Showing posts with label RIPA. Show all posts
Showing posts with label RIPA. Show all posts

Thursday, July 09, 2015

RIP Caspar

It's hard to believe but privacy activist, Caspar Bowden, has died following a short battle with cancer.

My first encounter with Caspar was on a listserv when he was director (and co-founder) of the Foundation for Information Policy Research. I believe it was the late 1990s but he was telling me off for spelling his name wrong. I apologised and we subsequently became friends. The substance of what we were discussing is lost to my memory but I suspect it was something around key eschrow and the original crypto wars at the time. It's shocking that Caspar should be lost to the security and privacy community just as that ugly battle is rearing its head again, with politicians and securocrats both sides of the Atlantic demanding back door access to encryption.

Combative and prickly, Caspar was also unfailingly kind and generous.

Whilst at FIPR Caspar worked tirelessly to inform parliamentarians and the public of the personal data pollution dangers of the burgeoning information age and ill designed regulations like the Regulation of Investigatory Powers Act (RIPA). He won the Winston award in 2000 for his work on RIPA and he carried that activism into his role as Chief Privacy Officer of Microsoft (initially for Europe, the Middle East and Africa, then for 40 countries worldwide) between 2002 and 2011. 

Long before the Snowden revelations, Caspar was warning of the nature of a huge range of privacy invading behaviour, commercial and governmental, and the facilitating evolving regulations round the world; not least the US Foreign Intelligence Surveillance Act 1978 (FISA) and the FISA Amendments Act 2008, in particular s1881, subsequently implemented as s702 FISA, Procedures for targeting certain persons outside the United States other than United States persons. His report, "The US surveillance programmes and their impact on EU citizens' fundamental rights", for the Civil Liberties, Justice and Home Affairs (LIBE) committee of the EU parliament is the definitive document on the subject.

It was Caspar's insistence on publicly spreading the word about this s702 'guilty of being a foreigner' provision of FISA that he recently explained led to his parting of the ways with Microsoft. 

Caspar was a big believer in a Rawlsian model of justice, a stickler when it came to the universality of human rights and was unstinting in his criticism of corporate or government entities or agents who sought to undermine those rights and principles; and even of US civil rights organisations who he felt passively endorsed the notion of better rights for US citizens.

He was a member of the board of directors of the Tor project. In recent times had become convinced of the potential of Qubes to form at least part of the technical architecture of a counter-insurgency against the seemingly all powerful, unstoppable erosion of personal privacy, by corporate and government agencies and others. 

Caspar was a rare polymath, an expert practitioner in the computer science, the laws of multiple jurisdictions, the technology more generally, identity management and information ethics. And he was prepared to wrestle with the user unfriendly inconveniences of privacy enhancing technologies, as the almost meltdown of his laptop, 4 minutes into his 'Reflections on Mistrusting Trust' talk at QCon last summer, demonstrated. 

For some time he had been contemplating and working on the establishment of a pan-European privacy rights organisation. It would be an appropriate legacy if an effective sustainable such institution could be brought into being.

There were few, if any, more deeply informed, active, passionate and energetic advocates for the privacy cause. Caspar you will be sadly missed. My thoughts and condolences go to your wife Sandi and family.

Update: a truly lovely personal tribute to Caspar by Malavika Jayaram, So long and thanks for all the fish, Caspar Bowden. Other really nice pieces from Natasha Lomas, Chris Soghoian, Robin Wilton, John Leonard, Ben Goldacre, Danny O'Brien, Martin Hoskins, Wendy Grossman, Simon Davies, Joanna Rutkowska, the Open Rights Group, Ind.ie, Sarah Clarke, Phil Booth, EDRi, the Tor Project, here, here, here, here, here, here, here, here, here, here, here, here, here, herehere and here.

Update 2: Guardian Obituary by Ross Anderson and tribute from John Naughton.

Thursday, June 11, 2015

A question of trust: notes on the terror watchdog report


The Terror Watchdog’s Report

The UK government has finally got round to releasing the report of the investigatory powers review by the independent reviewer of terrorism legislation, David Anderson QC and his team. Mr Anderson submitted the report to the Prime Minister on 6 May, just prior to the general election.

As Mr Anderson predicted, the report “won’t please everybody (indeed it may not please anybody)” but it is a substantive piece of work and deserves careful reading and consideration in full. In the press release accompanying the 379 page report he says:

“Modern communications networks can be used by the unscrupulous for purposes ranging from cyber-attack, terrorism and espionage to fraud, kidnap and child sexual exploitation.  A successful response to these threats depends on entrusting public bodies with the powers they need to identify and follow suspects in a borderless online world.

  But trust requires verification.  Each intrusive power must be shown to be necessary, clearly spelled out in law, limited in accordance with international human rights standards and subject to demanding and visible safeguards.

 The current law is fragmented, obscure, under constant challenge and variable in the protections that it affords the innocent.  It is time for a clean slate.  This Report aims to help Parliament achieve a world-class framework for the regulation of these strong and vital powers.”

So far so good. 

The report itself summarises the importance of privacy, threats to the UK, technologies implicated, laws, powers, safeguards and practices and the views from a disparate variety of actors from law enforcement and the intelligence services to service providers and civil society. It closes with a set of 5 governing principles and 124 specific recommendations. It was not limited to counter-terrorism considerations but also included counter-espionage, missing persons investigations, internet enabled crime (fraud, cyber-attacks, child sexual exploitation) and crime in general. 

The purpose of the report is:

a. to inform the public and political debate on these matters, which at its worst can be polarised, intemperate and characterised by technical misunderstandings; and
b. to set out proposals for reform, in the form of five governing principles and 124 specific recommendations. 

I think it’s fair to say it succeeds with both, even if I can’t agree with some of the recommendations.  Mr Anderson has had unrestricted access, at the highest level of security clearance, to the responsible government departments whilst conducting his review.

