7 ms·
On the new Dutch intelligence and security law
- ahubert 3y ago(happy to elaborate if there are any questions)
- repelsteeltje 3y agoSo, Dutch intelligence basically has legal leeway to pry anywhere. But I'm curious how they would hand over some "fact" to Police whom cannot normally access that information without some kind of warrant or legal approval from public prosecution. How does that work in practice (under Dutch law)?
- twsted 3y agoIsn't there any European law that could stop this exaggerated and self-granted power?
- ahubert 3y agoYes, parts of this law are very likely to be struck down by the European Court of Human Rights, if a case ever gets there. Specifically the 100% automatic powers to hack and intercept anyone who is hacked by state backed hackers are pretty unlikely to be legal under the ECHR.
- mk89 3y agoThere is literally nothing that can win against national security as "state actors (Russia, China, even mentioned in the text) trying to sabotage your infrastructure - look we have evidence but we're not gonna share it with the public".
- wolverine876 3y agoDo you mean that's a specific legal argument that is upheld in European courts or Dutch courts?
- mk89 3y agoNo, I would say that's just life experience until now. Nothing ever wins against "we need to keep the country safe".
- repelsteeltje 3y agoTaking the perspective that spying is warranted by the asset under threat rather than subject potentially posing it ... that is some pretty scary piece of legislation.
- HarHarVeryFunny 3y ago[flagged]
- sph 3y agoLet's try for once not to divert and sidetrack any world news topic with what the US is doing, please? Not everything should be an opportunity to talk about YOUR country.
- deleted 3y ago[deleted]
- HarHarVeryFunny 3y agoOK, but that wasn't my intent. I really meant who are we (the US) to criticize the Netherlands when we are doing the same ourselves (and not even fully admitting it). But, I can see that if you are from the Netherlands yourself, then you may very much want to - and have every right to - criticize it! Sorry.
- ethanbond 3y agoNow define “something suspect”
- dylan604 3y agoYou'll know it when you see it.
- idkdotcom 3y ago[dead]
- sib 3y agoWhen was the last time that something titled a "Temporary Cyber Act" was ever temporary (other than being replaced by something worse)?
- klabb3 3y ago“Nothing is so permanent as a temporary government program” – Milton Friedman
- ahubert 3y agoIt has already been announced that this law will likely be extended. They later walked that back, but did admit that it is entirely possible to extend this law.
- givemeethekeys 3y agoHey, you have to applaud them for naming it "temporary", instead of "patriot". What are you? Some kind of a treasonous terrorist? How dare you oppose THE PATRIOT ACT?! /s
- nsteel 3y agoThey get zero marks because it doesn't appear to be an acronym.
- peeters 3y agoIt needs more "Democratic" in it to make it clear it's definitely not authoritarian. Maybe "The Democratic People's Temporary Cyber Act for Freedom"
- deleted 3y ago[deleted]
- divbzero 3y agoGiven the prevalence of TLS, how much SIGINT can actually be done by tapping internet exchanges these days?
- gigel82 3y agoPresumably a government could also requisition the private key of several root authority certificates (whether or not they "proudly announce" that is another matter).
- repelsteeltje 3y agoDutch government doesn't have a good reputation there, shepherding control over security infrastructure. First, it's primary CA lost is signing key to Iran, and recently they meant to outsource control over their ".nl" TLD to AWS.
- mrngm 3y agoSmall addendum on that, DigiNotar was one of the four CA's handing out "PKIoverheid" certificates, so certificates for governmental purposes. See this archived copy of the FAQ (in Dutch) after the DigiNotar breach, specifically the question "Hoe weet de overheid dat certificaten van de 3 andere bedrijven in Nederland die PKI-overheidscertificaten uitgeven wel betrouwbaar zijn?": https://web.archive.org/web/20111019224308/http://www.rijksoverheid.nl/documenten-en-publicaties/brochures/2011/09/05/vraag-en-antwoord-over-diginotar.html https://web.archive.org/web/20111019224308/http://www.rijkso...
- amenghra 3y agoA root CA key doesn't automatically decrypt the TLS traffic. You just need a single root CA key for a widely trusted CA to perform an active MITM attack. The attack is however likely to show up in Certificate Transparency logs.
