France Goes Overboard In Data Retention: Wants User Passwords Retained

from the anti-privacy-laws dept

There have been plenty of stories about various governments, often at the behest of either law enforcement or the entertainment industry, pushing for data retention laws. It seems especially ironic in Europe, where privacy laws are a much bigger deal, that they would also push for data retention, which is the opposite of a privacy law. However, Andrew Swift points us to a new data retention law in France that goes way beyond your typical “keep the log files” data retention rule. Instead, it appears to require that ISPs and hosting companies retain all sorts of private information (Google translation from the original French). Swift summarizes for us the information that needs to be retained:

Information furnished when agreeing to a contract or opening an account, including first name, last name, business name, associated mailing addresses, and pseudonyms utilized, associated e-mail addresses and accounts, telephone numbers, and passwords as well as data permitting the verification or modification of the password.

These companies must also keep all user id’s and passwords for any internet connection, the IP address of the terminal used to connect, the time and date of every connection, and…

Here’s the kicker: for EVERY action of a user on the internet, these companies are now required to record the nature of the operation, whether it is writing an e-mail or downloading an image or video.

Just the fact that these companies would even have access to passwords should be problematic. Why aren’t these services encrypting the passwords? I’m really curious how a law like this could possibly work in conjunction with European privacy laws?

Not surprisingly, it appears that pretty much every online service provider is planning to challenge this decree in court (Google translation of the original French).

Filed Under: , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “France Goes Overboard In Data Retention: Wants User Passwords Retained”

Subscribe: RSS Leave a comment
Chris Rhodes (profile) says:

Yeah, Sure

Here’s the kicker: for EVERY action of a user on the internet, these companies are now required to record the nature of the operation, whether it is writing an e-mail or downloading an image or video.

After people get wind of this, I hope they have fun sorting through logs that look like:

3-11-2011@19:27 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@19:31 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@19:34 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@19:47 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@19:58 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@20:06 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)
3-11-2011@25:04 – XXX.XXX.XXX.XXX – Connection To: YYY.YYY.YYY.YYY (Tor Gateway Node)

el_segfaulto (profile) says:

Re: Re: Re:

Wow…if they are required to keep your password in an unencrypted form (and theoretically to update it as you update your password) then this just went to a really unsettling level. I think I heard an entire legion of blackhats menacingly wring their hands together. You are right about SHA vs AES, I’m not entirely sure why I typed AES…I’ll just chalk it up to lack of coffee.

Brad Hubbard (profile) says:

Re: Re: Re: Re:

Recall – this is the country that sued Google because a bunch of BANKING PASSWORDS were being sent, unencrypted, over open WIFI connections.

Clearly their laws and practices don’t make for good security policy. Maybe it’s a culture thing?

And why would you ever need a user’s password? Any decent program has a “become” feature for admins, so you can log in as that user. All the ones I write have it, anyhow.

Gwiz (profile) says:



What’s next in France?

Will their postal service be required to open each and every piece of mail and record everything in a log? How much you owe on your credit card, that fantasy filled letter form your girlfriend or that package from Victoria’s Secrets would all be fair game.

Also, in the US here we have very strict rules (HIPAA Privacy Rule) concerning the privacy of medical records and it could mean that the US medical establishment wouldn’t be able to corroborate with their French counterparts on diagnoses.

BBT says:

Oh good! a law requiring French sites to store passwords in plain text, one of the worst and most dangerous security practices imaginable! Now anyone who hacks into a french site’s database will have access to all the site’s visitors’ passwords. This is an epic failure.

French site administrators will now have the fun choice of obeying the law or putting their customers’ data in danger of being compromised. Brilliant!

ComputerAddict (profile) says:

Re: Re:

Before you jump on me, I’m not for this law…But

This law is for ISP’s not for Websites… your gmail password will stil be encrypted, it is just your password you use to CONNECT to the internet, not what you do once your online.

That being said this is obviously so they can connect as you, visit a bunch of nasty sites, and then sue you saying “You visited and downloaded the internet, pay us or goto jail.”

Also it doesn’t say (yet) that it has to be plain txt, thats an assumption, If anything I hope this encourages ISP’s to encrypt more data (with reversible encryption) like your address, billing info, and browsing history.

Again I think the idea is horrible, but lets not confuse ISP’s and Websites, or assume they have to be completely unencrypted.

zzlg says:

Re: Re: Re:

This law IS for websites and ISPs. The law concerns “online communications services to the public”, anything that includes the creation of content (websites, blogs, comments, participation in forums, etc.) publicly avalaible.

Private correspondence (ie email services) is excluded from the scope of this law.

John Doe says:

I absolutely agree with you on encrypting passwords...

No website should have access to your password. I wrote a public facing website and the password was one-way encrypted. If you forgot your password, you were issued a new one as the old one could not be decrypted. Every website should be operating the same way. If there is a database of passwords out there, then someone in the company has access to it and can use it for illegal reasons. Most people use the same password for many sites, so all they have to do is attempt to log into every bank and online stock trading company until they find yours.

Anonymous Coward says:

One of the reasons I don’t participate and comment at many sites is the requirement to join some sort of blog company in order to comment or that you need to sign up to do so. Call it childishness or paranoia or whatever. The fact that I can not do as I do here and comment without registration insures I will not comment but rather will read the article and go on.

I am sure more than anything it’s being driven by the need to put some sort of control on spamming and trolling, neither of which I am interested in. However because of this sort of restriction, places like ARSTechina and Torrentfreak no longer receive any sort of comment from me. (maybe that’s a good thing)

I do at times comment here, strictly because I can do so anonymously without the requirement to be counted, datamined, and tied to some sort of identification. Yes, I know that my IP is recorded because I haven’t used VPN or TOR and have not to this point chosen to do so.

It is rapidly reaching the point that I am considering the last two as self protection. It’s not that I’m guilty of anything, it’s that I don’t want to be followed where ever I go, linked to everything under the sun on the internet in a casual browse.

The one thing I am very sure of is that if you have a huge database being kept track of, somewhere a hacker will figure a way in. Governments are honey pots for them as that’s where large databases are. Info is key to money in one form or another. So making sure a large database to keep track of things like passwords will surely open their citizens to hacker access, simply because it is there.

Chris Rhodes (profile) says:

Re: Re:

Yes, I know that my IP is recorded because I haven’t used VPN or TOR and have not to this point chosen to do so. […]
It is rapidly reaching the point that I am considering the last two as self protection

Indeed. I have an older machine sitting about, and my current plan is to craft it into a “secure” desktop running a hardened version of Linux, with full disk encryption, TOR, and a bevy of other offerings both large and small to make tracking a virtual impossibility.

Should be a fun project.

Nick Taylor says:

I already put everything through a vpn – but as far as comments go, I’m a head-above-the-parapets kind of guy. I use my real name, and my real email-address (though I never register on a site to comment).

And I’ll say it out loud (with head above parapets): Any government that tries to inflict control over the internet does so without the consent of those that it would control – so is illegitimate, and must be got rid of.

Hugues Lamy (user link) says:

Use OpenId

What about service liked OpenID, Facebook Connect and other services by Yahoo and Microsoft. What about service aggregator like JanRain? The passwords are located on their servers. They use a callback method to give you access to the sites. This will but everybody using this technique to be guilty of not keeping the password. But you can’t have it.

Anybody know that the person that wrote the application doesn’t need the password to look into its database. I can only see that since the regular people use the same password everywhere, with one password you can get into other services to dig more dirt.I’m pretty sure that if you dig hard enough on somebody else past, you can find him guilty of something.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...