Friday, February 07, 2014

Submission to ISC Inquiry into Privacy and Security

I've sent a submission to the Intelligence and Security Committee's Inquiry into Privacy and Security. It was done in a hurry so hopefully is not too incoherent.

To the members of the Committee,

Thank you for the opportunity to make a submission to your inquiry into privacy and security.

My name is Ray Corrigan. I’m a Senior Lecturer in the Maths, Computing & Technology Faculty of The Open University though I write to you in a personal capacity.

Executive Summary

Privacy and security are not opposites but mutually dependent. It is essential the committee understand that the false privacy v security dichotomy that so often frames public debate seriously undermines policymakers’ and the public’s understanding of the issues at hand. The single most important airline security measure put in place following the terrible attacks on September 11th 2001 was the reinforcement of cockpit doors. That had absolutely no impact on the personal privacy of travellers. The hugely expensive naked scanners installed at airports, however, take a terrible toll on personal privacy whilst being functionally worse than useless as a security measure (and the X-ray variety has been shown to pose a risk to health). A door lock or a strong high fence provides security without compromising privacy.

Massive data collection and mining compromise privacy and security. The NSA gave 850,000 people access to classified materials as a routine part of their jobs. Their systems are big and complex and require a lot of staff to operate but there can be no security when that number of people has access to secrets. 

There is no “balance” to be achieved between the “individual right to privacy and the collective right to security”. The collective right to security requires an individual and collective right to privacy. The value of protecting individual and collective privacy is that those rights make a fundamental contribution to the overall health of society. Framing privacy as the opposite of security assumes privacy is only about hiding bad things. That couldn’t be more wrong.

It is fundamentally incompatible with the rule of law to collect information about every member of the population in the hope of conducting post hoc fishing expeditions to look for evidence of misbehaviour. Could I remind the committee of the belief of Cardinal Richelieu that given 6 lines written by the most honest man he could show you the evidence to hang him. 

It is unnecessary and completely disproportionate, not to mention dangerously ineffective, “to collect innocent communications in order to find those who might threaten our security.” Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services have to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance which, incidentally, in addition to being a clear and present danger to democracy, makes it mathematically impossible for dedicated intelligence services staff to do their job with any degree of effectiveness.

The committee should understand that computers are not magic. These machines do exactly what they are programmed to do not what you would like them to do.  I make this point specifically in light of the Prime Minister’s recent comments to the effect that the TV crime drama he likes so much justifies the mass data collection activities of the intelligence services. TV crime drama and Hollywood films generally are terrible guides to how computers actually work in practice.  The committee should additionally understand that there is no clear distinction to be made between communications data (or so called meta data) and communications content. If it is difficult to define the distinction from a social or legal perspective it is impossible to implement from the technical perspective.

a)      What balance should be struck between the individual right to privacy and the collective right to security?
How does this differ for internet communications when compared to other forms of
surveillance, such as closed-circuit television cameras? To what extent might it be
necessary and proportionate to monitor or collect innocent communications in order to find those which might threaten our security? How does the intrusion differ between data (the fact a call took place between two numbers) as opposed to content (what was said in the call)?

1. If the committee only takes one thing away from this submission let it be this –
       ·        Privacy and security are not opposites.
       ·        There is no balance to be struck between the individual right to privacy and the collective right to security.

2. Privacy has an image problem. It is constantly portrayed as out of date, costly, an obstacle to public safety and new and exciting forms of commerce and research. So if we pitch privacy against something as essential as national security, it is a no contest. What does it matter if we have to dispense with a little personal privacy for the guaranteed gain of being safer and more secure?

3. It matters because when you start with this fundamentally flawed premise and the committee’s flawed question, it leads you to the wrong answers.  The notion that privacy has to be sacrificed for security is wrong. More privacy does not mean less security any more than more security means less privacy. The associated (unspoken) idea that individual privacy is damaging to society is wrong. There’s no strict division between individuals and society. The welfare of both is inextricably interlinked. The fundamental right to privacy of the individual is one of the foundation stones of a healthy society. The value of protecting individual and collective privacy is incalculably important to the future of our information society.

4. The constant refrain about the need to balance privacy and security is quite simply wrong because it has a number of built in assumptions that are wrong.

5. It assumes that privacy and security are opposites which is false. A locked door and a tall strong fence provide security and facilitate privacy. A reinforced cockpit door – the most important airline security measure put in place since the atrocities of September 11th 2001 – does nothing to compromise privacy.

6. It assumes that undermining privacy through the use of magic modern computer systems will improve security. This is false. Democracy and freedom requires privacy and security. That such mass surveillance will not work can be demonstrated mathematically.

7. The esteemed chairman of the ISC, Mr Rifkind, has stated in parliament (in the debate on oversight of intelligence & security services on 31st October 2013) that

“Of the totality processed by computers, perhaps 0.01% will have selectors that the computer has been programmed to look for. The communications of the other 99.99%— covering virtually every citizen of this country, bar a very small number—are never even looked at by the computer, other than in relation to a selector, such as an e-mail address. Even for the tiny minority identified by the computers as potentially relevant to terrorism, if GCHQ, MI5 or MI6 want to read the content of any of the e-mails, they have to go to the Secretary of State for permission. Under the law, only if they are given permission can the content be read”

8. I'm going to do some very rough maths here in an attempt to explain the problem with Mr Rifkind’s point that only 0.01% of communications data is looked at.

9. 0.01% of 60 million people in the UK implicates 6000. Now the pattern flagging will be nowhere near as simple as that but just run with it as a crude estimate. We know from the deputy director of the NSA testifying before the House Judiciary Committee that you don't need to be a terrorist or have contact (deliberate or inadvertent) with a terrorist to be flagged as suspicious. The NSA (and presumably GCHQ?) is allowed to travel “three hops” from its targets – who could be people connected to people connected to people connected to you. 0.01% of the UK population or 6000 people are 2 degrees of separation from about 160,197,360 and 3 degrees of separation from over 26 billion others (about three and a half times the population of the world).

10. Even limiting suspicion to two hops, your 0.01% of data on UK residents, Mr Rifkind, implicates more than 2.6 times the entire UK population. So the question then becomes, given that we are all suspects, who decides which suspects the intelligence services' limited resources should be deployed to further investigate and pursue, once the computer algorithms have worked their magic? 

11. Every time the (theoretically 99.99% effective) magic terrorist catching system is asked for a suspect it implicates vastly more people than the security services could possibly investigate in any detail.

12. Mr Rifkind also rightly stated "Modern computers... are programmed to run using certain selectors". So who gets to program the computers and what are the specific 'selectors'/filters? Who decides what the selectors should be? Who decides who decides what the selectors should be? The chair of the ISC doesn't understand computers, so how can he effectively and his committee scrutinise the technical aspects of this work? How do you measure the efficacy of these filters given it is widely known in the tech community how ineffective electronic filters can be? How, when someone is tagged as suspicious via these secret algorithms, does the information on that individual then get further processed? What happens when someone is wrongly tagged and how do they retrieve their innocence and clean bill of electronic health? Are you aware of the nature of false negative results and false positive results?

13. In multiple media engagements the Prime Minister, the Home Secretary and other members of the government refer to "protecting the public" from the four horsemen of the infocalypse - terrorists, drug dealers, child abusers and organised crime - and more. The Prime Minister last week extolled the virtues of TV crime dramas as a guide to how electronic surveillance systems should be deployed in practice. TV crime drama and Hollywood films generally are terrible guides to how computers actually work in practice. 

14. Mathematically the four horsemen are not problems that lend themselves to mass data mining. Even highly accurate (to 99.99% and by the way no current system comes close to that) data mining systems will swamp investigators with false positives when dealing with a large population. Law enforcement authorities end up investigating and alienating large numbers of innocent people. That’s no good for the innocents, for the investigators or for society.

15. There is an oft repeated the myth that the 9/11 attacks would have been prevented if only the US intelligence and security services had known where Mohamed Atta was when he had made a phone call to a terrorist suspect in Syria. The assumption is the magic terrorist catching mass data collection and analysis apparatus now run by the NSA would have pinpointed his location and led to his arrest.

16. Wrong.

17. Atta was known to the intelligence and security services and considered a threat. Police, intelligence and security systems are imperfect. Even in 2001 they processed vast amounts of imperfect intelligence information. At least one FBI agent believed Atta to pose a serious and imminent threat. That belief got lost in the noise of the intelligence information processes, suspects and issues the agencies were then dealing with, to the degree that they did not detain Atta or his associates and prevent the attack.

