Apple joins the opposition to encryption-bypassing 'spy clause' in UK internet law
- Reference: 1688020810
- News link: https://www.theregister.co.uk/2023/06/29/apple_online_safety_bill_opposition/
- Source link:
"End-to-end encryption is a critical capability that protects the privacy of journalists, human rights activists, and diplomats," Apple argued in a [1]statement to the media.
"It also helps everyday citizens defend themselves from surveillance, identity theft, fraud, and data breaches. The Online Safety Bill poses a serious threat to this protection, and could put UK citizens at greater risk."
[2]
Apple, you may remember, [3]announced in December 2022 that it will provide end-to-end encryption (E2EE) for most iCloud services.
[4]
[5]
"Apple urges the government to amend the bill to protect strong end-to-end encryption for the benefit of all," the iGiant's statement on the internet bill continued.
The iGiant declined to address The Register 's specific inquiries about what, if anything, the American titan will do should Parliament adopt the bill.
[6]
As [7]the draft law is currently written, the UK's communications watchdog Ofcom will have the power to instruct chat app makers and other tech companies to monitor conversations and posts for child sexual abuse material and terrorism content. Such data should be blocked or deleted when found, and potentially even reported to the cops, the government hopes.
If that doesn't lead to apps watering down or backdooring their E2EE so that data can be inspected in transit, it may bring about automated on-device scanning, which could end up censoring people's private chats or leaking them to the authorities – whether illegal activity was correctly or incorrectly detected. Such technology would be government-accredited, which means the app makers may have little choice over its eventual implementation.
Under that regime, an app or platform can't really say it offers truly strong E2EE on all messages if there's a chance those messages can be silently inspected by someone or some system outside the private conversation. There's a concern this all starts with tackling child abuse and terrorists – something with which the population won't generally have a problem – but will later lead to broader surveillance and censorship. It smacks of a government fed up with not being able to peer into private chatter whenever it feels necessary.
[8]
The Open Rights Group has a paper on the proposals [9]here [PDF] if you want to read more about it. "According to an expert legal opinion, this bill would create the power to mandate some of broadest surveillance powers in any Western democracy," the body wrote in that document.
In February, encrypted chat service Signal [10]said it will stop operating in the UK if the British government goes ahead with its Online Safety Bill as it stands.
And in April, other E2EE comms platforms Element, Session, Threema, Viber, WhatsApp, and Wire urged UK lawmakers to [11]rethink the bill instead of "weakening encryption, undermining privacy, and introducing the mass surveillance of people's private communications."
Wikipedia, meanwhile, has called out another piece of the proposal that would require [12]verification of visitors' ages, and said if the Online Safety Bill passes with the age-gating requirement, its site may no longer be available in the UK.
[13]Wrong time to weaken encryption, UK IT chartered institute tells government
[14]Online Safety Bill age checks? We won't do 'em, says Wikipedia
[15]International cops urge Meta not to implement secure encryption for all
[16]One year after Roe v Wade overturned and 'uterus surveillance' looks grim
The controversial draft law, which the government claims will make the UK " [17]the safest place in the world to be online ," continues to face backlash because of its so-called " [18]spy clause " [PDF].
This provision requires companies to intercept and block child sexual exploitation and abuse (CSEA) material and terror content "whether communicated publicly or privately." That means encryption applied to messages and anything else shared must be bypassed to allow scanning – or scanning must occur prior to encryption or after decryption.
Those in favor of this E2EE workaround, as always, say it's to protect the children – as [19]Meta recently found out when an international group of law enforcement agencies urged the social media giant not to standardize strong E2EE on Facebook Messenger and Instagram. E2EE, according to the Virtual Global Taskforce, will prevent cops from fighting – wait for it – CSEA.
Apple is no stranger to this argument. In 2021, the fruiterer [20]floated a plan to scan photos on people's iPhones for CSEA automatically as they uploaded stuff to iCloud.
