UK ISP Boss Highlights Technical Stupidity Of The Snooper's Charter Proposal

from the surveillance-magic dept

There’s just something absolutely nutty when politicians with no technical knowledge whatsoever try to make technology policy, and it often crosses over into out-and-out slapstick when that technology policy involves surveillance. It’s why we see things like talk of “golden keys” for encryption that somehow wouldn’t be “backdoors” (even though they are). Over in the UK, they’re going through something similar with the current “debate” (if you can call it that) over the latest Snooper’s Charter bill, officially known as the “Investigatory Powers Bill” or the “IPBill.”

A key element in the bill is the demand for “internet connection records.” The draft bill has a whole section on these “ICRs” which it defines as:

A kind of communications data, an ICR is a record of the internet services a specific device has connected to, such as a website or instant messaging application. It is captured by the company providing access to the internet. Where available, this data may be acquired from CSPs by law enforcement and the security and intelligence agencies.

An ICR is not a person?s full internet browsing history. It is a record of the services that they have connected to, which can provide vital investigative leads. It would not reveal every web page that they visit or anything that they do on that web page.

That definition, by itself, seems somewhat self-contradictory, but we’ll leave that aside for now. Adrian Kennard, the head of a small UK ISP, Andrews & Arnold, has filed some comments highlighting how technically clueless this idea is:

The explanatory notes, and one of the clauses in the bill, make use of the term ?Internet Connection Record?. We are concerned that this creates the impression that an ?Internet Connection Record? is a real thing, like a ?Call Data Record? in telephony.

An ICR does not exist – it is not a real thing in the Internet. At best it may be the collection of, or subset of, communications data that is retained by an operator subject to a retention order which has determined on a case by case basis what data the operator shall retain. It will not be the same for all operators and could be very different indeed.

We would like to see the term removed, or at least the vague and nondescript nature of the term made very clear in the bill and explanatory notes.

From there, it goes even further, pointing out that the justification for needing these non-existent ICRs was a statement from UK Home Secretary Theresa May about how useful such info would be in finding a missing girl:

“Consider the case of a teenage girl going missing. At present we can ask her mobile provider for call records before she went missing which could be invaluable to finding her. But for Internet access, all we get is that the Internet was accessed 300 times. What would be useful would be to know she accessed twitter just before she went missing in the same way as we could see she make a phone call”

Except, as Kennard points out, that’s not how the internet actually works. You don’t “connect” to Twitter like that, because you’re constantly connected to Twitter:

…in yesterday?s meeting I, and other ISPA members immediately pointed out the huge flaw in this argument. If the mobile provider was even able to tell that she had used twitter at all (which is not as easy as it sounds), it would show that the phone had been connected to twitter 24 hours a day, and probably Facebook as well. This is because the very nature of messaging and social media applications is that they stay connected so that they can quickly alert you to messages, calls, or amusing cat videos, without any delay.

It should be noted that it is quite valid for a ?connection? of some sort to last a long time. The main protocol used (TCP) can happily have connections for hours, days, months or even years. Some protocols such as SCTP, and MOSH are designed to keep a single connection active indefinitely even with changes to IP addresses at each end and changing the means of connection (mobile, wifi, etc). Given the increasing use of permanent connections on mobile devices, it is easy to see how more and more applications will use such protocols to stay connected – making one ?internet connection record? which could even have passed the 12 month time limit by the time it is logged.

Connections are also typically encrypted and have some data passing all the time, so it would not be practical for an ISP, even using deep packet inspection, to indicate that the girl ?accessed twitter? right before she vanished, or even at all (just that there is a twitter app on the phone and logged in).

This seems like a rather important point: the people who put together the Snooper’s Charter for spying on the internet don’t seem to understand the first thing about how the internet actually works. And yet we’re supposed to give them sweeping powers to spy on it? How does that make any sense?

Filed Under: , , , , , , , , ,
Companies: andrews & arnold

Comments on “UK ISP Boss Highlights Technical Stupidity Of The Snooper's Charter Proposal”

Anonymous Coward says:

and because it IS SO STUPID is exactly why everyone’s fears and concerns will be ignored and it will be brought into law! the idea is not and never will be to catch terrorists, but to keep the ordinary people under the ‘scope, making sure they are not organising any protests against the government or members because of some other ridiculous thing they have done or intend to do, but want to keep secret!! and i doubt if any other UK government has been as secretive or underhanded as Cameron’s lot!!

