<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/snoopers-charter" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Snoopers-charter ]]></title>
                <link>https://www.itpro.com/tag/snoopers-charter</link>
        <description><![CDATA[ All the latest snoopers-charter content from the ITPro team ]]></description>
                                    <lastBuildDate>Thu, 01 Mar 2018 11:19:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Government 'must be held to account' over illegal Snooper's Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The High Court has been urged to give MPs until July 2018 to rewrite sections of the Investigatory Powers Act after they were deemed "incompatible" with European law.</p><p>Powers that forced communication companies to collect and store data on the UK population, including phone records and internet activity, were ruled illegal in January as they granted spy agencies access to user data for purposes other than fighting crime, and without court approval.</p><p>Digital rights group Liberty argued that ministers had been exercising these powers in the 14 months since the introduction of the Investigatory Powers Act (IPA), and has now demanded that they urgently rewrite the laws to comply with European legislation, as reported by the <a href="http://www.newsandstar.co.uk/news/national/article/Judges-urged-to-rule-against-Government-over-so-called-snoopers-charter-2d0fc388-9600-45b0-a961-2f56cb40f751-ds" target="_blank"><em>News & Star newspaper</em></a>.</p><p>Barrister Martin Chamberlain told the High Court on Tuesday that the government should be given a deadline of 31 July 2018 to change the laws around data retention in order to provide an "effective remedy", at which point groups such as Liberty could then seek further court action.</p><p>However, the government argued that the "vast majority" of the collected data would never be accessed by the government as most cases don't pertain to any criminal investigation.</p><p>James Eadie QC, representing the government, said that it had already proposed amendments to the IPA in November last year, though there have yet to be any legislative changes, despite the ruling in January.</p><p>He also argued that as the government has already begun the process of making changes, it should be given until April 2019 to allow it time to agree to new laws and introduce a "fully independent authorisation regime".</p><p>January's ruling ended a long-running case brought against the government by Labour's Tom Watson in 2014, which argued that sections of the Data Retention and Investigatory Powers Act (DRIPA) were unlawful. Those same sections were translated to the Investigatory Powers Act when DRIPA expired in 2016 and as such it has now been argued that the government needs to rewrite those provisions to comply with the EU.</p><p>Speaking before Tuesday's hearing, Liberty director Martha Spurrier said: "Our message to the Government is straightforward you're not above the law. Stop ignoring the courts, stop knowingly violating people's rights and get on with building a targeted surveillance system that protects our safety, our cybersecurity and our rights."</p><p><strong>30/01/2018: Court rules that UK's digital surveillance powers are illegal</strong></p><p>The UK government's broad digital surveillance tactics, first defined under old legislation, are unlawful, judges ruled today.</p><p>The ruling concerns a legal challenge brought by Labour MP Tom Watson against the government's defunct Data Retention and Investigatory Powers Act (DRIPA) legislation that set out mass surveillance laws in 2014.</p><p>Judges unanimously found that section one of DRIPA was inconsistent with EU law because it granted spy agencies and law enforcement access to UK citizens' phone records and internet activity for purposes other than fighting serious crime, without seeking or getting approval from a court or independent authority.</p><p>DRIPA forced communications companies to store detailed information on people's mobile phone data, as well as their emails, texts and internet communications.</p><p>The Investigatory Powers Act (also known as the 'Snooper's Charter') replaced DRIPA when it expired at the end of 2016, and effectively incorporated the DRIPA legislation amid other measures. Consequently, Watson said the government will need to make changes to this legislation as well to comply with the appeal court's ruling.</p><p>Watson, who first brought his challenge to DRIPA in 2014, said: "This legislation was flawed from the start. It was rushed through Parliament just before recess without proper parliamentary scrutiny.</p><p>"The government must now bring forward changes to the Investigatory Powers Act to ensure that hundreds of thousands of people, many of whom are innocent victims or witnesses to crime, are protected by a system of independent approval for access to communications data."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" data-original-url="/data-protection/24998/high-court-rules-dripa-is-unlawful">High Court rules DRIPA is unlawful</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" data-original-url="/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">Liberty wins right to challenge Snooper’s Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection" data-original-url="/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection">Blow for Snoopers Charter as EU court bans mass data collection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers" data-original-url="/policy-legislation/30075/uk-police-to-lose-data-snooping-powers">UK police to lose data snooping powers</a></p></div></div><p>Martha Spurrier, director of digital rights group Liberty, which represented Watson, added: "This judgement tells ministers in crystal clear terms that they are breaching the public's human rights. The latest incarnation of the Snooper's Charter, the Investigatory Powers Act, must be changed."</p><p>The government <a href="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers">opened a consultation on the Investigatory Powers Act in November last year</a>, admitting that independent oversight is necessary, and proposing safeguards around data retention.</p><p>However, <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/663668/November_2017_IPA_Consultation_-_consultation_document.pdf" target="_blank">this consultation</a> also rejected the accusation that its data retention regime is "general and indiscriminate".</p><p>Open Rights Group Scotland director Matthew Rice said: "The Investigatory Powers Act carves a gaping hole in the public's rights: public bodies able to access data without proper oversight, and access to that data for reasons other than fighting serious crime.</p><p>"These practices must stop, the courts have now confirmed it. The ball is firmly in the government's court to set it right."</p><p>Security minister Ben Wallace said in a statement emailed to <em>IT Pro</em>: "Communications data is used in the vast majority of serious and organised crime prosecutions and has been used in every major Security Service counter-terrorism investigation over the last decade. It is often the only way to identify paedophiles involved in online child abuse as it can be used to find where and when these horrendous crimes have taken place.</p><p>"This judgment relates to legislation which is no longer in force and, crucially, today's judgement does not change the way in which law enforcement agencies can detect and disrupt crimes.</p><p>"We had already announced that we would be amending the Investigatory Powers Act to address the two areas in which the Court of Appeal has found against the previous data retention regime. We welcome the fact that the Court of Appeal ruling does not undermine the regime and we will continue to defend these vital powers, which Parliament agreed were necessary in 2016, in ongoing litigation."</p><p>Today's decision comes after Watson <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">won his initial High Court challenge in 2015</a>.</p><p>When the government appealed the Court of Appeal referred the case to the European Court of Justice, <a href="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection" target="_blank" data-original-url="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection">which upheld the High Court's decision</a>, and set out safeguards the government must introduce in the Investigatory Powers Act, which critics claim aren't reflected in the government's consultation.</p><p>Liberty <a href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">is challenging Investigatory Powers' mass surveillance regime in a separate case</a> after crowdfunding a 50,000 legal fund.</p><p><em>Pictur courtesy of <a href="https://www.flickr.com/photos/defenceimages/7985695591/in/photolist-rZkbHU-QKVyJH-pQWQrj-RBqpvC-ZviKFL-i6QgZY-d869g9-ndzTh1-nrnq1y-TZVdWu-VffGtL-zYRw56-qxAPcU-oNth5R-TJ1Q2b-nv7eHS-n8Yvrr-kJT4NQ-s7pknP-fMnq4V-p8UHw9-qxNNQ6-rutV6t-dZbfG6-rQ1ZxB-9QxkDH-ojQNry-U2VzdW-ndZbaY-X9sLqz-ngsdja-4xFt7A-ruu1mt-TS1T5C-nHxGvf-rbgXkg-RKyVfC-JADu3w-bDhgic-ngp59u-hK1mfQ-nrnnH8-rd9mPX-nx3F1W-daEM5K-c8ZwqW-rd27Kh-r4wZx9-rsiyhm-qpX8iV" target="_blank">Defence Images</a></em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/privacy/30423/government-must-be-held-to-account-over-illegal-snoopers-charter</link>
                                                                            <description>