- vmoore 3y agoOther metadata like DNS, device fingerprints, SNI-leakage[0], timestamps, connection history, etc You can encrypt DNS with DoH if you want, but the DoH provider still sees its you. You can take it a step further with Oblivious DNS over HTTPS if you really want to conceal DNS activity[1]. Note: this technology is rather new and experimental. [0] https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication [1] https://research.cloudflare.com/projects/network-privacy/odns/ https://research.cloudflare.com/projects/network-privacy/odn...
- ls612 3y agoHow much cleartext is sent over the net? Nowadays almost everything is encrypted, even things like DoH are becoming standard via Cloudflare/Apple Private Relay.
- ipaddr 3y agoThey all work for the same team
- jrockway 3y agoIf I were a politician using this against an opponent, I'd write the following press release: Websites in the range 54.239.0.0/8 often host problematic content. My opponent visited several addresses in this range overnight and hid his traffic with military-grade message scrambling functionality. Of course that's just AWS and you can't even do HTTP/2 or HTTP/3 without encryption. But do the voters know that? Will they be educated on it? Probably not. And you're not saying anything untrue, you have facts and logs to back up your assertions!
- sva_ 3y agoI'm not a crypto expert by any means, but it is my understanding that government actors of larger countries probably have trusted CAs in most devices on the planet that they have control over, and they could issue certificates for arbitrary domain names; and your devices would for the most part be none the wiser. Of course this is only relevant for targeted surveillance, not mass surveillance. Happy to be corrected though, I've been wondering about this.
- ls612 3y agoThis is precisely the threat model that certificate transparency mitigates.
- mrngm 3y agoPerhaps think a bit smaller, and look at companies that operate office-sized TLS interception by installing a CA certificate on each (managed) end device, and generating certificates on-the-fly from that CA. Then, some middlebox is able to inspect the encrypted communication that passes through. Some web browsers have pinned certificates for certain services, Google Chrome/Chromium being one of those. Subsequently, the browser refuses to perform any more actions towards the server that serves an invalid (according to the browser) certificate. That browser is also one of the reasons the DigiNotar case in 2011 emerged to the surface.
- vmoore 3y ago> to protect The Netherlands against Russian and Chinese hackers So it's a noble cause then? Or does it have privacy implications for innocent netizens? I thought these exchanges would have been tapped in some form way before this announcement?
- sspiff 3y agoThe new law also lowers the bar for Dutch law enforcement to obtain records from these taps significantly, removing the necessity of a judge to rule whether the request is justified in the investigation. Surely no law enforcement would overreach when given tools like these, right? Right?
- davedx 3y agoYeah the Belastingdienst would never do anything naughty with powers like these. Let them in on it too!
- Notatheist 3y agoThey've already overreached in the past. https://nos.nl/artikel/2432715-inlichtingendiensten-moeten-grote-bak-data-burgers-verwijderen https://nos.nl/artikel/2432715-inlichtingendiensten-moeten-g... https://www.rtlnieuws.nl/tech/artikel/5294998/aftappen-aivd-mivd-tappen-inlichtingendiensten-privacy-internet https://www.rtlnieuws.nl/tech/artikel/5294998/aftappen-aivd-...
- coldtea 3y ago>So it's a noble cause then? If you consider "to play its part in the trade war between US-China which is extending into real WW 3" as noble, then yes, it's noble.
- lionkor 3y agoI wanna be noble, too! Where's the form to sign up as a proxy for some war?
- freedomben 3y agoIt's called "temporary" but I don't see anything about when it is removed. Even with a sunset period (like the US Patriot Act had) it's not typical for states to give up power like this, so I'm guessing this is the new normal :-( Is there specific intelligence leading to this? It seems very to the point about being related to Russia.
- fallingknife 3y agoThe Patriot Act was temporary too...
- shrimp_emoji 3y agoAnd some provisions expired thanks to Trump! Biden, on the other hand, renews them promptly, to bipartisan satisfaction. Funny how that works. :p
- Notatheist 3y agoI'm a technical artist not a security researcher so could someone here elaborate on the supposed threat? Assuming a genuine Russian/Chinese state hacker/outfit, what damage could they cause and how much of that damage would legislation such as this prevent?
