23 ms·
French bar owners arrested for offering free WiFi but not keeping logs
- rbecker 6y ago> The bar owners were arrested under a 2006 law that technically classifies WiFi hotspot providing establishments as ISPs, and requires them to store one year’s worth of logs or connection records for anti-terrorism purposes. I was under the impression that the European Court of Justice held data retention laws to be a violation of fundamental rights, and thus illegal: https://www.theinfostride.com/data-retention-directive-invalid-says-eus-highest-court/ https://www.theinfostride.com/data-retention-directive-inval... https://en.wikipedia.org/wiki/Data_retention#European_Union https://en.wikipedia.org/wiki/Data_retention#European_Union
- 02020202 6y agoIt's France, don't worry about it.
- zach_garwood 6y ago"Forget it, Jake, it's Chinatown."
- Hamuko 6y agoJust because the ECJ deems something illegal, it doesn't mean that local legislation is updated. It sounds a bit like that 2006 law has not been challenged in courts.
- dogma1138 6y agoThe blanket requirement in the directive was deemed unlawful, however it does not invalidates data retention legislation in member states.
- corty 6y agoAlso, the media mafia in France is particularly strong and French politics are firmly in their pockets, a bit more so than in the rest of the world. Which means that they will hold on to as strict a suppression of free internet as possible, as long as possible.
- pyrale 6y agoThis law is unrelated to the show business, a downloaded song will never warrant a court order to the ISP in the first place. There is a separate (and very inefficient) enforcement mechanism for copyright fraud.
- corty 6y agoDon't know about France, but in Germany similar rules were of course introduced for the usual pretend reasons of child porn and terrorism. A short time later, minor crime investigations and then civil matters were added as reasons to access ISP data. So even if the law currently isn't used like that, it very soon will be and that was most probably always the intent. In Germany, accesses for copyright prosecution far outnumbered everything else, serious crime was only ever a very minor amount.
- pyrale 6y agoThere are exemptions for regulatory purpose.
- djsumdog 6y agoThere has to be more to the story here. With the law starting in 2006, why are authorities just now going after these bars? Did something specific start this, or is it just the growing authoritarianism that comes with these endlessly long national emergencies?
- zahma 6y agoYou're probably right. There must have been some activity that drew the attention of law enforcement. It is a de facto obligation for cafés to offer free internet, so it's surprising to see such a law enforced in Grenoble of all places. My friend's café in Paris just has a password protected network, and I know for a fact they do not log traffic. I have seen other cafés with a registration system, and I'd bet those networks maintain logs. For the smaller cafés, even if they knew they had to, I'm not sure they would have the technical know-how to maintain logs. They've had some problems with piracy in the past, so perhaps that might have something to do with the arrests in Grenoble. If torrenting or some other form of piracy happens on a network, ISPs send letters to that IP's customer, giving them a warning. Perhaps these café owners were repeatedly warned to enact stricter measures against piracy (i.e. logs), and, failing that, they were arrested for failing to comply with other regulations that are actually enforceable. I can't imagine a café owner could ever be charged with piracy for maintaining an open network. For what it's worth, I looked around Le Monde and some other news sites to find more information, but there isn't much info to expand on the fact that these people were arrested.
- joubert 6y ago> It is a de facto obligation for cafés to offer free internet What do you mean by this?
- tenuousemphasis 6y agoPeople expect places like this to have free WiFi.
- 6y ago
- Raed667 6y agoI'm living in France, and "just" sharing the WIFI password is a very common practice in bars, coffee-shops, etc.. I only know of few places that actually use a compliant captive portal that requires some PII (name, email, phone...) to let you use the free WIFI. My problem with these kind of laws is that they get ignored most of the time and then allow for selective enforcement when the police/local-gov has issues with you.
- dogma1138 6y agoMost laws are ignored most of the time and selective enforcement is essentially the corner stone of modern policing, there are many more laws that can be effectively enforced and which laws exactly are at any given time is based on available resources and public policy.
- FpUser 6y ago>"Most laws are ignored most of the time and selective enforcement is essentially the corner stone of modern policing" In this case it is not a law, not in spirit. Rather a tool for "law" enforcement to nail inconvenient people.