18. There was too much data noise in the system and they lost him. You cannot cure that excess of data noise problem by treating the entire population as suspects, engaging in suspicionless, blanket collection and processing of personal data. You cannot find the real terrorist by assuming everyone is a threat.

19. Mass data collectors can dig deeply into the digital persona of anyone but don’t have the resources to do so with everyone. The resultant pursuit of false positive leads mean the real bad guys often get lost in the noise, as happened with the 9/11 attackers including Atta who were known to US authorities but not considered sufficiently important to intercept.

20. Finding the four horsemen is a needle in a haystack problem and you can’t find the needle by throwing infinitely more needle-free hay on your stack and/or creating multiple giant and exponentially growing data haystacks.

21. Operating multiple massive databases of intimate personal communications data makes the public more vulnerable to the four horsemen not less so.

22. That such mass databases are useless for finding terrorists is clear from the maths and the evidence. The NSA has admitted in spite of previous claims that their mass data collection and analysis stopped 54 major terror attacks since 9/11 it didn't really stop any, but may possibly have provided secondary supportive evidence in relation to one. The most recent argument they used to support the deployment of such systems is mass data collection might be useful as an "insurance policy". An insurance policy?! The infrastructure of mass surveillance might be useful in the future, somehow, to someone?

23. That such systems also make the public less safe is associated with the impossibility of securing mass silos of valuable personal data. Computer scientists simply do not know how to keep databases of the magnitude of those used by the NSA and GCHQ secure from external hackers or the multitude of insiders who have access to these databases as a routine part of their jobs (850,000 including Edward Snowden in the case of the NSA).  Security experts like Ross Anderson, Bruce Schneier, Edward Felten and Peter Sommer have written extensively about this.  To understand this you have to think about how such systems can fail - how they fail naturally, through technical problems and errors (a universal problem with computers), and how they can be made to fail by attackers (insiders and outsiders) with malign intentions e.g. the four horsemen. When the inevitable hacks, leaks, data contaminations happen, what then?

24. In its most insidious form the misleading privacy v security question is phrased as a statement along the lines “the innocent have nothing to hide”. This assumes two underlying falsehoods – firstly that privacy is only about hiding bad things and secondly that decimating privacy will solve the problem du jour. I hope I’ve demonstrated clearly to the committee that both these assumptions are wrong and that in answer to your questions –
      ·       There is no balance to be struck between the individual right to privacy and the collective right to security
·        It is neither necessary nor proportionate nor is it effective to engage in blanket monitoring or collection of  innocent communications in an attempt to find those who might threaten our security
25. On the question of whether the intrusion differs between data and content I would refer you to Peter Sommer’s writings and analysis e.g. analysis (sic) at
http://scramblingforsafety.org/2012/sf2012_sommer_commsdata_content.pdf
And his evidence before the select committee on the Communications Data Bill.
b) Whether the legal framework which governs the security and intelligence agencies’ access to the content of private communications is ‘fit for purpose’, given the developments in information technology since they were enacted.

26. The notion that the day to day activity of every citizen should be recorded in the expectation that those records can, in future, be mined for nefarious activity is anathema to a healthy functioning liberal democracy. Yochai Benkler in a recent Guardian article (http://www.theguardian.com/commentisfree/2013/oct/16/nsa-fbi-endrun-weak-oversight) put it more eloquently than I could:

     “Mass surveillance represents a commitment to near-universal all-seeing gaze, so as to assess and respond to threats that can arise anywhere, at any time. Privacy as a check on government power represents a constitutional judgment that a limited government must have limited power to inspect our daily lives, and that an omniscient government is too powerful for mere rules to restrain. The experience of the past decade confirms this incompatibility...

    Technology has enabled government to have investigative and situational awareness on a scale and scope that were science fiction when the Stasi shut its doors. The "state of emergency" mindset necessary to justify the program in the first place drives those charged with assuring the safety of Americans to always use this technology to its full potential; it also gives them an independent source of legitimacy for their actions – the fierce urgency of necessity.
    Their mission clashes with the fundamental premise of privacy as a civil right: that state power is best contained by making the overwhelming majority of what goes on in society invisible to the state. As Justice Alito put it in the supreme court's decision to strike down GPS tracking:

        [Historically] the greatest protections of privacy were neither constitutional nor statutory, but practical.

    Once the state knows about behaviour, it is hard to rely on rules alone to bear the full burden of preventing overreach by those who wield its awesome power...

    Rules alone cannot hold back the millions of potential abuses of an omniscient state.

    As long as government is allowed to collect all internet data, the perceived exigency will drive honest civil servants to reach more broadly and deeply into our networked lives.”
 
c) Proposals for specific changes to specific parts of legislation governing the collection, monitoring and interception of private communications.

27. As Jemina Stafford QC made clear in a formal opinion for a parliamentary committee last week, (http://www.tom-watson.co.uk/wp-content/uploads/2014/01/APPG-Final.pdf) the current mass data collection activities of sections of the UK government already undermine the right to privacy guaranteed in the Human Rights Act and article 8 of the European Convention on Human Rights. It is clear that the Regulation of Investigatory Powers Act does require an update but I don’t have any specific proposals to put before the committee at this stage.

28. However, I do have a general proposal that suspicion should be the test for surveillance.

29. The government of course has the right to intercept and record information when someone is suspected of a serious crime. But current operation [sic] appear to involve collection of data without suspicion: which is in effect mass surveillance. Due process, since the 1765 case of Entick v Carrington, requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To operate the mass date [sic] collection and analysis systems GCHQ has been reported as doing which give the entire population less protection than a hitherto genuine suspected criminal, based on a standard of reasonable suspicion, is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is indefensible in law.

30. I appreciate the ISC and a multitude of highly dedicated public officials are grappling with really complex issues here. But it is critically important that you understand –

·        Privacy and security are not opposites.

·        There is no balance to be struck between the individual right to privacy and the collective right to security.

·        Computers are not magic and never will be

·        Mass data collection and analysis is mathematically provable to be unfit for the purpose of hunting the four horsemen of the infocalypse

31. It is also hugely important that you be provided with the resources and expertise required to fulfil the immensely demanding duties required of the committee.

32. I'd leave you with one final thought. Nearly 250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you (the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas).

33. The good judge also declared personal papers to be one’s “dearest property”. I suspect he might view personal data likewise in the internet age. I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures. For a quarter of a millennium, fishing expeditions of the type that the GCHQ and NSA are engaged in have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern practices into line with that rule of law.
 Update: I neglected to number the paragraphs in my submission on Friday. Now rectified and amended above.

Wednesday, February 05, 2014

Further MP response on Snowden

I've had another response from my MP, Nicola Blackwood, this time to my admittedly somewhat caustic critique of Foreign & Commonwealth Office Minister of State, Hugh Robertson's, letter on the oversight of intelligence and security services. It appears as though she has misinterpreted the tone of that post and rapidly retreated behind the shield of the government mantra on the Snowden affair:
"Dear Mr Corrigan,
Thank you for your further email about intelligence services and I apologise for the lengthy delay in my response.
I am sorry to learn that you were disappointed by the Minister's response, and having read your blog I understand that you feel the Minister did not address the point at hand and you are disappointed that he is unable to comment on specific intelligence matters. I do apologise that I cannot offer any further information than the Minister, but I would stress that the UK has one of the world's strongest legal and regulatory frameworks governing the use of secret intelligence. UK legislation is fully compatible with the right to privacy in Article 8 of the European Convention on Human Rights (ECHR). Our secret intelligence agencies are subject to the provisions of the Data Protection Act 1998 and additional UK statutory controls and safeguards, including the relevant sections of the Intelligence Services Act, the Human Rights Act 1998, and the Regulation of Investigatory Powers Act, and robust oversight mechanisms including the Intelligence Security Committee and the Interception of Communications Commissioner.
You also ask how many constituents contacted me on this debate, I can tell you that 15 constituents in total wrote to me to ask that I attend the debate on 31st October. Unlike yourself, other constituents who had contacted me on this issue had done so in the form of a campaign template email. Thank you again for contacting me, I hope this response is helpful.
Kind regards
Nicola"
I've further responded as follows:
Nicola,
I fear the sardonic nature of my blogpost criticising the Minister's response may have led you to misreading it. It doesn't ask anywhere that the Minister should comment on specific intelligence matters. It does ask essentially, as did the FT in its editorial earlier this week, as do a multitude of security and legal experts with a deep understanding of the technology and the law, that Edward Snowden’s revelations be understood and acted upon, since they raise important questions about surveillance in a free society. As I said to you before, since Entick v Carrington in 1765, fishing expeditions of the type that the GCHQ and NSA are engaged in have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern practices into line with that rule of law.
Your stressing of the government line that 'the UK has one of the world's strongest legal and regulatory frameworks governing the use of secret intelligence' and the UK intelligence services are subject to 'robust oversight mechanisms' is, I'm afraid, in direct contradiction to the evidence. Academics do have a rather irritating affinity for evidence.:-) A senior legal adviser to GCHQ has noted "We have a light oversight regime compared with the US". The members of the Intelligence Security Committee do not understand the technologies and do not have the resources to do the oversight job expected of them. Only last week Jemina Stafford QC, in a formal legal opinion for a parliamentary committee, declared GCHQ's mass data collection activities to be illegal and to have been signed off by ministers in breach of human rights and surveillance laws.
I could go on but suspect your retreat into a repetition of the government mantra on the affair means you have already disengaged.
Thanks for letting me know 15 constituents contacted you to ask you to attend the parliamentary debate on the 31st October. It would be disappointing if you were to give limited credence to those who decided to use the internet and a campaign template email to communicate with you on this or any other matter. I appreciate you probably deal with a large number of communications but it would be sad to return to the Blairite days of officially counting more than 10,000 [sic] objections to the proposed ID card scheme as a single response because they were coordinated through an internet facilitated campaign.
I would make one final point before signing off. Law enforcement, intelligence and security services need to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbor suspicion. That is not, however, the same as building an infrastructure of mass surveillance which, incidentally, in addition to being a clear and present danger to democracy, makes it mathematically impossible for dedicated intelligence services staff to do their job with any degree of effectiveness.
Thanks for taking the time to respond again but it would appear that we are settling on different sides of the fence on the Snowden affair.
Regards,
Ray"

