Communications Data Bill: Be Very Afraid

20
Simon Phipps Director, Open Rights Group http://webmink.com Communications Data Bill Be Very Afraid...

description

What exactly is the problem with the UK's Communications Data Bill? That it's intrusive? Expensive? A hostage to fortune? All these and more. This presentation was delivered on behalf of the Open Rights Group at OggCamp 2012 and other venues.

Transcript of Communications Data Bill: Be Very Afraid

Page 1: Communications Data Bill: Be Very Afraid

Simon PhippsDirector, Open Rights Group

http://webmink.com

Communications Data Bill Be Very Afraid...

Page 2: Communications Data Bill: Be Very Afraid

CDB tl;dr (for early leavers...)

● New law that allows any agency so authorised to order your ISP to collect ALL meta-information about everyone's internet activity, retain it for a year and supply it to them for arbitrary analysis.

● Almost impossible to repair in a way that preserves citizen digital rights.

● Needs your input now.● Needs you to start supporting ORG

Page 3: Communications Data Bill: Be Very Afraid

The Topic Of The Hour

● Previously rumoured as “Interception Modernisation Programme” under Labour

● Announced as “Communications Capabilities Development Programme” in Queen's Speech

● Now “Communications Data Bill” (CDB)● Colloquially, “Snooper's Charter”

Page 4: Communications Data Bill: Be Very Afraid

Didn't The Coalition Say No?

● When the coalition was elected, they promised that:– “We will end the storage of internet and email records

without good reason”

● Nick Clegg added:– "We won't hold your internet and email records when there

is just no reason to do so."

● Seems someone had a “Yes, Minister” moment...

Page 5: Communications Data Bill: Be Very Afraid

CDB Is A Zombie Bill

● It gets killed ... It keeps coming back to life● Source is deep inside Home Office● Same outcomes sought repeatedly● This will probably not be the last time we need

to defeat it...

Page 6: Communications Data Bill: Be Very Afraid

CDB Structure

● Part 1 creates a new power to order ISPs to collect communications data

● Part 2 creates a system for assorted public bodies to get access to this data.

● Part 3 adjusts other laws to reflect the new powers and establishes who has oversight.

Page 7: Communications Data Bill: Be Very Afraid

What Data?

● Modelled on existing powers (“may read the envelope”): postal, phone records

● Any traffic data, use data, or subscriber data● But not the message itself● Kept for 12 months by default● Any civil, criminal or military proceedings can