- everybodyknows 6y ago>based on available resources and public policy You missed a few criteria: - Cultural, political, racial grievances of police. - Cultural, political, racial prejudices. That is, maybe no ill will per se toward a citizen who looks a certain way -- but assumed guilt by association. - Personal ambition, to be pursued by making lots of arrests, on maximal charges. - Fear. End of month approaching, and beat officer is behind on quota of citations/arrests. Punishment expected from chief or DA, if revenue from fines, or prestige from high-profile arrests are lacking. So, it's the selection of offenders, rather than of offenses due to resource constraints, that makes selective punishment so ethically offensive.
- dogma1138 6y agoThese technically fall under public policy, poorly aligned incentives and or insufficient judicial/executive oversight. If officers feel that they need to make their quota or even have an arrests/infraction quote then that's a clear failure of policy, if they feel that they can settled their own grievances by abusing their power it's again a failure of policy.
- heavenlyblue 6y agoWhy does a bar need to collect those logs if you could just make internet providers collect those?
- ComodoHacker 6y agoProviders record where you go, the bar records who you are.
- heavenlyblue 6y agoBut practically when I do this in the UK I can leave any information I want including my neighbour’s name and then start Googling for “bomb design at home without getting caught”
- unicornfinder 6y agoNot to mention VPNs exist
- DavideNL 6y agoPerhaps because bars can also store the devices MAC address which helps identify it... (recent iOS devices use random MAC addresses by the way for improved privacy in which case i think this wouldn't help/identify a device anymore.)
- netsharc 6y agoRandomized MAC addresses is a neat idea, it also helps bust through the time limits of free WiFi that only give you something like 30 minutes per day (because they use the MAC to identify if you've used up your 30 minutes).
- xaqfox 6y agoAndroid version 10 or over uses randomized MAC adresses by default, as well.
- CivBase 6y agoHow does this law reconcile with the GDPR?
- garyrichardson 6y agoThere are usually carve outs for security and “won’t someone please think of the children”
- gostsamo 6y agoGDPR allows for data required by law. Same is with payment and all kinds of banking information.
- CryptoPunk 6y agoData collection that is required by law enforcement is exempted from GDPR regulations.
- corty 6y agoNo. All regulations apply except for the right to (premature) deletion and the necessity of (another) reason for the data collection. Very much a situation of one regulation putting you in the crosshair of another one.
- CryptoPunk 6y agoThe Wikipedia page for GDPR says data collection for the following purposes is exempted from the regulations: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula... >>Lawful interception, national security, military, police, justice
- corty 6y agoThe article is between imprecise to wrong. A box above the respective paragraph says so. Article 2 contains said exceptions, but limits them to "member states" and "competent authorities. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02016R0679-20160504 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02... So only a government office would be exempt in those matters, not a private organisation, except when seen as performing a government function. That is somewhat up to interpretation, so maybe, maybe not.
- thraw201004 6y agoYet a paternity test is not allowed without the potential fraudsteress's permission.
- johnchristopher 6y agoS'funny because a few months ago, before I was robbed of my job, one of the big question in the tourism field was "what should we do about GDPR and logging regarding WiFi access in rented cottages and the like ?". No experts had any answers and it all came down to a laissez-faire attitude. My stance was: just rent out a WiFi portal for 5 bucks a month to offload the responsibilities on a third party. Just in case. The fact that the UMIH hides behind a mention of this problem in a newsletter speak volumes of how well informed they are and what services they bring to adherents.
- oneplane 6y agoRobbed of your job? How does that work? Someone comes for you with a weapon and yells "Your job or your life!"?
- salawat 6y agoSeeing as the poster seemed to work in the tourism industry, they may be chafing a bit due to present circumstances.
- oneplane 6y agoSo his job wasn't robbed but simply no longer required at the scale that it was before, resulting in fewer people needed to do it.
- salawat 6y agoI tend not to begrudge folks the right to be bitter or feel disenfranchised at the world. We all get the butt end of things in our own time, and it's never fun losing it. The market shifting, leaving one high and dry, while inevitable, should not obligate someone to be chipper and happy-go-lucky about it.
- mdpopescu 6y agoThis attitude, I believe, is at the root of 90% of the so-called market failures. This was a clear, direct intervention of the state in the market. The guy above me calls it "the market shifting". It would be ridiculous as parody.
