without having to keep making new laws. This means far too much ends up in scope.
However, being in technology, I (and many others) can see that even with such wide scope it is already out of date!
It relies on some basic concepts which are changing, and have changed in some cases :-
That there is a communications provider, and one that is in the UK
The bill takes steps to impose conditions on communications providers. It would be impractical to try and impose these on every end user, and would also defeat the point if those end users are the very people you are trying to monitor.
The problem is that there are increasingly not a communications provider at all. In most cases there is, at a low level (copper wires, radio waves) a provider, but they are not providing the communications that you want to monitor. It is a bit like modems - the only communications data for any Internet access back then would be that you called your ISP for X minutes. Well, the Internet is the medium by which we communicate now, and you can use layers and layers. A communication (a message) may be sent as part of the content of something done on a web site, so all you log is that someone accessed the web site, and not that using that web site they sent a message to someone else. In that case the web site operator is a communications provider of a sort, but may not be in the UK. Things like TOR complicate the matter even more - its is a "network" with no providers.
But there are things where there is no communications provider even at the low level - mesh networks. With so many people owning wifi equipment it becomes possible to create networks that work via your neighbours wifi and create a whole Internet with no actual "provider" involved.
So making laws that impact communications providers only really works whilst they exist at the level you wish to monitor.
That there is a sender and a recipient
This is a pretty fundamental assumption in the legislation, and already is not always the case. A tweet is public, and whilst people may follow some people, they can just see tweets anyway and search for them anyway. If I post a tweet, who is the recipient? Do we try to work out who it was aimed at in some way, or just say it was sent to 1000 people (my followers). What if it is then retweeted to a million people - who sent the "message" and who was it to?
That the communication is a message
Again, this is ingrained in the legislation - but a communication could perhaps be clicking "like" on a FaceBook post. Again, who is that communicating to, and what is the message?
That you can separate envelope from content
This is also fundamental as the government quite rightly feel that snooping on everyone's content (opening everyone's letters) would not be acceptable.
The problem is that it is no longer easy or even possible to tell the content from the addressing information. What is the "content" of clicking "like"? What if I tweet and include the string @xkcd in that "message"? Is that "content", being within my tweet, or is it the address, being that it would be shown to Randall if he ever logged in to twitter.
There is legislation saying, for example, that no part of the content of an email shall be logged, but they want logging of the addressing. So if I included in the content of the email my email address does that then stop that address being logged, as it is also a part of the content?
Even talking of "weblogs" they are specifically talking of URL up to first slash (which is entertaining as that is "http:/") but they basically mean logging the hostname part. That is fine until you realise that lots of web sites are in fact Facebook.com/somecompany, or someproxy.com/realwebsite, so you are not in fact logging the "site" being visited. Future changes to https may ensure that even the hostname cannot be logged.
So, I suggest that even now, the snooper's charter is already out of date for its stated purpose (as well as being technically impossible and immoral)
Update: The four horsemen (I mean Lords) are trying again http://www.bbc.co.uk/news/uk-politics-31062757
However, being in technology, I (and many others) can see that even with such wide scope it is already out of date!
It relies on some basic concepts which are changing, and have changed in some cases :-
That there is a communications provider, and one that is in the UK
The bill takes steps to impose conditions on communications providers. It would be impractical to try and impose these on every end user, and would also defeat the point if those end users are the very people you are trying to monitor.
The problem is that there are increasingly not a communications provider at all. In most cases there is, at a low level (copper wires, radio waves) a provider, but they are not providing the communications that you want to monitor. It is a bit like modems - the only communications data for any Internet access back then would be that you called your ISP for X minutes. Well, the Internet is the medium by which we communicate now, and you can use layers and layers. A communication (a message) may be sent as part of the content of something done on a web site, so all you log is that someone accessed the web site, and not that using that web site they sent a message to someone else. In that case the web site operator is a communications provider of a sort, but may not be in the UK. Things like TOR complicate the matter even more - its is a "network" with no providers.
But there are things where there is no communications provider even at the low level - mesh networks. With so many people owning wifi equipment it becomes possible to create networks that work via your neighbours wifi and create a whole Internet with no actual "provider" involved.
