11 ms·
Everyone who can now see your entire internet history, including the taxman
- Kepler-125c 10y agoAnyone reading this from the UK: don't lose hope. You can change things. The recent uptick in fascism in the UK is really disheartening but your voice needs to be heard. For example, they tried to bring in censorship in Australia and failed. Change is possible. Don't be a pushover. You must fight.
- therealidiot 10y agoCareful, those will sound like terrorist words to someone like Theresa May
- akerro 10y agoEasy, she will be banned once porn is banned too, she fucks entire nation after all.
- deleted 10y ago[deleted]
- dogma1138 10y agoIsn't there already an opt out porn filter in the UK?
- setq 10y agoOnly on mobile devices usually. I had to opt out to look at the thinkpad wiki so you can see how well that works.
- akerro 10y agoSame on freebsd forum.
- setq 10y agoEven worse as that's about as legitimate as it gets.
- pmlnr 10y agoAnd I thought it was just me for thinkwiki.org... why on earth is that an adult website?
- setq 10y agoProbably a shared host. All the other sites are porn. Which makes the point about how ridiculous recording an IP address is.
- dogma1138 10y agoI some how doubt that thinkwiki is on a shared hosting. Tons of developer/security websites are blocked on O2 "hacking tools".... They are using the same nonsensical lists that some web gateways use, anything that is even remotely objectionable is blocked.
- dogma1138 10y agoI some how doubt that thinkwiki is on a shared hosting. Tons of developer/security websites are blocked on O2 "hacking tools".... They are using the same nonsensical lists that some web gateways use, anything that is even remotely objectionable is blocked.
- Create 10y agoThey already do. And have been for a long time. No, it didn't get any better either. https://www.linuxjournal.com/content/nsa-linux-journal-extremist-forum-and-its-readers-get-flagged-extra-surveillance https://www.linuxjournal.com/content/nsa-linux-journal-extre...
- akerro 10y agohttps://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- antisthenes 10y agoAnd as always, England Prevails!
- HugoDaniel 10y agoThis is really bad. Using a vpn or other kind of service to hide that data from them will now make you even more of an outlier to even more eyes/people. You will stand out from being hidden, you will stand out for having a minimal "internet history", and you will stand out to those who can really fsck your life. Unfortunately privacy is not being taught and propagated to the general public in order to prevent this from harming you either you want it or not.
- croon 10y agoNew product idea: Sell a pre-loaded rpi with an automated "average user" browser that you install on your network, while you keep using VPN for everything else.
- wilgertvelinga 10y agoSouth Park is on the money again: http://southpark.wikia.com/wiki/TrollTrace.com http://southpark.wikia.com/wiki/TrollTrace.com.
- phaemon 10y agoThe petition against this bill is at: https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- vvvv 10y agoThanks for that, signed. It's absolutely terrifying.
- SeanDav 10y agoThanks for that link - only 35k signatures so far. People are sleepwalking into 1984.
- Warp__ 10y agoIt's rising all the time, 36,680 now! I'm not so sure that many portions of this law will stand up to legal scrutiny.
- TheGrumpyBrit 10y agoNobody wants to sign the list of "People whose internet history we should look at first"
- wastedhours 10y agoMight be a flippant comment, but that's the first thing that went through my mind. I've never gone deep into caring much about government overreach, but that was a terrifying subconscious reaction.
- noir_lord 10y agoWelcome to the Panoptican crossed with a somewhat gilded cage.
- gchadwick 10y agoThis may just be a reflection of the fact that signing petitions (especially online ones) achieves very little. Sure you might get a debate in parliament about it but that debate could involve a handful of MPs and take a few minutes, concluding that everything is fine. This has already been debated extensively in parliament, and got voted through.
- talktime 10y agoShame about David Davis - From this: David Davis: British 'intellectually lazy' about defending liberty https://www.theguardian.com/politics/2015/nov/08/david-davis-liberty-draft-investigatory-powers-bill-holes https://www.theguardian.com/politics/2015/nov/08/david-davis... To this: David Davis: Most public opponent of Theresa May’s snooping laws stops opposing them as soon as he enters cabinet http://www.independent.co.uk/news/uk/politics/david-davis-most-public-opponent-of-theresa-may-s-snooping-laws-stops-opposing-them-as-soon-as-he-a7144296.html http://www.independent.co.uk/news/uk/politics/david-davis-mo...
- rlpb 10y agoAIUI, he is now only allowed to oppose them in private (or leave the cabinet): "All ministers, whether senior and in the cabinet or junior ministers, must publicly support the policy of the government, regardless of any private reservations." https://en.wikipedia.org/wiki/Cabinet_(government) https://en.wikipedia.org/wiki/Cabinet_(government)
- dilemma 10y agoDoesn't sound democratic. Hmm...