Friday, January 31, 2014

ORG recruiting legal director

Some of the Open Rights Group's learn'd friends are calling for help to enable ORG to recruit a legal director:
"We are lawyers who work with the Open Rights Group. 
You and the Open Rights Group can make a huge difference in the UK and European courts, defending your digital rights. That’s why we are asking you to join ORG today, so they can hire a Legal Director. We need just 40 more people to hire them full time.

Help hire ORG's Legal Director 
But perhaps it’s best if we explain in our own words:
“The appointment of a legal director will make a real impact on the work of the Open Rights Group.  It has never been more important to have informed interventions at the High Court and appeal courts on matters to do with digital rights.
“I know from my own experience as appeal solicitor in the “Twitter Joke Trial” the difference it makes when courts properly understand technological issues, especially when imposing criminal liability on the citizen”
David Allen Green, solicitor at Preiskel & Co LLP, and member of Advisory Council, ORG.

“In the US, digital freedoms have been fought for and won in historic legal battles such as Reno v ACLU  and countless smaller cases where the EFF and other digital rights groups have helped take on cases involving freedom of speech online, privacy online, cyber- harassment, vindictive copyright enforcement and so on. In the UK until now civil society has never had the capacity to take such important legal cases. Help ORG hire a Legal Director to change this and bring UK law into the 21st century.”
Dr Lilian Edwards, ORG Advisory Council and Professor of Internet Law at Strathclyde University

“ORG is a vital partner with EFF in addressing mass surveillance. Just as GCHQ and NSA work together, it's increasingly critical that we strengthen the capabilities of groups on both sides of the Atlantic to push back to regain our privacy and free speech.”
Cindy Cohn, Legal Director, Electronic Frontier Foundation

“There is no doubt that Parliament and the Courts have struggled with the challenges posed by the explosion of online interaction and the growing importance of rights in an increasingly digital world. Decisions made now will shape the approach that the Law takes for decades and possibly longer. This is a key moment. ORG speaks up for those whose interests are usually discounted when it comes to governmental and judicial policy making – it speaks up for you and everyone else who lacks a vested interest and a lobbying budget. A Legal Director is exactly what ORG needs at exactly the time we all most need ORG.”
Seán Jones QC11KBW Chambers

“The law can be an instrument of repression but it can also be a powerful tool for change. Your support for ORG's Legal Director post can make a real difference in the fight for digital freedom in the UK.”
Eric Metcalfe, Monckton Chambers, former director of human rights policy at JUSTICE

“Please help with the appointment of a Legal Director for the Open Rights Group. In my personal experience, ORG have initiated valuable interventions on civil liberties issues affecting millions of adults in the UK, such as filtering.”
Myles Jackman, Law Society Junior Lawyer of the YearConsultant Solicitor-Advocate at Hodge Jones and Allen LLP @ObscenityLawyer

"As an American lawyer I've seen how important it is to have boots on the ground to defend civil liberties in court.  Even when the underlying law itself is designed to protect civil liberties, being able to appeal directly to the courts may be the only way to keep them protected not just in theory but in practice."
Cathy Gellis, US Tech and civil liberties lawyer

“I have had the honour of working with ORG to do some marvellous work: both intervening in high profile cases and working behind the scenes to help individuals who have fallen foul of laws that were not or should not have been drafted for the modern digital world. I am convinced that ORG could do so much more with the assistance of a full-time legal director and I am excited by all the things that ORG could do if it had one. Money pledged for this purpose will be money well spent.”
Francis Davey, Independent barrister and ORG legal volunteer
We need just 40 people to join to make this project happen.Please help us hire a full time Legal Director by joining the Open Rights Group today!
https://www.openrightsgroup.org/join/help-hire-orgs-legal-director
Yours,
ORG Legal volunteers and ORG Law group
_________
[1] British government to answer fast-track spy challenge https://www.privacynotprism.org.uk/news/2014/01/24/british-government-to-answer-fast-track-spy-challenge/"
Given this prompt I'd like to invite the academy to consider again the possibility of creating a network of digital rights cyberlaw clinics to provide ORG and their forthcoming legal director with pro bono support in critical cases.

Friday, January 17, 2014

BBC ignorance on mass surveillance again

I was listening to the BBC Radio 5 Live station on the way back from Milton Keynes this evening. They noted President Obama made a speech about reforming NSA practices.

Around about 5.55pm they spoke to a correspondent in Washington. She got almost everything about the Snowden mass surveillance revelations wrong.

She uncritically repeated the myth that the 9/11 attacks would have been prevented if only the US intelligence and security services had known where Mohamed Atta was when he had made a phone call to a terrorist suspect in Syria. She assumed  the magic terrorist catching mass surveillance apparatus now run by the NSA would have pinpointed his location and led to his arrest.

Wrong.

Atta was known to the intelligence and security services and considered a threat. Police, intelligence and security systems are imperfect. Even in 2001 they processed vast amounts of imperfect intelligence information. At least one FBI agent believed Atta to pose a serious and imminent threat. That belief got lost in the noise of the intelligence information processes, suspects and issues the agencies were then dealing with, to the degree that they did not detain Atta or his associates and prevent the attack.

There was too much data noise in the system and they lost him. You cannot cure that excess of data noise problem by treating the entire population as suspects, engaging in suspicionless, blanket collection and processing of personal data. You cannot find the real terrorist by assuming everyone is a threat.

Mass data collectors can dig deeply into the digital persona of anyone but don’t have the resources to do so with everyone. The resultant pursuit of false positive leads mean the real bad guys often get lost in the noise, as happened with the 9/11 attackers including Atta who were known to US authorities but not considered sufficiently important to intercept. Finding the terrorist is a needle in a haystack problem, and you don't make it easier by throwing more hay on the stack. It is mathematically impossible for such mass surveillance to be an effective tool for catching terrorists.

The BBC correspondent also implied that there was no problem with the blanket, suspicionless, mass collection of personal data that is going on and that Obama's plan to continue this practice but privatise it would cure most concerns.

Wrong.

I'm tempted to get into a long dissection of this dangerous meme but I'll keep it to a couple of points -

Blanket, suspicionless, untrammeled, mass surveillance is corrosive and wrong-headed. The implied notion that decimating privacy is not just the solution but the obvious solution to the security, terrorism or serious crime problem is naive. Spreading that invidious notion uncritically is irresponsible of the BBC.

Blanket, suspicionless, untrammeled, mass surveillance is dangerous no matter who the government tasks with the job of actually collecting, processing and storing the data.

There is no magic computer solution to the rare preventing terrorism problem.

Don’t get me wrong. Law enforcement and security services need to be able to move with the times, use modern digital technologies intelligently in their work and through targeted data preservation regimes – not a mass surveillance regime – engage in technological surveillance of individuals about whom they have reasonable cause to harbor suspicion. That is not, however, the same as building an infrastructure of mass surveillance.
 