Mason Wheeler (profile) says:

This seems like a rather important point: the people who put together the Snooper’s Charter for spying on the internet don’t seem to understand the first thing about how the internet actually works. And yet we’re supposed to give them sweeping powers to spy on it? How does that make any sense?

I’m reminded of one of the more thought-provoking passages from Brandon Sanderson’s epic, The Way of Kings:

I walked from Abamabar to Urithiru. In this, the metaphor and experience are one, inseparable to me like my mind and memory. One contains the other, and though I can explain one to you, the other is only for me.

I strode this insightful distance on my own, and forbade attendants. I had no steed beyond my well-worn sandals, no companion beside a stout staff to offer conversation with its beats against the stone. My mouth was to be my purse; I stuffed it not with gems, but with song. When singing for sustenance failed me, my arms worked well for cleaning a floor or hog pen, and often earned me a satisfactory reward.

Those dear to me took fright for my safety and, perhaps, my sanity. Kings, they explained, do not walk like beggars for hundreds of miles. My response was that if a beggar could manage the feat, then why not a king? Did they think me less capable than a beggar?

Sometimes I think that I am. The beggar knows much that the king can only guess. And yet who draws up the codes for begging ordinances? Often I wonder what my experience in life—my easy life following the Desolation, and my current level of comfort—has given me of any true experience to use in making laws. If we had to rely on what we knew, kings would only be of use in creating laws regarding the proper heating of tea and cushioning of thrones.

Anonymous Coward says:

Stupid Geek

Adrian Kennard obviously doesn’t have a clue about how the internet works. Of course internet “connections” are just like telephone “calls”. How could he not know that? Oh, wait, he’s one of those “geeks”, isn’t he? That explains it. Well, thank goodness there are plenty of government officials to straighten his little geek ass out and “educate” him on how the internet really works.

art guerrilla (profile) says:

Re: Stupid Geek

no, he’s just a tool…
my theory for why so many of these tech-ignorant ideas are floated, is because they DON’T want capable, knowledgeable, experienced nerds, et al to provide any significant advise and guidance (never mind leadership)…

that would shoot down ALL their idiotic ideas; and they don’t really care they are idiotic, they just want to out-bluster the other pols…

actually listening to the nerderati and basing decisions on that could lead to well-measured and smart responses (which might include ‘doing nothing’, gasp), and we can’t have that ! ! !

(reminder: action is not achievement)

David says:

Re: Stupid Geek

Internet connections are not like telephone calls. Internet consists of multiple protocols. TCP connections are a bit like a telephone call (with continuity) but without the realtime guarantees. UDP is more like a hitch hiking network where the order of departure and arrival (if a packet does not get terminally lost after all) are not really synchronized. ICMP is like one-time semaphoring.

And so on.

Anonymous Coward says:

Formal education

[Policymakers] don’t seem to understand the first thing about how the internet actually works.

Years and years ago, when I went back to school, my introductory, undergraduate networking course was 5 quarter-credits (we were on the quarter system), geared towards EEs and CSs (dual-listed course), and used an early edition of Andrew Tanenabum‘s Computer Networking as the course textbook.

Most policymakers would not have the prerequisites to get into that introductory, undergraduate course.

I don’t know quite what to do about the problem. Obviously, that level of formal education isn’t necessary for everyone. Many other people have informally picked up all that they need to become competent in their field, here and there as they went along. In fact, I myself was doing some professional computer networking before I decided to go back to school.

But, otoh, when I start to think about diving into the distinctions between circuit-switching and packet-switching, and then talking about virtual-circuits on top… contrasting that with connected-oriented versus connectionless protocols… distinguishing between protocols and services… You know, I think that people who haven’t had the advantage of a formal education are handicapped more than they might realize.

Iow, they don’t even know what they don’t know.

Whoever says:

Re: Formal education

Those policymakers don’t understand how the Internet works, but they have an army of advisers, many of whom do understand how the Internet works. They have access to GCHQ, where there are lots of geeks who have an excellent understanding of how the Internet works.

So, if the policymakers have plenty of people who can tell them that the proposed snooping isn’t going to provide useful information, what is it for? IMHO, it is likely that there is an ulterior motive for the snooper’s charter, which hasn’t yet been revealed.

