News: 1694081358

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK drops 'spy clause' for scanning encrypted messages, admits it's not 'feasible'

(2023/09/07)


Comment Sanity appears to have prevailed in the debate over the UK Online Safety bill after the government agreed to ditch proposals - at least for the time being - to legislate the scanning of encrypted messages.

In response to questions regarding the technical feasibility of scanning messages and the assessments that Ofcom must make, Lord Parkinson, a Digital, Culture, Media and Sport minister, [1]said : "If the appropriate technology does not exist that meets these requirements, then Ofcom will not be able to use Clause 122 to require its use."

Clause 122 in the Online Safety Bill relates to online terrorism and child exploitation content.

[2]

Parkinson said: "A notice can be issued only where technically feasible and where technology has been accredited as meeting minimum standards of accuracy."

[3]

[4]

Thus no scanning of encrypted messages unless it is technically feasible to do so. Quantum computing, anyone?

Victory? Not so fast...

The statements have been widely interpreted as a victory for technology firms, many of which had [5]threatened to exit the UK over the requirement that it must be possible for encrypted messages to be scanned for illegal content.

However, it could also be argued that the changes only represent the bare minimum needed to get the bill across the line. The controversial clauses remain largely in place, with the buck passed to future administrations, or to when reading the messages becomes "technically feasible."

Matthew Hodgson, CEO of Element, said: "The government saying 'no scanning until it's technically feasible' is nonsense. Scanning is fundamentally incompatible with end-to-end encrypted messaging apps. Scanning bypasses the encryption in order to scan, exposing your messages to attackers."

[6]

He told The Register that the statement and the reaction from some section of the tech community left him terrified. “It’s not a win at all,” he said.

Hodgson continued: “the ministers must be feeling utterly smug… the pressure has been removed from them to change the bill and stop scanning, and they didn’t have to do anything”

“It's terrible because the law still says that scanning can be obligated on encrypted messaging providers, it would still undermine end to end encryption. And all it is [doing] is pushing it slightly down the line until somebody decides it's technically feasible, which is a completely subjective thing.”

[7]

Martina Larkin, CEO of Project Liberty, queried the thinking behind the clause and said: "No one is questioning that more must be done to protect people, especially children, online. However the debate should not be about protecting children versus protecting privacy. We can have, and should have, both."

"When it comes to how we build a better web, everybody loses when rash decisions are made. Trying to protect children by building backdoors into encryption will have unprecedented negative consequences for online privacy, the use of people's data as well as the protection of free speech and democratic values. No one would ever willingly let a complete stranger read all of your mail, put cameras in their house, and follow their every move. So why do it online?"

[8]Now Apple takes a bite out of encryption-bypassing 'spy clause' in UK internet law

[9]Wrong time to weaken encryption, UK IT chartered institute tells government

[10]Online Safety Bill age checks? We won't do 'em, says Wikipedia

[11]International cops urge Meta not to implement secure encryption for all

We'll draw a discreet veil over the devices with potential for surveillance supplied by large technology companies that people have indeed cheerfully installed in their houses. Still, both Larkin and Hodgson make excellent points.

A spokesperson from Index on Censorship said: "The Online Safety Bill as currently drafted is still a threat to encryption and as such puts at risk everyone from journalists working with whistleblowers to ordinary citizens talking in private. We need to see amendments urgently to protect our right to free speech online."

Attempts to paint the UK government's apparent climbdown as a victory for big tech is missing the point. At best, a skirmish might have been won and a ceasefire temporarily declared. However, the larger battle over privacy and encryption on the internet has yet to be fought. ®

Get our [12]Tech Resources



[1] https://hansard.parliament.uk/lords/2023-09-06/debates/4AC6A32E-0C53-46C7-A714-AD4165C484D7/OnlineSafetyBill

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPnzpOA9UKt1AOsBa9AjqgAAAIo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPnzpOA9UKt1AOsBa9AjqgAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPnzpOA9UKt1AOsBa9AjqgAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/04/28/online_safety_bill_age_checks/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPnzpOA9UKt1AOsBa9AjqgAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPnzpOA9UKt1AOsBa9AjqgAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/06/29/apple_online_safety_bill_opposition/

[9] https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/

[10] https://www.theregister.com/2023/04/28/online_safety_bill_age_checks/

[11] https://www.theregister.com/2023/04/21/meta_encryption_police/

[12] https://whitepapers.theregister.com/



Mike 125

"...draw a discreet veil over the devices with potential for surveillance supplied by large technology companies that people have indeed cheerfully installed in their houses."

And in which they cheerfully drive around.

I love it when politicians are *finally* forced to accept a scientific and mathematical truth.

Dan 55

... until civil servants start pushing the same thing yet again about a year into a Labour government.