- tonyedgecombe 10y agoWell we could vote him out although that is unlikely as he is in a safe Tory seat.
- tehwalrus 10y agoThere is no restriction on where you must live to stand for parliament- I encourage you to stand against him! Although, I would concentrate on Theresa May herself (I considered doing this at the last election when all this was mooted but blocked by the lib dems, but I stood where I live instead.)
- rlpb 10y ago
- edem 10y agoHow can something as intrusive as this make it into a law? This is way worse than SOPA / PIPA was imho. Sucks to live in the UK now.
- joncrocks 10y agoBecause there is rarely anyone arguing against the state being more involved in peoples lives, against making activities of the state harder by safeguarding systems against abuse.
- edem 10y agoBut why is that? I mean in Hungary (where I live) there were demonstrations against Internet Tax which is a much smaller concern. This is a country where a lot of people live in apathy and there is no true democracy. UK is a much mature democracy where people care. Or not? I don't understand this.
- akerro 10y agoPetition Repeal the new Surveillance laws (Investigatory Powers Act) A bill allowing UK intelligence agencies and police unprecedented levels of power regarding the surveillance of UK citizens has recently passed and is awaiting royal assent, making it law. https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- gambiting 10y agoIf I live in the UK, but I am not a citizen, can I sign this petition?
- longwave 10y agoUK residents can also sign, there is a checkbox on the form to confirm you are a citizen or resident.
- ue_ 10y agoJust signed it. Please do the same, any resident or citizen.
- pmlnr 10y agoSigned. Even though it seems like neither online, nor live petitions and demonstrations have any effect on European* governments these days. * geographically
- PJDK 10y agoThe one I always come back to is the National Road Pricing Proposal a few years ago - a big petition (nearly 2 million) completely killed it. It does require a lot of people to get noticed though. https://en.wikipedia.org/wiki/Road_pricing_in_the_United_Kingdom#National_road_pricing_proposal_.282005-2007.29 https://en.wikipedia.org/wiki/Road_pricing_in_the_United_Kin...
- RegW 10y agoThen we keep kicking off serial petitions, until the ignoring of these petitions becomes a story and makes the news - and hopefully wakes everyone up. [edit: How many signatures does it take before the debate has to be followed by an action?]
- kinkdr 10y agoTime for ToR/VPN https://www.digitalocean.com/community/tutorials/how-to-setup-your-own-vpn-with-pptp https://www.digitalocean.com/community/tutorials/how-to-setu...
- jacobp100 10y agoWhich droplet would be best for between one to three people? From what I gather, the ISP has to record the sites you visit—but not the specific pages. Does VPN stop my ISP from seeing the loaded sites? Or do I need Tor for that? I’m not too concerned about complete privacy, I just don’t want every website I just don’t want my browsing history to be leaked.
- dvh 10y agoWith socks5 proxy (e.g. putty supports it), your ISP will only see you are connecting only to 1 IP address. Also if you are visiting https site your ISP only see domain name, not pages.
- noir_lord 10y agoIf you route traffic and DNS to a DO droplet outside the UK, all the ISP sees is a connection to that droplet and how much data was sent, not anything about what it was that was sent. It neatly circumvents this bullshit, some suspect doing so will put you on a list for a closer look but if your traffic is innocuous who cares, I'm more worried about my useless ISP leaking/losing such data than I am about state intelligence. Just the existence of these databases held by ISP's built under lowest cost bids will make them a massive target.
- mikebay 10y agoVPN is your friend. I hope people comes more aware of this government spying. Sad thing is that you needto select carefully services that you use also. Google, Facebook and Twitter you have to avoid. Freedom of speech is a joke these days really. I don't think petitions help anything.
- datenwolf 10y agoThe privacy concerns nonwithstanding, I'm puzzled how ISPs are supposed to actually implement that load of bollocks. We're talking DPI here, applied as a dragnet on each and every connection. The bill explicitly states that every connection is to be tracked, which means it disallows the stochastic methods that normally are used for traffic instrumentation. And even storing "just" the metadata, over the course of a year, that's quite a significant amount of data. Where the hell are ISPs supposed to store that? And store it securely in a way, that only "lawfull" access is possible. That bill is stupid and ludicrous and the people who came up with it should be institutionalized, IMHO. Not just because of the privacy concerns.