So making laws that impact communications providers only really works whilst they exist at the level you wish to monitor.
That there is a sender and a recipient
This is a pretty fundamental assumption in the legislation, and already is not always the case. A tweet is public, and whilst people may follow some people, they can just see tweets anyway and search for them anyway. If I post a tweet, who is the recipient? Do we try to work out who it was aimed at in some way, or just say it was sent to 1000 people (my followers). What if it is then retweeted to a million people - who sent the "message" and who was it to?
That the communication is a message
Again, this is ingrained in the legislation - but a communication could perhaps be clicking "like" on a FaceBook post. Again, who is that communicating to, and what is the message?
That you can separate envelope from content
This is also fundamental as the government quite rightly feel that snooping on everyone's content (opening everyone's letters) would not be acceptable.
The problem is that it is no longer easy or even possible to tell the content from the addressing information. What is the "content" of clicking "like"? What if I tweet and include the string @xkcd in that "message"? Is that "content", being within my tweet, or is it the address, being that it would be shown to Randall if he ever logged in to twitter.
There is legislation saying, for example, that no part of the content of an email shall be logged, but they want logging of the addressing. So if I included in the content of the email my email address does that then stop that address being logged, as it is also a part of the content?
Even talking of "weblogs" they are specifically talking of URL up to first slash (which is entertaining as that is "http:/") but they basically mean logging the hostname part. That is fine until you realise that lots of web sites are in fact Facebook.com/somecompany, or someproxy.com/realwebsite, so you are not in fact logging the "site" being visited. Future changes to https may ensure that even the hostname cannot be logged.
So, I suggest that even now, the snooper's charter is already out of date for its stated purpose (as well as being technically impossible and immoral)
Update: The four horsemen (I mean Lords) are trying again http://www.bbc.co.uk/news/uk-politics-31062757
2015-01-26
Watching the government do its work
For the first time I have been watching, and engaging with, live coverage of legislation happening.
The debate in The Lords on the Counter Terrorism and Security bill.
The debate in The Lords on the Counter Terrorism and Security bill.
They have added the whole of the Communications Data Bill as an amendment at a late stage in the Lords.
The debate was horrid to watch. I was screaming at the screen!
There are an amazing set of comments. Almost all are without any technical clue as to the serious implications. There are emotive statements like "talking to police after 7/7" - well that applies to any police on any motorway accident. So let's look at how many people terrorists kill. Fuck all!
There seemed to be no attempt to try and determine objective tests for any of this, and then apply them - it was nearly all "we feel this is a good/bad idea".
There seemed to be no attempt to try and determine objective tests for any of this, and then apply them - it was nearly all "we feel this is a good/bad idea".
Good points on the fact that the French had the data as proposed, and did nothing. Others using the French incident to justify this amendment. Some suggest that UK would have noticed if it had happened here. Even if they would, this is data to which the UK already has access with no need for new laws.
Several points on tracking locations of mobile phones, something which we have now, and is covered by existing laws, does not need these amendments let alone this new bill, and is unlikely to go away for any reason. Indeed LTE (4G) improves this. Why these points were raised is unclear.
The fact that there is a sunset clause was mention, but they admitted that realistically it would just be extended. The fact that the work involved in setting up all of this extra monitoring and providing access would probably take until the sunset clause, was not raised.
It was amusing that someone sensibly questioned the meaning of "communication" and "message", asking if a "tinder match" counted as a message! A later comment from someone else thanks someone for explaining tinder to her during the debate, with some amusement. This is, however, a very important point, and shows that differentiating the envelope from the content is really not easy.
Several points on tracking locations of mobile phones, something which we have now, and is covered by existing laws, does not need these amendments let alone this new bill, and is unlikely to go away for any reason. Indeed LTE (4G) improves this. Why these points were raised is unclear.
The fact that there is a sunset clause was mention, but they admitted that realistically it would just be extended. The fact that the work involved in setting up all of this extra monitoring and providing access would probably take until the sunset clause, was not raised.