                            <![CDATA[ Gov should be given until April to make changes to the Investigatory Powers Act, court told ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ej77YCoHmr8L8jqAXV4aNH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Mar 2018 11:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[Aerial view of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The High Court has been urged to give MPs until July 2018 to rewrite sections of the Investigatory Powers Act after they were deemed "incompatible" with European law.</p><p>Powers that forced communication companies to collect and store data on the UK population, including phone records and internet activity, were ruled illegal in January as they granted spy agencies access to user data for purposes other than fighting crime, and without court approval.</p><p>Digital rights group Liberty argued that ministers had been exercising these powers in the 14 months since the introduction of the Investigatory Powers Act (IPA), and has now demanded that they urgently rewrite the laws to comply with European legislation, as reported by the <a href="http://www.newsandstar.co.uk/news/national/article/Judges-urged-to-rule-against-Government-over-so-called-snoopers-charter-2d0fc388-9600-45b0-a961-2f56cb40f751-ds" target="_blank"><em>News & Star newspaper</em></a>.</p><p>Barrister Martin Chamberlain told the High Court on Tuesday that the government should be given a deadline of 31 July 2018 to change the laws around data retention in order to provide an "effective remedy", at which point groups such as Liberty could then seek further court action.</p><p>However, the government argued that the "vast majority" of the collected data would never be accessed by the government as most cases don't pertain to any criminal investigation.</p><p>James Eadie QC, representing the government, said that it had already proposed amendments to the IPA in November last year, though there have yet to be any legislative changes, despite the ruling in January.</p><p>He also argued that as the government has already begun the process of making changes, it should be given until April 2019 to allow it time to agree to new laws and introduce a "fully independent authorisation regime".</p><p>January's ruling ended a long-running case brought against the government by Labour's Tom Watson in 2014, which argued that sections of the Data Retention and Investigatory Powers Act (DRIPA) were unlawful. Those same sections were translated to the Investigatory Powers Act when DRIPA expired in 2016 and as such it has now been argued that the government needs to rewrite those provisions to comply with the EU.</p><p>Speaking before Tuesday's hearing, Liberty director Martha Spurrier said: "Our message to the Government is straightforward you're not above the law. Stop ignoring the courts, stop knowingly violating people's rights and get on with building a targeted surveillance system that protects our safety, our cybersecurity and our rights."</p><p><strong>30/01/2018: Court rules that UK's digital surveillance powers are illegal</strong></p><p>The UK government's broad digital surveillance tactics, first defined under old legislation, are unlawful, judges ruled today.</p><p>The ruling concerns a legal challenge brought by Labour MP Tom Watson against the government's defunct Data Retention and Investigatory Powers Act (DRIPA) legislation that set out mass surveillance laws in 2014.</p><p>Judges unanimously found that section one of DRIPA was inconsistent with EU law because it granted spy agencies and law enforcement access to UK citizens' phone records and internet activity for purposes other than fighting serious crime, without seeking or getting approval from a court or independent authority.</p><p>DRIPA forced communications companies to store detailed information on people's mobile phone data, as well as their emails, texts and internet communications.</p><p>The Investigatory Powers Act (also known as the 'Snooper's Charter') replaced DRIPA when it expired at the end of 2016, and effectively incorporated the DRIPA legislation amid other measures. Consequently, Watson said the government will need to make changes to this legislation as well to comply with the appeal court's ruling.</p><p>Watson, who first brought his challenge to DRIPA in 2014, said: "This legislation was flawed from the start. It was rushed through Parliament just before recess without proper parliamentary scrutiny.</p><p>"The government must now bring forward changes to the Investigatory Powers Act to ensure that hundreds of thousands of people, many of whom are innocent victims or witnesses to crime, are protected by a system of independent approval for access to communications data."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" data-original-url="/data-protection/24998/high-court-rules-dripa-is-unlawful">High Court rules DRIPA is unlawful</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" data-original-url="/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">Liberty wins right to challenge Snooper’s Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection" data-original-url="/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection">Blow for Snoopers Charter as EU court bans mass data collection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers" data-original-url="/policy-legislation/30075/uk-police-to-lose-data-snooping-powers">UK police to lose data snooping powers</a></p></div></div><p>Martha Spurrier, director of digital rights group Liberty, which represented Watson, added: "This judgement tells ministers in crystal clear terms that they are breaching the public's human rights. The latest incarnation of the Snooper's Charter, the Investigatory Powers Act, must be changed."</p><p>The government <a href="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30075/uk-police-to-lose-data-snooping-powers">opened a consultation on the Investigatory Powers Act in November last year</a>, admitting that independent oversight is necessary, and proposing safeguards around data retention.</p><p>However, <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/663668/November_2017_IPA_Consultation_-_consultation_document.pdf" target="_blank">this consultation</a> also rejected the accusation that its data retention regime is "general and indiscriminate".</p><p>Open Rights Group Scotland director Matthew Rice said: "The Investigatory Powers Act carves a gaping hole in the public's rights: public bodies able to access data without proper oversight, and access to that data for reasons other than fighting serious crime.</p><p>"These practices must stop, the courts have now confirmed it. The ball is firmly in the government's court to set it right."</p><p>Security minister Ben Wallace said in a statement emailed to <em>IT Pro</em>: "Communications data is used in the vast majority of serious and organised crime prosecutions and has been used in every major Security Service counter-terrorism investigation over the last decade. It is often the only way to identify paedophiles involved in online child abuse as it can be used to find where and when these horrendous crimes have taken place.</p><p>"This judgment relates to legislation which is no longer in force and, crucially, today's judgement does not change the way in which law enforcement agencies can detect and disrupt crimes.</p><p>"We had already announced that we would be amending the Investigatory Powers Act to address the two areas in which the Court of Appeal has found against the previous data retention regime. We welcome the fact that the Court of Appeal ruling does not undermine the regime and we will continue to defend these vital powers, which Parliament agreed were necessary in 2016, in ongoing litigation."</p><p>Today's decision comes after Watson <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">won his initial High Court challenge in 2015</a>.</p><p>When the government appealed the Court of Appeal referred the case to the European Court of Justice, <a href="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection" target="_blank" data-original-url="https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection">which upheld the High Court's decision</a>, and set out safeguards the government must introduce in the Investigatory Powers Act, which critics claim aren't reflected in the government's consultation.</p><p>Liberty <a href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">is challenging Investigatory Powers' mass surveillance regime in a separate case</a> after crowdfunding a 50,000 legal fund.</p><p><em>Pictur courtesy of <a href="https://www.flickr.com/photos/defenceimages/7985695591/in/photolist-rZkbHU-QKVyJH-pQWQrj-RBqpvC-ZviKFL-i6QgZY-d869g9-ndzTh1-nrnq1y-TZVdWu-VffGtL-zYRw56-qxAPcU-oNth5R-TJ1Q2b-nv7eHS-n8Yvrr-kJT4NQ-s7pknP-fMnq4V-p8UHw9-qxNNQ6-rutV6t-dZbfG6-rQ1ZxB-9QxkDH-ojQNry-U2VzdW-ndZbaY-X9sLqz-ngsdja-4xFt7A-ruu1mt-TS1T5C-nHxGvf-rbgXkg-RKyVfC-JADu3w-bDhgic-ngp59u-hK1mfQ-nrnnH8-rd9mPX-nx3F1W-daEM5K-c8ZwqW-rd27Kh-r4wZx9-rsiyhm-qpX8iV" target="_blank">Defence Images</a></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK faces challenges to bulk spying in European Court of Human Rights ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Representatives from the UK government have appeared in front of the European Court of Human Rights (ECHR) this week after a coalition of civil rights groups brought a challenge to the policy of bulk data collection by security agencies.</p><p>Amnesty International, Big Brother Watch, Liberty, Privacy International, as well as 10 other human rights and journalistic groups in Europe, Africa and Asia sought to challenge the legality of the UK's mass surveillance and data collection, in a <a href="http://www.echr.coe.int/Pages/home.aspx?p=home" target="_blank">court hearing</a> that started on Tuesday in Strasbourg.</p><p>The group argues that the government policy allowing UK security agencies to intercept data, which NSA whistleblower Edward Snowden's revelations brought to light, is a breach of the European Convention on Human Rights.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" data-original-url="/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">Investigatory Powers Tribunal escalates lawsuit to the EU</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" data-original-url="/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">Liberty wins right to challenge Snooper’s Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" data-original-url="/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade</a></p></div></div><p>Three separate cases are now being brought against the UK government, namely Big Brother Watch and Others v. the United Kingdom, Bureau of Investigative Journalism and Alice Ross v. the United Kingdom, and 10 Human Rights Organisations and Others v. the United Kingdom. The hearing on Tuesday was only the initial part of the process, with an official ruling set to be made at a later stage.