- loup-vaillant 10y ago> We're talking DPI here, applied as a dragnet on each and every connection. Didn't Tempora¹ achieve something very similar? This law sounds eerily similar. Still stupid and ludicrous, though. [1] https://en.wikipedia.org/wiki/Tempora https://en.wikipedia.org/wiki/Tempora
- Create 10y agoCreate 291 days ago | parent | on: UC Berkeley profs lambast new “black box” network ... Transparent monitoring for your protection In keeping with this spirit, here is a reminder of how we monitor (your) CERN activities. We monitor all network Traffic coming into and going out of CERN. Our new analysis infrastructure will be able to cope with the automatic live analysis of about one terabyte of data every day. All this data is stored for one year. http://cds.cern.ch/journal/CERNBulletin/2016/05/News%20Articles/2126902 http://cds.cern.ch/journal/CERNBulletin/2016/05/News%20Artic...
- datenwolf 10y agoThat's traffic analysis, not traffic metadata retention. The problem is not the computational load, but the storage capacity and bandwidth requirements. And what is stored at CERN is the analysis results of the data, not the data history itself. Also it's one TiB/day in total for the whole of CERN.
- shad0wca7 10y agoNow is an excellent time to set up a custom home router (I'm thinking pfsense to send all traffic through a VPN). The excuse of "if you have nothing to hide, you have nothing to fear" is not only intellectually feeble; it permits a gradual erosion of civil liberties that can easily find the average citizen on the wrong side of the law should any agency casually find it convenient for them to be so. It is a snowball. On that note. What VPN services are recommended and has anyone got some good guides to this?
- jbg_ 10y agoTo avoid this particular issue, it should be sufficient to rent a server outside of the UK and use OpenVPN. Maybe you even already have one.
- pYQAJ6Zm 10y agoI suggest AirVPN (no affiliation). I’ve been using it for more than a year, and it’s reliable, with plenty of servers and good speeds. If I am not mistaken, it’s operated from Italy. Another option is to rent a VPS/dedicated server somewhere outside the UK, with decent bandwidth and data cap, and configure your own VPN between your systems, using the rented server as the internet gateway.
- vixen99 10y agoNothing to hide? Notwithstanding that Cardinal Richelieu died in 1642, his threat should be wheeled out regularly: "If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him".
- chme 10y ago> Those ICRs effectively serve as a full list of every website that people have visited, not collecting which specific pages are visited or what's done on them but serving as a full list of every site that someone has visited and when. So running search engine crawlers like yacy or using browser link prefetchers, could cause sites to appear on this list, you haven't even visited? Even if you don't use that, you have to investigate every link and external site resource, if it points to a domain/site that also hosts illegal stuff? And how do I do that? Using VPN? Also content and owner of sites change. I can't imagine such "prove" holding up against a good lawyer in a fair court. What exactly are they logging? IP addresses, reverse domain names, dns lookups? They just should provide a white list of sites the lawful citizens are allowed to visit. That would make things much easier and safer for everyone. And the government exists to keep the citizen safe, isn't it? "The first duty of any government is to keep our country and our people safe." - David Cameron
- coldcode 10y agoThat will be the ultimate end game: whitelist of sites, all of them large companies controlled by the government. Either do what we require or be eliminated from the list. Even VPNs only work if the connection to the VPN is permitted.
- jonatron 10y agoThere's more information about ICRs here: https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/504192/Operational_Case_for_the_Retention_of_Internet_Connection_Records_-_IP_Bill_introduction.pdf https://www.gov.uk/government/uploads/system/uploads/attachm... The TLDR is it's netflow data eg: Source IP, Destination IP, FQDN, Date, Amount of Data
- jagermo 10y agoUK citizens, help me out: Is there a way you can appeal against laws like this? In Germany, something like that would be thrown out by the Bundesverfassungsgericht, the federal constitutional court. Is there nothing similar in the UK?
- rwmj 10y agoThe law is being appealed to the ECHR by Liberty and the Open Rights Group and others, so those organizations need people to join and fund them. Link: https://www.dontspyonus.org.uk/ https://www.dontspyonus.org.uk/
- jagermo 10y agoOk - so hyptothetically, if Brexit should happen, there would be no "internal" instance for something like this. That sounds scary.
- Lunar_Lamp 10y agoSlightly more complex than that, as the ECHR isn't an EU institution, so Brexit won't result in any significant change to the relationship with the ECHR (it's a little more complex than I've made sound, as there are some relatively minor links with the EU). However, May has stated her desire to also leave the European convention on human rights (and replace it with a UK owned Bill of Rights). This is not something that's happening as part of Brexit, and no bills have been presented before Parliament with this as a component or purpose. I would assume that the government would take the pragmatic approach that it's better to focus on Brexit for now, and deal with the ECHR once Brexit is over with. However, I have no inside knowledge of this, and that's just my wild and unsubstantiated assumption.
- jagermo 10y agoThank you - damn, i fell right into the "I thought Europe = EU" trap.
- yhavr 10y agoPff, vpn + a service that simulates behavior of a generic user, if one is so scared about suspiciously short browsing history.
- loup-vaillant 10y agoThat's a cost we shouldn't have to bear. An ISP is supposed to send IP packets through, not look into them, dammit.