The information security community and civil rights groups strongly opposed turning punters' own devices against them, and Apple ultimately ditched the plan. Instead it deployed [21]communication safety tools in iOS 15.2. ®
Get our [22]Tech Resources
[1] https://www.bbc.com/news/technology-66028773
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJ1WResgD62FgKj@g2IEJQAAAks&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2022/12/08/apple_encryption_icloud/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJ1WResgD62FgKj@g2IEJQAAAks&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJ1WResgD62FgKj@g2IEJQAAAks&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJ1WResgD62FgKj@g2IEJQAAAks&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://bills.parliament.uk/bills/3137
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJ1WResgD62FgKj@g2IEJQAAAks&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.openrightsgroup.org/app/uploads/2022/11/Whos-Checking-on-your-chats-in-private-online-spaces.pdf
[10] https://www.theregister.com/2023/02/25/signal_uk_online_safety_bill/
[11] https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/
[12] https://www.theregister.com/2023/04/28/online_safety_bill_age_checks/
[13] https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/
[14] https://www.theregister.com/2023/04/28/online_safety_bill_age_checks/
[15] https://www.theregister.com/2023/04/21/meta_encryption_police/
[16] https://www.theregister.com/2023/06/27/post_dobbs_uterus_surveillance/
[17] https://www.gov.uk/government/publications/online-safety-bill-supporting-documents/online-safety-bill-factsheet#what-the-online-safety-bill-does
[18] https://blogs.soas.ac.uk/cop/wp-content/uploads/2022/12/SOAS-ICOP-Briefing-Online-Safety-Bill.pdf
[19] https://www.theregister.com/2023/04/21/meta_encryption_police/
[20] https://www.theregister.com/2021/08/09/apple_csam_faq/
[21] https://support.apple.com/en-us/HT212850
[22] https://whitepapers.theregister.com/
Re: So, we're back to square one again
They only have to pass it once, then there is no going back.
Re: So, we're back to square one again
Laws can be removed as well, but that never seems to happen in practice, even when a party declares it as a manifesto "promise".
Re: So, we're back to square one again
I think it returns roughly every seven years.
Total Information Awreness, the Clipper chip - you name it.
The basic argument is that we must all install easily pickable locks in millions of houses so the police can briefly digress from their institutional problems and chase the ten or so troublemakers (compared in volume) while simultaneously enabling thousands of others to do the same, but undetected. It's almost like employment protection if it wasn't for the fact that simple statistics and frequent events suggest that there are quite a few dodgy ones hide amongst that force itself - which will then have a much easier life too.
Basically, allowing this idiocy will amplify crime to the point of having to return to cash-in-hand transactions.
Brexit and now this again tells me is that standards of education and analytical thinking in politics have declined to the point that [1]Idiocracy is heading towards becoming a documentary, but without as yet any sight on a happy ending.
[1] https://en.wikipedia.org/wiki/Idiocracy
Silly government. Just implement legislation that each computing device is required to have gov spyware installed. What could go wrong?!
I guess they could also use it to reduce the number of "leaks" from official government devices?
Reducing leaks? Silly you! Of course, there'd be an exception for gov devices, which will be prohibited from installing their own spyware. Where would we end up otherwise, with good governance?
Do they need to?
Everyone is already running Windows, and rumour has it Microsoft was actively involved in the Cloud Act (although I have as yet not seen any evidence of that, but it doesn't strike me as implausible).
Everyone?
OK, granted, replace that with "waaaaaaaaaaaaaay too many people and businesses".
:)
the safest place in the world to be online
Safest for the government they mean. Sort of like the Chinese system but with a couple of words like "responsible" and "reasonable" chucked in make it sound normal. Don't know why they don't just cough up the cash for Pegasus* like everyone else does or is it just a bit too targeted.
*Other sneaky scumbag software is available.
Some of broadest surveillance powers in any Western democracy
Brought to you by some of the dumbest politicians in any Western democracy.
And subsequently to be misused against us by some of the worst people in any foreign autocracy.
Proof of the UKs diminishing political structure ...
A colleague is involved in this story. When the news reached the HoC committee, a committee member asked "why didn't you say anything before ?"
The industry answer is there is so much fucking hot air from "the government" over this that and the other, that there is fuck all point in investing any time and effort until you know it's serious.
That, dear regtards, is the sign of a deeply dysfunctional government. No one trusts it enough to invest in engagement, so rather than carefully thought out laws that actually make sense, you descend into this pantomime run-in between ideology and technology.
Mind you, last time there was a "consultation" it was painfully clear that it was really just a "sign off on what we have decided" exercise. Again not a good use of time, money or reputation.
In a battle with Google, Microsoft, Apple, plus significant players like Signal, the UK can only lose. No matter what the TeleMailExpress report.