Key issues arising from the report seem to be:

               The need to start from scratch on a comprehensive and comprehensible, fit-for-purpose legislative framework for investigatory powers – including the retirement of the “incomprehensible to all but a tiny band of initiates” Regulation of Investigatory Powers Act (RIPA) 2000
               Continuation of communications data retention under the Data Retention and Investigatory Powers Act (DRIPA) 2014
               There should be judicial rather than Secretary of State authorisation of communications data warrants – the report itself describes this recommendation as “radical” departure
               The approval of bulk collection of communications data.
               Lack of acceptance of government’s glossy claims for the magic, unimpeachable value of government access to bulk communications data and recommendations for improved oversight of same
               Approval of extraterritorial reach of DRIP Act, for now, until improved international framework for data sharing is in place
               Abolition of existing oversight commissioners and replacement with Independent Intelligence and Surveillance commission
               The power, in Theresa May’s beloved snoopers’ charter, for the retention of internet searches should only apply where “a detailed operational case can be made out and a rigorous assessment has been conducted of the lawfulness, likely effectiveness, intrusiveness and cost”.
               An emphatic rejection of David Cameron & Theresa May’s notion of blanket encryption backdoors for government

 

Why Theresa and Dave are Glum

Though there is a lot in there, it’s becoming clear why the government delayed publication and both Theresa May and the Prime Minister’s spokeswoman seem to be already distancing themselves from the report.

You can understand why Theresa and Dave might be a bit miffed that Mr Anderson disapproves of blanket encryption backdoors (pointing out the agencies don’t want it and it would undermine security for everyone), has the nerve to suggest judicial rather than Executive oversight of interception warrants might be appropriate, kneecaps the snoopers’ charter and notes some of the claims about the value of communications data in the investigation of nefarious actors might be somewhat overblown.

You would expect them, however, to be positively dancing in the aisles as a result of his apparent support for the continuation of the bulk collection and retention of communications data and the continuation of the extra territorial reach of DRIPA beyond its sunset at the end of 2016.

I have to admit I share Privacy International’s disappointment that Mr Anderson didn't condemn bulk interception. However, whatever cheer the government’s senior Cabinet members derive from the nominal support for bulk collection will be tempered by Mr Anderson’s qualification of this approval by saying   "Though I seek to place the debate in a legal context, it is not part of my role to offer a legal opinion (for example, as to whether the bulk collection of data as practiced by GCHQ is proportionate). A number of such questions are currently before the courts..." [1.12].  

This continual emphasis in the report that he and the government should respect the courts as the requisite arbiters in determining the proportionality of indiscriminate bulk collection, within the framework of the European Convention on Human Rights (ECHR), is interesting. Even as he approves, also, of blanket data retention under DRIPA, he insists that retention would have to comply with the ECHR and the European Court of Justice decision in Digital Rights Ireland case in 2014, which banned indiscriminate data retention.

On the approval of the extra territorial DRIPA powers Mr Anderson is again careful to note:

"I understand those who argue that extraterritorial application sets a bad example to other countries, and who question whether it will ever or could ever be successfully enforced. It is certainly an unsatisfactory substitute for a multilateral arrangement under which partner countries would agree to honour each others’ properly warranted requests, which must surely be the long-term goal.”

So Mr Anderson’s report has turned out to be nothing like the useful excuse for pushing through the snoopers’ charter that the Home Secretary must have hoped it would be.

 

Why the report might not please anybody

It’s a real pity that, even within the constraints within which he was working, and the reasonable set of 5 principles outlined for underpinning investigatory powers, laid out in Part IV of the report, Mr Anderson did not condemn bulk collection of communications data. I accept it is not part of his role to offer a legal opinion on whether bulk collection is proportionate. 

Yet I find the justification for supporting bulk collection is rather weak and not commensurate with the deeper consideration of the rest of the report. It is linked to a principle of minimising no go areas for law enforcement as far as possible, whether in the physical or the digital world and justified on the grounds of 6 sample cases briefly outlined in Annex 9 of the report. None of these 6 cases provide the detail to demonstrate that bulk collection was the primary source leading to the identification of these criminals in the first instance.  

It is not in dispute that if law enforcement or the intelligence services have just cause to suspect some person/group of involvement in criminal activity, the availability of bulk data which includes the data of the suspect/s, will enable data mining that may be useful in an investigation. Bulk collection facilitates the significant discovery of multiple details about anyone once they become a suspect or a person of interest. Authorities simply do not have the resources to engage deep data mining the lives of everyone even if they have that data available.

Since the turn of the century, time and again from the 9/11 attacks to the murders of Fusilier Rigby and people at the Charlie Hebdo offices in Paris,  information overload caused by bulk data collection has been a primary factor in the failure to prevent terrorist attacks by known dangerous individuals. It is simply not proportionate to engage in bulk data collection in the hope that it will be useful when the authorities decides to look into someone they disapprove of. It actually actively impedes already over stretched investigatory authorities, who would be better served by putting the resources apparently available for such bulk collection, into recruiting more and better trained investigators and analysts.

Mrs May and Mr Cameron would do well to note that the opportunity costs of engaging in the security theatre that is bulk data collection and data retention, undermines security for everyone by making the jobs of those tasked with protecting us more difficult, whilst simultaneously denying them the resources to be more effective.

Update: the airline worker example from Annex 9, according to Joshua Rozenberg is Rajib Karim, who was convicted in 2011 and jailed for 30 years.

Wednesday, March 04, 2015

The coaltion and computers

The Institute for Advanced Legal Studies recently launched their Centre for Law and Information Policy.

The ever entertaining and informative DaithĂ­ MacSĂ­thigh opened proceedings, with a look at the UK coalition government's record over the past 5 years.

They have mostly had a domestic legislation focus. There is a perception that they engaged with technology issues but 5 years on they are looking pretty old and grey. Of the 130 Acts of Parliament adopted since 2010 there are only a few in the tech policy arena.

DaithĂ­ suggested three ways to think of this limited degree of regulation - rollback, re-balancing and re-regulation.

Rollback

ID cards were repealed with the Identity Documents Act 2010.