</p><p>In all three cases, the groups believe that due to the sensitive nature of the data they handle, their communications may have been intercepted by either the UK or US security agencies in the course of bulk data collection and data-sharing.</p><p>The practice of sharing data between agencies has been challenged by human rights groups in the past. In a <a href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" target="_blank" data-original-url="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">controversial ruling in 2016</a>, the Investigatory Powers Tribunal, which has jurisdiction over GCHQ, MI5 and MI6, ruled that the agreement between the UK's GCHQ and the US's NSA was unlawful, but that the full disclosure of the deal allowed for "adequate signposting" of secret policies. In other words, by revealing and exposing the practice, it complied with human rights law.</p><p>This has been challenged by human rights groups, which have now elevated the case to the ECHR in Strasbourg. The hearing on Tuesday was overseen by the court's president Linos-Alexandre Sicilianos, and judges from European countries, including the UK's Tim Eicke.</p><p>"Our organisations exist to stand up for people and challenge abuse of power," <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/european-court-human-rights-hear-landmark-challenge-mass-surveillance" target="_blank">said</a> Martha Spurrier, director of Liberty, one of the groups challenging the UK government. "We work with whistleblowers, victims, lawyers, journalists, and campaigners around the world, so confidentiality and protection of our sources is vital."</p><p>"The UK government's vast, cross-border mass surveillance regime - which lets it access millions of people's communications every day - has made those protections meaningless. No country that deploys industrial-scale state surveillance has ever remained a rights-respecting democracy. We now look to the court to uphold our rights where our government has failed to do so."</p><p>In a separate challenge, Privacy International claimed last month that bodies charged with overseeing UK spy agencies <a href="https://www.itpro.com/it-legislation/29749/uk-oversight-bodies-were-not-aware-of-spies-data-sharing" target="_blank" data-original-url="https://www.itpro.com/it-legislation/29749/uk-oversight-bodies-were-not-aware-of-spies-data-sharing">didn't actually know that the agencies were allegedly sharing people's data with foreign counterparts</a>.</p><p>After lengthy submissions by legal teams from both sides in the ECHR on Tuesday, questions were then directed at the UK government, including asking: who monitors the facilities being used to intercept data; who is responsible for turning those facilities on or off; whether all communication services are under surveillance; and whether data stored in cloud services outside the UK should be considered external communications.</p><p>The UK government argued that existing codes, including the Code of Practice for intercepted communications, provide effective oversight of the bulk collection of data, while allowing security agencies to do their work without breaching human rights law. The UK maintains that bulk collection of data is "of critical importance" to ensure national security.</p><p>"Whilst privacy rights are, of course, of importance, and to be respected, the right to life and the safety of citizens is paramount," argued the government's legal representative. "The core problem at the heart of the applicant's case, is that they seek to conjure up, by reference to what we suggest are grossly inaccurate speculations presented as fact."</p><p>However, human rights groups argued that the bulk collection of data violates Article 8 of the European Convention on Human Rights, which guarantees the right to privacy, specifically because it is untargeted and disproportionate. They also argue that new technology has allowed the government to access even greater amounts of user data online.</p><p>The hearing lasted almost three hours before the panel retired to deliberate on the hearing. A ruling date for the case has not yet been made, although we will update the story once it has been confirmed.</p><p>Separately, Privacy International's challenge to the UK's bulk data collection practices <a href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" target="_blank" data-original-url="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">was escalated to the European Court of Justice by the Investigatory Powers Tribunal in September</a>, giving the court the final say over whether the UK's data collection is lawful or not. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/29903/uk-faces-challenges-to-bulk-spying-in-european-court-of-human-rights</link>
                                                                            <description>
                            <![CDATA[ Privacy groups argue bulk data collection breaches Article 8 in landmark court case ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fLbQZ1GB873iHTDbwfUhHq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xURWtqy7YSfEkVz8HMM4xL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Nov 2017 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xURWtqy7YSfEkVz8HMM4xL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Snooping]]></media:description>                                                            <media:text><![CDATA[Snooping]]></media:text>
                                <media:title type="plain"><![CDATA[Snooping]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xURWtqy7YSfEkVz8HMM4xL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Representatives from the UK government have appeared in front of the European Court of Human Rights (ECHR) this week after a coalition of civil rights groups brought a challenge to the policy of bulk data collection by security agencies.</p><p>Amnesty International, Big Brother Watch, Liberty, Privacy International, as well as 10 other human rights and journalistic groups in Europe, Africa and Asia sought to challenge the legality of the UK's mass surveillance and data collection, in a <a href="http://www.echr.coe.int/Pages/home.aspx?p=home" target="_blank">court hearing</a> that started on Tuesday in Strasbourg.</p><p>The group argues that the government policy allowing UK security agencies to intercept data, which NSA whistleblower Edward Snowden's revelations brought to light, is a breach of the European Convention on Human Rights.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" data-original-url="/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">Investigatory Powers Tribunal escalates lawsuit to the EU</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter" data-original-url="/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter">Liberty wins right to challenge Snooper’s Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" data-original-url="/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade</a></p></div></div><p>Three separate cases are now being brought against the UK government, namely Big Brother Watch and Others v. the United Kingdom, Bureau of Investigative Journalism and Alice Ross v. the United Kingdom, and 10 Human Rights Organisations and Others v. the United Kingdom. The hearing on Tuesday was only the initial part of the process, with an official ruling set to be made at a later stage.</p><p>In all three cases, the groups believe that due to the sensitive nature of the data they handle, their communications may have been intercepted by either the UK or US security agencies in the course of bulk data collection and data-sharing.</p><p>The practice of sharing data between agencies has been challenged by human rights groups in the past. In a <a href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" target="_blank" data-original-url="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">controversial ruling in 2016</a>, the Investigatory Powers Tribunal, which has jurisdiction over GCHQ, MI5 and MI6, ruled that the agreement between the UK's GCHQ and the US's NSA was unlawful, but that the full disclosure of the deal allowed for "adequate signposting" of secret policies. In other words, by revealing and exposing the practice, it complied with human rights law.</p><p>This has been challenged by human rights groups, which have now elevated the case to the ECHR in Strasbourg. The hearing on Tuesday was overseen by the court's president Linos-Alexandre Sicilianos, and judges from European countries, including the UK's Tim Eicke.</p><p>"Our organisations exist to stand up for people and challenge abuse of power," <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/european-court-human-rights-hear-landmark-challenge-mass-surveillance" target="_blank">said</a> Martha Spurrier, director of Liberty, one of the groups challenging the UK government. "We work with whistleblowers, victims, lawyers, journalists, and campaigners around the world, so confidentiality and protection of our sources is vital."</p><p>"The UK government's vast, cross-border mass surveillance regime - which lets it access millions of people's communications every day - has made those protections meaningless. No country that deploys industrial-scale state surveillance has ever remained a rights-respecting democracy. We now look to the court to uphold our rights where our government has failed to do so."</p><p>In a separate challenge, Privacy International claimed last month that bodies charged with overseeing UK spy agencies <a href="https://www.itpro.com/it-legislation/29749/uk-oversight-bodies-were-not-aware-of-spies-data-sharing" target="_blank" data-original-url="https://www.itpro.com/it-legislation/29749/uk-oversight-bodies-were-not-aware-of-spies-data-sharing">didn't actually know that the agencies were allegedly sharing people's data with foreign counterparts</a>.