Net privacy wars will be with us always. Let's set some rules
- Reference: 1700469071
- News link: https://www.theregister.co.uk/2023/11/20/opinion/
- Source link:
Google dragged to UK watchdog over Chrome's upcoming IP address cloaking [1]READ MORE
Quick question number 2. Do you trust European governments? The Electronic Frontier Foundation (EFF) and hundreds of experts don't, pointing out that elements of proposed [2]revisions to EU regulations called eIDAS would exempt state-approved certificates from security action by browsers.
Let's take each story, both from the past fortnight, in turn. Google's IP Protection is basically an anonymizing proxy that means Chrome passes your IP to a third-party anonymizer. This assigns random IPs that change often enough that nobody can use it to identify you across sites. This is bad, says MOW, because it means only Google can do the tracking, which is unfair on other ad tech companies – for whom MOW speaks. It also encourages fraud and, oh yes, won't someone think of the children?
The eIDAS regulation is about trust. The digital certificates that control the security of protocols like HTTPS are issued by Certificate Authorities (CAs) which are part of a chain of trust. A site with a valid certificate is who it says it is. If a CA is compromised or malevolent, it gets removed from that chain and browsers no longer use keys provided by sites with the bad certs.
eIDAS wants this safety feature turned off for certificates issued by state-approved CAs. Even if the certificates falsely identify fake sites, users won't be able to tell. This would give states, state-approved organisations, or anyone corruptly part of that particular chain of trust, the ability to make fake sites that monitor and decrypt Web traffic silently and at scale. This is another bite of the end-to-end encryption cherry, and for the same reasons – helping fight crime and terrorism, prevent abuse, and, oh yes, think of the children.
[3]
These two stories have similarities. Both propose modifications to basic internet functionality in the name of security. Both are being opposed on the grounds that they do the opposite. Who to believe, and how to decide whether to support or decry them?
[4]
[5]
One way is to look at the combatants. Google is deeply untrustworthy on many levels, with a [6]long history of being caught out doing bad things with data. Nation states are all over the place, but even those with a strong commitment to regulation and the rule of law go as far as they can to grab data. State agencies, even the good ones, regularly do illegal things behind the shield of state security, and are as prone to incompetence and corruption as any human endeavor. MOW is a dark horse; it used to call itself Marketers for an Open Web and has a history of lobbying against Google's anti-tracking moves. Apply whatever rules you feel apply to trusting opaque lobbying groups. The EFF is a fully open group of people with a long record of identifying and warning about harmful attempts to damage user freedoms on the internet. Again, apply the trust you feel fitting.
[7]Introducing the tech that keeps the lights on
[8]YouTube cares less for your privacy than its revenues
[9]Intel's PC chip ship is sinking with Arm-ada on the horizon
[10]Windows 11: The number you have dialed has been disconnected
Yet trust, especially publicly expressed, is by itself a poor filter on which to make serious decisions. It can be swayed by random experiences, your social group, and where your paycheck comes from. We need a deeper analysis.
All privacy protects the good and the bad, it doesn't matter what the technical details are. Authoritarian regimes demand total privacy for themselves and none for their people, while liberal democracies define and protect personal privacy against intrusion, including that by the state. We have exceptions – search warrants, wiretaps, ISP log disclosures – but within a long-evolved system of oversight by the judiciary. We can assume that every privacy component in IT will change the balance of power between players, and every such component will at some point be attacked like an oyster by a hungry walrus.
Any such attacks can be tested against four factors – how big a change does it make, who is harmed and who benefits, how likely is it to go wrong, and what are the consequences when it does?
[11]
Looking at IP Protection, the size of the change it brings is the only factor. There are plenty of ways to anonymize your IP already, and Google strongly denies it will be able to track where others cannot, by dint of the basic architecture. It harms tracking cookies, and thus increases user privacy. It has no obvious harmful mode of failure unique to itself.
The eIDAS regulation makes an enormous change by mandating man-in-the-middle attack technology that it would be illegal for browser makers to defend against. It weakens the security on which the web is built in a unique way for unsophisticated users, while giving a wide range of entities the tools to decrypt data of all kinds. It is as likely to go wrong as any state-run secret security system, through incompetence, accident or malevolence, with consequences that could affect not just the half-billion EU citizens but all those who use EU-based services. Apart from any criminals with enough nous to get around the interception technology, of course.
It is the special nature of IT that it can apply to everyone all at once, in a way that previous state-sanctioned intrusions into our privacy cannot. It is a basic principle of law that the more harm a thing can do, the more heavily it is regulated, and it is impossible to look at the eIDAS proposal without demanding first what oversight and safeguarding is appropriate. IP Protection? Not so much.