It was amusing that someone sensibly questioned the meaning of "communication" and "message", asking if a "tinder match" counted as a message! A later comment from someone else thanks someone for explaining tinder to her during the debate, with some amusement. This is, however, a very important point, and shows that differentiating the envelope from the content is really not easy.
A few of the Lords and Ladies have clue and should be commended. Many are clueless. So many empty seats, it is scary. Making a list of "sane" Lords and Ladies is good though. I need to have dinner with them some time. Stras, Lane-Fox and Jones are on my "nice list". Some others too.
I am not sure how to conclude this post - but I am unsure that the way we run the country is actually sensible, sorry.
The fact that the steaming was iffy is a clue how important this is...
What gets me is how the hell should I need to be watching this - something is wrong if I cannot trust the powers that be to do the right thing!
Cool gadget
This looks cool, Philips InSight Wireless IP Camera. I just ordered one to play with from eBuyer. I may post some details of what I think about it.
But, bugger, chilling effect. I am already thinking should I get this?
After all, based on what David Cameron says, it could be illegal soon, and I may have to hand it in to the police station when they do an amnesty day on illegal crypto products.
After all, it says "Encrypted direct networking for secure connection" in the description.
I wonder if Sale of Goods legislation covers a product "becoming illegal" during its lifetime...
But, bugger, chilling effect. I am already thinking should I get this?
After all, based on what David Cameron says, it could be illegal soon, and I may have to hand it in to the police station when they do an amnesty day on illegal crypto products.
After all, it says "Encrypted direct networking for secure connection" in the description.
I wonder if Sale of Goods legislation covers a product "becoming illegal" during its lifetime...
Let's make a law, that will fix it
Sadly we see this a lot, at UK and EU level. The cookie law was one example of totally stupid knee jerk reaction - it has not, in fact, stopped people being tracked at all - what it has done is cause constant annoyance to everyone visiting a new web page and being plastered with "cookie policy, click to agree" banners, and then having a cookie to record that they disagreed (or not being allowed to use the site). Even the ICO were non compliant on their web site when the law came in to force and many sites are not now. It did nothing and we all said it would do nothing.
Human rights
There are laws you cannot make - top level things that would break international treaties, breach human rights, or just lead to civil war. I nearly did not put this category in this post, but then realised that a right to privacy is one of those human rights things... Hmmm
Laws that cannot be detected to be enforced
You can't sensibly make something illegal that is impossible to detect and so enforce. In some ways the laws that existed against being gay are a bit like that - essentially the only proof was something done in the private, so only by admission or catching someone in the act would you catch some. It is a stupid law for moral reasons, but also for purely practical reasons of being hard to enforce.
Outlawing something everyone wants
Another good example is laws that try to outlaw something that is, by human nature or common practice, something people want to do. A good example is banning alcohol in the US. When you make a law like that you don't stop people doing it, but you drive it underground, making it hard to detect. You also create a huge problem that people become criminals anyway, so they have something to hide. People with something to hide get sucked in to more criminal behaviour and can be blackmailed. Before you know it you have the mob. Regulating such things so that you allow most people to do what they want within limits and still be legal is much more likely to succeed and make the criminal element unprofitable. The same is true for copyright violation - allowing people to easily and cheaply and legally access material is the way to stop the unwanted behaviour, not laws making something simple and wanted actually illegal.
Making everyone a criminal
Another big problem is that it is easy to make everyone a criminal with a stupid law. This has all sorts of problems. Much like the above, you could create an underground market of some sort, but if you really make something we all do every day illegal you end up with a law that is largely ignored. There is simply no way to enforce such laws. This is where banning use of any means of communications that cannot be read under an order from the Home Secretary (something David Cameron is calling for) would be silly. Everyone that uses FaceBook, iMessage, online banking, the conservative party web site, or even a cash machine, would be a criminal.
Making everyone a criminal causes all sorts of issues. You have people that try to comply, but can't so they take their business or themselves out of the UK. You have the problem with people with "something to hide" so can be blackmailed. You also create a convenient "We can arrest anyone we like" logic for police, as they just have to arrest you for having an iPhone. It is unworkable.