Anonymous Coward

While it's fun to blame civil servants I think in this case it's the politicians who want this... or at leats want to publicly say 'Look at me, look at me. We beat down those nasty techies, even when they said it was impossible and now we're saving the children. Hoorah for us!'

Dan 55

Here's [1]an example of a civil servant with a bee in his bonnet about something over something which happened about 15 years previously.

[1] https://www.theregister.com/2018/01/15/philip_rutnam_gsm_gateway_ban/

Pascal Monett

They didn't "accept" anything. They're just waiting for it to be "technically feasible".

Which proves that they don't understand that it is not feasible, technically or otherwise.

This is just basic political maneuvering. Move the goalposts, look like you're doing something.

Version 1.0

So has AI been upgraded to start scanning encrypted messages? Maybe not yet, but next week probably.

Andy The Hat

If they (set A: HMGov scanning only for the public good and not for snooping) can decrypt it then they (set B: any.body potentially decrypting it, certainly not for the public good and definitely for snooping).

When does set(a) intersect with set(b), who is in that intersection and who controls them?

No one would ever willingly let a complete stranger read all of your mail

Dr Paul Taylor

But they do!

Increasingly nowadays I send URLs with /private/ and /drafts/, which are "Disallow:"ed in my robots.txt, but then find them in my logs accessed by Microsoft, Amazon, Google, Apple, etc, or obfuscated into "safe" links.

These things have been explicitly enabled in the recipients' handling of incoming email. Or more likely by their pointy-haired Boss.

Anybody know of a way of blocking such accesses on a website?

Re: No one would ever willingly let a complete stranger read all of your mail

Zippy´s Sausage Factory

I suppose you could implement filtering by IP range or browser agent, or maybe both? Or perhaps password protect those sections? But that'll depend on what tools your web host provides I guess.

Re: No one would ever willingly let a complete stranger read all of your mail

Jellied Eel

Anybody know of a way of blocking such accesses on a website?

I suspect the only viable solution is a very good lawyer and a very large stick. I also suspect the reason why this legislation is being walked back a bit its because law enforcement and security services can compel 'wire taps' already from Big Tech. Alternatively, just define messenger app providers as Communications Service Providers, and add them into the mix that are compelled to provide lawful intercept capabilities under national Communications Act(s).

Biggest challenge is that doesn't allow bulk collection, but the FANGS already have that covered. Their marketing will tell you that your messages are encrypted, but only after their OS has taken a peek and/or copy.

Re: No one would ever willingly let a complete stranger read all of your mail

Geoff Campbell

If it's a private internal site, keep it private and internal. Set it up on a local web server, with access for people on the internal network. Remote access via VPN if required.

GJC

Re: No one would ever willingly let a complete stranger read all of your mail

Jamie Jones

Putting "/private" etc. into robots.txt is akin to sticking a sign on your front lawn saying "Don't steal my diamonds when I'm out all day every Monday".

Blocking by IP is almost as flakey.

If you are unable to have proper protection on the content, at least just whitelist known safe addresses (and not the whole dynamic range of an ISP!)

All major webserving software allows you to restrict URL's to a user/password without needing to do any HTML or coding

Dr Dan Holdsworth

To be honest I think that this Bill should be preserved as it is forever more, not because it might be useful but more as a warning from the past as to just how bloody stupid politicians can actually be.

The American NSA have built a similar monument to stupidity, namely an enormous disk farm wherein encrypted communications that they want to decrypt and which might possibly be decrypted in the dim and distant future are stored against that forlorn and frankly laughable day.

Not sure I understand this.

Headley_Grange

I read about this yesterday and didn't see it such a positive light. My reading is that the scanning doesn't have to be of the encrypted message, just the message before it's encrypted and sent - similar to the system Apple proposed a couple of years ago. If I'm right the gov. can pass this law, then write scanning code, licence it as an approved technology then mandate it's incorporation into the messaging apps. If (somehow, maybe by using some of those stocks of unobtanium they have) they can do this without sending any elements of the pre-encrypted message online for processing, then the encryption argument goes away, debatably. Find a way to vault dodgy looking messages on the device so they can't be deleted and send the cops round to check them (which could become a sport in its own right).

Or maybe I've just not understood.

Re: Not sure I understand this.

Mishak

Similarly, what does "only were technically feasible" actually mean? Is breaking into the end-to-end encryption chain not "technically feasible"?

There were no words to say that any scanning had to meet minimum levels of security (which would render it "technically infeasible").

I'm not convinced this isn't just subterfuge to get the bill passed in a form that allows the original intent to be enforced.

Scanning just hurts the innocent

alain williams

who risk having legitimate communications intercepted and undesirable things done with them.

The real undesirables will just use an unbreakable encryption mechanism - regardless of how outlawed this is.