Re: Proof of the UKs diminishing political structure ...
The UK is a sinking ship that continues to inflict pain on itself.
Mostly this absurd legislation with the absurd Orwellian NewSpeak discussions ("We believe E2EE can be safely backdoored whilst keeping users' privacy") is meant to disguise the utter incompetence of the UK Government and its politicians in cleaning up the mess Brexit has caused. Britain is becoming poorer by the minute and the politicians are helpless to do anything about it.
Re: Proof of the UKs diminishing political structure ...
> We believe E2EE can be safely backdoored whilst keeping users' privacy
Politicians genuinely believe their laws (words on paper) can alter the nature of reality. It's still soothsaying and sorcery just this time in bespoke Saville Row tailoring.
Re: Proof of the UKs diminishing political structure ...
I have to wonder whether we've ever had a competent government that actually defended our freedom and served the people. We do have a history of pushback and Great Charters and suchlike in this country, but I would be surprised whether enough of our MPs know what is or what it meant ("it's just about Barons and entitlements hehehe..." read past the first few clauses you fanny).
Even Boris let this abomination of a bill slip through under his premiership, and he once claimed he'd rather eat an ID card than be issued one. I wonder what changed for him, or was his objection simply because the Other Party had suggested ID cards? Stopping it could've been the One Good Thing he did in office, if he really believed that.
I don't know what's going on, while I welcome the inevitable kicking coming at the next election, I wonder will the Other Party deliver for our online and civil freedom?
Ofcom....and partial solutions to personal privacy.....
Quote: "....Ofcom will have the power to instruct chat app makers and other tech companies to monitor conversations and posts...."
Privacy? So lots of interweb providers will be monitoring throughput:
- service providers running server-based services
- app providers giving users (or selling) apps to run on the user's own equipment
- "other tech companies".......whatever that means (Palantir, perhaps?)
This is not unforeseen: here's a link from 1999: https://www.wired.com/1999/01/sun-on-privacy-get-over-it/
Well....I for one have not "got over it". Why is it not clear to everyone that ANY use of interweb services (Signal, Telegram, WhatsApp)...any use of these services is a single point of failure for privacy?
The (partial) solution: use peer-to-peer messaging where the ONLY messaging software is resident on user end-points.....and the encryption protocols exist ONLY on the end-points. (So no dependencies on any third-party "service".)
Coming back to the quote above: peer-to-peer software seems to be outside the remit of Ofcom......and the nice people in Cheltenham and Fort Meade will have no big-dollar corporate support.
"Partial" privacy as I said...........but better than "get over it"!!
Re: Ofcom....and partial solutions to personal privacy.....
The problem with the peer to peer stuff is getting it on your phone. Android you can sideload, but do most people know how to do that? As for iPhone, well, good luck with that.
"Strong" encryption?
I'm a bit confused about the use of the phrase. It implies there is "weak" encryption, with a line drawn somewhere between the two. I'd be interested to know where the line is and if there is any consensus about where it is. I'd imagine that the security services would like to class anything above ROT13 as strong.
Can I suggest everyone stops calling it "strong" encryption? Strong encryption = encryption, any other form of "encryption" is meaningless.
Circle-jerk of bullshit
"There's a concern this all starts with tackling child abuse and terrorists – something with which the population won't generally have a problem"
I don't know who "THE POPULATION" is supposed to be because I have a problem with this method of " tackling child abuse and terrorists". There is a small teeny-eeny itsy-bitsy problem with using what is essentially spyware installed on the phones of terrorists and child abusers, and that is that the government doesn't know who the terrorists and child abusers are. What this bill is actually saying to the public at large is "you are all potential terrorists and child abusers and we will spy on all of your communications until we catch you". It's not a problem that it's a slippery slope starting with something innocuous that could potentially be abused later - It's highly abusive right from the start.
That's even ignoring the fact that it isn't going to be possible to reliably scan on-device without getting a bunch of false positives, which is guaranteed to end up ruining some innocent people's lives because "computer says so" will morph into "AI says so", and the AI is always right as any fool know!!!
So, we're back to square one again
We've already had this discussion, we've heard all the arguments, we've seen all the rebuttals.
And UK Gov is starting it all over again.
Is this insanity, or are they just suckers for punishment ?