4 ms·
The full report[1] has a number of interesting details about how the UK intelligence agencies monitor people. The "DIFFICULTIES ACCESSING COMMUNICATIONS CONTENT
by omh 12y ago
The full report[1] has a number of interesting details about how the UK intelligence agencies monitor people.
The "DIFFICULTIES ACCESSING COMMUNICATIONS CONTENT" section, from p139, mentions things like how GCHQ monitors backbone traffic.
It's clear that if the UK have evidence of someone breaking the law then there are options available.
What they're complaining about are suspects who are just being monitored as "suspicious".
But even if they'd wanted to ask e.g. Yahoo to monitor the suspects, I can't see how that would have operated. Obviously UK ISPs can identify and monitor specific people (or at least their home/mobile internet). But remote services can't tie things back to an individual[2].
Really they seem to be suggesting that anyone running a large internet service proactively monitor everything for "terrorism" and notify the relevant international authorities when this happens. From the report:
We note that several of the companies ascribed their failure to review suspicious
content to the volume of material on their systems. Whilst there may be practical
difficulties involved, the companies should accept they have a responsibility to notify
the relevant authorities when an automatic trigger indicating terrorism is activated
and allow the authorities, whether US or UK, to take the next step. We further note
that several of the companies attributed the lack of monitoring to the need to protect
their users’ privacy. However, where there is a possibility that a terrorist atrocity is
being planned, that argument should not be allowed to prevail.
I find it hard to believe that anyone technical is suggesting this!
The MPs on the committee might not understand how impractical it is but what about the people from GCHQ who were suggesting this? Either they seriously think this is a good ide, or they're just trying to get more ammunition for increased monitoring powers within the UK.
[1] https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/20141125_ISC_Woolwich_Report%28website%29.pdf?attachauth=ANoY7cq6KIdy5014o5lXRc58Fk12qvGJutA-2NNk39lGLC7CTJgyEUU6UnuCdQvNzlcKkljlfWOnd-5CSQQSmXunk3Jf6D5OxlzwawR1njGi7BvtGUBTtosSdClA08uOcWb9FH2JK5YS9tNC1IBnxjvO35NkvAml42JBBuX0YrdsqcY-8MJKu6xj95EMuYHxynatt8CDVjyWNHR6qKlwl_50xjtBRHjyFtK8t3KXJtkhjiNUj1wOpkV_m_KNvmJjqxIxIPr8NvWk&attredirects=0 https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/indep...
[2] I suppose they could use the IP address, if GCHQ did the cross referencing for changing NAT etc. But that would be impractical for some ISPs where the IP changes regularly.
- Silhouette 12y ago[2] I suppose they could use the IP address, if GCHQ did the cross referencing for changing NAT etc. But that would be impractical for some ISPs where the IP changes regularly. Don't worry, they've got that one covered: http://www.ispreview.co.uk/index.php/2014/11/uk-counter-terrorism-security-bill-mean-isps.html http://www.ispreview.co.uk/index.php/2014/11/uk-counter-terr...
- omh 12y agoIt's not clear what those proposals really mean. But even if Vodafone were sending a constant stream of IP->subscriber mappings to GCHQ then GCHQ would have to send them on to Facebook/Google/Yahoo etc. in close to real time in order to get what they're after.
- notahacker 12y agoThe key pages of the full report relevant to the US providers believed to include Facebook are 127-133. Some of the statements it makes are much more modest than the politicised responses; others a fair bit more dubious.... either way I think the below are more interesting talking points than the original article... (i) They believe multiple accounts were closed by the service providers themselves due to "terrorist content", so they believe the service providers are failing in an assumed duty to share information with UK intelligence services more than an assumed duty to scan the content. (ii) Some [likely US] providers did share details directly with UK intelligence after the fact whilst others were achieved indirectly via a [presumably US] "partner agency". (iii) The "partner agency" didn't share everything that was possible to share either, which [unlike the computer service providers] GCHQ apparently considers normal and acceptable given their "resource constraints". (iv) The report claim that Adebowale "obviously" had a "number of accounts" with the service provider the media are claiming to be Facebook, some of which were closed down "because they hit triggers which we believe were related to their criteria for closing things down on the basis of terrorist content". Which suggests either the provider in question wasn't Facebook, or that the report authors have a serious lack of understanding either of what a Facebook account is or what Facebook's policy on an individual having several accounts is. (v) GCHQ suggests that an account with the text "let's kill a soldier" should have triggered algorithms detecting potential terrorist content, which implies they believe that [allegedly] Facebook could or should have algorithms that can parse sentences containing trigger words that happen to be extremely common, rather than simple blacklists and flagging functionality.