- moonshinefe 10y agoyeah ok, tell this to the casual user. The flippant response doesn't help anything.
- yhavr 10y agocasual user doesn't see a reason to care about its privacy anyway. if it changes its mind, google already has a lot of guides on the first page of like "protect privacy internet".
- Warp__ 10y agoI would urge everyone who can to sign the petition against it. This, in my mind is a problem, not because of the obvious costs (ISPs storing _literally all_ metadata for a year), and the insidous privacy concerns, but how bad Govts are at keeping information secure. Below are 3 recent and well known examples of Government Mass Data leaks- this information will be compromised at some point, for profit or espionage. https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach https://en.wikipedia.org/wiki/Office_of_Personnel_Management... http://news.bbc.co.uk/1/hi/uk/7449927.stm http://news.bbc.co.uk/1/hi/uk/7449927.stm https://www.troyhunt.com/when-nation-is-hacked-understanding/ https://www.troyhunt.com/when-nation-is-hacked-understanding... IMHO, trotting out "If you've got nothing to hide, you've got nothing to fear" BS doesn't mean that at some point, that data will be misused, even if the UK (My) Government doesn't suddenly turn dictatorial.
- TheGrumpyBrit 10y agoI have lots to hide, and I have plenty to fear from the current government. I sincerely doubt that there's anybody out there who doesn't. I'm not going to worry too much about GCHQ and other Security Services, because I seriously doubt they'll be making any requests - I have no doubt that they have a far more comprehensive database in place already, and they're only included in the proposal to lend an air of legitimacy to the proceedings. What concerns me is the sheer number of groups that are being given access from the start, not because of who is on it, but because somebody has compiled that list in the first place. It suggests that there is already a longer term plan in place for the use of this data, and these are the entities who will need access to achieve that end. Otherwise, surely the approach would be a lot more cautious - "We'll limit it to GCHQ and the Secretary of State for now, and all requestss can go through the SoS. That will give us an idea of who actually needs this data on a case by case basis, and we can tweak the legislation as necessary based on that." Then you look a little closer at some of the entries. Why would the Fire Service need access? Nothing in their job involves anything to do with individuals, at least not to the degree that they have any requirement for access to any data about them. Well, it doesn't say Fire Service. It says "Fire and Rescue Authorities under the Fire and Rescue Services Act 2004". Take a look at that act. Unless you're in Greater London, your fire and rescue authority is your local council. Why did they feel the need to slip your council in through the back door like that? Granted, access is limited to "Watch Manager (Control)", which sort of sounds like a Fire Service position, but it's vague enough that you could legitimately assign that job title to a Traffic Warden's supervisor without anybody batting an eye. Why do the Food Standards Agency need access? Access for them is restricted to Grade 6, which doesn't seem to have any job title definitions, only a pay range - as of August 2015 it was £54,000 to £69,500. So any person who commands that salary, regardless of whether they need it for that job, will have this access? That doesn't seem a particularly clever way to manage data access.
- lordnacho 10y agoSounds like it is both intrusive and useless at the same time. If you're not going to see what people did on a site, what's the point? Presumably nefarious stuff like pedo rings and dark markets will not stay in the same place very long. At the same time, people can see what kind of politics you're into. Or porn. Or dating. Which is not terribly useful for the public interest, but you can see a cop abusing this for personal gain. I think Snowden mentioned his colleagues used to stalk their exes. Also, anyone who's accidentally left WireShark open will know how much data you're sucking up. It's not actually a small amount, and it compounds if you're an ISP. And it sure isn't easy to filter huge pcap files, which you'll have to do if you want to find something specific. And then you have to glue the clues together, totally non trivial. Last, how will this be used in court? Knowing what sites someone visited is not evidence they did something. Some guy visits an ISIS homepage, is that because he's curious or he's getting bomb manuals? At best you can use it to suggest some guy is a sympathiser, when he might well not be.
- deleted 10y ago[deleted]
- nailer 10y ago> I think Snowden mentioned his colleagues used to stalk their exes. It's a matter of public record that MI5 staff have been abusing their powers and had to be disciplined: http://www.thetimes.co.uk/article/mi5-misuse-of-surveillance-law-revealed-rhrdrh6rk http://www.thetimes.co.uk/article/mi5-misuse-of-surveillance...
- noir_lord 10y agoYep and if you think 50-200,000 civil servants/others are going to be any better behaved you'd have to be very optimistic!. That's before some idiot walks out the door with the entire database for an ISP and leaves it on a train.