trigger indefinite retention● No requirement for any citizen to be told

Page 8: Communications Data Bill: Be Very Afraid

Delivered-To: [email protected]: by 10.68.48.163 with SMTP id m3csp12715pbn; Thu, 26 Jul 2012 07:11:49 -0700 (PDT)Received: by 10.60.168.230 with SMTP id zz6mr41583709oeb.11.1343311909082; Thu, 26 Jul 2012 07:11:49 -0700 (PDT)Return-Path: <[email protected]>Received: from mail-ob0-f182.google.com (mail-ob0-f182.google.com [209.85.214.182]) by mx.google.com with ESMTPS id r4si21118589obz.27.2012.07.26.07.11.48 (version=TLSv1/SSLv3 cipher=OTHER); Thu, 26 Jul 2012 07:11:48 -0700 (PDT)Received-SPF: pass (google.com: domain of [email protected] designates 209.85.214.182 as permitted sender) client-ip=209.85.214.182;Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 209.85.214.182 as permitted sender) [email protected]: by mail-ob0-f182.google.com with SMTP id un3so2755750obb.41 for <[email protected]>; Thu, 26 Jul 2012 07:11:48 -0700 (PDT)X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to:x-mailer:x-gm-message-state; bh=/Z6B9ypN63nfDMrE4IT82Mugj6vTi/XfrBaT+4V2X8k=; b=mMYeUXuUVFvFbZx/JQwHHxef13P++yjuvrq2HdidgokubuMCiwg7ewtoaFnhLYCDNZ M7Cv0Zxl719jP3qS0DeCZQXwIQY5LZe5B4ouEKbQ4UQFR8jTaOpha1jkdhL6QyzEJcnk N1kbfidqqg8NMo6bVJEG0+mGsItSvnDfxsGaepb2lux1ehDlTDNnxY/XIsgo5KQP0Ipk +J1zqQh3zjXS1c7LJ4cL3giX5QTo0driOOvnz/LAjp/cMTzidDnPjaUDAO6vfZ31JvUl ieIYIKB8s3PQguKIPDhwhBKDmpduaMXZUmRK9RjiHTVJgTpj+D9taNeC2byohcLV8C8r bwLg==Received: by 10.182.116.2 with SMTP id js2mr42185754obb.38.1343311908355; Thu, 26 Jul 2012 07:11:48 -0700 (PDT)Return-Path: <[email protected]>Received: from [10.168.10.10] (cosm4.all-cosme.info. [173.192.35.87]) by mx.google.com with ESMTPS id qv2sm10759032obb.11.2012.07.26.07.11.44 (version=SSLv3 cipher=OTHER); Thu, 26 Jul 2012 07:11:47 -0700 (PDT)Subject: Re: Speaking At OggCampMime-Version: 1.0 (Apple Message framework v1084)Content-Type: multipart/alternative; boundary=Apple-Mail-3--67519763From: Simon Phipps <[email protected]>In-Reply-To: <CAFW3EdH1zPQ42PqZW8=HsQx6CCVUxMT3nL3746s9up5aKAAzhQ@mail.gmail.com>Date: Thu, 26 Jul 2012 15:11:40 +0100Cc: Jim Killock <[email protected]>, Peter Bradwell <[email protected]>, Ryan Jendoubi <[email protected]>, Mark Johnson <[email protected]>Message-Id: <[email protected]>References: <CAFW3EdFKOjNQkkyREOP0qyAX7iVhuNeC8QpQUOwBQ2vxFV-V-w@mail.gmail.com> <[email protected]> <CAFW3EdHA=3__ZkaPvMGsAYP34oCLX-_XSbZ4kzGk-AF3U_OHug@mail.gmail.com> <[email protected]> <CAFW3EdGCY6gzP_erUF-SGBmELT2DUo1j3z74vqHjpUc1NWLRaA@mail.gmail.com> <[email protected]> <CAFW3EdH1zPQ42PqZW8=HsQx6CCVUxMT3nL3746s9up5aKAAzhQ@mail.gmail.com>To: Dan Lynch <[email protected]>X-Mailer: Apple Mail (2.1084)X-Gm-Message-State: ALoCoQmaq4J5AUU0LXmhSdsgSViBrM1WrP9ho/r7yY512bu2pMzZY3z4mqwCSX5L5HlRmLOTgRdI

--Apple-Mail-3--67519763Content-Transfer-Encoding: quoted-printableContent-Type: text/plain;

charset=us-ascii

Looking forward to being there again :-)

S.--Simon Phipps, http://webmink.com/Meshed Insights & KnowledgeMobile: +1 415 683 7660New office line: +44 238 098 7027

On 26 Jul 2012, at 15:08, Dan Lynch wrote:

> Hi Jim,>=20> Many thanks for letting us know. This will be Simon's 3rd year talking =at OggCamp. He's a regular. Should be fun. Mark, our schedule =coordinator will see this email and should be able to take it from here.>=20> Enjoy your time off :)>=20> Dan>=20> On 26 Jul 2012 14:09, "Jim Killock" <[email protected]> wrote:> Hi Dan>=20> Simon Phipps has kindly volunteered to speak at OggCamp on the CDB for =us.=20>=20> There is a little info about him and further links here:>=20> http://www.openrightsgroup.org/people/board>=20> I am away for three weeks, so please direct any enquiries to Peter or =Simon about any other details in the meantime.>=20> Thank you,>=20> Jim>=20>=20> Jim Killock=20> Executive Director> Open Rights Group> +44 (0) 7894 498 127> Skype: jimkillock> Email: [email protected]> http://twitter.com/jimkillock> http://www.openrightsgroup.org/>=20