When can you make a law?
A law has to do some good and meet an actual requirement. It has to be proportionate - the cost of complying and enforcing the law has to reflect the benefit gained (questionable for many anti-terror related laws). It has to be detectable and enforceable. It also has to be something the public are happy with, as, after all, the government do work for the people!
Obviously a law does not have to be 100% - some people with evade detection. For most laws this is a simple matter of economics - a trade off for effort to catch every last transgressor compared to the cost/damage caused by them. However, for anti-terror laws, this is not the case. We are making anti-terror laws when there have been tiny numbers of terrorist attacks. Allowing one terrorists cell to evade the law would be unacceptable, if we are to believe the rhetoric of politicians. For an anti-terror law to be justified in the first place you have to make it one that can be 100% enforced as it only takes one nutter with a small nuke to ruin your whole day.
Human rights
There are laws you cannot make - top level things that would break international treaties, breach human rights, or just lead to civil war. I nearly did not put this category in this post, but then realised that a right to privacy is one of those human rights things... Hmmm
Laws that cannot be detected to be enforced
You can't sensibly make something illegal that is impossible to detect and so enforce. In some ways the laws that existed against being gay are a bit like that - essentially the only proof was something done in the private, so only by admission or catching someone in the act would you catch some. It is a stupid law for moral reasons, but also for purely practical reasons of being hard to enforce.
Outlawing something everyone wants
Another good example is laws that try to outlaw something that is, by human nature or common practice, something people want to do. A good example is banning alcohol in the US. When you make a law like that you don't stop people doing it, but you drive it underground, making it hard to detect. You also create a huge problem that people become criminals anyway, so they have something to hide. People with something to hide get sucked in to more criminal behaviour and can be blackmailed. Before you know it you have the mob. Regulating such things so that you allow most people to do what they want within limits and still be legal is much more likely to succeed and make the criminal element unprofitable. The same is true for copyright violation - allowing people to easily and cheaply and legally access material is the way to stop the unwanted behaviour, not laws making something simple and wanted actually illegal.
Making everyone a criminal
Another big problem is that it is easy to make everyone a criminal with a stupid law. This has all sorts of problems. Much like the above, you could create an underground market of some sort, but if you really make something we all do every day illegal you end up with a law that is largely ignored. There is simply no way to enforce such laws. This is where banning use of any means of communications that cannot be read under an order from the Home Secretary (something David Cameron is calling for) would be silly. Everyone that uses FaceBook, iMessage, online banking, the conservative party web site, or even a cash machine, would be a criminal.
Making everyone a criminal causes all sorts of issues. You have people that try to comply, but can't so they take their business or themselves out of the UK. You have the problem with people with "something to hide" so can be blackmailed. You also create a convenient "We can arrest anyone we like" logic for police, as they just have to arrest you for having an iPhone. It is unworkable.
When can you make a law?
A law has to do some good and meet an actual requirement. It has to be proportionate - the cost of complying and enforcing the law has to reflect the benefit gained (questionable for many anti-terror related laws). It has to be detectable and enforceable. It also has to be something the public are happy with, as, after all, the government do work for the people!
Obviously a law does not have to be 100% - some people with evade detection. For most laws this is a simple matter of economics - a trade off for effort to catch every last transgressor compared to the cost/damage caused by them. However, for anti-terror laws, this is not the case. We are making anti-terror laws when there have been tiny numbers of terrorist attacks. Allowing one terrorists cell to evade the law would be unacceptable, if we are to believe the rhetoric of politicians. For an anti-terror law to be justified in the first place you have to make it one that can be 100% enforced as it only takes one nutter with a small nuke to ruin your whole day.
2015-01-25
Can we use David Cameron's super powers for good?
On a Radio 5 interview, Professor Glees, who advises the government said, "The government can require, by law, that software allows a back door entry in to it, that's a fact"
I have just realised that this must mean David Cameron has super powers, and we never knew it.
Please can "The government require, by law, that software is not a computer virus"?
That would be really useful. Tacking computer viruses is a big issue, but I never knew the government had a magic wand until now. Let's use it for good.