- m0nty 10y ago> If you're not going to see what people did on a site, what's the point? Because you are not a unique and special snowflake. If you regularly go to /r/The_Donald, it says something specific about your politics (probably). Same for /r/LateStageCapitalism or /r/trees. It might not say much, but it adds up to a profile of who you are and what you think about. If you are emailing certain people, or tweeting them or whatever, GCHQ can build a social graph of people you know, who they know, etc. If you are the friend (or friend of a friend) of a person of interest, you're more likely to be of interest yourself. There are not many criminals like the una-bomber working entirely on their own - most of us need encouragement and/or provocation, and nowadays much of that happens online. If your search phrases include things like "how to make a bomb", you're probably going to be on a database somewhere. There have been numerous serious court cases (e.g. murder trials) where the prosecution have presented evidence that the accused's search history included phrases like "how to dispose of a body" or "how to poison someone". In other cases, jurors have been dismissed for using Google to research the background to the case they are serving on. I wonder where the information about these searches came from? Metadata is important for identifying "interesting" people. When you have found them, you "zoom in" and start hoovering up all the information you can find, not just the metadata. It's the greatest spying tool ever, and a way to implement highly repressive government too - just start monitoring people with different lifestyles or "way out" opinions. http://ghanadailies.com/2016/11/22/uk-government-plans-porn-user-database/ http://ghanadailies.com/2016/11/22/uk-government-plans-porn-... https://www.theguardian.com/commentisfree/2016/nov/23/niche-porn-sites-sex-spanking-website-videos-pornography https://www.theguardian.com/commentisfree/2016/nov/23/niche-...
- jmkni 10y agoSlightly unrelated, but there have been a couple of stories in this area recently which have been widely circulated here and on Reddit all by the Belfast Telegraph. I wonder why that is, just really good SEO on their part?
- dingaling 10y agoMostly SEO. The "Bely Tely" has been moving towards more mass-market tabloid for several years after losing the quality market within Northern Ireland to the Irish News. Yes, within NI a 'southern' paper now achieves about the same circulation as one from Belfast and a considerably better reputation for journalism. Quite a remarkable failure on the BT's part. As a result the BT has been trying to adapt by widening its news remit and shifting into the tabloid space, as a visit to one of its web pages will quickly show. But most of its 'world news' stories are just AP feed, nothing special. My neighbour's fiance is a night-club photographer who sells to the BT; 20 years ago such a thing would have been unthinkable in that paper.
- yason 10y agoHow do they think they can map connection logs with specific persons using the connection? All they can see that from one physical address these particular websites were visited. Sometimes that can actually map to a single person but mostly not. This makes the data more useless than they think but also potentially dangerous if they do not understand what the data means.
- moonshinefe 10y agoIn court they don't often bother with that distinction. If you own the connection, it's considered it's you sending/receiving the data. Not saying that's a correct interpretation, but that's likely the conclusion they'll come to.
- setq 10y agoThis why I do anything nefarious on Tesco free Wi-Fi!
- dogma1138 10y agoI wonder if they understand how the internet works... <iframe src=http://www.isis.com http://www.isis.com style="visibility:hidden"> Welcome to the watch list.
- pmlnr 10y agoSomeone should hack the UK BBC site, Dailymail, etc; and place a few iframes similar to this on them. It would most probably solve this whole case.
- Warp__ 10y agoCopy of a Comment Elsewhere: I don't have anything to hide- but a malicious attacker could easily cause me to. Step One: Maliciously cause the target to click on a link or open a url (Phishing, Exploit, RFE, XSS etc) Step Two: With JS, one can easy introduce HTTP connections to any number of websites, such as maybe the Talibans official website (They have one!), Google Searches for (to think of a few) "Gaziantep Places to Stay", "Turkey Flights", "Opposition to the Kuffar at home", "Dabiq Magazine", "how to join the Khalifah" etc This could easily be done in a realisic appearing manner, especially to ISP/GCHQ filters and alerts. Step Three: If any of this tallies with any physical activity (Let's say the target wanted to go Clay Pigeon Shooting, or Visited a Gun Club because he has in interest in .22 target shooting), then they have a case. Sure, it's defendable, and this is a really simplistic example. But it's basically ruined the target's life. Remember, it's probably not the "Government" doing this, as this info will be leaked.
- interweb-spider 10y agoIt should be noted that over HTTPS even the ISP can only know the domain connected to but not the URL.
- pidg 10y agoThe data that ISPs will be forced to record is just the domain and time of access, not the full URL. The devil is in the metadata.
- ollybee 10y agoReading the legislation its not "Entire Internet history" as most people would understand it. It looks very much like they are asking for NetFlow data without saying that explicitly. They want a Time stamp, port, source and destination IP and amount of data transferred. This is terrifying, I think the “Internet history” narrative is being setup to be deliberately confusing.