</p><p>After lengthy submissions by legal teams from both sides in the ECHR on Tuesday, questions were then directed at the UK government, including asking: who monitors the facilities being used to intercept data; who is responsible for turning those facilities on or off; whether all communication services are under surveillance; and whether data stored in cloud services outside the UK should be considered external communications.</p><p>The UK government argued that existing codes, including the Code of Practice for intercepted communications, provide effective oversight of the bulk collection of data, while allowing security agencies to do their work without breaching human rights law. The UK maintains that bulk collection of data is "of critical importance" to ensure national security.</p><p>"Whilst privacy rights are, of course, of importance, and to be respected, the right to life and the safety of citizens is paramount," argued the government's legal representative. "The core problem at the heart of the applicant's case, is that they seek to conjure up, by reference to what we suggest are grossly inaccurate speculations presented as fact."</p><p>However, human rights groups argued that the bulk collection of data violates Article 8 of the European Convention on Human Rights, which guarantees the right to privacy, specifically because it is untargeted and disproportionate. They also argue that new technology has allowed the government to access even greater amounts of user data online.</p><p>The hearing lasted almost three hours before the panel retired to deliberate on the hearing. A ruling date for the case has not yet been made, although we will update the story once it has been confirmed.</p><p>Separately, Privacy International's challenge to the UK's bulk data collection practices <a href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" target="_blank" data-original-url="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">was escalated to the European Court of Justice by the Investigatory Powers Tribunal in September</a>, giving the court the final say over whether the UK's data collection is lawful or not. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liberty wins right to challenge Snooper’s Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The High Court has granted human rights charity Liberty the green light to challenge the Investigatory Powers Act, also known as the Snooper's Charter.</p><p>Liberty will contest the mass collection of everybody's communications data and internet history, which it believes breaches British people's rights.</p><p>The act compels telcos and ISPs to retain and hand over logs of everybody's emails, phone calls, texts and entire web browsing history to state agencies to store, data-mine and profile at will.</p><p>The European Court of Justice issued a <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/government-breaking-law-collecting-everyones-internet-and-call" target="_blank">judgement</a> last December in a separate case brought by Tom Watson MP, represented by Liberty lawyers. It ruled that the same powers in the Data Retention and Investigatory Powers Act (DRIPA) the previous law governing UK state surveillance were unlawful. Liberty launched its challenge in the wake of this decision.</p><p>While the act received Parliament's approval last year, Liberty contends that the government failed to provide evidence that surveillance of everybody in the UK was lawful or necessary. It added that whistleblowers and experts warned that the powers would make it more difficult for security services to do their jobs effectively.</p><p>Martha Spurrier, director of Liberty, today said the organisation was "delighted" to have been granted permission to challenge the law.</p><p>"It's become clearer than ever in recent months that this law is not fit for purpose. The government doesn't need to spy on the entire population to fight terrorism. All that does is undermine the very rights, freedoms and democracy terrorists seek to destroy," she said. </p><p>"And as increasingly frequent hacking attacks bring businesses and public bodies to their knees, our government's obsession with storing vast amounts of sensitive information about every single one of us looks dangerously irresponsible."</p><p>The human rights organisation can also apply for a cost-capping order, which, if granted, the case will be listed for a full hearing in due course. The High Court has also allowed Liberty to seek permission to challenge three other parts of the Act once the government publishes further codes of practice, or by March 2018 at the latest.</p><p>Its challenge is being crowdfunded via CrowdJustice, raising more than 50,000 from the public in less than a week in January to exceed an initial target of 10,000.</p><p>Over 200,000 people signed a petition calling for the repeal of the Investigatory Powers Act after it became law late last year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate" data-original-url="/it-legislation/27661/investigatory-powers-bill-petition-forces-debate">Investigatory Powers Bill petition forces debate</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/28973/liberty-wins-right-to-challenge-snooper-s-charter</link>
                                                                            <description>
                            <![CDATA[ Campaign group's crowdfunded challenge gets High Court go-ahead ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i894iufqQUD4YKCr4aEU5h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jun 2017 16:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Statue of a woman holding the scales of justice]]></media:description>                                                            <media:text><![CDATA[Statue of a woman holding the scales of justice]]></media:text>
                                <media:title type="plain"><![CDATA[Statue of a woman holding the scales of justice]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The High Court has granted human rights charity Liberty the green light to challenge the Investigatory Powers Act, also known as the Snooper's Charter.</p><p>Liberty will contest the mass collection of everybody's communications data and internet history, which it believes breaches British people's rights.</p><p>The act compels telcos and ISPs to retain and hand over logs of everybody's emails, phone calls, texts and entire web browsing history to state agencies to store, data-mine and profile at will.</p><p>The European Court of Justice issued a <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/government-breaking-law-collecting-everyones-internet-and-call" target="_blank">judgement</a> last December in a separate case brought by Tom Watson MP, represented by Liberty lawyers. It ruled that the same powers in the Data Retention and Investigatory Powers Act (DRIPA) the previous law governing UK state surveillance were unlawful. Liberty launched its challenge in the wake of this decision.</p><p>While the act received Parliament's approval last year, Liberty contends that the government failed to provide evidence that surveillance of everybody in the UK was lawful or necessary. It added that whistleblowers and experts warned that the powers would make it more difficult for security services to do their jobs effectively.</p><p>Martha Spurrier, director of Liberty, today said the organisation was "delighted" to have been granted permission to challenge the law.</p><p>"It's become clearer than ever in recent months that this law is not fit for purpose. The government doesn't need to spy on the entire population to fight terrorism. All that does is undermine the very rights, freedoms and democracy terrorists seek to destroy," she said. </p><p>"And as increasingly frequent hacking attacks bring businesses and public bodies to their knees, our government's obsession with storing vast amounts of sensitive information about every single one of us looks dangerously irresponsible."</p><p>The human rights organisation can also apply for a cost-capping order, which, if granted, the case will be listed for a full hearing in due course. The High Court has also allowed Liberty to seek permission to challenge three other parts of the Act once the government publishes further codes of practice, or by March 2018 at the latest.</p><p>Its challenge is being crowdfunded via CrowdJustice, raising more than 50,000 from the public in less than a week in January to exceed an initial target of 10,000.</p><p>Over 200,000 people signed a petition calling for the repeal of the Investigatory Powers Act after it became law late last year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate" data-original-url="/it-legislation/27661/investigatory-powers-bill-petition-forces-debate">Investigatory Powers Bill petition forces debate</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK government's draft spying powers get leaked online ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK government has drawn up details of its surveillance powers and put them out for a secretive consultation without letting the public know.</p><p>The government wants to give itself the ability to monitor British people's communications and force UK firms to include encryption backdoors in their products. Under the proposed Investigatory Powers (Technical Capability) Regulations 2017, telecoms providers must allow the government to simultaneously spy on one in 10,000 of their customers at any time.</p><p>Telcos would also have to provide any information the government requests within one working day, and must notify Home Secretary Amber Rudd if there will be any changes to their service, including the development of new services - these will have to be built with the obligations and requirements of the technical capability notice in mind.