The Protection of Freedoms Act 2012 had something to say about CCTV, DNA retention and RIPA amongst other things. DaithĂ­ didn't mention it but this Act has little known provision, s26(5), which I highly recommend every child in the country, based at schools unconscionably collecting biometric data, exploit to its absolute maximum effect:
26 Requirement to notify and obtain consent before processing biometric information
[...]
(5) But if, at any time, the child—

(a) refuses to participate in, or continue to participate in, anything that involves the processing of the child’s biometric information, or

(b) otherwise objects to the processing of that information,

the relevant authority must ensure that the information is not processed, irrespective of any consent given by a parent of the child under subsection (3).
So calling all teens - how would you like to annoy your teachers and possibly even parents and simultaneously strike a major blow against the sickening normalisation of the unethical mass collection of kids' biometrics in schools? Roll out section 26(5), get your mates together and opt out of your school fingerprint (or other biometric) collection systems. Tell your headteachers you are not numbers to be processed and you refuse to participate, any longer, in school schemes that are undermining the fundamental rights of yours and future generations.

The Enterprise and Regulatory Reform Act 2013 was a bit of a mongrel covering a range of disparate issues and apparently included some amendments to the Wireless Telegraphy Act.

In the rollback box there is also some interesting unfinished business relating to the promised repeal of sections 17 and 18 of the Digital Economy Act 2010.

Re-balancing

The Defamation Act 2013 introduced a series of revisions considered pro-defendant including a single publication rule, restrictions on jurisdiction shopping and a fourth type of intermediary protection. That made the tech and media industries happy.

On the intellectual property front, in the summer and autumn of 2014 a series of changes, including recognition of exceptions for parody, format shifting and quotation, were made by statutory instrument to implement parts of the Hargreaves Report. The entertainment industry were not best pleased with the changes and have engaged an expensive collection of m'learned friends in an attempt to quash the private copying changes under a judicial review. Oh yes. Judicial review is still available to those wealthy few who can afford it.

In the recently passed Counter Terrorism and Security Act 2015 there is a provision to set up a Privacy and Civil Liberties Board (not to mention the appalling McCarthyite section 26 "prevent" duty)

Re-regulation

In terms of re-regulation the abomination that is the Data Retention and Investigatory Powers Act 2014 was rushed through Parliament in the week before MPs went off for their summer holidays.

Having sung lalala with their fingers in their ears for months, following the abolition of the data retention directive by the Court of Justice of the European Union, DRIPA was the government's panicked "something must be done" response and its reach was extended to MAC addresses in section 21 of the Counter Terrorism and Security Act, 2015.

Elsewhere on what DaithĂ­ was labelling re-regulation, powers of censorship  and online gambling provisions have been extended. And one of the coalition's final provisions is the revenge porn measures in the Criminal Justice and Courts Act. Sections 33-35 are not exactly exemplars of legislative clarity and were passed with no evidence and no scrutiny.

The digital goods add on to the Consumer Rights Bill is still working its way through Parliament.

Big Projects

The final string to the coalition's tech bow was outwith the legislative bandwagon. They don't want to use legislation too readily after all, since it could be seen as at odds with their aim to reduce bureaucracy.

Their big big project is, of course, big data, wherever they can get it.

The Health and Social Care Act 2012 is enabling them to wreak all kinds of ignorant havoc with medical confidentiality, for example. Ross Anderson, only last week described the Hospital Episode Statistics data warehouse and the horrendous care.data programme as residing in the 7th circle of hell, as far as lack of respect for medical confidentiality and privacy is concerned.

Whilst I'm mentioning Ross, could I also highly recommend the Nuffield Council on Bioethics report of which he is a joint author, The collection, linking and use of data in biomedical research and health care:ethical issues. Ross neatly sums up;
As the information we gave to our doctors in private to help them treat us is now collected and treated as an industrial raw material, there has been scandal after scandal. From failures of anonymisation through unethical sales to the care.data catastrophe, things just seem to get worse. Where is it all going, and what must a medical data user do to behave ethically?
We put forward four principles. First, respect persons; do not treat their confidential data like were coal or bauxite. Second, respect established human-rights and data-protection law, rather than trying to find ways round it. Third, consult people who’ll be affected or who have morally relevant interests. And fourth, tell them what you’ve done – including errors and security breaches.
The coalition's other big project was tax relief for the video games industry. Needless to say, the industry approved. So popular was it that the government decided to extend a similar provision to theatres.

Finally, hugely unwelcome all around parliament, Leveson landed upon the government and the effects are still unclear.

Conclusions

DaithĂ­'s conclusions on all this brought us back to where he started. The coalition began with some promising promises on technology and civil liberties but it proved all too easy for them to talk in libertarian soundbites on the outside, then quickly succumb to the temptations of power. He was more generous than I would have been in describing the coalition as looking merely old and grey.

Their consolidation and expansion of the mass surveillance agenda and practices (DaithĂ­ didn't mention the Snowden affair but I'm sure would have done if time had allowed) and the government's entrenched view of UK residents as industrial raw material, as Ross Anderson so eloquently puts it, to be mined for the response to whatever stick the rabid 24 hour news media are currently beating the government over the head with, will do untold damage to fundamental rights for generations to come.

Update: I expect DaithĂ­ would also have included a treatise on the Justice and Security Act 2013 (including reinforcement of secret courts and secret "evidence") and the decimation of legal aid, if he'd had the chance.

Tuesday, February 10, 2015

Liberty, PI, Amnesty v Foreign Secretary at IPT

I had a quick go yesterday at explaining the Investigatory Powers Tribunal (IPT) ruling, in Liberty & Ors v The Secretary of State for Foreign and Commonwealth Affairs & Others (Case No: IPT/13/77/H).

When government, for an indeterminate number of years prior to 5th December 2014 has said,
“All of the work of the intelligence and security services is carried out in accordance within a strict legal and policy framework, which ensures that our activities are authorised, necessary and proportionate ...”
they were being economical with the truth. They were, during that period, in fact flagrantly undermining the rights to privacy and freedom of expression under articles 8 and 10 respectively of the European Convention on Human Rights (ECHR).

The government can, according to the IPT however, make that claim now because we are told there is a legal and policy framework. We are not just entrusted with the privilege of knowing what those legal and policy framework rules are.
Secret laws and policies.

For secret government mass surveillance activities.