[12]
This is all by way of proposing very basic risk assessment principles, which is, SpaceX's Starship concrete tornado notwithstanding, hardly rocket science. It is, or should be, the meat and drink of regulators and lawmakers. Especially with the latter, though, it is missing entirely from the most dangerous proposals, and that can't be accidental, not every time. Perhaps we shouldn't ask who we should trust, but who it is that doesn't trust us – and why. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2023/11/11/google_proxy_plan_cma/
[2] https://www.theregister.com/2023/11/08/europe_eidas_browser/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVs8UxAMZSvGqjDKBOF6UQAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVs8UxAMZSvGqjDKBOF6UQAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVs8UxAMZSvGqjDKBOF6UQAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://proton.me/blog/big-tech-three-billion-fines
[7] https://www.theregister.com/2023/11/13/data_diodes_comment/
[8] https://www.theregister.com/2023/11/06/youtube_ad_blockers_opinion/
[9] https://www.theregister.com/2023/10/30/arm_intel_comment/
[10] https://www.theregister.com/2023/10/23/column/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVs8UxAMZSvGqjDKBOF6UQAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVs8UxAMZSvGqjDKBOF6UQAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: who it is that doesn't trust us – and why
"but get a warrant first"
And that is the centre of the big state objectives. In every possible instance where there is a genuine need, they already could get a warrant. The point is they don't want to. The article refers humorously to "liberal democracies", but where are these fabled places? The US, UK, EU all have governments insisting that they need sweeping powers to monitor and intercept their own citizens communications with zero meaningful oversight, and all are pressing ahead with different means to achieve the same goal.
Re: who it is that doesn't trust us – and why
All of the above, absolutely. A bit more detail into the government part, because that's the context for which the final comment seemed mostly directed at....
...for a large part of the development of liberal democracy, there were a lot of 'gentlemen's rules', and while a lot of principles about seperation of power, avoiding conflict of interest etc did eventually get codified into constitutions and laws, there are still a large number of practices that evolved based on an understanding that the people in politics would operate from a basic code of honour. There have always been shysters in politics, but representative democracy opened the door to them in volume, since large populations give rise to both larger democratic institutions as well as a higher ratio of voters to representatives (making it easier for shysters to get elected from among a large voter pool who do not know them personally, only from propaganda). And now, many of these gentlemen's rules are no longer observed, and those observing them are taken advantage of.
As more and more shysters entered politics for their own benefit, the potential grew for more collusion and corruption between legislative bodies, administrative bodies and large business interests. Again, corrupt businessmen, politicians and administrators are nothing new, they just became supercharged by the "economies of scale" provided by population and industrial growth. What was already correctly identified 50+ years ago as the 'military-industrial complex' is now a supercharged cancerous growth that also includes tech companies (which are, first and foremost, data-gathering/processing aka spying companies).
All of this has been built on asymmetric information - in spite of the liberal mantra of transparent government and private personal life, the reality is that everyone's private life is available to those in power with a few clicks of a button (what's a warrant requirement after all, when judges are politically appointed??), and Freedom of Information legislation barely scratches the surface of the inner workings of government. (In addition to which, all the entities tasked with oversight and enforcement of the laughably weak rules in place are, themselves, branches of government).
So saying "Governments don't trust their electors - they might vote for the wrong party next time" is also itself only scratching the surface... every government employee is beholden in some way to political will to keep or advance in their job, and every politician is beholden to the lobbyists who pay for their election campaign (and yes there are many honest exceptions but far less than the actively corrupt or those simply keeping out of the line of fire). If people really knew what was going on behind the scenes, they wouldn't be voting for a different party, they would be storming the Bastille.
Covert monitoring in the lands of the free and democracy, at least the axis of evil states don't try and hide what they are doing behind fancy laws and acronyms, may I dare say it, even the Nazis far more open when it came to state monitoring.
"The eIDAS regulation is about trust"
Actually, it's not about trust at all - it's about being forced to accept potential exposures that you may not even be aware of. That's what the tech politicos mean when they say "trust". Real trust is based on being informed and having the option not to trust, but the choice we have been handed is "accept blindly anything we throw at you or do without this service". And both the tech behemoths and governments seem to be in agreement that this is perfectly OK, despite cases where not accepting this may be life threatening. Already some five years ago the vast extent of tracking on government and health service web sites was [1]clearly documented , but nothing seems to have changed for the better. Indeed the UK health service has recently made national scale changes to how folks can book appointments with their GP -- now exclusively via a central NHS online portal. This of course opens the possibility of the central NHS having a record of every interaction between patient and doctor, which you don't have to be paranoid to construe as a backdoor method of circumventing the central medical records register that was rejected by both the UK and European supreme courts as too intrusive.
But quite apart from the privacy implications, the extent to which we unwittingly accept the presence of third party trackers and scripts with unknown function every time we visit a web site (even one we have decided to trust in the genuine sense) has become a major cause for concern. Not least from the security perspective it's darned dangerous, as is evidenced by the number of ransomware attacks the occur because someone 'clicked on a link'. It's impossible to trust something you are completely unaware of, so we must stop misusing the word to signify blind acceptance, or preferably abandon the bad practice its misuse signifies. Some hope, I fear.
[1] https://www.cookiebot.com/media/1136/cookiebot-report-2019-ad-tech-surveillance-2.pdf
who it is that doesn't trust us – and why
Governments don't trust their electors - they might vote for the wrong party next time.
Search engines makers don't trust their users - they might not go to the page we've been paid to put at the top of the list.
Browser makers don't trust anyone - they might have the temerity to use a different browser.
OS makers don't trust anyone - how dare the user choose options other than those which we have, in our magnanimosity, selected for them?
Computer makers don't trust anyone - you want to run an OS that isn't the one that mandated all these clever security chips?
There's an old Yorkshire saying: they're all mad bar thee and me, and I'm not right sure about thee... The only half-way secure internet is one with hard encryption in transit. If you want to know who I talk to, use traffic analysis - but get a warrant first. But gentlemen do not read other people's mail.