</p><p>Furthermore, telecoms providers must provide backdoors to encrypted data sitting in their services so that the government can access any communications. Telecoms providers must "remove electronic protection applied by or on behalf of the telecommunications operator to the communications or data".</p><p>The notice also extends to the postal service, where the government will have the power to "open, copy and reseal any postal item" in order to inspect its contents.</p><p>The Open Rights Group leaked the <a href="https://www.openrightsgroup.org/assets/files/pdfs/home_office/ANNEX_A_Draft_Investigatory_Powers_(Technical%20Capability)_Regulations.pdf" target="_blank">draft</a> yesterday on its <a href="https://www.openrightsgroup.org/ourwork/reports/home-office-consultation:-investigatory-powers-(technical-capability)-regulations-2017" target="_blank">website</a> and highlighted that the short four-week consultation had not been publicised to the tech industry or to the public. Under <a href="http://www.legislation.gov.uk/ukpga/2016/25/section/253" target="_blank">Section 253 (6) of the Investigatory Powers Act</a>, the Secretary of State is under no obligation to consult the public, but instead must consult a small selection of organisations likely to be affected by the proposals.</p><p>Concluding on 19 May, responses to the consultation can be sent to investigatorypowers@homeoffice.gsi.gov.uk.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/860168834300485633"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/860168834300485633"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>These measures have passed through a <a href="https://www.gov.uk/government/organisations/technical-advisory-board/about/membership" target="_blank">Technical Advisory Board</a> composed of six industry representatives from O2, BT, BSkyB, Cable and Wireless, Vodafone and Virgin Media, alongside six representatives from UK spy agencies and a neutral chair.</p><p>Open Rights Group's executive director, Jim Killock, said: "These powers could be directed at companies <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">like WhatsApp</a> to limit their encryption. The regulations would make the demands that Amber Rudd made to attack end-to-end encryption a reality. But if the powers are exercised, this will be done in secret.</p><p>"The public has a right to know about government powers that could put their privacy and security at risk. There needs to be transparency about how such measures are judged to be reasonable, the risks that are imposed on users and companies, and how companies can challenge government demands that are unreasonable. Selective, secret consultations have no place in open government."</p><p>The Investigatory Powers Act passed through Parliament <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">last November</a> despite facing strong opposition, and received Royal Assent soon after to become an act. However, large parts of it were struck down by the European Court of Justice in February over its <a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">bulk data collection plans.</a> It was thought then that the government would seek new ways to reinstate bulk data collection.</p><p><em>IT Pro</em> has approached the Home Office for comment.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Investigatory Powers 'will cost UK £1 billion'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28603/uk-governments-draft-spying-powers-get-leaked-online</link>
                                                                            <description>
                            <![CDATA[ Open Rights Group lifts curtain on Home Office's secretive consultation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tJzjFkbCR62XeQWVmxjNMd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 May 2017 11:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has drawn up details of its surveillance powers and put them out for a secretive consultation without letting the public know.</p><p>The government wants to give itself the ability to monitor British people's communications and force UK firms to include encryption backdoors in their products. Under the proposed Investigatory Powers (Technical Capability) Regulations 2017, telecoms providers must allow the government to simultaneously spy on one in 10,000 of their customers at any time.</p><p>Telcos would also have to provide any information the government requests within one working day, and must notify Home Secretary Amber Rudd if there will be any changes to their service, including the development of new services - these will have to be built with the obligations and requirements of the technical capability notice in mind.</p><p>Furthermore, telecoms providers must provide backdoors to encrypted data sitting in their services so that the government can access any communications. Telecoms providers must "remove electronic protection applied by or on behalf of the telecommunications operator to the communications or data".</p><p>The notice also extends to the postal service, where the government will have the power to "open, copy and reseal any postal item" in order to inspect its contents.</p><p>The Open Rights Group leaked the <a href="https://www.openrightsgroup.org/assets/files/pdfs/home_office/ANNEX_A_Draft_Investigatory_Powers_(Technical%20Capability)_Regulations.pdf" target="_blank">draft</a> yesterday on its <a href="https://www.openrightsgroup.org/ourwork/reports/home-office-consultation:-investigatory-powers-(technical-capability)-regulations-2017" target="_blank">website</a> and highlighted that the short four-week consultation had not been publicised to the tech industry or to the public. Under <a href="http://www.legislation.gov.uk/ukpga/2016/25/section/253" target="_blank">Section 253 (6) of the Investigatory Powers Act</a>, the Secretary of State is under no obligation to consult the public, but instead must consult a small selection of organisations likely to be affected by the proposals.</p><p>Concluding on 19 May, responses to the consultation can be sent to investigatorypowers@homeoffice.gsi.gov.uk.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/860168834300485633"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/860168834300485633"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>These measures have passed through a <a href="https://www.gov.uk/government/organisations/technical-advisory-board/about/membership" target="_blank">Technical Advisory Board</a> composed of six industry representatives from O2, BT, BSkyB, Cable and Wireless, Vodafone and Virgin Media, alongside six representatives from UK spy agencies and a neutral chair.</p><p>Open Rights Group's executive director, Jim Killock, said: "These powers could be directed at companies <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">like WhatsApp</a> to limit their encryption. The regulations would make the demands that Amber Rudd made to attack end-to-end encryption a reality. But if the powers are exercised, this will be done in secret.</p><p>"The public has a right to know about government powers that could put their privacy and security at risk. There needs to be transparency about how such measures are judged to be reasonable, the risks that are imposed on users and companies, and how companies can challenge government demands that are unreasonable. Selective, secret consultations have no place in open government."</p><p>The Investigatory Powers Act passed through Parliament <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">last November</a> despite facing strong opposition, and received Royal Assent soon after to become an act. However, large parts of it were struck down by the European Court of Justice in February over its <a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">bulk data collection plans.</a> It was thought then that the government would seek new ways to reinstate bulk data collection.</p><p><em>IT Pro</em> has approached the Home Office for comment.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Investigatory Powers 'will cost UK £1 billion'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The government needs to abandon its war on WhatsApp ]]></title>
                                                                                                <dc:content><![CDATA[ <p>It seems that encryption has been firmly established as the whipping boy <em>du jour</em> for pearl-clutching, public-safety panic merchants. Specifically, it's encrypted messaging services like WhatsApp and iMessage that have found themselves in the crosshairs.</p><p>Following last week's terror attack by the Houses of Parliament, it has emerged that the killer was communicating with someone via WhatsApp in the moments preceding his assault. It has been speculated although not confirmed that he may have been in contact with someone who conspired with him to plan the attack, although this afternoon the Met Police have said there's no evidence he was directed by Islamic State.</p><p>This has fuelled <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">fresh calls to severely weaken</a> or outright ban the use of encryption by such services to secure their messages, echoing last year's fierce debate over <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">whether or not Apple should hack the iPhone</a> of the San Bernardino killer. It's worth noting at this point that even though a third-party company did eventually hack into Syed Farook's phone, there is no indication that it offered any actionable intelligence.</p><p>Nevertheless, home secretary Amber Rudd and other Tory MPs are using this tragedy as an excuse to castigate and demonise encryption, with talk of coercing tech companies into installing backdoors into their code. It's not the first time the government has proposed this, either; it was <a href="https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=0ahUKEwjI4bTDkvfSAhViD8AKHf7wAaQQFgghMAE&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F23840%2Fwhatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds&usg=AFQjCNHAGYm0-jC2c91ZwBkAsT239KrU_g&sig2=Y1Gr3EnMau4ZnhnX0j7gBQ&bvm=bv.150729734,d.ZGg" target="_blank">included in early versions of the Snooper's Charter</a>, but was ultimately dropped from the bill.