News: 1699374851

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK may demand tech world tell it about upcoming security features

(2023/11/07)


The UK government has set in train plans to introduce legislation requiring tech companies to let it know when they plan to introduce new security technologies and could potentially force them to disable when required.

The measures were announced just minutes ago in the King's Speech – when the country's monarch reads out a speech that is written by the ruling political party, marking the start of the parliamentary year. They could mean the Home Office get advance access to technical details of security measures employed by popular big tech platforms so it can access user data and monitor nefarious activity.

In guidance notes to the legislative program

[1]PDF

, the government said the Investigatory Powers (Amendment) Bill would reform the "notices regime," so it could anticipate the risk to public safety posed by the "rolling out of technology by multinational companies that precludes lawful access to data." The government claimed getting forward notice of security technologies would "reduce the risk of the most serious offences such as child sexual exploitation and abuse or terrorism."

[2]

The Bill is also set to update the conditions for use of Internet Connections Records held by service providers. The government said new measures would "ensure that these can be used effectively to detect the most serious types of criminal activity and national security threats, underpinned by a robust independent oversight regime."

[3]

[4]

Additionally, the government said it wants to increase the resilience of the warrant authorization processes to "ensure the security and intelligence agencies, as well as the National Crime Agency, can always get lawful access to information in a timely way."

The Open Rights Group, a digital rights campaign organization, said the proposed laws — which are yet to be debated and voted on in Parliament — could mean that global tech companies are forced to get permission from the UK government if they want to make changes to security features in their products and services, in effect becoming a further attack on end-to-end encryption, which keeps communications and transactions safe.

[5]

Abigail Burke, platform power programme manager, said: "End-to-end encryption keeps our data and our communications safe and secure. The proposed reforms to the Investigatory Powers Act are the government's latest attack on this technology.

[6]UK Online Safety Bill to become law – and encryption busting clause is still there

[7]Element users are asking for protection against government encryption busting

[8]Get your staff's consent before you monitor them, tech inquiry warns

[9]Now Apple takes a bite out of encryption-bypassing 'spy clause' in UK internet law

"If enacted, these reforms pose a threat to companies' ability to keep our data safe and increase the risk of criminal attacks. We urge the government to engage with civil society and tech companies, and to reconsider these potentially dangerous proposals," she said.

The amendments to the controversial Investigatory Powers Act follow the [10]passing of the Online Safety Bill into law . The new rules give the government powers to introduce online child protection laws, one that includes clause 122, the infamous "spy clause," albeit with some caveats, despite the protests from tech companies and privacy campaigners. ®

Get our [11]Tech Resources



[1] https://assets.publishing.service.gov.uk/media/654a21952f045e001214dcd7/The_King_s_Speech_background_briefing_notes.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUrBkyb77N1pmwsi9SVg1QAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUrBkyb77N1pmwsi9SVg1QAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUrBkyb77N1pmwsi9SVg1QAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUrBkyb77N1pmwsi9SVg1QAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/09/20/uk_online_safety_bill_passes/

[7] https://www.theregister.com/2023/10/24/element_spy_clause_protection/

[8] https://www.theregister.com/2023/08/10/workplace_monitoring_select_committee/

[9] https://www.theregister.com/2023/06/29/apple_online_safety_bill_opposition/

[10] https://www.theregister.com/2023/09/20/uk_online_safety_bill_passes/

[11] https://whitepapers.theregister.com/



Politicians

navarac

Most politicians haven't a clue about computer systems, or computer security. Mind you, they haven't much of a clue about anything, except their own priorities.

Re: Politicians

Primus Secundus Tertius

That is what representative democracy means. Politicians have a lot in common with ordinary people.

Re: Politicians

ITMA

"Politicians have a lot in common with ordinary people"

Since when?

Re: Politicians

elsergiovolador

It's not about having a clue. We have probably the most corrupt government in history and they just want to know business and personal secrets.

What do they need these for?

Sell IP to foreign states?

Harass undesirable groups?

If only people could learn from history. Even a proposal of Stasi-on-steroids level of surveillance should have people proposing it given P45 and perhaps getting them sectioned.

Password: ICanStillDoThis

theOtherJT

echo "U2FsdGVkX185WSn42PIqjIEiRYpf8M2qpeb+tnTPaat3hikN4Z//LAEyF8A5hPAznOnRyYMitPmbUizJFqrnVWizwS7yDqr4M2dmWzu0Gyqn4wVR50xKHINzabgz+xJ2" | openssl aes-256-cbc -a -d -salt

And I'm going keep posting this every time this bloody stupid topic comes up.

It'll just endanger legitimate users and do precisely nothing to prevent people with genuinely nefarious intent from encrypting their comms.

Re: Password: ICanStillDoThis

ITMA

"...prevent people with genuinely nefarious intent from encrypting their comms"

Such as... politicians...

Re: Password: ICanStillDoThis

druck

And commentards.