Approved by a secretive tribunal historically predisposed towards approving of government secrecy, with the sole limited exception being this Liberty & Ors case.
The most recent IPT ruling takes great pains, from the start, to emphasise that they ruled, in December 2014, that the UK security services intelligence sharing with the NSA, in connection with the Prism and Upstream, is lawful.
"Save in one possible (and to date hypothetical) respect"
The limited and hypothetical exception is laid out in paragraph 53 of their 5 December judgement.
"53. The one matter of concern is this. Although it is the case that any request for, or receipt of, intercept or communications data pursuant to Prism and/or Upstream is ordinarily subject to the same safeguards as in a case where intercept or communication data are obtained directly by the Respondents, if there were a 1(b) request, albeit that such request must go to the Secretary of State, and that any material so obtained must be dealt with pursuant to RIPA, there is the possibility that the s.16 protection might not apply. As already indicated, no 1(b) request has in fact ever occurred, and there has thus been no problem hitherto. We are however satisfied that there ought to be introduced a procedure whereby any such request, if it be made, when referred to the Secretary of State, must address the issue of s.16(3)"
But the exception was hypothetical, had not happened and they were therefore "satisfied as to the lawfulness" of the intelligence services' activities relating to Prism and Upstream. From the 6 February decision:
"10. By our Order of 5 December 2014 we made declarations that the Prism and/or Upstream arrangements (subject to the exception referred to in paragraphs 7 and 8 above) did not contravene Articles 8 or 10 ECHR, and further that the RIPA regime in respect of ss. 8(4), 15 and 16 of RIPA similarly did not contravene Articles 8 or 10 ECHR.
By paragraph 4 of the Order, we directed that the parties serve written submissions according to an agreed timetable, and with a view to the two outstanding issues being resolved by the Tribunal, by agreement of the parties, without a further hearing:

“4. i) Whether by virtue of the fact that any of the matters now disclosed in the judgment of 5 December 2014 were not previously disclosed, there had prior thereto been a contravention of Articles 8 or 10 ECHR. (“The First Issue”).
ii) Whether by virtue of the facts and matters set out in paragraph 53 of the judgment of 5 December 2014, there is a contravention of Articles 8 or 10 ECHR.” (“The Second Issue”). "
We'll get to the IPT's specific answers to these questions presently but (spoiler alert) they basically conclude i) keeping the existence of the rules secret was illegal but isn't anymore since we now know the rules exist (it's slightly more subtle than that, in that there is a the question of "adequate signposting" to the rules) and ii) don't worry about it, the government promise to behave.

Perhaps surprisingly, (though I expect the legal representatives advised of the serious possibility of a limited win on the secret rules grounds and decided to focus exclusively on that), Liberty and co chose not to challenge the RIPA regime at this particular stage. So the IPT take the open goal opportunity to pat GCHQ and co on the back,
"12. ... As requested by the Respondents, therefore, the Tribunal can make it clear, for the avoidance of doubt, that the declaration it made on 5 December 2014 in relation to the RIPA regime was that it is in accordance with the law/prescribed by law and was so prior to the Tribunal’s Judgment of 5 December 2014."
They next tackle the question of whether the absence of government acknowledgment of secret rules governing mass surveillance was illegal.
"15. We set out the requirements of Article 8 in paragraph 37 of the December Judgment:
“37. The relevant principles appear to us to be that in order for interference with Article 8 to be in accordance with the law:
(i) there must not be an unfettered discretion for executive action. There must be controls on the arbitrariness of that action.
(ii) the nature of the rules must be clear and the ambit of them must be in the public domain so far as possible, an “adequate indication” given (Malone v UK [1985] 7 EHRR 14 at paragraph 67), so that the existence of interference with privacy may in general terms be foreseeable."
So there must be rules reigning in "unfettered... executive action" i.e. theoretically the government is subject to some controls. The rules don't have to be public but the public must know enough to be able to deduce that our privacy may be undermined.
"16. We continued:
“41. We consider that what is required is a sufficient signposting of the rules or arrangements insofar as they are not disclosed. . . It is in our judgment sufficient that:
(i) Appropriate rules or arrangements exist and are publicly known and confirmed to exist, with their content sufficiently signposted, such as to give an adequate indication of it (as per Malone: see paragraph 37(ii) above).
(ii) They are subject to proper oversight.”
I'll leave you to decide on the difference, if any, between "the nature of the rules must be clear..." etc and " what is required is a sufficient signposting of the rules or arrangements insofar as they are not disclosed" etc.

Bottom line?

Secret rules governing mass surveillance are ok as long as the public know there are rules, even if they are not allowed to know what the rules are and as long as the rules "are subject to proper oversight".

The IPT did get a confidential look at the "arrangement below the waterline" i.e. secret rules, in secret and:
"17. We set out our conclusions, so far as relevant to this question, in paragraph 55:
“55. After careful consideration, the Tribunal reaches the following conclusions:
(i) Having considered the arrangements below the waterline, as described in this judgment, we are satisfied that there are adequate arrangements in place for the purpose of ensuring compliance with the statutory framework and with Articles 8 and 10 of the Convention, so far as the receipt of intercept from Prism and/or Upstream is concerned.
(ii)This is of course of itself not sufficient, because the arrangements must be sufficiently accessible to the public. We are satisfied that they are sufficiently signposted by virtue of the statutory framework to which we have referred and the Statements of the ISC and the [Interception of Communications] Commissioner quoted above, and as now, after the two closed hearings that we have held, publicly disclosed by the Respondents and recorded in this judgment.”
In other words - trust us, there is "adequate" secret oversight of mass surveillance ensuring it complies with human rights.

But don't worry, we've got your back. Not only can we confirm the the existence of adequate secret controls but we realise the fact of the existence of these secret rules must be in the public domain. And hey presto! By way of our wondrous work in getting this information disclosed to the public - i.e. that secret rules exist - the public know that secret rules exist. High fives and self congratulatory kudos all round.

But wait.

Liberty's QC, Matthew Ryder, pointed out that it was only because this case was pursued that the government were forced into releasing the information that secret rules existed that, in turn, satisfied the IPT that the public now know that secret rules exist.

The IPT response?
"19. ... We agree."
Not much to add to that.

