British intelligence recycles old argument for borking encryption: think of the children!
- Reference: 1658475009
- News link: https://www.theregister.co.uk/2022/07/22/british_encryption_scanning/
- Source link:
Nearly four years ago Ian Levy, technical director of the UK National Cyber Security Centre, along with technical director for cryptanalysis at the British spy agency GCHQ Crispin Robinson, [1]published a paper arguing for " [2]virtual crocodile clips " on encrypted communications that could be used to keep us all safe from harm. On Thursday they [3]gave it another shot [PDF], with a new paper pushing a very similar argument, while acknowledging its failings.
"This paper is not a rigorous security analysis, but seeks to show that there exist today ways of countering much of the online child sexual abuse harms, but also to show the scope and scale of the work that remains to be done in this area," they write.
[4]
"We have not identified any techniques that are likely to provide as accurate detection of child sexual abuse material as scanning of content, and whilst the privacy considerations that this type of technology raises must not be disregarded, we have presented arguments that suggest that it should be possible to deploy in configurations that mitigate many of the more serious privacy concerns."
[5]
[6]
The somewhat dynamic duo argues that to protect against child sexual abuse and the material it produces it's in everyone's interests if law enforcement has access to private communications. The same argument has been used many times before, usually against one of the Four Horsemen of the Infocalypse: terrorists, drug dealers, child sexual abuse material (CSAM), and organized crime.
The plan is to restart attempts at " [7]client-side scanning " but with service providers – who are ostensibly offering encrypted communications – asked to insert themselves in the process to check that CSAM isn't being sent around online. Law enforcement could then work with these companies to crack down on the CSAM scourge.
[8]
Apple infamously tried to make the same argument to its users last year before backing down. It turns out promising privacy and then admitting you're going to be scanning users' files isn't a popular selling point.
Apple can't solve it, neither can we
In their latest paper Levy and Robinson argue that this isn't a major issue, since non-governmental organizations could be used to moderate the scanning of personal information. This would avoid the potential abuse of such a scheme, they argue, and only the guilty would have something to fear.
It's not a new argument, and has been used again and again in the conflict between encryption advocates who like private conversations and governments that don't. Technology experts mostly agree such a system can't be insulated from abuse – backdoors can always be found, after all. Governments would prefer to think otherwise, but the paper does at least acknowledge that people seeking privacy aren't suspects.
"We acknowledge that for some users in some circumstances, anonymity is, in and of itself, a safety feature," Levy and Robinson opine. "We do not seek to suggest that anonymity on commodity services is inherently bad, but it has an effect on the child sexual abuse problem."
Which is a bit like saying conversations can be used to plan crimes so they too should be monitored. No one's denying the incredible harm that stems from the scum who make CSAM, but allowing monitoring of all private communications – albeit by a third party – seems a very high price to pay.
[9]New UK Home Sec invokes infosec nerd rage by calling for an end to end-to-end encryption
[10]Apple didn't engage with the infosec world on CSAM scanning – so get used to a slow drip feed of revelations
[11]We ain't afraid of no 'ghost user': Infosec world tells GCHQ to GTFO over privacy-busting proposals
[12]Client-side content scanning as an unworkable, insecure disaster for democracy
Apple [13]backed down on [14]its plans to scan users' files for such material in part because it has built its marketing model around selling privacy as a service to customers – although this offer does not apply in China. Therein lies the point – if Apple is willing to let Middle Kingdom mandarins access data, there's no guarantee that it won't do the same for others if it's in the corporate interest.
That scheme saw the idea of searching for images using the NeuralHash machine-learning model to identify CSAM – a model the authors say "should be reasonably simple to engineer." The problem is that the same technology could also be used to identify other images – such as pictures mocking political leaders or expressing a viewpoint someone wanted to monitor.
[15]
Levy and Robinson think this is a fixable problem. More research is needed into verifying age, they suggest – something the UK is wrestling with at the moment. Also, human moderators should be involved before the information on suspected images is passed on to law enforcement.
Not my problem
Interestingly, the two make the point repeatedly that this is going to be the service providers' responsibility to manage. While making the point that the paper is not official government doctrine, it's clear Her Majesty's Government has no intention of picking up the tab for this project, nor overseeing its operation.
"These safety systems will be implemented by the service owner in their app, SDK or browser-based access," they say. "In that case, the software is of the same standard as the provider's app code, managed by the same teams with the same security input."
And allowing private companies to access user data with government approval has always worked so well in the past. This is an old, old argument – as old as encryption itself.
We saw it first crop up in the 1970s when Whitfield Diffie and Martin Hellman published on public-key encryption (something GCHQ had developed independently years before.) Such systems were labelled munitions, and their use and export severely limited – PGP creator Phil Zimmerman suffered three years of investigations in the 1990s over trying to allow private conversations.