- imglorp 6y agoKeeping logs seems like a high bar for a non expert with a commodity home ap/router. A $US40 WRT54G only has 4mb of flash, for example. Are they expecting lay people to spend 10x that or more to set up an external log aggregation server with DPI and audit trail?
- deleted 6y ago[deleted]
- kleiba 6y agoIf you're a lay person you have the option to hire someone. Let's not forget, we're talking about businesses here (bars), not individuals.
- cultus 6y agoHiring an actual IT person to set it up would be a very difficult expense for many small businesses. Cafes usually operate on very tight margins. I just find this law completely ridiculous and an obvious result of hysteria. It is not a rational response to the very tiny risk of the dastardly and scary terrorists using free wifi.
- pbhjpbhj 6y agoAs all businesses require it the chances that ISPs don't offer a service that includes that feature seems extraordinarily low. Seems like knowingly selling a service that wasn't capable of logging, under a legislative background that requires it, would also likely be unlawful.
- kleiba 6y agoNo-one is forcing you to offer free wifi. Like with any business decision, you need to weigh the cost of the investment versus the expected return.
- R0b0t1 6y agoApparently. Laws being divorced from reality isn't a new thing.
- hprotagonist 6y ago“register with your email to use this wifi” seemed very common in the EU the times i’ve been there in the last 5 years. All i have to say is that butts@butts.com logs in with the password “butts” at a truly surprising number of cafes across europe!
- microcolonel 6y agoMaybe there should be a "butts was here" sticker.
- Izkata 6y agoHave you heard of "warchalking"?
- scurvy 6y agoSounds like it's time to bring back BugMeNot.
- michaelt 6y agoAccess BugMeNot to get a password to connect to the internet, you say?
- scurvy 6y agoIntegrate it into KeePass or 1Password. I'm sure Yahoo will pay a billi for that.
- progval 6y agoI once had a similar issue with a hotspot, that required email confirmation but didn't let me access my email. It's possible to work around when you have a phone connection with limited bandwidth and a low monthly cap, but meh.
- LeoPanthera 6y agoWhen I was a young lad, it was standard practice for many internet apps to work on the principle of local caching. You'd connect to the internet, refresh your local copy, disconnect, and then work from the local copy. NNTP worked this way, POP3 worked this way. There were even apps that grabbed the current news and stock prices in the brief minutes that you were connected. It's a good model, and it would work well here, and for any circumstance when your connectivity is intermittent.
- JdeBP 6y agoThe original piece is at https://dna.fr/faits-divers-justice/2020/09/27/en-garde-a-vue-a-cause-du-wifi-de-leur-bar https://dna.fr/faits-divers-justice/2020/09/27/en-garde-a-vu... .
- mytailorisrich 6y agoThe fact that the article states that this happened to several bars, all in Grenoble suggests that there is probably more than meets the eye. There is a lot of mafia activity in Grenoble and bars (as well as pizzerias and night clubs...) are notorious for being fronts and for whatever other dodgy activities. I would not be too surprised if the bars in question have links to the criminal world and the police simply used whatever hard evidence of wrongdoing they could find to bring them down or perhaps as a way to gain further access to documents, etc. I'm pretty sure that a bar owner "unknown to police services" (as they say) would simply receive a warning that logs must be kept, at least at first.
- gruez 6y agoThis seems like a just world hypothesis rationalization of the civil rights abuse that's going on. It's basically saying "they must be guilty, otherwise they wouldn't have been arrested!". Maybe this time they really are The Bad Guys, but the problem is that if this behavior is tolerated, it's very possible for the police to do the same for dissidents, activists, or someone who pissed off the mayor.
- crazygringo 6y agoI don't see the parent comment as defending it, merely describing it.
- mytailorisrich 6y agoI must say I do not understand the hostile replies to my previous comment. Like it or not, the law mandates something and thus that must be complied with. Now, despite what some people might like to think, the police do not barge in and arrest people as soon as they notice that they are not keeping logs. If they do arrest someone for this that person is a repeat offender or someone who's in police's sight for serious criminal activity. That's simply the mundane reality. Of course reality does not lend itself well to outrage....