Paragraph 20. of the judgement is fun but really for the lawyers. Rough translation:
The government say: leave us alone, there was enough information to deduce that rules existed.

Privacy International barristers, Dan Squires and Ben Jaffey say: maybe but there was not enough information about the nature and ambit of the rules (in the language of the Padfield decision noted in para 15) or sufficient signposting to the content of the rules to give an adequate indication (Padfield & IPT from para 15 & 16) of the ballpark they might reside in.
I won't quote the IPT in paragraph 20 agreeing with Privacy International but the IPT agreed with Privacy International.

We finally reach the heart of the decision so loudly proclaimed as historic by Liberty, Privacy International, Amnesty and The Guardian.
"21. ... We are however satisfied ... that, without the disclosures made, there would not have been adequate signposting, as we have found was required and has now, as a result of our Judgment, been given.
22. Although the first requirement of Article 8, set out in paragraph 37(i) of the December Judgment and in paragraph 15 above, is satisfied, the second requirement, as set out in paragraph 37(ii) of the December Judgment, was only satisfied by the Disclosures being made public in our Judgment.
23. We would accordingly make a declaration that prior to the disclosures made and referred to in the Tribunal’s Judgment of 5 December 2014, the regime governing the soliciting, receiving, storing and transmitting by UK authorities of private communications of individuals located in the UK, which have been obtained by US authorities pursuant to Prism and/or (on the Claimants’ case) Upstream, contravened Articles 8 or 10 ECHR, but now complies."
So,
There are secret rules controlling government action in this area.

There would not have been "adequate signposting" to the secret rules governing Prism & Upsteam intelligence sharing, without the disclosures the government made in this case.

Prior to these disclosures the government were in breach of  Articles 8 or 10 of the European Convention on Human Rights (ECHR), protecting privacy and freedom of expression; as there was inadequate signposting to the secret rules.

The Prism & Upstream intelligence sharing regime, by virtue of government disclosures, as a result of this case, of adequate signposting to the secret rules, now comply with Articles 8 or 10 of the ECHR.
Having shot the government metaphorically in the foot then bandaged the wound so it was no longer noticeable, the IPT move thence to the" hypothetical" Regulation of Investigatory Powers (RIPA) loophole. "Hypothetical" because they are assured by the government that the issue has never arisen.

The RIPA issue in the case is more complicated than the question of the existence of secret rules, so  in deference to the patience and stamina of readers who have got this far, I'm going to take a relatively short run at it. It is addressed in paragraphs 24 to 31 of the decision. Let's skip the hypotheticals on the 1(b) request and the dancing in and out of sections 5, 8, 15 and 16 of RIPA and get to the government promise outlined in paragraph 30.
"30. The Respondents have now given the further Disclosure, as contained in paragraphs 19 and 20 of their submissions:
“19. For the avoidance of doubt, the concern identified by the Tribunal would not arise in the first place if a request were made pursuant to paragraph 1(b) of the Disclosure for material to, from or about specific selectors (relating therefore to a specific individual or individuals). In such a situation, the request would be a “targeted” one and the Secretary of State would therefore have approved it for the specific individual(s) in question. In that case, the proper parallel would be with a warrant under s.8(1) of RIPA, not s.8(4). Thus, the safeguards under s.16 of RIPA would not be at issue even by analogy because s.16 of RIPA only applies to the examination stage following interception under s.8(4) warrants (i.e. “untargeted” interception).
20. In those circumstances, the remaining concern is in relation to such untargeted interception. The Respondents can confirm that, in the event that a request falling within paragraph 1(b) of the Disclosure were to be made and approved by the Secretary of State other than in relation to specific selectors (i.e. “untargeted”), the Intelligence Services would not examine any communications so obtained according to any factors as are mentioned in section 16(2)(a) and (b) of RIPA unless the Secretary of State personally considered and approved the examination of those communications by reference to such factors.” "
This requires careful and repeated reading but purports to be an assurance from the government to close this one lacuna, in a veritable colander of RIPA loopholes. The assurance attempts to give the impression that the Secretary of State must sign off on surveillance targeted at specific individuals.

In other words the government promise to behave... honestly... on this specific RIPA pathway.

Secretary of State approval is now supposed to apply both:
to targeted interception of communications
and to targeted data mining of the giant data silos collected through untargeted interception.
I'm not sure I derive a great deal of comfort from that.

On the latter, just to repeat;
"The Respondents can confirm that, in the event that a request falling within paragraph 1(b) of the Disclosure were to be made and approved by the Secretary of State other than in relation to specific selectors (i.e. “untargeted”), the Intelligence Services would not examine any communications so obtained according to any factors as are mentioned in section 16(2)(a) and (b) of RIPA unless the Secretary of State personally considered and approved the examination of those communications by reference to such factors.”
Privacy International and Amnesty accepted the government assurances explicitly. Liberty were silent on the matter. The IPT takes the declaration as a resolution.
"31. Privacy in their reply submissions, with which Amnesty agrees, accept that “that safeguard is now in place, but was not in place before December 2014”. Liberty does not expressly so accept, but made no submissions to the contrary in their reply. In any event we agree, and the disclosure which resolves the lacuna is now made public in this judgment."
Given the importance the government RIPA promise and the IPT's acceptance that it closes a loophole, they conclude the case at paragraph 32:
"32. In our judgment the appropriate course is to alter the declaration we were otherwise minded to make as set out in paragraph 23 above in respect of the First Issue, so that the declaration we propose to make would recite that “prior to the disclosures made and referred to in the Tribunal’s Judgment of 5 December 2014 and this judgment” the Prism and/or Upstream arrangements contravened Articles 8 or 10 ECHR, but now comply."
So, prior to -
the disclosure of adequate signposting to secret rules governing Prism and Upstream intelligence sharing
And
the government's promise not to exploit one of many RIPA loopholes  
- the UK government, for many years, contravened articles 8 and 10 of the European Convention on Human Rights. Now, thanks to the disclosures and promises extracted as a result of this case, they are no longer undermining the right to privacy and freedom of expression. At least as far as the IPT is concerned, within the narrow confines of the issues it examined in this case.