Re: Password: ICanStillDoThis

Yet Another Anonymous coward

>"U2FsdGVkX185WSn42PIqjIEiRYpf8M2qpeb+tnTPaat3hikN4Z//LAEyF8A5hPAznOnRyYMitPmbUizJFqrnVWizwS7yDqr4M2dmWzu0Gyqn4wVR50xKHINzabgz+xJ2"

How dare you sir ! My mother was a saint

Re: Password: ICanStillDoThis

druck

And I'm going keep posting this every time this bloody stupid topic comes up.

No, it will just make you look like a twat, especially if is all double spaced lines instead of inside pre and code tags.

Re: Password: ICanStillDoThis

theOtherJT

I didn't realize we allowed to use code tags on here? That's good to know. Thank you.

When did the UK Govt. ...

Adair

become the worldwide arbiter and enforcer of who does what, when, where, and how in the global IT world?

I'm sure they have some say locally, and are entitled to express an opinion globally, but if 'Corporation X', based in the United Republic of Erewhon, decides to release an app that can be installed anywhere someone has unrestricted access to the internet what do they care about what the UK Govt. thinks or says?

Unless they have assets in the UK 'Corporation X' probably doesn't give a shit what the UK Govt. thinks or says.

It's just more political posturing from a political party in the late stages of senescence and facing an immanent election.

Won't work.

Tron

Tech companies just won't release stuff in the UK. Post-Brexit, it is an easy to isolate market.

Re: Won't work.

Yet Another Anonymous coward

And cut themselves off from one of the top 30 performing economies in Europe ?

Re: Won't work.

Adair

Amongst the top thirty you say. One out of thirty, plus the rest of the world (barring some basketcase distopias). On that basis I somehow think they would cope.

Anonymous Coward

"reduce the risk of the most serious offences such as child sexual exploitation and abuse or terrorism"

Bullshit. They will be using ring cam footage to fine people for leaving their bins out a bit too long. Don't toe the government line online (or in the real world it seems)? That's you fucked. I find it amazing that they are now equating terrorism to opinion. I may not like what some people say but I'll fight for the right for them to say it. My grandad fought in the second world war as an RAF pilot but he didn't fight for this bullshit.

elsergiovolador

It's probably going to be used by the police to stalk their partners, exes or "love interests".

Wouldn't be surprised if poorly paid police officers sold access as a side gig to burglars or other miscreants.

Add to that, today announced, more powers for police to enter without a warrant, they could probably become burglars themselves. Knowing when people are not home and know that they talked where they hide money or what expensive they bought recently.

Aleph0

"King's Speech – when the country's monarch reads out a speech that is written by the ruling political party"

Disclaimer, being from abroad I'm totally unfamiliar with the British political system, but after reading this fine article I'm kinda curious whether the monarch has the option of saying to whoever is handing the text "Nope, I won't read this shit"...

Ken Hagan

Queen Anne refused the Royal Assent to (i.e. vetoed) [1]a bill in 1708 . Since then, nothing much.

[1] https://en.m.wikipedia.org/wiki/Scottish_Militia_Bill_1708

ITMA

There is this thing called the "Royal Assent" by which the monach can refuse to enact a Bill thus preventing it from becomming law.

However, it being done would cause major constitutional problems:

https://en.wikipedia.org/wiki/Royal_assent#:~:text=The%20only%20situation%20in%20which,the%20bill%20from%20becoming%20law.

Damn - Ken beat me to it!

Mark 65

Yeah, but Charlie could become a legend if he did it. Just imagine this getting a regal "go get f*cked".

elsergiovolador

Monarch probably thinks he is a butterfly. Don't expect any action ;-)

All you need to know

JimmyPage

is the Queen was "forced" to sign the bill that illegally prorogued parliament.

And that blew up a lifetimes fiction that we have a Monarch "to stop tyranny".

Bollocks they do.

Hmmm

SVD_NL

"No we will not require companies to backdoor their security"

law passes

"We will however require advance notice before they implement (any?) data security system! Oh and don't forget, think of the children and screw terrorists!"

I do hope this will be as vaguely worded as the rest of the bill, because that will allow tech companies to take advantage of that...

"rolling out of technology by multinational companies that precludes lawful access to data." Leaves a lot of potential to spam the government with the most inconsequential changes.

Re: Hmmm

Anonymous Coward

Are you thinking time-based ciphers?

Total isolation is coming

may_i

If the UK keeps up their "trust big brother" strategy, I can see the country's isolation from the rest of the world reaching the point where their Internet peers unplug the connections leading to the UK. It's probably the right thing to do. Let the island descend into its dystopian future while the rest of us carry on without it. I certainly can't see tech companies keeping any presence in the UK when law after law gets passed which aim to turn every tech company into the UK's bitch and make them complicit in the dismantling of privacy, freedom of expression and freedom of thought.

This kind of crap makes me ashamed to admit that I was born in and grew up in the UK. Thank $deity I don't live there any more. I will not ever be returning.

nobody trusts

Omnipresent

the eeeeeeeevilllllllll at play in tech anymore.