--Apple-Mail-3--67519763Content-Transfer-Encoding: quoted-printableContent-Type: text/html;

charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; =">Looking forward to being there again =:-)<div><br></div><div>S.<br><div><span class=3D"Apple-style-span" style=3D"border-collapse: separate; =color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; =font-variant: normal; font-weight: normal; letter-spacing: normal; =line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: =0px; text-transform: none; white-space: normal; widows: 2; word-spacing: =0px; -webkit-border-horizontal-spacing: 0px; =-webkit-border-vertical-spacing: 0px; =-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span =class=3D"Apple-style-span" style=3D"border-collapse: separate; color: =rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: =normal; font-weight: normal; letter-spacing: normal; line-height: =normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; =text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div =style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =Helvetica; font-style: normal; font-variant: normal; letter-spacing: =normal; line-height: normal; orphans: 2; text-align: -webkit-auto; =text-indent: 0px; text-transform: none; white-space: normal; widows: 2; =word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =-webkit-border-vertical-spacing: 0px; =-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div =style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><span class=3D"Apple-style-span" style=3D"orphans: =2; text-indent: 0px; widows: 2; -webkit-text-decorations-in-effect: =none; "><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><span class=3D"Apple-style-span" style=3D"orphans: =2; text-indent: 0px; widows: 2; -webkit-text-decorations-in-effect: =none; "><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><div style=3D"border-collapse: separate; color: =rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: =normal; font-weight: normal; letter-spacing: normal; line-height: =normal; text-transform: none; white-space: normal; word-spacing: 0px; =-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =font-size: medium; =">--</div></div></span></div></span></div></span></div></span></div></span=></div></span><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: =space; -webkit-line-break: after-white-space; "><span =class=3D"Apple-style-span" style=3D"orphans: 2; text-indent: 0px; =widows: 2; -webkit-text-decorations-in-effect: none; "><div =style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><span class=3D"Apple-style-span" style=3D"orphans: =2; text-indent: 0px; widows: 2; -webkit-text-decorations-in-effect: =none; "><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><div style=3D"border-collapse: =separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: =normal; font-variant: normal; font-weight: normal; letter-spacing: =normal; line-height: normal; text-transform: none; white-space: normal; =word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =-webkit-border-vertical-spacing: 0px; -webkit-text-size-adjust: auto; =-webkit-text-stroke-width: 0px; font-size: medium; "><b>Simon =Phipps</b>, &nbsp;<a =href=3D"http://webmink.com/">http://webmink.com/</a></div></div></span></d=iv></span></div></span></div><span class=3D"Apple-style-span" =style=3D"font-style: italic; ">Meshed Insights &amp; =Knowledge</span><span class=3D"Apple-style-span" style=3D"orphans: 2; =text-indent: 0px; widows: 2; -webkit-text-decorations-in-effect: none; ="><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><span class=3D"Apple-style-span" style=3D"orphans: =2; text-indent: 0px; widows: 2; -webkit-text-decorations-in-effect: =none; "><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =-webkit-line-break: after-white-space; "><span class=3D"Apple-style-span" =style=3D"orphans: 2; text-indent: 0px; widows: 2; =-webkit-text-decorations-in-effect: none; "><div style=3D"word-wrap: =break-word; -webkit-nbsp-mode: space; -webkit-line-break: =after-white-space; "><div style=3D"border-collapse: separate; color: =rgb(0, 0, 0); font-family: Helvetica; font-variant: normal; font-weight: =normal; letter-spacing: normal; line-height: normal; text-transform: =none; white-space: normal; word-spacing: 0px; =-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ="><font class=3D"Apple-style-span" size=3D"2"><i>Mobile:</i><span =class=3D"Apple-converted-space">&nbsp;</span>&nbsp;+44 774 776 2816 =&nbsp;<i>or</i>&nbsp;&nbsp;+1 415 683 =7660</font></div></div></span></div></span></div></span></div></span><font= class=3D"Apple-style-span" color=3D"#0641f4" size=3D"2"><i>New office =line: &nbsp;</i>+44 238 098 7027</font><div><font =class=3D"Apple-style-span" color=3D"#0641f4" =size=3D"2"><br></font></div></div></span><br =class=3D"Apple-interchange-newline"></span><br =class=3D"Apple-interchange-newline"></div><br><div><div>On 26 Jul 2012, at 15:08, Dan Lynch wrote:</div><br =class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><p =dir=3D"ltr">Hi Jim,</p><p dir=3D"ltr">Many thanks for letting us know. =This will be Simon's 3rd year talking at OggCamp. He's a regular. Should =be fun. Mark, our schedule coordinator will see this email and should be =able to take it from here.</p><p dir=3D"ltr">Enjoy your time off =:)</p><p dir=3D"ltr">Dan</p><div class=3D"gmail_quote">On 26 Jul 2012 14:09, "Jim Killock" &lt;<a =href=3D"mailto:[email protected]" =target=3D"_blank">[email protected]</a>&gt; wrote:<br =type=3D"attribution"><blockquote class=3D"gmail_quote" style=3D"margin:0 =0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div style=3D"word-wrap:break-word">Hi Dan<div><br></div><div>Simon =Phipps has kindly volunteered to speak at OggCamp on the CDB for =us.&nbsp;</div><div><br></div><div>There is a little info about him and =further links here:</div>