Update: I meant but neglected to include Caspar Bowden's wonderful description of the decision -

"IPT "illegality" finding a Pyrrhic victory, harpoon hurled at heart of "margin of appreciation". ECtHR reviews "safeguards" not spy methods"

Also Privacy International's note about the secret rules: 
"What was publicly disclosed, therefore, is little more than a Tribunal’s summary of secret policies disclosed in a secret hearing, which policies describe only the broadest of restrictions on the receipt of intelligence material by the UK, and remain buried in a 77-page long decision from the IPT, not enshrined in any accessible law or statute. 
We think that falls far short of what is called for by the “in accordance with law” requirement, and in the coming weeks will be appealing to the European Court of Human Rights to argue our case there, demanding an end to unlawful mass intelligence sharing, and ensuring privacy protections for all. "

Friday, January 16, 2015

Expanding powers, mass surveillance is easy. Tackling terrorism is hard

I wrote to my MP Nicola Blackwood on 1 December 2014 expressing concern about the Counter Terrorism and Security Bill.

I've had a reply today, copy below.
"Dear Mr Corrigan,

Thank you for your email regarding the Counter Terrorism and Security Bill, I do apologise for the delay in my response.

I understand your concerns about the Data Retention and Investigatory Powers Act, in particular that it came before the House as emergency legislation, and I share your desire to ensure that people’s civil liberties are protected at all times. I have consistently said it is absolutely essential that powers to monitor communications are confined to what is entirely necessary and proportionate to protect our national security, and also to be accountable.

To be clear, this legislation goes no further than regulations which are already in place. Rather, it brings clarity to existing law following a ruling of the European Court of Justice (ECJ) in April. The ECJ’s ruling would have struck down regulations that let internet and phone companies retain communications data for law enforcement purposes for 12 months, and therefore a clearer legal framework was needed to underpin companies’ cooperation with law enforcement and intelligence agencies to intercept the communications of serious organised criminals and terrorists. I understand that some companies had already made clear to the Government that they would be unable to work with the UK on this unless that law was consolidated and made clear.

As you may know, I am a member of the Home Affairs Committee, who play an active role in scrutinising Government legislation, the Home Secretary, Rt Hon Theresa May MP, appeared before the Committee to discuss the provisions of the Act. The Government has stated that communications data and interception plays an important role in prosecuting cases of serious organised crime. Therefore, whilst before the Committee, I took the opportunity to ask the Home Secretary about this and she clarified that such data is used in 95% of cases that the Crown Prosecution Service deals with in relation to serious and organised crime; it has been used in all major counter-terrorism investigations over the last decade.

With regards to your concerns about the Counter Terrorism and Security Bill and data retention, this Bill will require Communications Service Providers to retain data that can link a specific device or individual to an IP address. This data will only be available to those public bodies who are entitled to it for lawful purposes, where it is necessary and proportionate to do so on a case-by-case basis.

Currently there are gaps in communications data capability that have a serious impact on the ability of law enforcement to carry out their functions. One such gap is the ability to identify who in the real world was using an Internet IP address at a given point in time. Without this data, it is not always possible to attribute a particular action on the internet to an individual person. For example, it would improve the ability of the police and other agencies to identify terror suspects who may be communicating with each other via the internet and plotting attacks. The Bill also establishes a Civil Liberties Board that would provide further assurance to the public about counter-terrorism arrangements, including ensuring that legislation and policies have due regard for civil liberty and privacy. The Government is also restricting the number of public bodies that can ask for communications data and publishing annual transparency reports, making more information publicly available than ever before. Progress of the bill through Parliament can be found online via: http://services.parliament.uk/bills/2014-15/counterterrorismandsecurity.html.

The Security Service believes that since the attacks on 7 July 2005, around forty terrorist plots have been disrupted. As you may know the independent organisation responsible for gauging the threat posed by terrorism to the UK, the Joint Terrorism Analysis Centre, recently decided to raise the threat level posed by terrorism to 'severe' and I am confident that this is an objective assessment of the situation the UK faces.

Please be assured that through my role on the Home Affairs committee, I will continue to scrutinise Bills of this nature. You may be interested in the seventeenth report by the committee on Counter Terrorism, which is currently awaiting a response from the Government. Further information about this and the role of the committee is available at: http://www.publications.parliament.uk/pa/cm201314/cmselect/cmhaff/231/23102.htm, which I hope you will find useful. I have also passed on your concerns about the Counter Terrorism and Security Bill to James Brokenshire MP, Minister for Security and Immigration and I will of course pass on to you any response I receive in due course.

Thank you again for taking the time to contact me.

Kind regards,

Nicola"
I've responded again but don't hold out much hope of getting through.
Dear Nicola,

I'm disappointed that you would continue to claim the Data Retention and Investigatory Powers Act (DRIPA) 2014 goes no further than regulations which were already in place.

It's a relatively short Act and well worth reading in full but to take just three of the eight sections of the Act:
Section 1 of the DRIPA attempted to re-enact the Data Retention Regulations 2009 (S.I. 2009/859), in addition to giving the Secretary of State, under sections 1(3), 1(4) and 1(7) wide ranging Henry VIII clause powers to amend the law, essentially as and when she likes.

Section 4 expanded the the immensely complex Regulation of Investigatory Powers Act (RIPA) 2000 interception powers, including the extra-territorial reach of those powers.

Section 5 expanded the scope of the meaning of "communications service" to a degree that it could be interpreted to mean any entity using a computer and the internet.
I'd additionally refer you, in particular, to excellent legal analyses by Steve Peers, Graham Smith, Tom Hickman, Liberty, the Open Rights Group, Privacy International, Big Brother Watch, Article 19 and English PEN.

I'm familiar with the Home Secretary's appearance before the Home Affairs Committee saying communications data is used in 95% of cases that the Crown Prosecution Service deals with in relation to serious and organised crime. The only surprise was that it was not 100%.

I won't repeat the objections I have already outlined in relation to the Counter Terrorism & Security Bill, other than to re-inforce my concern about the Bill's Section 21 obligation on public bodies including universities, schools, nurseries and councils to prevent terrorism.