- bigbubba 6y agoIn other words, taking Al Capone down for tax evasion. But as I understand it, taking down Al Capone in that way was only necessary because at the time the laws now used to attack organized crime (RICO for instance) didn't yet exist. If France doesn't presently have laws that allow the government to attack these sort of organizations [doubt], they really should be writing such laws instead of leaning on selective enforcement of chickenshit violations.
- xiaodai 6y agoAnd China is a police state...
- epr 6y agoI'm confused. Aren't these registrations on wifi usually (almost always?) tied to a spoofable mac address? In that case, can't any competent bad actor simply record traffic to pick up mac addresses of others on the network, then impersonate them?
- crazygringo 6y agoIt's still useful for all sorts of things. Knowing when connected/disconnected, so you can check surveillance cams for people going in and out of the cafe, or nearby on the sidewalk, around those times. Checking if the same spoofed MAC address reconnected at other times, or in other nearby cafes. Maybe you can figure out what VPN they connected to. And so on. It's just a tool that can sometimes be useful in a multitude of ways, even if the MAC address is spoofed.
- ThinkingGuy 6y agoWhen they say the law requires "logs," precisely what information are the referring to? MAC address of the connecting device? Personal info of the device owner? Websites visited? SSH sites connected to? DNS queries? All of the above?
- mrkramer 6y agoProbably MAC addresses and DNS queries.
- microcolonel 6y agoI believe they are required to gather PII and tie it to the connection.
- hansvm 6y agoMildly off topic: When entering fake information into captive portals from bar owners who actually comply with bs laws like these, please take care to use something like a `.invalid` tld so that some unsuspecting third party isn't suddenly subject to your emails. <your_handle>@gmail.invalid works basically everywhere.
- dylan604 6y agoI'm sorry, but if you have a valid email address of butts@butts.com, then you deserve the spam. Also, if you do actually own that address, thanks for hosting it so that bounce tests don't fail immediately!!
- gruez 6y ago>[...] so that some unsuspecting third party isn't suddenly subject to your emails why not something like byfmupajzmvdaxef@{gmail.com,outlook.com,yahoo.com}? I doubt that large email providers are going to be inconvenienced by the spam. Your solution is likely to get rejected by overzealous form validation (for good reason!).
- kubanczyk 6y agoYou've probably meant: ';drop+table+users;@gmail.com
- baobabKoodaa 6y agoLittle Bobby Tables, we meet again.
- contravariant 6y agoNot technically a valid email, although you could try "';DROP TABLE USERS;--"@gmail.com Weirdly enough it's the semicolon that isn't allowed, not the single quote.
- kubanczyk 6y agoNah, it will pass many validators even with semicolons (like http://emailregex.com http://emailregex.com, which yours would fail btw). You are right though about better leaving spaces verbatim and adding the hyphens.
- mrkramer 6y ago"public WiFi users in France need to make sure they never connect without a VPN." There is probably a law which says VPN vendors need to keep logs otherwise their anti-terrorist laws are short sighted.
- crazygringo 6y agoWhy now, and why these specific 5 restaurants? It definitely feels like a pretext for something else going on, who knows what -- whether it's a police racket or something shady going on in the restaurants they're sending a warning about. This is what these obscure, rarely-enforced laws seem to exist for in the first place. If the police were really interested in enforcement over this, they'd send a letter to every restaurant, bar, and cafe owner in the country that they have 3 months to comply and it will become part of regular inspections. Targeting 5 individual restaurants (through arrests) is definitely not about simply enforcing this regulation. Note: I'm NOT defending this as a legitimate law enforcement tactic. Just describing what seems to be happening.
- lorenzorhoades 6y agoWell... Sending out a letter can get lost in the junk mail,. I'm sure the other establishments got this message though.
- aksss 6y agoWell put.
- nraynaud 6y agoThere are currently 2 local factors: - the Charlie Hebdo attack is currently on trial, and during the trial it was revealed that the weapons were sold by a police informant who had sent a report on the sale to his handlers, and that they did nothing. In particular the sale happened in a place chosen to give the police the option to either monitor or interrupt the sale. - there is a current increase in the monitoring and criminalisation of muslim activities in France, my guess is that the police wanted to spy on someone and found out that the logs had not been kept.