2015-01-24
Radio 5 interview shows stupidity
There is an excellent radio 5 interview on the whole issue of banning encryption, well worth a listen.
There is a lovely quote in it from the so called expert that advises the government, Professor Glees.
"The government can require by law that software allows a back door entry in to it, that's a fact"
I actually laughed out loud at that, really. It is so funny, but somehow, it seems he was not joking.
Firstly, as Professor Glees may not understand it, I'll explain that software is just a set of instructions that a computer follows.
A lot of the software used for encryption is open source. It is published openly and it is written, reviewed ,and maintained by volunteers all over the world for no money. It means there is no person or company that the law can apply to. There is no door the police (in any country) can bash down and demand the software is changed or not distributed. There is no person you can lock up or fine. It is free, open, and has copies everywhere on the Internet. It means that the set of instructions are out there and exist and can be used by anyone with a computer. This software is secure by design and does not have any "back door entry in it".
But let's bring it back to basics. There are things called "books" which are something of which Professor Glees may have heard. These too can contain instructions which can be followed. They could be instructions one can put in to a computer, but there are instructions which don't even need a computer. There is a book published in 1882 on the subject for use with telegraphs, so this is not new.
I have a simple video showing how you can use one of the simplest but most secure means to send secrets [here], do watch. This involves following instructions, the very thing computers do. I wrote out a set of instructions in my blog post [here]. Both the video and my blog, and countless other books, web page, videos, and even university courses, count, in a way, as "software", a set of instructions you could, if you wanted, put in to a computer.
Now, in order to "require, by law, that software allows a back door entry in to it" as specified by Professor Glees he would have to require my blog and that video are changed to add instructions like "Now you have made two copies of the key, one for the sender and one for the recipient, you have to make a third, and post it to GCHQ at this address". Indeed, every copy of every book and every web page explaining encryption is in effect "software" and they would all have to be found and need instructions like that added, or access blocked somehow. I suspect, for books, the only real way to get close to this involves piling books up outside libraries and burning them - that'll work!
Of course, if I was following that 1882 book, or my blog, or that video, and I came to the bit that says "send your keys to GCHQ", I could ignore that bit! When putting these instructions in to the computer, I could leave those bits out. Nobody would know. The encrypted messages would still pass around just like ones with the "back door entry". Remember, that these systems have to interwork with normal systems outside the UK (unless UK is to be disconnect from the Internet), so the presence of the "back door entry" is not something you can detect on the wire somehow. Only if someone actually wanted to spy on me, and tried to use this "back door entry", demanded copies of keys or whatever, would they find that I had not included one as required by law, but otherwise I would be fine.
This means that law abiding citizens and companies and engineers would have to follow these rules, or be committing a crime.
For criminals, ignoring these extra instructions, or loading software that does not have a "back door entry" will just be committing one more crime and only visible if/when they are caught. Of course, as proper encryption is legal everywhere else in the world, getting such software would be easy.
As explained on the Interview, you'd need a special weak version of iPhones and Windows and OS X in the UK. Indeed, somehow, you'd need a special weak version of Linux and FreeBSD and other open operating systems. When I download some crypto app for linux, somehow you have to stop me editing it to remove the "back door entry". Just as it would be hard to catch every iPhone as visitors come through customs it would be hard to catch every download of linux or other operating system, app, patch, library, source code, that could be loaded to bypass these mad laws. You would need special weak versions of cisco, juniper and FireBrick routers for use in the UK. You'd need to stop people downloading loads of standard apps from the Apple app store, and from Android stores, and somehow have Androids that are "locked down" that they cannot download any of these secure apps if someone does get a copy. You'd have to make Windows and iMac somehow locked down so that people could not download apps of their choice, and somehow do the same with linux and BSD. Heck, you'd even need a special version of the telephone I have on my desk as it can do encryption if I ask it to, and it is an outdated model that is no longer supported. Somehow you need special versions of code for equipment made by companies that do not exist any more. Even your TV would need a software upgrade to a special version.