Since I wrote to you on 1 December, Security Minister, James Brokenshire has gone on record at the Joint Committee on Human Rights session on 3 December 2014, as saying that section 21 sanctions under the Act could include prison time for university staff. The Committee has since recommended that the new "prevent"duty is not appropriate for application to universities. I would therefore appreciate an indication of where you stand on this.

More generally, though, I would make a handful of concluding points.

Changing the law is easy.

Expanding powers is easy.

Throwing public money at the security services, computers and mass surveillance is easy.

Playing the tough-on-terrorism rhetoric to the gallery and the press is easy.

And the, so far, short 21st century history of the effects of these easy activities is not pretty.

Actually tackling terrorism is hard.

It requires gold standard human intelligence as well as signals intelligence (and not the mythical magic terrorist catching machines and laws policy makers seems to believe in).

It requires social and economic stability.
It requires trust in the institutions of state, like the police and security services.

It requires equality of opportunity, regardless of background, race, creed, disability, gender or any other form of human categorisation.

It requires an absence of the demonisation of entire communities or peoples just because someone commits an act of violence they claim to be in the name of that community or their religion.

It requires a respect for and implementation of the rule of law and fundamental rights all over the world.

It requires an absence of state, commercial or cause sanctioned rendition, torture, maiming and murder sometimes on an industrial scale and by remote control.

It requires care, concern and deeply embedded respect for human dignity from individuals through all levels of society and its public, commercial and other institutions.

You were sold a pig in a poke with DRIPA. Don't buy into the same confidence trick with the Counter Terrorism & Security Bill and the snoopers' charter and the Prime Minister's new grand plan to ban encryption and ensure there are no communications the government cannot read.

It is too easy and does incalculable damage.

Regards,

Ray
Update: Thanks to the eagle eyed spotters of the spelling error in the title, now corrected.

Tuesday, July 29, 2014

Response from MP on DRIPA

On the first Monday of her summer holidays and after the Data Retention and Investigatory Powers Act had become law with her support the previous week, my MP, Nicola Blackwood, responded to my notes to her expressing concerns about the then DRIP Bill. Copy of her response below which essentially repeats the Conservative Party line.
"Dear Mr Corrigan,
Thank you for your emails about the Data Retention and Investigatory Powers Act, which has now received Royal Assent, and for your telephone call to my office. My staff passed on your message, and I know this is a subject you feel strongly about.
 I do understand the concerns that have been raised with regard to this legislation, in particular that it has come before the House as emergency legislation, and I share your desire to ensure that people’s civil liberties are protected at all times. I have consistently said it is absolutely essential that powers to monitor communications are confined to what is entirely necessary and proportionate to protect our national security, and also to be accountable.
 To be clear, this legislation goes no further than regulations which are already in place. Rather, it brings clarity to existing law following a ruling of the European Court of Justice (ECJ) in April. The ECJ’s ruling would have struck down regulations that let internet and phone companies retain communications data for law enforcement purposes for 12 months, and therefore a clearer legal framework was needed to underpin companies’ cooperation with law enforcement and intelligence agencies to intercept the communications of serious organised criminals and terrorists. I understand that some companies had already made clear to the Government that they would be unable to work with the UK on this unless that law was consolidated and made clear.
 That is why the Act brings together our data retention regulations in primary legislation, where at present it is under secondary legislation, and enables agencies to maintain their existing capabilities. In addition, it makes clear that the requirements include companies based abroad, whose phone and internet services are used in the UK. These powers, already in place, are held through not only the data retention directive and regulations, but also in relation to lawful intercept provisions of the Regulation of Investigatory Powers Act (2000).
 As you may know, the Home Secretary, Rt Hon Theresa May MP, came before the Home Affairs Select Committee, of which I am a member, last week to discuss the provisions of the Act. The Government has stated that communications data and interception plays an important role in prosecuting cases of serious organised crime. Therefore, whilst before the Committee, I took the opportunity to ask the Home Secretary about this and she clarified that such data is used in 95% of cases that the Crown Prosecution Service deals with in relation to serious and organised crime; it has been used in all major counter-terrorism investigations over the last decade.
 Theresa May MP also explained that the Government had carefully considered how to respond to the ECJ ruling, and I was reassured by her clear statement that no more powers are being sought. I agree with the statement made by the Home Secretary that these powers are only to be used ‘with very carefully controlled access arrangements to ensure that any request is necessary and proportionate to the investigation that is taking place’. The existing EU directive, which was overturned by the ECJ, had meant that the period of data retention was an ‘absolute period’ of 12 months and there was no flexibility within this. By contrast, the new regulations will mean that data can only be held for a maximum of 12 months.
 Crucially, alongside the introduction of this legislation the Government is further strengthening the oversight of intelligence capabilities. Between now and 2016, the Government will review the Regulation of Investigatory Power Act (RIPA) to make recommendations to reform and update it- this has now been reaffirmed in the wording of the Act. Ministers are also establishing a Privacy and Civil Liberties Oversight Board which I understand will work to ensure civil liberties are properly considered when the Government sets counter-terrorism policy. I have received assurances from Ministers that the Government is also restricting the number of public bodies that can ask for communications data and will be publishing annual transparency reports. This will make more information publically available than ever before.
 The Home Affairs Committee expressed our view to the Home Secretary that we supported the Bill as a whole, and particularly welcomed Clause 6(3), or the ‘sunset provision’, which means that the legislation will ‘expire’ on 16th December 2016 and will therefore be repealed or renewed at this point. Further, on the day of the vote, the Government accepted new amendments to the Bill which bind us to six-monthly reviews of its operation by the Interception of Communications Commissioner.
 Ministers are mindful that without legislation, we face the prospect of a serious degradation in the ability of law enforcement and intelligence agencies to do their jobs. It is for the reasons detailed above, i.e. that the Act does not extend existing powers and that safeguards and oversight mechanisms are expanded, that I voted for it in the House of Commons last week. The ECJ ruling disbanded the existing EU directive on the basis that it lacked sufficient safeguards, allowing phone and internet companies to store data but did not establish how this data could be accessed or for what purposes. Whereas this new legislation makes clear that the legal framework in which companies must work within, and the circumstances in which this data can be used for vital law enforcement and for our national security.
 I have attached above a copy of the letter I received from Home Office Minister, James Brokenshire MP, which explains the Act in full. I do hope this response is helpful, and thank you, once again, for taking the time to contact me on this important issue.
 Kind regards
Nicola"
The letter from Security Minister James Brokenshire which Ms Blackwood attached to her response read -
"HOUSE OF COMMONS
LONDON SW1A 0AA 10th July 2014
 Dear Colleague,
 COMMUNICATIONS DATA AND LAWFUL INTERCEPTION
It is the first duty of Government to protect the public and we are today introducing emergency legislation to ensure that our law enforcement and intelligence agencies have access to the tools they need to keep us safe.  Access to information relating to communications, subject to robust safeguards, is vital in the fight against crime and terrorism and has been used successfully for many years.