- deleted 3y ago[deleted]
- mk89 3y ago> what damage could they cause You want to listen to what they want to do before they do something to your country. This is what this thing allows you to do: every internet packet transiting through the Dutch internet exchanges will be "scanned" (largely read-only). However: > The powers granted to the services are broad, but also largely ‘read-only’. Largely `read-only`, the way I read it, means that in some cases they can actually replace whatever is going through the cable. I imagine something like: - terrorist A and B are texting each others, and you replace some of the text that they are sending each other (before this is received over the phone, because you own the "hop"), so that you can maybe redirect them straight into the police hands. If done properly, I believe this can prevent quite some bad damage - not the simple example above, but probably also major things like serious attacks (e.g., ransom attacks on public institutions, etc). That's my guess - how easy or realistic this is, I can't tell you.
- radicalbyte 3y ago[flagged]
- mk89 3y agoDon't worry, as long as we don't militarise ourselves anymore.... oh shoot, that's also happening!
- FirmwareBurner 3y agoOh no, an army on bikes, what are we gonna do about it?! /s
- Arrath 3y agoLose Singapore?
- sph 3y ago> With the Temporary Cyber Act, we will make optimum use of the data carried on our cables to protect The Netherlands against Russian and Chinese hackers Twenty years ago, the excuse was "we are restricting your freedom because of what happened in 11/9." Then in the internet age, the excuse became "we are restricting your freedom to save the children from online abuse." Now, Europe has unlocked the option to restrict its citizens' freedom because of the "war." I ask my fellow computer engineers what the hell are we waiting for to pool our minds and resources towards a truly decentralised, encrypted and anonymous overnet. Something a little more practical than I2P, Tor, Freenet, etc. "Oh bad people will use it to do crime" is not a serious enough excuse to just passively accept the government tightening the noose around our digital presence, for total control by the State, all in name of safety and security. Was Bitcoin (2009) the last hurrah of the crypto-anarchist ideals of freedom of thought, freedom from the Big Brother and freedom from the ever-looming State? https://groups.csail.mit.edu/mac/classes/6.805/articles/crypto/cypherpunks/may-crypto-manifesto.html https://groups.csail.mit.edu/mac/classes/6.805/articles/cryp...
- deleted 3y ago[deleted]
- Eager 3y agoI used to be so optimistic and less cynical. Now I look at this and all that comes to mind is that actions like this would provide a basis for tapping people closer to source. All the p2p and e2e encryption in the world won't help if someone is reading every key you type, or in the near future, every thought that crosses your mind. Still, I applaud your spirit.
- zx10rse 3y agoIt won't happen people choose comfort instead of freedom. Eventually it will become a full blown totalitarian state, and we are going to relive 20th century again it seems. I can't wait to pay ESG tax because I am breathing.
- deleted 3y ago[deleted]
- 3y ago
- dylan604 3y agoAs long as they are proud of it. No bad laws have ever been implemented where everyone was proud of it, so this must mean it's not a bad law!! And the people rejoiced...just not on the internet as they didn't want to be spied on
- FirmwareBurner 3y ago>No bad laws have ever been implemented where everyone was proud of it "Nobody who speaks German can ever be evil" - The Simpsons
- gpvos 3y agoHow do you know everyone is proud of it? For starters, I'm not.
- dotBen 3y agoAren't all governments tapping connectivity the occurs within their borders (whether it be in internet exchanges, sea cables that come onto their shores, etc - kinda doesn't matter where it physically happens)? I assume this is going on routinely already.
- bradley13 3y agoPerhaps it is. That doesn't mean it should be. Governments think they are above their own laws. Warrants? Privacy rights? Due process? Why bother?
- wkat4242 3y agoWell in this case they did amend the law through parliament. Not that I agree with it, no, but it's not like they're acting above it.
- throwaway11460 3y agoThat doesn't make it automatically right, just, or even legal. Does it hold up against the European Convention on Human Rights, EU directives, regulations and the country constitution? What does the constitutional court, EU court of justice and EU court of human rights think? These are not hypothetical questions. I'm not Dutch but in my own (EU) country it's a very common occurrence that the higher courts significantly modify or entirely cancel a fully approved law - often retroactively. Sometimes the state has to pay out damages. IMHO a parliament acting like they can just vote for anything and that's it is exactly the definition of acting above the law.