Shirley

Anonymous Coward

The beauty of encryption is that you can tell everyone exactly how it works and that is precisely zero help in cracking it. Just stay away from any random number generators recommended by the NSA/GCHQ

One time pad - with a twist

Duncan Macdonald

If you need to send a message that needs to be kept secret - encrypt it with a one time pad. (That is the normal bit.)

Then the twist - take an innocent message of the same length and derive a one time pad as the exclusive OR of the innocent message and the encrypted message.

If forced to decrypt the message by the police - use the derived one time pad to give the innocent message.

One defining feature of a one time pad is that the encrypted message gives no indication apart from the size of the original message content.

An encrypted string "bivbh jwhxjpwnkhtesq23" could decrypt to "Birthday party tomorrow" or "Bomb Moscow on Monday." depending on the one time pad.

Re: One time pad - with a twist

Emir Al Weeq

It's a shame your downvoter didn't comment: I'd like to hear their reasons.

Granted the exchange of one time pads is not always easy and, in this case you'd also need to prepare innocent messages so that both sides' versions agreed. (The real message would probably need to be padded to match length.) But it is a solution, albeit an ugly one.

TheMaskedMan

When the online safety bill passed, I commented that I suspected that those in government would find a way to get their snooping desires over the line despite the "when possible" clause. And here it is.

Tech companies told the government they couldn't change things to suit political agendas, so the government preempts that in future. Persistent little shits, aren't they.

Anonymous Coward

You spelled "c*nts" wrong

I think

Boris the Cockroach

we're all missing the obvious question to be asked of any politician whos backing all these new spying laws.

"What are you so afraid of that means no one can have a private chat without being listened to? '

forced to get permission from the UK government if they want to make changes to security features

Howard Sway

Hmmm, let's introduce a captcha style test where you get presented with a photo containing government ministers and have to "select every square containing a corrupt or clueless arsehole".

Starting soon.

Tron

Microsoft, Google and Apple are going to have ensure that their software updates, especially virus checking (which might block snooping) fully geocheck before working, so they cannot function in the UK. So no updates for UK users on their operating systems or browsers. The USG will support this, as they don't want a foreign power to have a back door into their systems, even an ally.

The aggressive stance against backwards compatibility in browsers will soon lock UK users out of much of the net.

It will be an issue for UK banks, as users will rapidly have browsers that are not secure, so a reversion to offline banking will be required - cheque books, paper statements etc.

Foreign companies operating in the UK would not be able to use insecure systems that allowed the UK government to snoop on them, and most software would no longer be available here anyway, so they would have to up sticks and move out.

Privacy will be an issue for things like medical data, if a back door is enforced. The NHS, which isn't that secure as it is, will have to move back to paper records, and it then won't be flogging data to US companies. Unless it pays folk to type it all in from paper records on disconnected systems.

You could still develop next gen tech in the UK (if you were crazy enough, or too poor to do it elsewhere), but should not release it in the UK, as it wouldn't be considered safe internationally and insurers wouldn't permit it for corporate use. Again, geocheck out functionality in the UK with an ISP check, with GPS as a second line of defence.

There could actually be a few quid to be made licensing code that reliably blocks functionality in the UK, if you get your skates on.

Re: Starting soon.

Anonymous Coward

The reality is, as you make all common encryption weak/backdoored everyone seeks alternate solutions and so you cannot get want you want. I look at the parallels to the huge taxes Australia places on tobacco these days forcing the price of a packet of smokes to ~US$25 a pack. Unsurprisingly this has fueled black-market sales. Whether you agree with the policy or not is irrelevant as I'm merely referring to the consequences of the action. Weakening the encryption of regular products will drive the use of those not willing to play the game. Ne'er-do-wells will already have their own means of avoiding this.

It's both stupid and pointless.

UK exceptionalism strikes again

deaglecat

The world is a bigger place than we seem to think.

... oh and Newsflash: we don't have an empire anymore.

Re: UK exceptionalism strikes again

Anonymous Coward

What about Northern Ireland?

It would be almost impossible to write up such a law

DS999

Is patching a security hole a "security feature"? Is fixing a bug found in key exchange a "security feature"? Is making it so group chats are end to end encrypted instead of just person to person a "security feature"? Is strengthening or replacing an encryption algorithm a "security feature"?

They would either require notification of almost every software release/patch, or leave enough gray area that companies notify of nothing and courts uphold their (in)action.

And what are they expecting, the ability to approve/disapprove of each one? Probably moving at typical bureaucrat speed so they'd say "let us know about your upcoming features and we'll get back to you in six to nine months with whether you're allowed to use them or not."

Hopefully big tech gives them the big finger, and once everything from Microsoft, Apple, Google, Linksys etc. is stops getting updates in the UK and it becomes a hacker's paradise, enough citizens show up with pitchforks and torches that whoever thought up this dumb idea is forced to flee the country!

Re: It would be almost impossible to write up such a law

Anonymous Coward

Is patching a security hole a "security feature"?

If it is one of the flaws the spooks are using...yes.

A great empire, like a great cake, is most easily diminished at the edges.
-- B. Franklin