The BBC has an appalling record on the reporting of the Snowden affair. I know there are some very smart people in the BBC who get the serious implications of what Edward Snowden has put into the public domain. But the collective ignorance of the corporation as a public service broadcasting institution has almost gone so far as to have become a public menace.

It's hard to decide if their failures are worse when they follow the government wish for them to ignore the issues or when on the odd occasion they do get round to it, it is often to spread the corrosive memes of governments caught in the act... "nothing to hide nothing to fear", "only there for your protection", "essential for national security", "privacy must be balanced with security"...

As a result of their complete failure to fulfil their public service remit on the Snowden affair, every suit, producer, presenter, correspondent and journalist at the BBC should be made to repeat at least a hundred times a day:
Quite simply an infrastructure of mass surveillance is not conducive to the public good.
Perhaps that might be a little long for the attention span the corporation believe they cater to.  How about
Mass surveillance is not conducive to the public good.
Maybe something a little simpler: 
Mass surveillance is bad for you and it doesn't work
That might do it.
Mass surveillance is bad for you and it doesn't work
Mass surveillance is bad for you and it doesn't work
Mass surveillance is bad for you and it doesn't work...
To the good folk at the Beeb who do get Snowden - I know how frustrating it can be when an institution you care about gets really important things wrong.  Good luck with what will undoubtedly be heroic, exhausting, painful and sometimes risky internal efforts to turn your supertanker round.

BBC page screening parts of Obama's NSA reform speech.

Channel 4 News on the speech here.

Update: thanks to @eldonnn for alerting me to the error in my original post.

Saturday, January 11, 2014

Thoughts on BBC failure on Snowden

Adrian Chiles is an affable broadcaster who now works for the BBC and ITV. He does the Drive programme on BBC Radio 5 Live on a Friday. I happened to catch a bit of it on the way home from work yesterday evening, just as he was introducing Myles Allen, Geosystem Science Professor and Head of the Climate Dynamics group at Oxford University's Atmospheric, Oceanic and Planetary Physics Department.

The short extract from the programme is worth listening to (before it gets timed out on the BBC iPlayer). It is one illustration of the low level of understanding BBC presenters seem to have of science and technology.

The segment begins a little over 2 hours in at  2:11:24. Mr Chiles was friendly as always. Prof Allen was engaging and informative but it sounded to me that the presenter was not really following him too well. In fairness to Mr Chiles, unlike many of his colleagues who determinedly and rudely cut people off and paint the world in simplistic "balanced" extremes, he did his best to listen, ask questions and give the good professor the opportunity to make his points. Mr Chiles then closed by deciding he's going to get a tractor to deal with the bad weather.

I use this example not to criticise Mr Chiles in particular - he's a terrific broadcaster who does his job really well, particularly on the sports end of his varied portfolio - but because in spite of his difficulty in following the argument he, at least, made an effort. Many of his colleagues use straw men, sarcasm, the god of "balance", attack the messenger and/or a variety of other tactics to cover their low level understanding of or lack of interest in science; some even boast and cheer about that ignorance.

However, in an information age, the scientific, technological and mathematical ignorance of mainstream public service broadcast and print journalists presents a significant democratic deficit.

The 4th Estate is supposed to talk truth to power and provide a check on the branches of government and hopefully help prevent them getting out of control. Well parts of the US and UK government are out of control.

Edward Snowden has revealed the levers of power are being wielded in secret to engage in suspicionless mass surveillance of entire populations, via complex modern technologies. Also that the political hierarchy in charge of this activity have been dangerously clueless about the mass surveillance infrastructure they have funded, constructed and facilitated.

If the journalists tasked with holding these people to account don't understand the science, technology or mathematics then they cannot do their job with any degree of credibility. IMHO the BBC has largely failed in its public duty to report on the Snowden affair with any degree of credibility. The poor scientific and technical background of many of their mainstream presenters will have been a contributory factor in this failure.

The latest from the NSA is that they now seem to be admitting (in spite of previous claims that this mass surveillance stopped 54 major terror attacks it didn't really stop any, but may possibly have provided secondary supportive evidence in relation to one) that the best argument they can come up with is mass data collection might be useful as an "insurance policy". What?! An insurance policy?! The infrastructure of mass surveillance might be useful in the future, somehow, to someone?

Who? Why? When? How? What? Where? Those six honest serving men serve pretty well in the science and technology arena too. BBC presenters might like to take note.

Opt out of NHS data grab before it's too late

The inimitable Ross Anderson, Professor in Security Engineering at the University of Cambridge Computer Laboratory, has succinctly pointed out the importance of opting out of the latest NHS data grab before it is too late. I hope he won't mind me reproducing his advice here in full:
"The next three weeks will see a leaflet drop on over 20 million households. NHS England plans to start uploading your GP records in March or April to a central system, from which they will be sold to a wide range of medical and other research organisations. European data-protection and human-rights laws demand that we be able to opt out of such things, so the Information Commissioner has told the NHS to inform you of your right to opt out.
Needless to say, their official leaflet is designed to cause as few people to opt out as possible. It should really have been drafted like this. (There’s a copy of the official leaflet at the MedConfidential.org website.) But even if it had been, the process still won’t meet the consent requirements of human-rights law as it won’t be sent to every patient. One of your housemates could throw it away as junk before you see it, and if you’ve opted out of junk mail you won’t get a leaflet at all.
Yet if you don’t opt out in the next few weeks your data will be uploaded to central systems and you will not be able to get it deleted, ever. If you don’t opt out your kids in the next few weeks the same will happen to their data, and they will not be able to get their data deleted even if they decide they prefer privacy once they come of age. If you opted out of the Summary Care Record in 2009, that doesn’t count; despite a ministerial assurance to the contrary, you now need to opt out all over again. For further information see the website of GP Neil Bhatia (who drafted our more truthful leaflet) and previous LBT posts on medical privacy."

Wednesday, January 08, 2014

Foreign & Commonwealth Office Minister of State, Hugh Robertson, response on oversight of security services

My MP, Nicola Blackwood, has had a reply from Foreign & Commonwealth Office Minister of State, Hugh Robertson, to her letter "to the Foreign Secretary, on behalf of a number of your constituents, about concerns about oversight of the security services". Mr Robertson describes himself as "the minister responsible for this issue."  I wrote to Ms Blackwood about the Snowden affair in October and briefly again in December when she got back to me.

Copy of Mr Robertson's letter to Ms Blackwood here. (Update: I've removed the embedded copy of the letter from this post because of the irritating glitch in Blogger/ Google Drive that causes the homepage to jump to the Drive pdf insert).

In summary, Mr Robertson's response states "it is the longstanding policy of successive British Governments not to comment on intelligence matters" but that he would like to draw our attention to -
  • the statement the Foreign Secretary made to Parliament on 10 June
  • the Intelligence & Security Committee (ISC) statement of 17 July saying the initial NSA/Prisrn allegations were unfounded
  • the ISC press release of 17 October saying they intended to do further work
  • Home Office minister James Brokenshire's statement in the parliamentary debate of 31 October saying we should be proud of UK oversight of intelligence agencies 
  • a link to the Hansard transcript of the debate www.publications.parliament.uk/pa/cm201314/cmhansrd/cm131031/hallindx/131031-x.htm 
Seriously? Six months on and the best the UK government can do is -
  • We don't comment on intelligence matters
  • All praise William Hague
  • There's nothing to see here, move along
  • We'll check the law anyway
  • We had a chat about it and the minister said we should be proud and here's the web link to prove it
So though I would thank Mr Robertson for taking the time to write to Ms Blackwood in relation to the concerns I raised with her, I would note, for the record, that his letter provides no reassurance on any of the fundamental issues at play here.  The one positive thing to come out of this non-response from the minister is that a number of Ms Blackwood's constituents (plural), not just this lone academic, have been concerned enough to contact her about untrammeled mass electronic surveillance.

(The helpful link provided by Mr Robertson to the parliamentary debate of 31 October would suggest that he is not, unsurprisingly perhaps, a B2fxxx reader; not, at least, of the three relatively long posts on this blog on that debate)

Monday, December 23, 2013

Patent trolls aka Patent Assertion Entities (PAEs) and the FTC

The Federal Trade Commission has had a public consultation on patent trolls. The FTC, however, adopt the industry's own description of itself as "Patent Assertion Entities (PAEs)". Once the government accepts patent trolls as legitimate economic actors, the battle to explain (or even attempt to understand properly) the complex calculus of their effect on the economy is effectively over.

