Brexit trade deal advises governments to use Netscape Communicator and SHA-1. Why? It's all in the DNA
- Reference: 1609394650
- News link: https://www.theregister.co.uk/2020/12/31/brexitl_obsolete_tech_explained/
- Source link:
Buried in the 1,000+ pages of the UK-EU trade deal are references to the obsolete Netscape Navigator browser and even Netscape Communicator, which was declared end-of-life in 1997.
“s/MIME functionality is built into the vast majority of modern e-mail software packages including Outlook, Mozilla Mail as well as Netscape Communicator 4.x and inter-operates among all major e-mail software packages,” says [1]page 921 of the deal , in a part named “ANNEX LAW-1: EXCHANGES OF DNA, FINGERPRINTS AND VEHICLE REGISTRATION DATA”.
Rather than being a throwback to the dusty days of dial-up internet and shouting at your mum for picking up the phone while you try to download cat GIFs, however, that annex contains the full and current text of the Prüm Convention – the treaty underpinning the European Union’s bloc-wide DNA database, to which the UK wants to keep access after departing the EU on Friday (1 January).
Unilaterally modifying a treaty with more than 20 international signatories could open a can of worms – so it’s no surprise that the whole thing has been included in the Brexit trade deal, AES-256, SHA-1 and all.
The obsolete programs and security standards laid down in the Brexit trade deal are mandated for use with the Prüm database, with criminal suspects’ fingerprints, DNA and car registration details being sent around the bloc’s various police forces by email as described in both the EU treaty and the Brexit trade deal annex.
With Britain leaving both the EU’s political and legal control, a new legal basis had to be found to enable ongoing access to the DNA database. Putting it into the UK-EU trade deal appears to be the solution.
An EU thing that’s valued by UK.gov
Government minister James Brokenshire [2]told Parliament in summer:
The Government has considered the impact of sharing suspects’ data as it concerns individual freedoms. However, I am reassured by protections applicable to England and Wales which carefully govern the retention of biometric data, and which confer protections to data from individuals who have not been convicted.
Brokenshire also confirmed that since the UK joined the scheme in July 2019, around 12,000 people’s fingerprints and DNA profiles had been sent to British police through the EU DNA database – and 41,000 Britons’ information had gone to EU countries in return.
It is not immediately obvious whether the EU’s systems for moving personal data around the internet have had security updates since 2008, though one would hope the bloc’s focus on data protection would have seen the infosec parts of the Prüm treaty being pragmatically set aside.
Nonetheless, the security standards mandated are dangerously out of date and no-one serious would advocate using them today. For example, the SHA-1 hashing algorithm is [3]no longer supported by Microsoft and the 25 year-old hash function can now [4]be cracked for less than $50,000.
Politico-legal analysis in 280 characters
When the “obsolete security” part of the deal began circulating on Twitter this week, people whose critical thinking skills begin and end with Ctrl-F inevitably began airing their political views about the inclusion of ancient tech in the trade agreement.
Yet simply copying and pasting snippets from the annex into popular search engines takes the curious reader to its original source: [5]EU Council decree 2008/615/JHA , dated 23 June 2008. That document adopts the Prüm Convention that was signed in 2005 by a handful of European countries, making it part of EU law.
The EU’s own [6]EUR-lex website , a website of EU laws similar to legislation.gov.uk, appears to show that the 2008 EU treaty’s wording has never been updated. In June this year, however, the EU Council [7]accepted that it “needs to ensure full alignment of the new Prüm Framework with the [EU Law Enforcement Directive], especially regarding the data protection safeguards.”
Somebody’s finally noticed that the Prüm Convention’s recommendations are out of date but updating it will not be a fast process.
Sadly the BBC, whose hacks were presumably enjoying an extended period of festive cheer, [8]reported all this dull-but-important detail by churning throwaway speculation – and even managing to quote “experts” who were curiously incurious about where the original text came from, or why a 2020 trade deal would mandate early 2000s tech.
Sneering Britons were informed that it was probably down to some tired civil servant inappropriately using copy and paste from a “late 1990s security document”; an “explanation” that is simply untrue.
Sometimes the truth is both dull and not immediately obvious – two categories of information that El Reg , at least, still specialises in ferreting out. ®
Bootnote
Netscape is not the only example of elderly tech being used to define EU legal standards. The Register knows of at least one diagram in EU transport safety regulations that was created by hand using MS Paint.
Get our [9]Tech Resources
[1] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/948119/EU-UK_Trade_and_Cooperation_Agreement_24.12.2020.pdf#page=921
[2] https://questions-statements.parliament.uk/written-statements/detail/2020-06-15/HCWS290
[3] https://www.theregister.com/2020/07/29/microsoft_windows_sha_1/
[4] https://www.theregister.com/2020/05/28/openssh_deprecating_sha1/
[5] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32008D0615
[6] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=LEGISSUM%3Ajl0005
[7] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020DC0262&qid=1609329857982
[8] https://www.bbc.co.uk/news/technology-55475433
[9] https://whitepapers.theregister.com/
Re: Ms paint
Visio for wizards.
Re: Dull and not immediately obvious
Indeed, while many news sources fall over themselves to get a half-story out the door for clicks, I tend to wait a couple of days for El Reg's take: a deeper analysis with a different angle.
(Hey, is that worth a discount on my subscription?)
"cat GIFs" if that's what you're calling it.
pussy cat? Closer?
Brokenshire
... Sounds like the place I live, these days. Especially after Jan 1st.
Re: Brokenshire
You Kent be serious?
Fare Thee Well
See ya Netscape! Maybe soon from the sound of it!
So no-one's....
Going to say anything about the "Mozilla Mail"? There's Mozilla's Thunderbird, there's Apple/Windows Mail but no Mozilla Mail.
And thats before we get into issues of encryption etc.
Also fascinated to hear what a 'Prüm Application' is... I understand that there's a Prüm Convention but not Application.
Finally raise a glass to the bods at El Reg still posting articles even when it's so close to 24 hours of beer (formally known as new years celebrations)
Re: So no-one's....
https://en.wikipedia.org/wiki/Mozilla_Mail_&_Newsgroups
It illustrates at least two well-known principles: (a) there's [at least] one on every committee and (b) nobody gets round to updating the documentation.
It's not too difficult to visualise the sort of thing that must have happened. A working group is appointed and deals with all the techy bits around data representation with the actual communication being dealt with on a level of "Just email it, encrypted and signed". Then some pedant says "No, you need to specify that" so some poor soul gets the job of writing it up.
The draft of that addition goes back to the committee and some PHB pipes up with "Ooh, that sounds very complicated. Won't it cost a lot of money?". It gets explained that Outlook, Netscape or whatever he's using handles that already. "Well put that in, then." And so the document ends up with an explanatory paragraph that didn't need to be and shouldn't have been in there and which has aged to the point of ridicule. But, of course, nobody wants to revisit it to take it out; as the article indicates, when the documentation is an international agreement the inertia is a few orders of magnitude worse than what most of us experience in this respect.
As to levels of encryption maybe reality has already replaced that specified. Presumably keys will have expired and been reissued using later releases of PGP the S/W. Of course, as diplomats will have been involved there might have been undue influence of the US who don't like the rest of the world using encryption at all. And on the subject of keys - the document is, as far as I can make out, quite bereft of any mention as to how these will be managed. That's consistent with the committee considering that the whole communication issue was outside its scope.
Netscape Navigator, of course, lives on. It's now called Seamonkey. It's what I'm typing on right now.
Ms paint
Should be a required skill for all IT staff. Shows you've suffered in the trenches