</p><p>Naturally, the idea of messing with encryption has got the tech sector up in arms. <a href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" target="_blank" data-original-url="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">Critics have called it "deeply misguided"</a> and other (less printable) things. Supporters of the plan say that spies need to be able to read the messages of terror suspects, but experts are queuing up to tell Rudd and the rest of the anti-crypto club that technology simply doesn't work that way.</p><p>In an exchange that would be funny if it weren't so deeply depressing, Conservative MP Nadine Dorries made the case that WhatsApp should "develop a terrorist related exception" to encryption technology - presumably this is some kind of Java-based magic wand that would allow GCHQ to hack only the baddies'.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846272022644711424"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846272022644711424"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This, along with Rudd's laughable quote that we need people who "understand the necessary hashtags", betrays a deep lack of technological knowledge throughout government. Of course, one would hope that the country's elected leaders have better things to do than immersing themselves in the finer points of C++ and Python, but on the other hand, having one of the country's top ministers saying things like "we don't want to go into the cloud" is embarrassing, especially when she clearly doesn't have the faintest idea what it means.</p><p>The experts are right, of course; if government spooks can read the WhatsApp messages of one terrorist, they can read the messages of everyone, from the 12-year-old at the bus stop all the way to the Pope. (This is assuming he doesn't use a rival app, of course - PopeChat, perhaps.)</p><p>This is troubling for a number of reasons, most notably from a privacy standpoint. Naturally, the public has been assured that they won't be covertly spied on by the intelligence services, who pinkie-promise that they'd only look at terrorists' communications. We're expected to take this on faith, but <a href="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says" target="_blank" data-original-url="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says">incidents like the Snowden leaks</a> suggest that perhaps the government's methods aren't always unimpeachable.</p><p>We've also got to consider what future governments could do with any anti-encryption laws. If an anti-democratic, fascistic party found itself in power, for example, these laws could be very easily used to identify and round up immigrants, LGBTQ people and other undesirables'. It's a lot easier to grant powers than it is take them away and this goes double when applied to governments.</p><p>Here's the thing, though: aside from the many legal, political and ethical issues with installing backdoors into services like WhatsApp, the biggest problem is practical. The fact is, there's simply no way to block the use of encryption on a technical level. Theresa May could force WhatsApp to stop encrypting its messages, but how long do you think it would take terrorists to simply switch to a different app?</p><p>Not only are there innumerable encrypted chat apps available for web and mobile devices, there's also plenty of free resources online to help you build your own, meaning that even an outright ban on encryption wouldn't work. If there's one thing you learn on the internet, it's that there's <em>always</em> a workaround.</p><p>Any steps to weaken the encryption of WhatsApp and other services would almost certainly do nothing to help fight terrorism. Instead, all it's likely to do is force terrorists to use even less visible means of communication, whilst simultaneously putting the safety and privacy of innocent people at risk.</p><p>Despite the repeated protestations of the security and technology communities, the government continues to revisit this stunningly ignorant and fundamentally flawed plan. Before it goes any further, you should know that Rudd and her cronies aren't just declaring war on WhatsApp - they're endangering your freedoms too.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" data-original-url="/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">“Deeply misguided”: tech industry rejects Rudd’s attack on encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28381/the-government-needs-to-abandon-its-war-on-whatsapp</link>
                                                                            <description>
                            <![CDATA[ Encryption might seem like an easy target, but mess with it at your peril ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6ubZNTbj5JJZTopSZR1uEt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Mar 2017 16:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It seems that encryption has been firmly established as the whipping boy <em>du jour</em> for pearl-clutching, public-safety panic merchants. Specifically, it's encrypted messaging services like WhatsApp and iMessage that have found themselves in the crosshairs.</p><p>Following last week's terror attack by the Houses of Parliament, it has emerged that the killer was communicating with someone via WhatsApp in the moments preceding his assault. It has been speculated although not confirmed that he may have been in contact with someone who conspired with him to plan the attack, although this afternoon the Met Police have said there's no evidence he was directed by Islamic State.</p><p>This has fuelled <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">fresh calls to severely weaken</a> or outright ban the use of encryption by such services to secure their messages, echoing last year's fierce debate over <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">whether or not Apple should hack the iPhone</a> of the San Bernardino killer. It's worth noting at this point that even though a third-party company did eventually hack into Syed Farook's phone, there is no indication that it offered any actionable intelligence.</p><p>Nevertheless, home secretary Amber Rudd and other Tory MPs are using this tragedy as an excuse to castigate and demonise encryption, with talk of coercing tech companies into installing backdoors into their code. It's not the first time the government has proposed this, either; it was <a href="https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=0ahUKEwjI4bTDkvfSAhViD8AKHf7wAaQQFgghMAE&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F23840%2Fwhatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds&usg=AFQjCNHAGYm0-jC2c91ZwBkAsT239KrU_g&sig2=Y1Gr3EnMau4ZnhnX0j7gBQ&bvm=bv.150729734,d.ZGg" target="_blank">included in early versions of the Snooper's Charter</a>, but was ultimately dropped from the bill.</p><p>Naturally, the idea of messing with encryption has got the tech sector up in arms. <a href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" target="_blank" data-original-url="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">Critics have called it "deeply misguided"</a> and other (less printable) things. Supporters of the plan say that spies need to be able to read the messages of terror suspects, but experts are queuing up to tell Rudd and the rest of the anti-crypto club that technology simply doesn't work that way.</p><p>In an exchange that would be funny if it weren't so deeply depressing, Conservative MP Nadine Dorries made the case that WhatsApp should "develop a terrorist related exception" to encryption technology - presumably this is some kind of Java-based magic wand that would allow GCHQ to hack only the baddies'.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846272022644711424"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846272022644711424"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This, along with Rudd's laughable quote that we need people who "understand the necessary hashtags", betrays a deep lack of technological knowledge throughout government. Of course, one would hope that the country's elected leaders have better things to do than immersing themselves in the finer points of C++ and Python, but on the other hand, having one of the country's top ministers saying things like "we don't want to go into the cloud" is embarrassing, especially when she clearly doesn't have the faintest idea what it means.</p><p>The experts are right, of course; if government spooks can read the WhatsApp messages of one terrorist, they can read the messages of everyone, from the 12-year-old at the bus stop all the way to the Pope. (This is assuming he doesn't use a rival app, of course - PopeChat, perhaps.)</p><p>This is troubling for a number of reasons, most notably from a privacy standpoint. Naturally, the public has been assured that they won't be covertly spied on by the intelligence services, who pinkie-promise that they'd only look at terrorists' communications. We're expected to take this on faith, but <a href="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says" target="_blank" data-original-url="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says">incidents like the Snowden leaks</a> suggest that perhaps the government's methods aren't always unimpeachable.</p><p>We've also got to consider what future governments could do with any anti-encryption laws. If an anti-democratic, fascistic party found itself in power, for example, these laws could be very easily used to identify and round up immigrants, LGBTQ people and other undesirables'. It's a lot easier to grant powers than it is take them away and this goes double when applied to governments.