Some of the submissions make interesting reading, though unsurprisingly, Intellectual Ventures (IV) have a slightly different perspective to, say, the Electronic Frontier Foundation (EFF) and Public Knowledge (PK). 

IV conclude:
For all the reasons described above, the information requests do not meet the requirements of the Paperwork Reduction Act, nor, more importantly, will they assist the Commission in meeting the goals of the 6(b) study. As currently drafted, the requests miss the opportunity to focus on the broader, economy - wide effects of patent assertion activity by different types of entities, and thus provide the Commission with no ability to compare the costs and benefits of PAE activity to its alternatives. The requests will also create enormous burdens for respondents, require unnecessary information, and generate a record far too large for the Commission to process efficiently. This combination may significantly delay the issuance of the report, which would greatly diminish its value. Because timely insights are critical, and IV is eager to work cooperatively with the Commission to ensure that it receives the information it needs to meet its goals in a timely manner, we respectfully urge the Commission to modify the requests as noted above.
Translation: stop irritating us with costly red tape and produce a report telling everyone how wonderful we are.

The EFF and PK, on the other hand, say:
The proposed Section 6(b) study would significantly advance the quantity and quality of public information regarding patent assertion entities. The study would, thus, both directly help the diverse targets of PAE activity and enable the FTC and other policymakers to better serve consumers and preserve competition. The FTC is also particularly well suited to make these requests; it has the necessary statutory authority and experience in consumer protection and patent policy to conduct this particular study. Finally, the Section 6(b) study's proposed respondents would find complying with the questions manageable and straightforward. Because the public understanding of PAEs remains limited by PAEs' covert practices, the FTC should proceed in asking these entities to provide basic answers that would serve consumers, small businesses, policymakers, and the general public.
Translation: these sneaky patent troll parasites are sucking real innovators and consumers dry; and the FTC are well placed to expose them to the public gaze and take them down a peg or two. It won't cost the trolls anything to fill in a few forms to attempt to justify themselves, so it's the least they should be asked to do.

Wednesday, December 18, 2013

Glenn Greenwald testimony at EP Inquiry on mass surveillance

Glenn Greenwald testified this morning at the EU parliament LIBE committee hearing on mass electronic surveillance. Copy of the recorded session below.



It's worth viewing in full if you can find a spare 90 minutes (otherwise wait for the transcript). If you can't last the full 90, there is a 7 minute video of extracts from Mr Greenwald's statement -



Mr Greenwald subsequently took exception to the misrepresentation of his evidence on twitter by conservative MP Julian Smith.

Video of the full morning session, including evidence from security specialists Christopher Soghoian of the ACLU, Christian Horcher, Prof Bart Preneel of the University KU Leuven in Belgium and Stephan Lechne of the IPSC (one of the seven institutes of the European Commission's Joint Research Centre) will be available shortly.

Update: Christopher Soghoian's written testimony has been made available by the ACLU.

Wednesday, December 11, 2013

Former whistleblowers: open letter to intelligence employees

Former whistleblowers, , , , , , , have published an open letter to intelligence employees in today's Guardian. I hope they won't mind if I reproduce it here in full.
"At least since the aftermath of September 2001, western governments and intelligence agencies have been hard at work expanding the scope of their own power, while eroding privacy, civil liberties and public control of policy. What used to be viewed as paranoid, Orwellian, tin-foil hat fantasies turned out post-Snowden, to be not even the whole story.
What's really remarkable is that we've been warned for years that these things were going on: wholesale surveillance of entire populations, militarization of the internet, the end of privacy. All is done in the name of "national security", which has more or less become a chant to fence off debate and make sure governments aren't held to account – that they can't be held to account – because everything is being done in the dark. Secret laws, secret interpretations of secret laws by secret courts and no effective parliamentary oversight whatsoever.
By and large the media have paid scant attention to this, even as more and more courageous, principled whistleblowers stepped forward. The unprecedented persecution of truth-tellers, initiated by the Bush administration and severely accelerated by the Obama administration, has been mostly ignored, while record numbers of well-meaning people are charged with serious felonies simply for letting their fellow citizens know what's going on.
It's one of the bitter ironies of our time that while John Kiriakou (ex-CIA) is in prison for blowing the whistle on US torture, the torturers and their enablers walk free.
Likewise WikiLeaks-source Chelsea (née Bradley) Manning was charged with – amongst other serious crimes – aiding the enemy (read: the public). Manning was sentenced to 35 years in prison while the people who planned the illegal and disastrous war on Iraq in 2003 are still treated as dignitaries.
Numerous ex-NSA officials have come forward in the past decade, disclosing massive fraud, vast illegalities and abuse of power in said agency, including Thomas Drake, William Binney and Kirk Wiebe. The response was 100% persecution and 0% accountability by both the NSA and the rest of government. Blowing the whistle on powerful factions is not a fun thing to do, but despite the poor track record of western media, whistleblowing remains the last avenue for truth, balanced debate and upholding democracy – that fragile construct which Winston Churchill is quoted as calling "the worst form of government, except all the others".
Since the summer of 2013, the public has witnessed a shift in debate over these matters. The reason is that one courageous person: Edward Snowden. He not only blew the whistle on the litany of government abuses but made sure to supply an avalanche of supporting documents to a few trustworthy journalists. The echoes of his actions are still heard around the world – and there are still many revelations to come.
For every Daniel Ellsberg, Drake, Binney, Katharine Gun, Manning or Snowden, there are thousands of civil servants who go by their daily job of spying on everybody and feeding cooked or even made-up information to the public and parliament, destroying everything we as a society pretend to care about.
Some of them may feel favourable towards what they're doing, but many of them are able to hear their inner Jiminy Cricket over the voices of their leaders and crooked politicians – and of the people whose intimate communication they're tapping.
Hidden away in offices of various government departments, intelligence agencies, police forces and armed forces are dozens and dozens of people who are very much upset by what our societies are turning into: at the very least, turnkey tyrannies.
One of them is you.
You're thinking:
● Undermining democracy and eroding civil liberties isn't put explicitly in your job contract.
● You grew up in a democratic society and want to keep it that way
● You were taught to respect ordinary people's right to live a life in privacy
● You don't really want a system of institutionalized strategic surveillance that would make the dreaded Stasi green with envy – do you?
Still, why bother? What can one person do? Well, Edward Snowden just showed you, what one person can do. He stands out as a whistleblower both because of the severity of the crimes and misconduct that he is divulging to the public – and the sheer amount of evidence he has presented us with so far – more is coming. But Snowden shouldn't have to stand alone, and his revelations shouldn't be the only ones.
You can be part of the solution; provide trustworthy journalists – either from old media (like this newspaper) or from new media (such as WikiLeaks) with documents that prove what illegal, immoral, wasteful activites are going on where you work.
There IS strength in numbers. You won't be the first – nor the last – to follow your conscience and let us know what's being done in our names. Truth is coming – it can't be stopped. Crooked politicians will be held accountable. It's in your hands to be on the right side of history and accelerate the process.
Courage is contagious.
Signed by:
Peter Kofod, ex-Human Shield in Iraq (Denmark)
Thomas Drake, whistleblower, former senior executive of the NSA (US)
Daniel Ellsberg, whistleblower, former US military analyst (US)
Katharine Gun, whistleblower, former GCHQ (UK)
Jesselyn Radack, whistleblower, former Department of Justice (US)
Ray McGovern, former senior CIA analyst (US)
Coleen Rowley, whistleblower, former FBI agent (US)"

Monday, December 09, 2013

Kids can opt out of school fingerprinting

May I recommend Jon Baines' short blogpost pointing out that kids can opt out of school fingerprinting and/or biometrics collection whether the school or their parents like it or not. Jon succinctly draws attention to Chapter 2 of Part 1 of The Protection of Freedoms Act 2012.
"The school
must ensure that a child’s biometric information is not processed unless—
(a)at least one parent of the child consents to the information being processed, and
(b)no parent of the child has withdrawn his or her consent, or otherwise objected, to the information being processed….
The relevant authority must ensure that reasonable alternative means are available by which the child may do, or be subject to, anything which the child would have been able to do, or be subject to, had the child’s biometric information been processed.
But also note (here’s the totally rad bit) that, even if your parents are OK with it, you have the right to object, and if you do, that trumps what your parents, and your school, think. Cool eh?
if, at any time, the child—
(a)refuses to participate in, or continue to participate in, anything that involves the processing of the child’s biometric information, or
(b)otherwise objects to the processing of that information,
the relevant authority must ensure that the information is not processed, irrespective of any consent given by a parent of the child"

Friday, December 06, 2013

"Academic progress" a matter for the academy not the Home Secretary?