- _pdp_ 10y agoI predict that a year from now there will be a massive data leak (perhaps known to some underground circles only) with personal details matched to browser history - why - because most agencies in UK does not know how to handle your data securely. Meanwhile, you better setup your VPN on DO or one of the cheap ARM-based cloud hosting companies. That's what I did and it works flawlessly for as cheap as $5 a month - or the price of a cup of coffee. This setup is fine for all types of activities except downloading larger data files, which can be offloaded elsewhere with some clever routing or just jumping on a different box. I do understand that this might be too much for the average Joe but if you care about your privacy, that exactly what it takes.
- lostboys67 10y agoOr I suspect some bent copper will be caught selling celebs data to the tabloids again.
- Warp__ 10y agoCopy of my comment on other thread: I would urge everyone who can to sign the petition against it. This, in my mind is a problem, not because of the obvious costs (ISPs storing _literally all_ metadata for a year), and the insidous privacy concerns, but how bad Govts are at keeping information secure. Below are 3 recent and well known examples of Government Mass Data leaks- this information will be compromised at some point, for profit or espionage. https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach https://en.wikipedia.org/wiki/Office_of_Personnel_Management... http://news.bbc.co.uk/1/hi/uk/7449927.stm http://news.bbc.co.uk/1/hi/uk/7449927.stm https://www.troyhunt.com/when-nation-is-hacked-understanding/ https://www.troyhunt.com/when-nation-is-hacked-understanding... IMHO, trotting out "If you've got nothing to hide, you've got nothing to fear" BS doesn't mean that at some point, that data will be misused, even if the UK (My) Government doesn't suddenly turn dictatorial.
- dasboth 10y agoThis is an important point. Even if, for whatever reason, you agree with governments being able to access this data in extreme cases (suspected terrorism, whatever) and even if we put aside concerns about governments misusing this power, this bill also relies on ISPs keeping data safe. That is a huge risk in itself. Not to mention the number of government agencies and departments that can access your data [0]. Does the Department for Transport, Food Standards Scotland or the Welsh Ambulance Services NHS Trust really need access to my browsing history? [0]: http://yiu.co.uk/blog/who-can-view-my-internet-history/ http://yiu.co.uk/blog/who-can-view-my-internet-history/
- Warp__ 10y agoYes, I have no idea how an Ambulance Service Middle Management (For Example) needs to know my information.
- nbevans 10y agoThe list of agencies that will have access without any form of court order or warrant is truly terrifying. I had not realised it was so severe. It was promoted as being something that can only be "responsibly accessed". But this does not appear to be the case at all? I'm concerned that information gathered from this will be used in court prematurely to perform "character assassination". And as we know, UK courts have a public gallery full of news reporters searching for juicy stories.
- Paul_S 10y agoWhen China does it it's oppression but when we do it it's for our own good.
- lucozade 10y agoWhen China does it they just do it without mentioning it. When we do it, we announce it in the Queen's speech then have a law be published, read and voted through both Houses. As much as I don't like it, an awful lot of other people either don't care or are fine with it. I wish the result was different but this is what you can get when you have a democracy. I absolutely would not want to swap the systems.
- return0 10y agoHow long before they extend this to VPN users?
- amouat 10y agoIt's not clear how that would be technically possible. ISPs could report users which use VPNs, but assuming the VPN isn't in UK jurisdiction, the govt has no way of forcing the VPN to keep or hand over logs. Their best bet would probably be to hack the VPN provider...
- StavrosK 10y agoIs this possible with TLS? How would they know anything more than the host you're connecting to? Still, though, disgusting.
- Jaruzel 10y agoThe bill details that only the host name is collected anyway. The ISPs will not be compelled to store and share the full URL you visited.
- shocks 10y agoIs it better to go with a VPN service, or rent your own server and DIY?
- jmcdowell 10y agoYea I'm in the same boat, seen a recommendation for AirVPN which seems very affordable and easy to use but then also those recommending to set your own up, is this doable without much knowledge in the area of VPNs?
- Jaruzel 10y agoHave a look at PureVPN also.
- tehmaco 10y agoI've got a couple of cheap VPS's with OpenVPN installed and the bandwidth/latency is best described as "intermittent", as there'll be a lost of hosts sharing it on the low end ones. NordVPN is one I keep seeing talked about, so I'll be looking into them this weekend :)
- shocks 10y agoI heard good things about NordVPN and ExpressVPN. I've been using PIA for a year and it's about to expire - hence trying to decide what is next! Advantages of a service seem to be location switching, good apps, cheap, and IP mixing. Disadvantages are that you have to trust them not to keep logs, and lots of Cloudflare captchas, and they would seem like a good target for being compromised by the government.