And once you have that special code and special versions of iPhones, which the criminals can just ignore, you then need to somehow make it so that criminals don't crack this "back door entry" which has been added, even though it has somehow been added to open source code, and so can be seen and understood (makes cracking it just slightly easier if you have the source code). And when (not if) this back door is cracked you have to have some secure way to update every single device in the country from desk phones, mobile phones, apps on computers and TV sets and everything to the new version with the better back door that has not been cracked yet, while you cross your fingers for a week or so until it is hacked again.
Of course, even if not cracked for a long time, all confidence in any UK based security would be lost by the rest of the world. It would be against card payment processing rules for anyone to accept cards from any of the UK browsers because they would be known to have this "back door entry", so no card payments on-line would be possible from any UK law abiding citizen (criminals would not have that problem, obviously, as they can just run old/safe versions of browsers and access via TOR/VPNs).
Now, remember, Internet Explorer 6 (IE6) which dates to 2001, that is 14 yeas ago. That has in it secure(ish) encryption code. If it has taken 14 years for Microsoft to get people to stop using IE6 when there are good reasons for people to upgrade. How long would it take to get everyone to upgrade their browsers to include the government mandated back door? And that is just one app on one type of device (PC).
Finance would have to leave the UK, probably in order to comply with security requirements by law in other countries if not simply due to lack of confidence from any customers who find they deal with the UK.
And with all of that, you still have the fact that a child with pen, paper and some dice could send secret messages if they want, even if that means ignoring the extra line of instructions to send a copy of the key to GCHQ. You can make that illegal, just like you could make farting illegal, and probably with about as much chance of it being implemented.
And who the hell pays for all of these changes to every computer, every app, every browser, every telephone and device?
Sorry for repeating myself here - just trying to find ways to explain the scale of the problem to people like Professor Glees, who clearly has no fucking clue, much like Theresa May and David Cameron. Somehow we need to get the message across.
There is a lovely quote in it from the so called expert that advises the government, Professor Glees.
"The government can require by law that software allows a back door entry in to it, that's a fact"
I actually laughed out loud at that, really. It is so funny, but somehow, it seems he was not joking.
Firstly, as Professor Glees may not understand it, I'll explain that software is just a set of instructions that a computer follows.
A lot of the software used for encryption is open source. It is published openly and it is written, reviewed ,and maintained by volunteers all over the world for no money. It means there is no person or company that the law can apply to. There is no door the police (in any country) can bash down and demand the software is changed or not distributed. There is no person you can lock up or fine. It is free, open, and has copies everywhere on the Internet. It means that the set of instructions are out there and exist and can be used by anyone with a computer. This software is secure by design and does not have any "back door entry in it".
But let's bring it back to basics. There are things called "books" which are something of which Professor Glees may have heard. These too can contain instructions which can be followed. They could be instructions one can put in to a computer, but there are instructions which don't even need a computer. There is a book published in 1882 on the subject for use with telegraphs, so this is not new.
I have a simple video showing how you can use one of the simplest but most secure means to send secrets [here], do watch. This involves following instructions, the very thing computers do. I wrote out a set of instructions in my blog post [here]. Both the video and my blog, and countless other books, web page, videos, and even university courses, count, in a way, as "software", a set of instructions you could, if you wanted, put in to a computer.
Now, in order to "require, by law, that software allows a back door entry in to it" as specified by Professor Glees he would have to require my blog and that video are changed to add instructions like "Now you have made two copies of the key, one for the sender and one for the recipient, you have to make a third, and post it to GCHQ at this address". Indeed, every copy of every book and every web page explaining encryption is in effect "software" and they would all have to be found and need instructions like that added, or access blocked somehow. I suspect, for books, the only real way to get close to this involves piling books up outside libraries and burning them - that'll work!
Of course, if I was following that 1882 book, or my blog, or that video, and I came to the bit that says "send your keys to GCHQ", I could ignore that bit! When putting these instructions in to the computer, I could leave those bits out. Nobody would know. The encrypted messages would still pass around just like ones with the "back door entry". Remember, that these systems have to interwork with normal systems outside the UK (unless UK is to be disconnect from the Internet), so the presence of the "back door entry" is not something you can detect on the wire somehow. Only if someone actually wanted to spy on me, and tried to use this "back door entry", demanded copies of keys or whatever, would they find that I had not included one as required by law, but otherwise I would be fine.