The Court of Appeal published an important decision on universities' border control obligations yesterday, Pokhriyal v The Secretary of State for the Home Department [2013] EWCA Civ 1568 (05 December 2013)

Academics and university administrators really should read Lord Justice Jackson's conclusions on the appeals of two foreign students whose leave to remain in the UK has expired.

The bottom line is that the Court decided that despite the Byzantine immigration rules universities are now obliged to incorporate into our operational processes, "academic progress" is a matter for the academic institution not the Home Secretary or her officials acting in her stead (see paragraph 58). The good judge firstly outlines the facts of the case.
"
  1. These are appeals by two foreign students whose leave to remain in this country has expired. They challenge the Secretary of State's decisions, upheld by the First-tier Tribunal and the Upper Tribunal, that their proposed further courses do not constitute academic progress from their previous studies.

  2. The first appellant is Himanshu  Pokhriyal  ("HP"). The second appellant is Amjad Hussain ("AH"). Although there is no order for anonymity, it is easier to refer to both appellants by their initials.

  3. Both appellants came to the UK as Tier 4 (general) students under the Points Based System ("PBS"). The rules governing the PBS are set out in the Immigration Rules and the appendices to those rules. These provisions have now achieved a degree of complexity which even the Byzantine Emperors would have envied."
Jackson LJ then goes on to outline some of the immigration rules before considering each student in turn. Let's focus on HP's case ("CAS", incidentally is the Confirmation of Acceptance for Studies form a college or university fills out on behalf of the student and submits electronically to the UK Border Agency):
"HP
  1. HP is an Indian national, born in 1986 and now aged 27. HP came to the UK for the purpose of studying in September 2008. He was granted leave to enter as a Tier 4 (general) student under the PBS. He was subsequently given leave to remain in that capacity until 4th January 2012.

  2. Initially HP studied for a postgraduate diploma at the London School of Business Management. HP subsequently transferred to other colleges, where he studied business administration and business management. These courses were classified as NVQ level 7.

  3. In late 2011 HP decided that he needed to obtain a qualification in IT, in order to improve his career prospects. He applied for and secured a place at St Stephen's College to study for a diploma in IT. This was a two and a half year course, classified as NVQ level 5.

  4. HP applied to the Secretary of State for an extension of his leave to remain in the UK, so that he could undertake the IT course. In support of that application St Stephen's College issued a CAS, which it sent to UKBA.

  5. In the box on the CAS marked "evidence provided" the college described the previous courses which HP had undertaken. The college then added this:
  6. "ACADEMIC PROGRESSION: Student has studied a PGD for general academic purposes but as he wants to go into the IT industry, a qualification in IT combined with the PGD would offer him better opportunities. Student wishes to follow a career in IT in India and in particular with the Tata Group. He believes that his previous studies in the UK combined with an IT qualification would provide him with additional opportunities in following his chosen career path."
  7. By a letter dated 9th February 2012 the Secretary of State refused HP's application on the ground that HP's new course did not constitute "academic progress" within the meaning of paragraph 120B of Appendix A to the Immigration Rules. Accordingly HP failed to achieve the required 30 points under paragraph 245ZX (c) of the Immigration Rules.

  8. HP appealed unsuccessfully against that decision first to the First-tier Tribunal, then to the Upper Tribunal. He now appeals to the Court of Appeal."
In paragraphs 33 to 55 Lord Justice Jackson outlines the Court's interpretation of the pertinent immigration rules and then concludes on HP:
"
  1. The issue in HP's case is a short one. It turns upon the words used by St Stephen's College in the CAS, which I have quoted in Part 2 above. The issue is whether those words constituted confirmation that the IT course for which HP had been accepted represented academic progress.

  2. In my view that passage did constitute such confirmation. It begins with the words in capitals "ACADEMIC PROGRESSION". In other words the college regarded the IT course as academic progress. The college uses the word "progression" as a synonym for "progress". There then follows an explanation as to why the IT course represented academic progress. The reason why the new course at NVQ level 5 was academic progress from the previous course at NVQ level 7 was, in effect, explained by the fact that the student needed skills in a different field in order to complement his original qualification and to obtain future employment.

  3. The Secretary of State in her refusal letter, the First-tier Tribunal and the Upper Tribunal all fell into the same error. They all considered the evidence and formed their own view as to whether the IT course constituted academic progress. The question whether the IT course was academic progress was a question for St Stephen's College, not the Secretary of State. On appeal the First-tier Tribunal and the Upper Tribunal should not have interfered with the college's decision, when the college had plainly addressed its mind to the question of academic progress and formed a reasonable view on the subject.

  4. In these circumstances, I see no basis to invalidate the college's confirmation of academic progress. As the Secretary of State acknowledges in paragraph 375 of her guidance statement to colleges, a course at a lower level can on occasions constitute academic progress. This, in the college's view, is such a case. The IT course would enhance the business skills which HP had gained in his earlier studies.

  5. In the result, therefore, HP satisfied the requirements of paragraph 120B of Appendix A. Accordingly he scored 30 points under paragraph 245ZX (c) of the Immigration Rules. If my Lords agree, HP's appeal will be allowed."
Shorthand - the college not the Home Office gets to decide what constitutes "academic progress". That's important for the higher education sector to be aware of in times of widespread fear mongering around immigration.

Longmore LJ and Vos LJ agreed with Lord Justice Jackson's opinion but for different reasons.

Lord Justice Vos says in the cases of the two students considered the conclusions could be clear. However he felt it is allowable for the Secretary of State to -
"challenge the validity of the confirmation of academic progress... but that it would be better to leave a consideration of what those circumstances might be to a case in which such a challenge is made...
Suffice it to say for the purposes of these cases that I entirely agree that any argument as to whether or not a particular course does or does not represent academic progress is intended, under the Appendix A of the Rules and the guidance documents, to take place only between the college and the Secretary of State. The student is not intended to be involved"
Lord Justice Longmore's concurrence focuses on procedural errors on the part of the UK Border Agency in turning down the other student (AH's) application to stay. He also raises an interesting concern that since the student has no part in the CAS process how can they appeal if there are errors on the part of the college or the UKBA?

Expect more of these cases given the government's obsession with being seen to crack down on immigration and Vos LJ's concurrence which may be interpreted as an invitation to the Home Secretary.

Just one final general point in relation universities getting dragged into the immigration vetting business - when I signed up to the Open University nearly two decades ago it was for education duty not border control duty. 

Tuesday, December 03, 2013

I hit a Twitter limit...

I believe I have just been slighted (if not censored) by Twitter.  While tweeting on Guardian editor, Alan Rusbridger's, evidence before the Home Affairs select committee I hit a limit:
"You are over the daily limit for sending Tweets. Please wait a few hours and try again"
The daily limit is 1000 tweets a day and I've reached nothing like that number. So presumably I've run into the "daily update limit is further broken down into smaller limits for semi-hourly intervals" condition. So what is the smaller limit for semi hourly intervals? A quick count suggests I've posted about 125 tweets today, around 150 in the past 24 hours, a personal daily record, no doubt, but not really within the proverbial ass's roar of the 1000.

Neither could I continue tweeting the evidence of Sir Bernard Hogan-Howe QPM, Metropolitan Police Commissioner, and Cressida Dick QPM, Assistant Commissioner, Metropolitan Police.

They have confirmed, as far as I can tell but there was a lot of confused back and forth in the questioning, that they are engaging in a continuing enquiry into evidence seized from David Miranda. Ms Dick said they would go where the evidence takes them and will be careful and proportionate. They are working closely with the CPS on the investigation. "It appears possible that some people may have committed offences". The law surrounding all this is complicated and the CPS will decide whether to prosecute once the Met has pursued their scoping exercise and investigation of the Miranda materials. 

Mr Hogan-Howe eventually intervened to remind us that the Miranda material was currently the subject of a judicial review. The courts have reserved their judgement on whether the Met got the material lawfully under schedule 7 of the Terrorism Act and they will have to wait to see how that progresses.

Alan Rusbridger earlier said he didn't know if the Guardian or its staff were under police investigation.

Debate on oversight of intelligence & security services Part 3

On the day that The Guardian's editor is due to appear before the Home Affairs committee I thought it was time to round off my reporting on the parliamentary debate on the of oversight intelligence & security services. The debate is over a month old now and with the exception of the Guardian has, sadly, largely been ignored by the mainstream media.