As recently as 2019, someone at the US Department of Justice [16]slipped the leash and suggested they didn't want a backdoor, but a front one – again using the CSAM argument. Some things never change. ®
Get our [17]Tech Resources
[1] https://www.lawfareblog.com/principles-more-informed-exceptional-access-debate
[2] https://www.theregister.com/2018/11/29/gchq_encrypted_apps
[3] https://arxiv.org/pdf/2207.09506.pdf
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ytp1PpQydC9VkJHYbU7zLgAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytp1PpQydC9VkJHYbU7zLgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytp1PpQydC9VkJHYbU7zLgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/10/15/clientside_side_scanning/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytp1PpQydC9VkJHYbU7zLgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2019/07/31/home_sec_priti_patel_five_eyes_encryption_controversy/
[10] https://www.theregister.com/2021/08/18/apples_csam_hashing/
[11] https://www.theregister.com/2019/05/30/tech_hits_back_at_gchq_ghost_user_privacy_buster/
[12] https://www.theregister.com/2021/10/15/clientside_side_scanning/
[13] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/
[14] https://www.theregister.com/2021/08/18/apples_csam_hashing/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytp1PpQydC9VkJHYbU7zLgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2019/10/04/us_government_encryption/
[17] https://whitepapers.theregister.com/
... Her Majesty's Government has no intention of picking up the tab for this project, nor overseeing its operation ...
Which basically means that there is little chance of it ever becoming a reality. Industry is not going to pick up the tab (not to say the negative kudos) doing something that only the government wants.
"Her Majesty's Government has no intention of picking up the tab"
More likely means that HMG will try to persuade behemoth snoopers to extend their "services" free of charge (possibly in return for the currently mooted promises of "deregulation"). Privacy? Hand me a dictionary.
Only the Guilty?
As only the guilty have anything to fear, I presume that Messrs Levy and Robinson would have no issue with me having a browse through the contents of their phones?
Re: Only the Guilty?
That is my response. Sure - bork encryption. Hell, get rid of it in its entirety. For everyone with no exceptions - not politicians, not the military, not government, not banks - absolutely no one can use [unborked] encryption.
Write it into law that it's a crime punishable with prison for anyone found breaching said law.
Let's see how long they stick to the "think of the kids" and "you only have anything to hide if you're guilty" when they have to eat their own dog food.
Re: Only the Guilty?
That reminds me when militaries around the world used rare indigenous language speakers as a form of encryption.
Given that over 250 languages are spoken in London alone, how are they going to go around that.
Only English allowed?
Re: Only the Guilty?
As only the guilty have anything to fear, I presume that Messrs Levy and Robinson would have no issue with me having a browse through the contents of their phones? .... Roj Blake
One imagines that MPs are terrified of what would be found out about them and their proposing shenanigans should their WhatsApp and Signal and Telegram communications be monitored rather than their being granted an immunity/exemption from snooping by the UK’s own Secret and Security Services.
Many would tell you they should be at the top of any leading list of likely candidates to be victimised by errant abuse and misuse of that very particular and peculiar privilege.
One wonders what MI5/MI6/GCHQ really think of that arrangement if it so easily and quickly can lead to wholesale chaos with parties in conflict and opposition. Common sense and a greater wisdom would dictate that they totally ignore the prohibition and discover all that is necessary for a true picture of events be produced and directed for subsequent daily media presentation and virtual realisation.
Re: Only the Guilty?
would have no issue with me having a browse through the contents of their phones?
ThIs iS dIfFeReNt!
What, again ?
I thought they had just proposed a law to make the telecoms guys responsible for being able to intercept before encryption.
Why are they flogging this dead horse again ?
I think that recent events have shown that the authorities really don't spend a lot of time concerned about the children.
Though they may spend rather too long thinking about them.
Well, they would say that
wouldn't they?
Quite apart from online...
Re: Quite apart from online...
Ugh, don't even joke about it, there's already creepy politicians in the US wanting to inspect the contents of kids' undies in case they're trans.
Re: Quite apart from online...
I think we've reached the point when mandatory psychological examination should be required for anyone putting themselves forward for political office.
Re: Quite apart from online...
There's the theory that if you're putting yourself forwards for policitial office you've immediately ruled yourself out as being unsuitable.
Re: Quite apart from online...
Yep - I'm a fan of the jury system. Pick people at random. Maybe require them to do a basic test or two to weed out the extreme nutters and intellectually challenged. On average you would probably find a more representative and even more competent crew than our current legislators.
I mean if you trust them, as we did, to make the right call on people's lives when we had capital punishment - we should be able to trust them with lesser stuff now.
As an example the Royal Statistical Society did a test on our current bunch of MPs to test their basic numeracy. Let's just say a considerable number wouldn't be able to understand the answers. Frightening when they end up on relying on their version of 'common sense' rather than be able to take account of the expert evidence.