This means that law abiding citizens and companies and engineers would have to follow these rules, or be committing a crime.
For criminals, ignoring these extra instructions, or loading software that does not have a "back door entry" will just be committing one more crime and only visible if/when they are caught. Of course, as proper encryption is legal everywhere else in the world, getting such software would be easy.
As explained on the Interview, you'd need a special weak version of iPhones and Windows and OS X in the UK. Indeed, somehow, you'd need a special weak version of Linux and FreeBSD and other open operating systems. When I download some crypto app for linux, somehow you have to stop me editing it to remove the "back door entry". Just as it would be hard to catch every iPhone as visitors come through customs it would be hard to catch every download of linux or other operating system, app, patch, library, source code, that could be loaded to bypass these mad laws. You would need special weak versions of cisco, juniper and FireBrick routers for use in the UK. You'd need to stop people downloading loads of standard apps from the Apple app store, and from Android stores, and somehow have Androids that are "locked down" that they cannot download any of these secure apps if someone does get a copy. You'd have to make Windows and iMac somehow locked down so that people could not download apps of their choice, and somehow do the same with linux and BSD. Heck, you'd even need a special version of the telephone I have on my desk as it can do encryption if I ask it to, and it is an outdated model that is no longer supported. Somehow you need special versions of code for equipment made by companies that do not exist any more. Even your TV would need a software upgrade to a special version.
And once you have that special code and special versions of iPhones, which the criminals can just ignore, you then need to somehow make it so that criminals don't crack this "back door entry" which has been added, even though it has somehow been added to open source code, and so can be seen and understood (makes cracking it just slightly easier if you have the source code). And when (not if) this back door is cracked you have to have some secure way to update every single device in the country from desk phones, mobile phones, apps on computers and TV sets and everything to the new version with the better back door that has not been cracked yet, while you cross your fingers for a week or so until it is hacked again.
Of course, even if not cracked for a long time, all confidence in any UK based security would be lost by the rest of the world. It would be against card payment processing rules for anyone to accept cards from any of the UK browsers because they would be known to have this "back door entry", so no card payments on-line would be possible from any UK law abiding citizen (criminals would not have that problem, obviously, as they can just run old/safe versions of browsers and access via TOR/VPNs).
Now, remember, Internet Explorer 6 (IE6) which dates to 2001, that is 14 yeas ago. That has in it secure(ish) encryption code. If it has taken 14 years for Microsoft to get people to stop using IE6 when there are good reasons for people to upgrade. How long would it take to get everyone to upgrade their browsers to include the government mandated back door? And that is just one app on one type of device (PC).
Finance would have to leave the UK, probably in order to comply with security requirements by law in other countries if not simply due to lack of confidence from any customers who find they deal with the UK.
And with all of that, you still have the fact that a child with pen, paper and some dice could send secret messages if they want, even if that means ignoring the extra line of instructions to send a copy of the key to GCHQ. You can make that illegal, just like you could make farting illegal, and probably with about as much chance of it being implemented.
And who the hell pays for all of these changes to every computer, every app, every browser, every telephone and device?
Sorry for repeating myself here - just trying to find ways to explain the scale of the problem to people like Professor Glees, who clearly has no fucking clue, much like Theresa May and David Cameron. Somehow we need to get the message across.
Subscribe to:
Posts (Atom)
Dodecahedron
I was shown a dodecahedron with LEDs inside. Looked great, so decided to have a go. The principle is not that hard - a PCB strip on the insi...
-
Broadband services are a wonderful innovation of our time, using multiple frequency bands (hence the name) to carry signals over wires (us...
-
For many years I used a small stand-alone air-conditioning unit in my study (the box room in the house) and I even had a hole in the wall fo...
-
This is an appeal for (sensible) comments. I am working on revised A&A tariffs for broadband. For those that are not sure how they wor...