Dominic Raab made the most telling contribution to the session, as I mentioned in Part 1. Part 2 of my report concluded with Malcolm Rifkind's endeavours to defend the Intelligence and Security Committee (ISC) which he chairs and the intelligence services his committee is tasked with overseeing. The committee has 9 members (7 MPs and two members of the House of Lords) and a part time investigator. The intelligence services have a staff of over 13000 and a 2013/14 budget of £2.1 billion, according to the Guardian.

Picking up again from Mr Rifkind's evidence, he believed -
  • there is no interception if it is only done by computers and the data is not seen by a human being
  • the Justice & Security Act 2013 has brought a "cultural revolution" to the ISC
  • hinted that critics claiming that the ISC didn't know about the Tempora undersea cable interception programme did "not have the faintest idea whether the Committee was aware of programmes of any kind."
  • computers are clever
  • 99.99% of the data they gather and process is never looked at so describing the activities of the intelligence services as mass surveillance was unconscionable
He then responded to a question from Tom Watson about the dangers of automated mass data analyses:
"the intelligence agencies have far more important things to do than to look at patterns of behaviour, unless they are directly relevant to a terrorist threat or serious crime. That is their function and legal duty, and if they go beyond it, they are committing a crime—even if they had the time, which they do not have, or the inclination to do so...
no other country in the world, including democratic ones, has both substantial intelligence agencies and such a degree of oversight."
He concluded by noting the Justice & Security Act 2013 has given the ISC all the oversight powers that critics have been asking for and the committee should be judged on their use of those powers and
"Right hon. and hon. Members should by all means scrutinise whether we use the powers properly, but they should please do so on the basis of knowledge about the Act"
He's right that Right hon. and hon. Members should understand the Act but an at least rudimentary but preferably deep understanding of the technology and the mathematics is also crucial. Such understanding was not evident in the contributions of the members of the ISC to the debate.

Rodney Buckland (Conservative) was next in line and he raised the need for reform of the Regulation of Investigatory Powers Act (RIPA) and the question of Schedule 7 of the Terrorism Act, widely believed to have been abused in the detention of David Miranda at Heathrow airport. David Anderson QC, the independent reviewer of terrorism legislation, has recently indeed called for an end to detention at borders without suspicion. His note to the Home Affairs select committee on the matter is available at the Parliament website.

Mr Buckland felt "the threshold of reasonable suspicion should come into play at the point when a person is formally detained" under schedule 7. He concluded by criticising the Guardian and saying privacy was important but in a balanced way, so we could catch terrorists too.

At this point Graham Brady who had taken over chairing the session part way through said he was restricting the remaining 3 speakers to 6 minutes each.

Richard Graham paraded his colours as a former diplomat and an anecdote about his first professional stint abroad - his first phone call, he says, got interrupted by a 3rd party asking him to repeat his last sentence. Mr Graham's purpose seemed to be to-
  • ridicule Julian Huppert, David Winnick and the anti mass surveillance side of the debate as being motivated by hysteria and naivete
  • note the hilarity of the shock at the news that spies actually spy
  • defend the honour and impeccable integrity, in addition to the law abiding citizenship and valour, of the chaps and chapesses in the intelligence services
  • allow these good folks, without undue interference, the capacity to get on with battling the multitude of "more complicated and more sophisticated" threats we face - including include nuclear proliferation, cyber-attacks, attacks on our intellectual property, organised crime and new weapons - that could destroy us. (Interesting to see intellectual property getting a mention in this context).
Dr Julian Lewis followed Mr Graham. He had three points to make in addition to praising Julian Huppert (anti) and Martin Horwood (pro) -
  • It is unacceptable for huge numbers of junior staff to have access to classified material
  • It's harder to track people today than it was in the past (seriously!); therefore data on everyone needs to be gathered for post hoc mining; and so what if there are lots of irrelevant data haystacks
  • Edward Snowden is no more a whistleblower than Julian Assange. What Snowden did was "irresponsible—" Unfortunately he didn't get to use his prepared label for Mr Snowden since the chairman cut him off, his 6 minutes were up.
Tobias Elwood was next and immediately undermined his contribution by stating
"The debate is about the balance of individual privacy versus the collective right to security."
No it really is not about balancing privacy and security. It is a completely false assumption to consider privacy and security to be opposites. Reinforcing cockpit doors has not undermined privacy in any way but is probably the single most important security measure brought into aviation since the 9/11 attacks.

Mr Elwood has suffered a personal loss due to a failure of the intelligence services to share information in timely fashion. His brother was killed in the Bali bombing as a result.

Diana Johnson stepped up to have a dig at Nick Clegg -
"Even the Deputy Prime Minister, given his recent comments to the media, appears to have missed the reforms that strengthened the Intelligence and Security Committee. That is surprising, considering he has 19 special advisers."
 - offer her interpretation of RIPA, express her confidence in the ISC and her hopes the committee will show its ability to conduct public hearings and restore public confidence.

At 4.18pm the Parliamentary Under-Secretary of State for the Home Department, James Brokenshire, got to his feet.and delivered a largely monotonal reading from his brief.
  • the intelligence services do essential work "confronting the diverse terrorist threat that this country continues to face"
  • the importance of scrutiny of the intelligence services is underlined by the loss of Mr Elwood's brother in the Bali bombing
  • intelligence work should happen within a strict legal and policy framework and it does and it has strict oversight but the intelligence services need "to maintain an edge in tackling terrorism and stopping criminals"
  • much oversight must happen behind closed doors to keep secret information secret
  • secrecy is essential  
  • intelligence services are overseen by more mechanisms than many other areas of government 
  • the ISC is good and got more power this year from the Justice and Security Act
  • in response to a question from Tom Watson on why Tempora did not receive parliamentary scrutiny Mr Brokenshire said it "not appropriate" for him to comment on such things in public
  • when Mr Brokenshire prevaricated following a question from Dr Huppert on on whether the ISC can investigate on long running operations, Mr Rifkind jumped in to his rescue - the ISC "have completed discussions with the Government, the results of which will appear in a memorandum of understanding that will be published and include details of how these matters will be dealt with. That will ensure that that consideration cannot be used as an improper way of preventing the ISC from obtaining access to operations that—by any normal, common-sense approach—could be considered as completed."
  • David Anderson QC, the independent reviewer of terrorism legislation is deserving of praise (mind you this was before Mr Anderson suggested restrictions on the use of Schedule 7 of the Terrorism Act)
  • GCHQ doesn't look inside the UK - this is misleading since GCHQ does look inside the UK under section 16 of RIPA
Mr Brokenshire concluded:
"It is this multi-faceted oversight that complements rigorous internal controls within the agencies themselves. The agencies’ recruitment and training procedures are all designed to ensure that those operating within the ring of secrecy can be trusted to do so lawfully and ethically. A culture of compliance with both the letter and the spirit of the law pervades everything that they do...
 This has been an important debate, highlighting the strength of the scrutiny that we have and the different layers of scrutiny that operate in this country. I believe that we have every reason to be proud of those oversight arrangements and of the work of our agencies."
We've no reason to doubt that many of the intelligence agencies' 13,000 plus employees do some terrific work. Mr Brokenshire's claim that we should be proud of the scrutiny of the intelligence services doesn't pass the laugh test in the light of the reports all round the world based on the Snowden documents, however. We have every reason to be concerned that
  1. 850,000 people have access to classified UK and US government material
  2. the UK and US governments through the NSA and GCHQ have been complicit in the clandestine construction of an electronic infrastructure of mass surveillance
  3. government intelligence & security services with the aid of large commercial organisations engage in mass surveillance - indiscriminately collecting, processing and storing the personal data - of that large proportion of the population using and/or visible to communications networks
  4. the NSA and GCHQ have been systematically undermining encryption technology that underpins privacy and the security of commerce on the internet by encouraging vendors and standards bodies to build back doors into their systems
  5. the notion that only the good guys will exploit such security holes is naive; they have through this process effectively destroyed trust in these systems
  6. large technology companies have been quietly cooperating with all this, though once it became public they changed their PR approach to claim victimhood along with the masses
  7. the laws to facilitate this mass surveillance are already in place and where they do interfere the NSA and GCHQ have operational methods for circumventing such inconveniences ('what not to say' rules when dealing with overseers)
  8. those engaged in the formal oversight mechanisms of the intelligence services work have little or no understanding of the technologies involved, what exactly they are being used for and what the consequences might be
  9. the UK government - with echoes of the Spanish Inquisition's, Nazi Germany's and Mao Zedong's book burning - is prepared to be responsible for the physical destruction of mainstream press equipment 
  10. the UK government is prepared to threaten the press with D notices and prior restraint through the courts 
  11. UK government ministers including the Prime Minister David Cameron are prepared to threaten the press (e.g in the debate on the European Council, Hansard Official Report, 28 October 2013; Vol. 569, c. 667.)
  12. the NSA’s own internal auditors found its agents broke privacy rules thousands of times each year
  13. the US government via the NSA reportedly route significant funds ($100 million) to the UK government intelligence service GCHQ 
  14. GCHQ appreciate their "light oversight regime compared to the US" 
  15. the secret US FISA Court's ability to oversee US spy agencies is very limited
  16. US intelligence chief James Clapper lied (responded in the "least untruthful manner") to Congress about the extent of NSA surveillance
  17. we have expanded secret courts in the UK
  18. some of the regulations and laws governing the operations of the intelligence and security services are themselves secret
  19. politicians are all too willing to demonise the messengers and trot out poisonous soundbites - the innocent have nothing to fear; our critics comfort/support our enemies/terrorists; government's first duty is to protect the public; be afraid but give us the power and we'll protect you; move on there's nothing to see; ...national security...; trust us we're acting within the law - to defend the indefensible and sate their ambitions
  20. the fourth estate - mainstream broadcasters and press - in the UK has largely been content to ignore or marginalise Guardian revelations, allowing that publication to plow an isolated furrow on the Snowden affair; worse still the Murdoch press and the Daily Mail, in particular, have actively attacked and sought to undermine the Guardian reporting on the Snowden affair; fueling the government's political attack dogs' outrageous accusations that the Guardian is aiding terrorism by publishing Snowden's revelations
  21. the UK is prepared to detain people (e.g. Glenn Greenwald's partner, David Miranda) at borders without suspicion to the limits of Schedule 7 of the Terrorism Act
  22. the Secretary General of the Council of Europe, Thorbjørn Jagland, was sufficiently concerned to write to the UK Home Secretary about Mr Miranda's detention and the destruction of the Guardian's computers
  23. the information consuming public take an essentially soporific attitude to all this
  24. the US has been tapping the phones of world leaders including Angela Merkel, the German Chancellor
  25. the surveillance infrastructure has been used for industrial espionage
  26. the strong incentives now pushing towards the balkanisation of the internet
I would repeat, therefore, that the reporting of the Snowden documents, the behaviour of the US and UK governments and our respective intelligence & security services and the subsequent reaction to this have raised fundamental questions of public interest (even if, in our world of short attention spans, the public is only superficially and transitionally interested, if at all) about -