<div><br></div><div><a =href=3D"http://www.openrightsgroup.org/people/board" =target=3D"_blank">http://www.openrightsgroup.org/people/board</a></div><di=v><br></div><div>I am away for three weeks, so please direct any =enquiries to Peter or Simon about any other details in the =meantime.</div>

<div><br></div><div>Thank =you,</div><div><br></div><div>Jim</div><br><br><div><span =style=3D"text-indent:0px;letter-spacing:normal;font-variant:normal;text-al=ign:-webkit-auto;font-style:normal;font-weight:normal;line-height:normal;b=order-collapse:separate;text-transform:none;font-size:medium;white-space:n=ormal;font-family:Helvetica;word-spacing:0px"><span =style=3D"text-indent:0px;letter-spacing:normal;font-variant:normal;font-st=yle:normal;font-weight:normal;line-height:normal;border-collapse:separate;=text-transform:none;font-size:medium;white-space:normal;font-family:Helvet=ica;word-spacing:0px"><div style=3D"word-wrap:break-word">

<span =style=3D"text-indent:0px;letter-spacing:normal;font-variant:normal;font-st=yle:normal;font-weight:normal;line-height:normal;border-collapse:separate;=text-transform:none;font-size:medium;white-space:normal;font-family:Helvet=ica;word-spacing:0px"><div style=3D"word-wrap:break-word">

<span =style=3D"text-indent:0px;letter-spacing:normal;font-variant:normal;font-st=yle:normal;font-weight:normal;line-height:normal;border-collapse:separate;=text-transform:none;font-size:medium;white-space:normal;font-family:Helvet=ica;word-spacing:0px"><div style=3D"word-wrap:break-word">

<span =style=3D"text-indent:0px;letter-spacing:normal;font-variant:normal;font-st=yle:normal;font-weight:normal;line-height:normal;border-collapse:separate;=text-transform:none;font-size:medium;white-space:normal;font-family:Helvet=ica;word-spacing:0px"><div style=3D"word-wrap:break-word">

<div>Jim Killock&nbsp;<br>Executive Director<br>Open Rights Group<br><a =href=3D"tel:%2B44%20%280%29%207894%20498%20127" value=3D"+447894498127" =target=3D"_blank">+44 (0) 7894 498 127</a><br>Skype: =jimkillock</div><div>Email:&nbsp;<a =href=3D"mailto:[email protected]" =target=3D"_blank">[email protected]</a></div>

<div><a href=3D"http://twitter.com/jimkillock" =target=3D"_blank">http://twitter.com/jimkillock</a><br><a =href=3D"http://www.openrightsgroup.org/" =target=3D"_blank">http://www.openrightsgroup.org/</a><br></div></div></spa=n></div></span></div></span></div></span></span></div><br></div></blockquote></div></blockquote></div><br></div></body></html>=

--Apple-Mail-3--67519763--

OK

Not OK

Page 9: Communications Data Bill: Be Very Afraid

Exactly What Data?