- wkat4242 3y ago> That doesn't make it automatically right, just, or even legal. Does it hold up against the European Convention on Human Rights, EU directives, regulations and the country constitution? What does the constitutional court, EU court of justice and EU court of human rights think? It should, it's the job of the first chamber (aka the 'senate') to validate this. Unfortunately they have been playing politics more than anything. > I'm not Dutch but in my own (EU) country it's a very common occurrence that the higher courts significantly modify or entirely cancel a fully approved law - often retroactively. This sounds more like the common law system (US, UK, Ireland). In Holland it's not like that. The senate is supposed to check that an in fact a local judge can't directly reference the constitution. In common law they can and they create precedents to scope out a law further after implementation. The EU does overrule it of course. And yes perhaps they can get fined damages. That would be good IMO because it will stop them doing it. But they didn't do anything wrong technically in that sense. The worst thing they did technically was that this law was inplemented by a cabinet that had already stepped down after the coalition fell apart. New votes were held and a new parliament was formed, but the old cabinet is still in place until a coalition is formed to create the new cabinet. The biggest problem there was that 24% of people voted for the extreme-right fascist party and nobody except the neoliberals (the party they split out from) and the farmers want to form a government with them. So it will take a lot of time. But the old (neoliberal) cabinet is not supposed to push through any legislation that can be considered controversial. They are doing that all the time though.
- deleted 3y ago[deleted]
- molticrystal 3y agoJust how badly is the internet compromised at this point, as in are there any countries or internet corporate policies that forbid contributing to this type of action and would route around the Netherlands due to it violating privacy?
- GauntletWizard 3y agoTo some extent, this is a gross misuse of their government power. To another extent, tap away. There is no reason for your network traffic not to be an end-to-end encrypted. I'm more or less fine with the government getting my SNI headers, though I will be investing more in Tor and other obfuscation for some purposes.
- tdudhhu 3y agoThis is a 'temporary' law that will be reconsidered after 4 years (most of the time this means it will just be continued). The CTIVD will have supervision during and after the tab (good). Private data can be held much longer without government approval (why?). There is no permission needed to tap another server when a party, that is under surveillance, is moving there. --- I have mixed feelings about this. We know Russia is trying to disrupt the Netherlands because of previous taps. So on one hand it is good that the government can quickly react to such threads. On the other hand it has huge privacy implications. Some people in this thread think that TLS will keep us private but that is not how it works when they can listen to all traffic. For example they can see I posted a request to Hacker News on a specific time. Then it is a matter of finding all posts that were made around that timestamp to see what I wrote and what my username is.
- ozim 3y agoI am sure it is there to stay as no other thing is going to stay forever as much as “temporary” law giving authorities more power.
- mk89 3y ago> For example they can see I posted a request to Hacker News on a specific time. Then it is a matter of finding all posts that were made around that timestamp to see what I wrote and what my username is. I think this is a lot of work to do. Just ask some 3 letters agencies for some help on some malware or on some "router firmware bugs" to be exploited etc. They don't care about hacker news readers or posting comments (because this implies you must know the DNS first, etc). They care about botnets DDoS-ing your railway infrastructure, ransomware on hospitals, serious stuff that can lead the country to chaos.
- satellite2 3y agoOn hn everything is public so if you only have the time at which two or three posts where submitted you can find the user in question easily.
- dang 3y agoThe submitted title ("Dutch gov. proudly announces it will tap Europe's largest internet exchanges") badly broke HN's title guideline, which asks: "Please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&sort=byDate&type=comment&query=%22level%20playing%20field%22%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
- Tknl 3y agoDon't forget Dutch citizens voted previously in a national referendum against mass surveillance which was promptly ignored and the right to call a referendum repealed.
- hcfman 3y agoIndeed, and the government don't care about the laws anyway. I lived next door to someone that was busted for growing weed. The neighbor on the other side was involved at the time and then continued to harrass him then me because I complained about it for the next 10 1/2 years. The law only allows use of a civilian for a year with a contract in advance and no committing crimes. Didn't stop them. They spent more than 1 million euros in harrassing someone who was already convicted and then their neighbor because they complained. I was told by the police that my phone had been tapped already, though I had already guessed that.