Communications data – the who, where, when and how of a communication but not its content – is a vital tool in the investigation of crime and safeguarding the public.  It has been used in 95% of serious and organised crime investigations handled by the Crown Prosecution Service and every major Security Service counter-terrorism investigation over the last decade.

The interception of the content of communications is of critical importance to the preservation of national security. Since 2010, the majority of the Security Service’s top priority UK counter-terrorism investigations have used intercept capabilities in some form to identify, understand or disrupt plots seeking to harm the UK and its citizens.  However, two recent developments have put these crucial capabilities at risk.  Without legislation, we face the real prospect of a serious degradation in the ability of law enforcement and intelligence agencies to do their jobs.

Firstly, the European Court of Justice judgment of 8 April declared the EU Data Retention Directive (2006) invalid.  This Directive required Member States in Europe to provide for a mandatory communications data retention framework covering certain data for the purpose of the investigation of serious crime.  Following the judgment, our domestic Data Retention (EC Directive) Regulations 2009, which transposed the Directive, remain in force.  However, we need to legislate to maintain an effective mandatory communications data retention framework, and to address the ruling unambiguously and immediately.

If companies could no longer be required to retain communications data, law enforcement’s capability to prevent and detect crime and protect the public would be severely degraded; many investigations would be delayed and some would cease entirely.

The second component of the Bill will put beyond doubt that companies providing communication services to customers in the UK must comply with lawful requests under the Regulation of Investigatory Powers Act 2000 irrespective of where those companies are located.    A number of overseas communication service providers have questioned whether they are required to comply with obligations under the Act in relation to the interception of communications.
 With the increasing globalisation of communications, any decrease in cooperation from overseas providers could have a devastating impact on national security.  If we lose visibility of what terrorists are saying to each other, we will lose the ability to understand and mitigate the threat that they pose.

This Bill will ensure that communications data continues to be available when it is needed.  Whilst most of the European Court’s criticisms are already addressed in UK law, the Bill will also respond to the judgment.  The European Court’s judgment did not take into account national laws on access to communications, and in particular the UK’s access regime with its robust safeguards.  Our communications data regime is internationally respected, and already addresses most of the criticisms made in the judgment.  However, we are introducing a number of new safeguards to respond to the judgment, such as enhancing our data retention notice regime, and formalising the requirements placed on communications companies to safeguard this crucial data.  We will also create a Code of Practice on Data Retention, which will put best-practice guidance on a statutory footing.  Furthermore, the Bill will also put beyond doubt the extra-territorial application of RIPA to ensure that companies, irrespective of where they are based, can comply with their obligations.

The legislation does not create any new powers, rights of access or obligations on communications companies beyond those that already exist. It does not seek to replicate the proposals that were included in the Draft Communications Data Bill, published in 2012. And it would sit aside the already robust regime RIPA provides to regulate access to retained data.

We must act now to ensure that the capability of our law enforcement and intelligence agencies to prevent and detect crime, protect the public and ensure national security does not rapidly and seriously diminish.  The need to act is made all the more pressing because the threats we face remain considerable, not least the collapse of Syria, the emergence of the Islamic State of Iraq and the Levant, organised crime that crosses national boundaries and the expanding scope of cybercrime.

All these threats and many more should remind us that the world is a dangerous place and the United Kingdom needs the capabilities to defend its interests and protect its citizens.

The proposals on communications data and investigatory powers which I have set out above are necessary to ensure that law enforcement and security agencies are able to continue making use of these essential tools. These provisions are not intended to fill the gap which we were looking to close with the draft communications data bill but to ensure that law enforcement can continue to access the material which they currently have access to.

JAMES BROKENSHIRE "
I've responded briefly -
Dear Nicola,

Thanks for taking the time to send a response on the first day of your summer holidays. I can only repeat that for something as serious as an emergency law that requires blanket, indiscriminate communications data retention, targeted not at criminals but  the entire population, every single MP should take notice and make the requisite time to read the proposed legislation and associated documents.

It is incumbent upon MPs to understand what the laws that you are passing actually say, rather than what the party briefing or ministerial assurances might be telling you they say. When the time comes to apply the law, ministerial assurances are not worth the paper they are written on.

Without going through the process of matching each government assurance with contradictory evidence, something I suspect would be of little interest, I would like to draw your attention to one important misunderstanding. It seems increasingly to be the belief amongst MPs that blanket data collection and retention is acceptable in law and that the only concern should be the subsequent access to that data. Assertions to this effect are simply wrong.

The April European Court of Justice(ECJ) judgement restated the position clearly that mass indiscriminate data retention "constitutes in itself an interference with the rights guaranteed by Article 7 of the Charter." (Para 34 of the decision). Article 7 of the Charter of Fundamental rights, as you know, guarantees everyone “the right to respect for his or her private and family life, home and communications”. The European Court of Human Rights (ECtHR) laid down the same prohibition of blanket retention in the S. and Marper v UK case in December 2008.

Please do not be misled into the erroneous belief that retention is acceptable and access is therefore the only problem. Underpinning any future regulatory framework in this area with such a fundamentally flawed assumption would be a big mistake on many levels. Both retention and access in and of themselves present serious article 7 and article 8 challenges, as the ECJ, the ECtHR and many other national courts have made clear.

Have a good holiday.

Regards,

Ray