</p><p>Here's the thing, though: aside from the many legal, political and ethical issues with installing backdoors into services like WhatsApp, the biggest problem is practical. The fact is, there's simply no way to block the use of encryption on a technical level. Theresa May could force WhatsApp to stop encrypting its messages, but how long do you think it would take terrorists to simply switch to a different app?</p><p>Not only are there innumerable encrypted chat apps available for web and mobile devices, there's also plenty of free resources online to help you build your own, meaning that even an outright ban on encryption wouldn't work. If there's one thing you learn on the internet, it's that there's <em>always</em> a workaround.</p><p>Any steps to weaken the encryption of WhatsApp and other services would almost certainly do nothing to help fight terrorism. Instead, all it's likely to do is force terrorists to use even less visible means of communication, whilst simultaneously putting the safety and privacy of innocent people at risk.</p><p>Despite the repeated protestations of the security and technology communities, the government continues to revisit this stunningly ignorant and fundamentally flawed plan. Before it goes any further, you should know that Rudd and her cronies aren't just declaring war on WhatsApp - they're endangering your freedoms too.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" data-original-url="/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">“Deeply misguided”: tech industry rejects Rudd’s attack on encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ “Deeply misguided”: tech industry rejects Rudd’s attack on encryption ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Last week, Britain was shocked by a terror attack in Westminster that left five dead and 50 injured. When Home Secretary Amber Rudd appeared on The Andrew Marr Show to discuss the government's response to the tragedy, she had some strong words for encrypted messaging apps.</p><p>In particular, she said that <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">WhatsApp's use of end-to-end encryption was "completely unacceptable"</a>, and said that communications apps provide "a secret place for terrorists to communicate with each other". She also appeared to suggest that a spy-friendly backdoor into communication technologies would be a good thing, saying: "We have to have a situation where we can have our security services get into the terrorists' communications."</p><p>The immediate reaction to the Home Secretary's comments has been one of mockery, with various critics taking to social media to pour scorn on Rudd's apparent lack of technological understanding, taking particular issue with her assertion that the country needs people "who understand the necessary hashtags" in order to fight online terrorism.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/845920861806907392"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/845920861806907392"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846013777745195008"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846013777745195008"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Rudd has also been criticised for what some say is an overly simplistic view of encryption, and Wikipedia founder Jimmy Wales offered to explain the basics of encryption to her.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846251961280331776"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846251961280331776"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846264301610512385"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846264301610512385"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846283352256733184"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846283352256733184"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>However, many public figures and industry professionals, particularly within the cybersecurity field, have expressed genuine concerns over her statements. Some fear that the government could use this latest atrocity as an excuse to push through legislation that would cripple - or outright ban - encrypted communication, <a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">further damaging UK citizens' privacy</a>.</p><p>"These terrorists want to destroy our freedoms and undermine our democratic society," said Liberal Democrat shadow Home Secretary and former Deputy Assistant Commissioner in the Metropolitan Police, Brian Paddick. "By implementing draconian laws that limit our civil liberties, we would playing into their hands. Having the power to read everyone's text messages is neither a proportionate nor an effective response."</p><p>"These services have become mainstream since revelations of government mass surveillance came to light," argued F-Secure's Andy Patel. "As much as they provide a safe space for terrorists to communicate, they also help keep activists, journalists, and members of the general public safe from surveillance and government prosecution."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/845953706201927681"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/845953706201927681"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>There are also arguments that weakening encryption would actually put the UK at risk from cyber attacks. Open Rights Group executive director Jim Killock said: "Compelling companies to put backdoors into encrypted services would make millions of ordinary people less secure online. We all rely on encryption to protect our ability to communicate, shop and bank safely."</p><p>TechUK deputy CEO Antony Walker agreed, stating: "Encryption technologies are a fundamental tool for ensuring the UK remains cyber-secure. End-to-end encryption is the best defence we have available to keep the data and services we all rely on safe from misuse. From storing data on the cloud to online banking to identity verification, end-to-end encryption is essential for preventing data being accessed illegally in ways that can harm consumers, business and our national security."</p><p>In particular, concerns have been raised that these measures could make it easier for Britain to be hacked by agents of a foreign power, particularly given the current <a href="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack" target="_blank" data-original-url="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack">allegations of Russian hacking</a> looming over the US government. Sam Dumitriu, head of projects at thinktank the Adam Smith Institute, called the proposal "deeply misguided", and warned of the dangers of thinking that encryption can be weakened selectively.</p><p>"It is mathematically impossible to build a backdoor for just the good guys," he said. "It means building a backdoor to your private message for Putin's favourite hacker Guccifer. It means opening up your private photos to perverts like the iCloud hacker."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846031303787065345"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846031303787065345"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This is something that the government <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">has advocated before</a>. Prime Minister Theresa May was an outspoken opponent of encryption during her stint as Home Secretary, and her flagship Investigatory Powers Act (also called the Snooper's Charter) initially included similar provisions.</p><p>The tech industry at large has also taken exception to her implication that tech companies aren't doing enough to cooperate with the security services and stamp out terrorism on their platforms. "Tech companies take their responsibilities to work with the authorities on extremism and counter-terrorism investigations very seriously," Walker rebutted.</p><p>"Working within the strict confines of the law they engage daily in constructive and proven partnerships with security agencies, the police, policy makers and wider civil society bodies. Counter-terrorist operations would not succeed without the ongoing assistance and support of tech companies."</p><p>Killock also agreed that companies had a responsibility to help police with their investigations. "It is right that technology companies should help the police and intelligence agencies with investigations into specific crimes or terrorist activity, where possible," he said. "This help should be requested through warrants and the process should be properly regulated and monitored."</p><p>WhatsApp, for its part, has decried the attack, and pledged to work with the government. "We are horrified by the attack carried out in London earlier this week and are cooperating with law enforcement as they continue their investigations," a spokesperson for the company said.</p><p>Some are now nervously awaiting further privacy-impinging legislation from the Conservative Party, with questions still hanging over whether or not such a bill would actually prove effective. F-Secure's Patel claimed that even if WhatsApp abandons encryption, terrorists would simply find an alternative.</p><p>"If a service is forced to weaken, backdoor, or remove its encryption people will move to another one. While governments utilise technology to better track and monitor potential activist or terrorist activities, they shouldn't expect it to solve the root causes of these problems."</p><p>In the words of the shadow Home Secretary, "the real question is, could lives have been saved in London last week if end-to-end encryption had been banned? All the evidence suggests that the answer is no".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26305/whatsapp-announces-end-to-end-encryption" data-original-url="/security/26305/whatsapp-announces-end-to-end-encryption">WhatsApp announces end-to-end encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption</link>
                                                                            <description>