- thomc 10y agoIt was clear the UK was going this way for a while so I switched to a small cloud host for VPN which exits in another country. $5 a month and it took only a couple of minutes to setup OpenVPN with a simple shell script[0]. Also important is to setup outbound firewall (or other mechanism) so that if the VPN goes down, you don't spew your traffic over the open connection [1]. I don't notice any speed difference from daily usage over the last year. Large file downloads I task my NAS to download outside the VPN. My purpose is only to prevent the ISP from collecting logs about usage, I don't expect it to have much effect if I'm targeted for surveillance and I'm fine with that. Who knows how ISPs will handle the data (we've seen targeted advertising and content injection in the past) let alone all the agencies with less than stellar security practices. [0]: https://github.com/thomascannon/scripts/tree/master/vpn https://github.com/thomascannon/scripts/tree/master/vpn [1]: https://github.com/thomascannon/scripts/tree/master/vpn/vpn-firewall https://github.com/thomascannon/scripts/tree/master/vpn/vpn-...
- mhrigb 10y ago1235
- deleted 10y ago[deleted]
- drcongo 10y agoThere's currently a very good (and timely) deal on PureVPN lifetime subscription for Black Friday. I have no affiliation here, but figured this might be of interest to a lot of people in the UK. [1] https://deals.geekwire.com/sales/lifetime-of-purevpn https://deals.geekwire.com/sales/lifetime-of-purevpn
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- f4stjack 10y agoMwahaha. Let skankhunt42 worry about this.
- rubberstamp 10y agoI am not from UK, but listen to me if any folks from UK are reading this. This is one of the things that is harmful to your privacy. Should the list of websites that you visit be available for government unless you are under active investigation? Its not just the list of websites but every packet data that your devices send out, which means government could see your messages, data sent to dropbox, online spreadsheet like google docs etc. This is mass surveillance. You should be proud that your government have a website were you can start petitions. Now please use this feature and sign the petition so that this surveillance law can be repealed. The petition against this bill is at: https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199 You sign the petition and ask your close friends and family to do the same. What you do not need is an intrusive government. I am voicing this because even though I am not a UK citizen, I do not want law makers in my country thinking "Oh those chaps has a fine surveillance law and their citizens are okay with it. Lets adopt that law". Now get to action. Sign the petition at https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- ppod 10y agoCitizens are ok with it. There is huge public support for this: https://yougov.co.uk/news/2015/01/18/more-surveillance-please-were-british/ https://yougov.co.uk/news/2015/01/18/more-surveillance-pleas... Don't rely on that one, google for yourself any poll in the last 10 years. In fact, think about just about any issue that you care about but is not current government policy, and google an opinion poll on it. You'll begin to see that democracy functions very effectively indeed. There are exceptions, such as the death penalty in the UK, but mostly legislation follows the opinion of the public (the voting public actually) quite closely, as we see with gay marriage and drug decriminalisation.
- zerebubuth 10y agoA little over half of those polled were okay with "Police and intelligence agencies [having] access to this information for anti-terrorism purposes". The YouGov report also shows that there's much less trust in politicians and civil servants to "behave responsibly" with such data. The Guardian article says that "[records] will be made available to a wide range of government bodies", which sounds like politicians and civil servants to me. Given that the government doesn't have a great track record of proportionate use of these powers, I think this isn't the same as the question asked in the poll. (For example, at a local level http://www.telegraph.co.uk/news/uknews/3333366/Half-of-councils-use-anti-terror-laws-to-spy-on-bin-crimes.html http://www.telegraph.co.uk/news/uknews/3333366/Half-of-counc...) [Edit: grammar and clarity.]
- deleted 10y ago[deleted]
- rubberstamp 10y agoLike I said in the other thread https://news.ycombinator.com/item?id=13034747 https://news.ycombinator.com/item?id=13034747 I am not from UK, but listen to me if any folks from UK are reading this. This is one of the things that is harmful to your privacy. Should the list of websites that you visit be available for government unless you are under active investigation? Its not just the list of websites but every packet data that your devices send out, which means government could see your messages, data sent to dropbox, online spreadsheet like google docs etc. This is mass surveillance. You should be proud that your government have a website were you can start petitions. Now please use this feature and sign the petition so that this surveillance law can be repealed. The petition against this bill is at: https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199 You sign the petition and ask your close friends and family to do the same. What you do not need is an intrusive government. I am voicing this because even though I am not a UK citizen, I do not want law makers in my country thinking "Oh those chaps has a fine surveillance law and their citizens are okay with it. Lets adopt that law". Now get to action. Sign the petition at https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- jyriand 10y agoAny ideas who will pay ISP's for supporting this kind of tracking? Customers or goverment?