Re: Quite apart from online...
"I'm a fan of the jury system. Pick people at random."
I vaguely remember on jury trial. Accused was a hospital worker. Petty thefts of patients' ' property started when he was put on the ward. Some property was marked with a powder. He wasn't caught with the property on him but he did have the marker. Thefts stopped when he was removed from the ward.
Not guilty.
Re: Quite apart from online...
"The best argument against democracy is a five minute conversation with the average voter." - Winston Churchill.
If you think politicians are bad, I can only assume you never talk about politics to strangers. You would not believe what some people believe.
Re: Quite apart from online...
Airport body scanners.
Here we go again...
.....In their latest paper Levy and Robinson argue that this isn't a major issue, since non-governmental organizations could be used to moderate the scanning of personal information. This would avoid the potential abuse of such a scheme, they argue, and only the guilty would have something to fear.
"Two notorious characters from the British security services" must be the only people on the planet that think "potential" abuse can be avoided. Room 641A, plus countless other examples make their premis laughable.
And, of course, they always separate the Four Horsemen of the Infocalypse: terrorists, drug dealers, child sexual abuse material (CSAM), and organized crime. If they lumped them all together the dramatic effect is lost.
What are they trying to hide?
Never mind the man behind the curtain. Look over here.
Who are they trying to con ?
Having no Encryption won't solve child porn, nor will it help against organised crime or terrorism.
If one avenue becomes closed, others will be used.
I mean, stealing national secrets with a usb drive smuggled out in a short (coffee cup, lip balm, pack of smokes) who would ever imagine that that could happen to secure government, tempested and air gapped devices ?!?!
Having regular snooping, or scanning of user data by a private company in the interest of 'national security' ???
Come on, do they think we're all stoopid, and if they don't encrypt our data, how will it meet data protection compliance?
Oh yes, we've got it covered, we'll use a physical key on the cupboard. :(
Did I mention useless political posturing?...and perhaps a darker long-term goal?
There are lots of people (and groups) who can implement private encryption before their messaging enters either a client or directly into a service provider channel.
Then.....the service provider is to be made responsible for scanning the messaging for "illegal content". How would that work? Service providers get to set up an internal cryptography group? And since well designed AES (or samba, or chacha) ciphers are thought to be secure......to what end?
Maybe the long-term STASI goals are actually:
(1) Make private encryption (and the possession of encryption tools) completely illegal
(2) Make service providers responsible for blocking any message that looks like encryption
(3) Make service providers responsible for reporting anything that looks like encryption to "the authorities"
But then "We do not seek to suggest that anonymity on commodity services is inherently bad....." Really?
And all this before we start thinking about the mapping of end-points to specific real people:
(4) The smartphone is a burner (no account registered, pay-as-you-go minutes bought for cash)
(5) The email account is fictitious (say gmail authenticated with a burner phone)
(6) The email account has an assigned "app password" so that software can do the heavy lifting (i.e. no GUI interface is ever seen by anyone)
(7) The laptop and the email client is only ever used from a public wifi connection, never from a place of domicile
Yup......the privacy argument says this is a piece of political posturing.....
.....because anyone who wants to avoid ALL the downsides associated with the STASI scanning content can do so.....see above!
.....and there's always steganography!!!
Google* Golden Opportunity?
since non-governmental organizations could be used to moderate the scanning of personal information and
Her Majesty's Government has no intention of picking up the tab for this project, nor overseeing its operation
Company x is now going to monitor all encrypted communications, since the government will not oversee the operation it will be an entirely private company affair - think of all the additional data a company such as Google* could get for marketing opportunities as a result, which would of course be acceptable as their revenue stream for doing all this work.
They definitely would NOT abuse it in any way of course.
* Other companies are available to abuse your personal data
Surveillance
Why stop at private communication? We have the technology to install cameras and microphones in every home.
Re: Surveillance
As most domestic abuse and child abuse takes place in homes, having telescreens that transmit as well as receive would definitely stop crime
Common Purpose
They are simply lying. They want to get rid of encryption, so that they can obtain data points to calculate a factor in your social credit score.
Did you send a photo with a BBQ you've been doing in your garden? Oh you supposed to reduce meat in your diet! We know that from your connected health data. That's minus 20 points for you and your coming salary will be programmed to no longer work on meat products. If you buy sugary products your salary will be set to expire in month's time.
No paper of this nature should be given credence unless its authors are prepared to expose themselves in the way they'd expose others: they should include all their online credentials for banking, shopping, email and everything else.
If they do include such details then the paper shouldn't be given credence as the authors are either outright liars or stupid.
"These safety systems will be implemented by the service owner in their app, SDK or browser-based access,"
So, BrowseBork 2.6 will have the new-fangled SmutMonitor(tm). Ok, I'll just use BrowseBork 2.5.
Dear government
Mind your own sodding business.