  • security (no top secret can be secure if nearly a million people have access to it as a routine part of their jobs)
  • privacy (you have none on the internet)
  • anonymity (again you have none on the internet)
  • free speech (when does a whistleblower become a traitor?; why and how is is ok to smash up a computer in the offices of the Guardian in the UK in 2013?)
  • management and oversight of the police, intelligence and security services (what are the political, legal, environmental, societal, economic, technical and architectural checks and balances, if any and are they fit for purpose?)
  • the size, power and reach of the security/intelligence/surveillance/anti-terror industrial complex
  • secret courts (FISA, FISAAA 2008; the UK now has its own secret courts courtesy of the Justice and Security Act 2013 which came into force in June)
  • circumvention of human rights laws and constitutional protections (Prism, Tempora, XKeyscore, GCHQ-NSA data sharing?)
  • dangerous normalisation of activities that would have horrified earlier generations and been condemned as the actions & infrastructure of a despotic police state if connected with the Soviet Union, East Germany, China et al
  • the surveillance activities implicated by the Snowden documents are a breach of international law not matter how carefully or effectively GCHQ or the NSA has circumvented their own domestic laws
  • activities excused as efforts to secure the safety of citizens of one country should not violate fundamental human rights of citizens of another country
  • Finally for now, as Brazilian president, H.E. Dilma Rousseff, said at the UN General Assembly recently
""The arguments that the illegal interception of information and data aims at protecting nations against terrorism cannot be sustained...
In the absence of the right to privacy, there can be no true freedom of expression and opinion, and therefore no effective democracy. In the absence of the respect for sovereignty, there is no basis for the relationship among Nations.
We face, Mr. President, a situation of grave violation of human rights and of civil liberties; of invasion and capture of confidential information concerning corporate activities, and especially of disrespect to national sovereignty...
Friendly governments and societies that seek to build a true strategic partnership, as in our case, cannot allow recurring illegal actions to take place as if they were normal. They are unacceptable."

Monday, December 02, 2013

Response from MP on parliamentary surveillance debate

My MP, Nicola Blackwood, has written to explain she could not make it to the recent parliamentary debate last week on oversight of intelligence & security services. She has also written to William Hague to raise the concerns I expressed in my note to her prior to the debate.
"Dear Mr Corrigan,

Thank you for contacting me about the debate on oversight of the intelligence services. I do apologise for the delay in my response.

Unfortunately, I was unable to attend this debate due to a long-standing diary commitment. I have, however, read the transcript of the debate and have engaged with Ministers about the issues raised. If you would like to read the transcript of the debate yourself, it can be found at the following address: http://www.theyworkforyou.com/whall/?id=2013-10-31a.333.0

I appreciate your desire to ensure that powers to intercept communication are confined to what is necessary and proportionate to protect our national security, and also to be accountable. It is important to remember here the important work our security services do in tackling terrorism and international crime. However, I firmly believe, as does the Government, that it is absolutely right for this intelligence work to be carried out in accordance with a strict legal and policy framework that ensure that activities are authorised and entirely necessary.

Ministers have assured me that to intercept the content of any individual's communications in the UK requires a warrant signed personally by the Foreign Secretary, the Home Secretary, or by another Secretary of State. Every individual decision is taken based on legal and policy advice and warrants are required to be absolutely necessary and carefully targeted. Furthermore, the Interception of Communications Commissioner also has oversight powers in relation to decisions about whether to authorise the use of intrusive powers, for example in authorising the interception of communication.

At a parliamentary level, the Intelligence and Security Committee (ISC) examines the policy, administration, past operations and expenditure of the intelligence agencies and parts of the wider Government intelligence community. I am pleased that the powers of the ISC have recently been extended by the Government through the Justice and Security Act 2013, which makes it a committee of Parliament; provides greater powers; and increases its remit, including oversight of operational activity.

Ultimately there remains a need for secrecy within the intelligence community to allow agencies to function effectively, but I have received assurances from Ministers that the activities of the intelligence agencies do not, and will not, go unchecked.

I have written to the Foreign Secretary, William Hague, to raise your concerns and shall of course be pleased to pass on any response I receive in due course.

Thank you again for taking the time to contact me about this important issue, and I hope this response is helpful.

Kind regards
Nicola"
Ms Blackwood is a member of the Home Affairs select committee which Guardian editor, Alan Rusbridger, will be appearing in front of at 3pm tomorrow, followed at 4pm by Metropolitan Police Commissioner, Bernard Hogan-Howe and Assistant Commissioner, Cressida Dick. I've sent her a short response.
"Dear Nicola,

Thanks for your response and apologies for the delay in getting back to you.

Though I haven't had the time yet to cover the entire debate, you might find it useful to scan my analyses prior to Guardian editor Alan Rusbridger's appearance before the Home Affairs select committee's counter-terrorism evidence session tomorrow afternoon -

Debate on oversight of intelligence & security services Part 1 at http://b2fxxx.blogspot.co.uk/2013/11/debate-on-oversight-of-intelligence.html

Debate on oversight of intelligence & security services Part 2 at http://b2fxxx.blogspot.co.uk/2013/11/debate-on-oversight-of-intelligence_6.html

Your time is short but I would particularly recommend you pay careful attention to your colleague Dominic Raab's contribution to the debate, available at http://www.publications.parliament.uk/pa/cm201314/cmhansrd/cm131031/halltext/131031h0001.htm#13103154000332

I look forward to the Home Affairs committee proceedings tomorrow with interest.

Regards,

Ray"
The other members of the committee joining Ms Blackwood are Keith Vaz (Chair), Ian Austin (Labour), James Clappison (Conservative), Michael Ellis (Conservative), Paul Flynn (Labour), Lorraine Fullbrook (Conservative), Julian Huppert (Liberal Democrat), Yasmin Qureshi (Labour), Mark Reckless (Conservative), David Winnick (Labour). On past evidence we might expect Mr Austin to be critical of the Guardian and Messrs Huppert & Winnick to be supportive.