- wtk 10y agoI rarely sign anything, but I had to do it this time. https://petition.parliament.uk/petitions/173199 https://petition.parliament.uk/petitions/173199
- zerognowl 10y agoIn typical UK surveillance state fashion they pander to base fears and unforgivably overlook how bad censorship and surveillance is in places like China. It's not that the UK GOV "doesn't understand how the Internet works" as claimed by many on this topic, but that the citizenry don't care enough to encrypt. The citizenry aren't scared enough to encrypt. Education is the key here, and it needs to be bashed into a citizen's skull that The Internet is not a black box, and that traffic moving en clair is fair game by Governments, even criminal threat actors in Starbucks with their fake Free Wifi. We need to keep building abstractions on top of The Internet to make it expensive for spying to take place. The usual solutions apply; TOR, VPNs, TLS/SSL, PGP, et al.
- yagga 10y agoOur whole civilization leap frogged forward with the invention of the Internet. Because it connected us humans mentally. We able to share thoughts and ideas and have conversations with anyone on a planet without physical movement. It is a mechanical telepathy if you think about. What we are seeing with implementing such laws is a more larger trend. Mental world is being taken under control by Mr. Smiths, agents of the matrix. Our thoughts and self-expressions more than ever are under the surveillance. What I don't know is whether it is a good or bad thing in general for the mankind, but they way our technology worshipping civilizations develops it seems to be unavoidable. It seems we are way too far in this to go back.
- jasonkostempski 10y agoI would imagine telepathy being something more accurate than other forms of communication, this is more like having a transcript of every communication and loosely assigning accountability to content.
- yagga 10y agoSo true. Thanks.
- besselheim 10y agoOnly the connection history - hostname and date/time of access, and only if authorised for an investigation. It's akin to the phone companies logging each number called. This isn't as intrusive as people are making it out to be.
- balabaster 10y agoI will seriously never understand the imbalance of resources spent and the bills and laws passed in the name of "fighting terrorism" and "think of the children" which affects less people every day than pretty much every alternative way to suffer and die. It doesn't make any sense. We spent trillions of dollars every year making intelligence and the military war machine one of the largest shadow economies in the world... We could pretty much solve every other form of death and illness with that money in less time, we could raise everyone in the country out of poverty with that money so they could stand on their own two feet. We could educate those that need education so they could get jobs and stand on their own without the need for Government handouts. So what the fuck. Some days though, all you can do is throw your hands in the air in resignation and say "Fuck it, you're all crazy! You cause problems and you spend billions of dollars to band-aid the symptoms, just like you do with your medical system." The underlying cancer is this mentality. We'll do what the fuck we want and treat people the way we fucking want because it makes us rich and then we'll spend billions to deal with the symptoms of this dumbass behaviour. I hope the riches are worth it because the behaviour is (and I don't treat this word lightly, nor do I mean it with any disrespect whatsoever to those that unfairly get labeled with it) retarded.
- abecedarius 10y agoYes, it would be stupid as a policy for the common good. But the common good is not really anyone's job. You know that XKCD comic about standards? ("Now you have n+1 of them.") Modern governance after a few centuries of evolution is like that times a million, and this misadapted collective decision-making is the great crisis of our time, a much bigger deal than climate change, for example. (If we could collectively think clearly and coordinate then we'd see climate change as a serious problem needing both immediate action and longer-term research and technology development, but probably well within our power.) Programmers might help by making better tools for thinking and coordinating. Perhaps with a collective IQ boost for enough of us we can avoid the worst.
- noir_lord 10y agoHumans are absolutely terrible at assessing risk probabilities. People worry about flying when stastically they are far more likely to die on the drive to the airport. They worry about terroism when they are 50lbs overweight. ...and on and on, You'd rather hope the government would be better at assessing these risks in terms of a policy framework but they aren't they appeal to whatever the papers are focussing on and subscribe to the "we must do something, this is something ergo we must do it" school of thought. It's worrying how far we haven't come.
- jeffbush 10y agoI think for many people nowadays, privacy is a quaint, antiquated notion, like Victorian modesty. Things like social media and YouTube have encouraged people to make their lives public, so having the government gather data seems fairly minor. I find this all very disturbing, but, having grown up without the Internet, perhaps I'm just a relic from a bygone area. Still, I can't shake the uneasy feeling that this all will lead to a very bad place...
- johnmiddleton 10y agoThe only people that this is good news for are the VPN providers. Do we really trust "the state" with this information. History should tell us that once can never be sure of what use data can be put to by future regimes. It's time to educate people about the value of encryption and the security and safety it provides, each of us, one by one.
- hx87 10y agoMight as well make it available to everyone then. If we can't have privacy we should at least have transparency.
- Cpoll 10y agoThis is a good thing. With such a wide "readership," the data's bound to leak. When it does, it will make Ashley Madison look like a small thing, and be a good argument against future surveillance.
- thesmileyone 10y agoGlad this topic came up here. So my question is...how to block it? VPN? Also what stops them selling access to this?