- throwaway0a5e 6y ago>there is a current increase in the monitoring and criminalisation of muslim activities in France, my guess is that the police wanted to spy on someone and found out that the logs had not been kept. Inconveniencing the police is a surefire way to get prosecuted to the fullest extent of the law.
- jacknews 6y agoIf only they'd used Alcatel routers, then 'authorities' could have monitored everything through the back door, and there would be no need for private logs.
- shoulderfake 6y agowhy do you need logs?
- kazinator 6y agoJust find out what the logs look like and write a script to randomly generate them.
- layoutIfNeeded 6y agoAt my first job we were developing a huge enterprise app in J2EE, where clean build times were around 15 minutes. We also had tons of issues with the toolchain for which the “solution” was “mvn clean install”. So I made a small program which printed snippets of pre-recorded Maven build output in an infinite loop, and launched it on my second screen whenever I wanted some time off from coding that enterprise crap. Nobody would complain that I’m browsing Facebook or swiping in Tinder, as I was clearly waiting for the “build” to finish :)
- jagger27 6y agoThis reminds me that I should setup a proper captive portal for my family’s restaurant.
- p0nce 6y agoLiving in this particular french city, I actually need these WiFi access to work, be it logged or not. Many independent workers resort to bars and café as cheap coworking space and this may just going to lead owners to stop offering WiFi (which is often quite necessary). SO again I'm not sure why this one city is targetted but surely it has to do with he recent feud with the ministry and the city mayor.
- Zigurd 6y agoYC idea: Lint for law Lint doesn't have to be perfect, especially when faced with a "code base" that's chaotic and full of dubious legacy. "Code review" in the form of constitutional cases and legislative attempts at reform are a severe bottleneck. Automation that flags egregious smells and incompatibility seems valuable. A state that claims a "cleaner" code base could use that to attract business looking for lower legal overhead.
- boopmaster 6y agoFrench bars and cafes desperately could use VPN services that secures DNS, thus the logs would be MAC addresses and a single endpoint, with time stamps/ durations only.
- icco 6y agoIs this reported anywhere in a more major publication? This lacks so many details.
- offtop5 6y agoI feel like it would be vastly easier to just not offer WiFi. Many coffee shops turn it off on weekends , to "encourage socialization"( as in stop people from sitting around for hours ).
- epicureanideal 6y agoRecommended book: "By the People: Rebuilding Liberty Without Permission"
- sytelus 6y agoMost routers don't even support keeping logs. Where these laws come from?
- touristtam 6y agoFor anyone crying about this: * Noone is supposed to ignore the law (that's the motto in France judicial system) * This was a law enacted in 2006: https://en.wikipedia.org/wiki/Law_on_the_fight_against_terrorism https://en.wikipedia.org/wiki/Law_on_the_fight_against_terro...
- dzink 6y agoAny place (country, city, you name it) where people have high trust in government is authorized to develop a lot of laws to "protect" citizens. Part of the trust comes from the fact that laws are not enforced (the more you have, the less anyone knows them all) and most voters feel like they are on the "good" side of the law. However the more obscure laws and rules are out there by different agencies, the more the legal profession becomes a power. Those wealthy enough to afford multiple lawyers or tax experts also become unscathed. So government starts burdening its regular citizens far more than the most powerful. If the government, or a corrupt official, or a really bad dictatorial newly elected official ever has beef with you, or is short on money because of uncontrolled spending, they can always find a rule to convict you by to extract whatever you have they need (a decision by your company, or a vote, or your money, etc). So leftover regulatory debt needs some kind of mechanism to be cleared, or a system needs to be created that allows you to thoroughly evaluate your standing with all rules. Or you do a civic test every year and if majority of people don't know about a rule in it, the government has to drop that rule (so it puts an onus on the government to not only clean up its laws, but communicate them better, and fix/reduce them if it cant be clear about the rule).
- dang 6y agoWe changed the URL from https://www.cozyit.com/french-bar-owners-arrested-for-offering-free-wifi-but-not-keeping-logs/ https://www.cozyit.com/french-bar-owners-arrested-for-offeri..., which appears to have been outright plagiarism. We've banned that site as well.