Re: Scanning just hurts the innocent

Jason Hindle

Erm, yes and no. Useless for things like spying and terrorism - you can hide a paragraph inside an misplaced apostrophe in a thankyou message for last night's lovely meal. OTOH, some people people really are thick enough to send illegal pr0nographic images using the likes of WhatsApp, Signal and Telegram. Tracking those down is fine in principle, but when I hear the tub-thumping, populist rantings of some of our politicians (I'm looking at you Cruella Braverman) I'm thinking I really don't want them to have that power.

Scanning has no use - no need to wait for feasible

Pascal Monett

Did I miss something ? Didn't we just have [1]an article proving that not backdooring encryption does not prevent the law from doing its job ?

Can someone please take a cluebat and beat some sense into these people ?

I'd pay to see that.

[1] https://www.theregister.com/2023/09/02/europol_balkan_cartel/

Let us replace "Back Door" with "Fire Door"

Evil Scot

The BBC did a good story on how the Big Social Media sites were used for grooming.

(A well researched story in MSM????)

Basically victims were invited onto another platform to share images. Platforms which are obviously outside of the law.

The "fire door" would be a means of submitting a conversation to the correct authorities where the messages are signed as from the sender or senders device.

Whitewash?

DJO

Is this some sneaky deflection?

Anybody in intelligence will tell you (possibly only when under duress) that the metadata is often the most useful thing - who contacted whom and when and how often is very revealing and is easy to automate most of the drudge work.

Actually going through a zillion messages is much harder to automate so would require improbable staffing levels to do properly, of course if they only use it on specified targets then it's easier but there are already laws in place that can be applied to suspects where there is adequate probable cause to convince a judge to issue a warrant.

Re: Whitewash?

StrangerHereMyself

No this is BS. You can't prosecute anyone on metadata. At best metadata will give you some clues WHERE to look. It won't give you hard-evidence.

When it becomes possible

Anonymous Coward

May I suggest a few more laws:

1. When you get a time machine, kill Hitler.

2. All perpetual motion machines must be connected to the National Grid and used for public good.

3. When you can bring back the dead, it must be conducted in an orderly manner and in strict reverse order of death year.

4. No telepathy without proper consent.

5. Faster than light drives must be launched from Birmingham. No FTL is allowed to be launched near London.

Re: When it becomes possible

RockBurner

Define "near".

(in the context of FTL drives, London is slap-bang next to Tokyo, or any other residential area on this little blue dot).

Re: When it becomes possible

DJO

While he was undoubtedly an evil piece of shit the argument for strangling him at birth is mixed.

Germany was racing to WWII anyway due largely to resentment of the Treaty of Versailles - with Hitler we got the Holocaust and a military failure, without Hitler we would probably been spared the Holocaust but with a competent military leader Germany could easily have been victorious.

About those bad guys......

Anonymous Coward

Matthew Hodgson, CEO of Element, said: "The government saying 'no scanning until it's technically feasible' is nonsense. Scanning is fundamentally incompatible with end-to-end encrypted messaging apps."

Note the assumption: We (the lawmakers) ASSUME that the only encryption in use is that supplied by interweb service providers.

Suppose I and my friends are encrypting everything BEFORE anything enters an interweb service. So (GCHQ, NSA).....scan away to your heart's content.

We quite like D/H and TRIPLE chacha20 before anything is sent on the interweb. In our particular case scanning isn't "fundamentally incompatible" with anything at all!

.......and how many REALLY BAD GUYS will be doing just what we are doing?

Re: About those bad guys......

nijam

> Scanning is fundamentally incompatible with end-to-end encrypted messaging apps.

Scanning is fundamentally incompatible with security.

Dead

StrangerHereMyself

So the Online Safety Bill (OSB) is effectively dead? I find it disconcerting that they're now downgrading the scanning of CP to "best effort" at the very last moment. They should've simply scrapped the text regarding client-side scanning and saved themselves a whole lot of hassle and poohah.

I suppose the outlook of WhatsApp and Apple leaving the UK market was frightening even to MP's, who feared an uprising by their constituents.

Re: Dead

Adrian 4

No, they're frightened of having to stop using them themselves, instead having to use a proper verified email system that's open to their party whips and future investigations.

Re: Dead

G40

They’ve only just realised the bill refers to their WhatsApp…

How many hors d'oeuvres you are allowed to take off a tray being carried by
a waiter at a nice party?
Two, but there are ways around it, depending on the style of the hors
d'oeuvre. If they're those little pastry things where you can't tell what's
inside, you take one, bite off about two-thirds of it, then say: "This is
cheese! I hate cheese!" Then you put the rest of it back on the tray and
bite another one and go, "Darn it! Another cheese!" and so on.
-- Dave Barry, "The Stuff of Etiquette"