● Information about how the service is used by people, except for the contents of communications

● Any information that a telecoms operator has about people who use their service

● Traffic data: Anything associated with a communication for the purpose of facilitating transmission, which also satisfies at least one of these criteria:– Identifies any person, apparatus, or location which the communication is being sent

to or from

– Identifies apparatus involved in sending the communication

– Controls apparatus involved in sending the communication

– Identifies the time when something relating to the communication occurs

– Identifies data that is associated with the communication

● For postal operators: anything the postal service uses to transmit the communication, anything about how people are using the postal service, and any other data that the postal service has about people who use the service

Page 10: Communications Data Bill: Be Very Afraid

That's a lot!

● Yes, and for a long time & a lot of eyes● Enormous volume of data● Can be data mined, heuristically analysed &

triangulated with other data● Can be managed by a central service● Can be shared with wide range of users● With friction of mechanical records removed, offers

unprecedented ability to deduce anyone's location, actions, opinions and associations

Page 11: Communications Data Bill: Be Very Afraid

Who can request?

(a) a police force,

(b) the Serious Organised Crime Agency,

(c) Her Majesty’s Revenue and Customs,

(d) any of the intelligence services,

(e) any public authority designated for the purposes of this Part by order of the Secretary of State,

Page 12: Communications Data Bill: Be Very Afraid

For What Purpose?

(a) in the interests of national security,

(b) for the purpose of preventing or detecting crime or of preventing disorder,

(c) for the purpose of preventing or detecting any conduct in respect of which a penalty may be imposed under section 123 or 129 of the Financial Services and Markets Act 2000 (civil penalties for market abuse),

(d) in the interests of the economic well-being of the United Kingdom,

(e) in the interests of public safety,

(f) for the purpose of protecting public health,

(g) for the purpose of assessing or collecting any tax, duty, levy or other imposition, contribution or charge payable to a government department,

(h) for the purpose, in an emergency, of preventing death or injury or any damage to a person’s physical or mental health, or of mitigating any injury or damage to a person’s physical or mental health,

(i) to assist investigations into alleged miscarriages of justice, or

(j) where a person (“P”) has died or is unable to identify themselves because of a physical or mental condition, to assist in identifying P, or to obtain information about P’s next of kin or other persons connected with P or about the reason for P’s death or condition.

The Secretary of State may by order amend this subsection so as to add to or restrict the permitted purposes.

Page 13: Communications Data Bill: Be Very Afraid

Who & For What Purpose

● Anyone the Secretary of State wants.● Anyone to whom the Secretary of State

delegates● For any purpose the Secretary of State wants.

Page 14: Communications Data Bill: Be Very Afraid

Justifications

● “We have to keep up with the technology criminals are using”

● “It's meta-data that contains no personal details”

● “We'll ask OfCOM first”● “We will make sure the data is used properly”● “It will only cost £1.8bn”

Page 15: Communications Data Bill: Be Very Afraid

What's Wrong With That?

● “Keeping Up”– This is not the postal service

– There's no public accountability or judicial oversight

● “No Personal Data” – Meta-data allows triangulation

– Mass data allows heuristic analysis

● “Ask OfCOM/Data Protection”– Already ineffective on behalf of citizens

● “Used properly”– Mission creep will happen

– Home Secretary can arbitrarily extend without oversight

Page 16: Communications Data Bill: Be Very Afraid

Triangulation

Page 17: Communications Data Bill: Be Very Afraid

Mission Creep

● Congestion charge cams● Traffic status cams● Routine police tool● Car park cams● Routine business tool

● Once created, any resource can be repurposed in response to a popular crisis

Page 18: Communications Data Bill: Be Very Afraid

Summary

● CDB makes us all a suspect. ● Instead of being under surveillance when there

is evidence of wrongdoing, you will be under suspicion by default.

● Once created, this resource can only grow in scope & use

Page 19: Communications Data Bill: Be Very Afraid

What shall I do?

In order of engagement:● Join Open Rights Group

– http://openrightsgroup.org

● Read ORG materials– https://wmk.me/TMvWns

● Respond to consultation THIS WEEK– http://www.parliament.uk/business/committees/committees-a-

z/joint-select/draft-communications-bill/news/call-for-evidence/

● Join (or start) a local ORG chapter

Page 20: Communications Data Bill: Be Very Afraid

Simon PhippsDirector, Open Rights Group

http://webmink.com