                            <![CDATA[ Experts warn that banning encryption leaves UK open to hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g7ctqudKUMDsHFkhdUJLVg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Mar 2017 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Last week, Britain was shocked by a terror attack in Westminster that left five dead and 50 injured. When Home Secretary Amber Rudd appeared on The Andrew Marr Show to discuss the government's response to the tragedy, she had some strong words for encrypted messaging apps.</p><p>In particular, she said that <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">WhatsApp's use of end-to-end encryption was "completely unacceptable"</a>, and said that communications apps provide "a secret place for terrorists to communicate with each other". She also appeared to suggest that a spy-friendly backdoor into communication technologies would be a good thing, saying: "We have to have a situation where we can have our security services get into the terrorists' communications."</p><p>The immediate reaction to the Home Secretary's comments has been one of mockery, with various critics taking to social media to pour scorn on Rudd's apparent lack of technological understanding, taking particular issue with her assertion that the country needs people "who understand the necessary hashtags" in order to fight online terrorism.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/845920861806907392"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/845920861806907392"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846013777745195008"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846013777745195008"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Rudd has also been criticised for what some say is an overly simplistic view of encryption, and Wikipedia founder Jimmy Wales offered to explain the basics of encryption to her.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846251961280331776"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846251961280331776"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846264301610512385"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846264301610512385"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846283352256733184"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846283352256733184"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>However, many public figures and industry professionals, particularly within the cybersecurity field, have expressed genuine concerns over her statements. Some fear that the government could use this latest atrocity as an excuse to push through legislation that would cripple - or outright ban - encrypted communication, <a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">further damaging UK citizens' privacy</a>.</p><p>"These terrorists want to destroy our freedoms and undermine our democratic society," said Liberal Democrat shadow Home Secretary and former Deputy Assistant Commissioner in the Metropolitan Police, Brian Paddick. "By implementing draconian laws that limit our civil liberties, we would playing into their hands. Having the power to read everyone's text messages is neither a proportionate nor an effective response."</p><p>"These services have become mainstream since revelations of government mass surveillance came to light," argued F-Secure's Andy Patel. "As much as they provide a safe space for terrorists to communicate, they also help keep activists, journalists, and members of the general public safe from surveillance and government prosecution."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/845953706201927681"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/845953706201927681"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>There are also arguments that weakening encryption would actually put the UK at risk from cyber attacks. Open Rights Group executive director Jim Killock said: "Compelling companies to put backdoors into encrypted services would make millions of ordinary people less secure online. We all rely on encryption to protect our ability to communicate, shop and bank safely."</p><p>TechUK deputy CEO Antony Walker agreed, stating: "Encryption technologies are a fundamental tool for ensuring the UK remains cyber-secure. End-to-end encryption is the best defence we have available to keep the data and services we all rely on safe from misuse. From storing data on the cloud to online banking to identity verification, end-to-end encryption is essential for preventing data being accessed illegally in ways that can harm consumers, business and our national security."</p><p>In particular, concerns have been raised that these measures could make it easier for Britain to be hacked by agents of a foreign power, particularly given the current <a href="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack" target="_blank" data-original-url="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack">allegations of Russian hacking</a> looming over the US government. Sam Dumitriu, head of projects at thinktank the Adam Smith Institute, called the proposal "deeply misguided", and warned of the dangers of thinking that encryption can be weakened selectively.</p><p>"It is mathematically impossible to build a backdoor for just the good guys," he said. "It means building a backdoor to your private message for Putin's favourite hacker Guccifer. It means opening up your private photos to perverts like the iCloud hacker."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/846031303787065345"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846031303787065345"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This is something that the government <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">has advocated before</a>. Prime Minister Theresa May was an outspoken opponent of encryption during her stint as Home Secretary, and her flagship Investigatory Powers Act (also called the Snooper's Charter) initially included similar provisions.</p><p>The tech industry at large has also taken exception to her implication that tech companies aren't doing enough to cooperate with the security services and stamp out terrorism on their platforms. "Tech companies take their responsibilities to work with the authorities on extremism and counter-terrorism investigations very seriously," Walker rebutted.</p><p>"Working within the strict confines of the law they engage daily in constructive and proven partnerships with security agencies, the police, policy makers and wider civil society bodies. Counter-terrorist operations would not succeed without the ongoing assistance and support of tech companies."</p><p>Killock also agreed that companies had a responsibility to help police with their investigations. "It is right that technology companies should help the police and intelligence agencies with investigations into specific crimes or terrorist activity, where possible," he said. "This help should be requested through warrants and the process should be properly regulated and monitored."</p><p>WhatsApp, for its part, has decried the attack, and pledged to work with the government. "We are horrified by the attack carried out in London earlier this week and are cooperating with law enforcement as they continue their investigations," a spokesperson for the company said.</p><p>Some are now nervously awaiting further privacy-impinging legislation from the Conservative Party, with questions still hanging over whether or not such a bill would actually prove effective. F-Secure's Patel claimed that even if WhatsApp abandons encryption, terrorists would simply find an alternative.</p><p>"If a service is forced to weaken, backdoor, or remove its encryption people will move to another one. While governments utilise technology to better track and monitor potential activist or terrorist activities, they shouldn't expect it to solve the root causes of these problems."</p><p>In the words of the shadow Home Secretary, "the real question is, could lives have been saved in London last week if end-to-end encryption had been banned? All the evidence suggests that the answer is no".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26305/whatsapp-announces-end-to-end-encryption" data-original-url="/security/26305/whatsapp-announces-end-to-end-encryption">WhatsApp announces end-to-end encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The fight against the Investigatory Powers Bill isn't over yet ]]></title>
                                                                                                <dc:content><![CDATA[ <p><strong>Update:</strong> it would appear that Theresa May et al's grasping hands may be kept away from our personal data after all. The Investigatory Powers bill has been struck down - sadly not by public outcry and concerted demonstrations that reinforced the country's resistance to dystopian state surveillance, but by the European Court of Justice.</p><p>The court ruled that the bulk data collection outlined by the Snooper's Charter in all cases other than when it was specifically related to "serious crime". Although it told <a href="https://arstechnica.co.uk/tech-policy/2017/02/investigatory-powers-law-missing-draft-communications-data-code" target="_blank"><em>Ars Technica</em></a> it has some ominously vague backup plans in place, the Home office has nevertheless confirmed that it has put the plan on hold, for now.</p><p>Privacy campaigners should not be resting on their laurels just yet, though. The government is likely to be exploring other options in order to reinstate bulk data collection. Worryingly, the political climate has now become so chaotic that any future versions run the risk of passing with even less scrutiny than the original.</p><p>The ECJ's decision is a heartening one for those of us who don't wish to surrender our online identities to the security services but, make no mistake, this fight is far from over.</p><p>---</p><p>Do you like to be watched?</p><p>If the answer is no, I've got some bad news for you. The Investigatory Powers Bill - commonly known as the Snooper's Charter - has been passed by Parliament, meaning the government now has the power to examine and dissect virtually every element of your online life.</p><p>Although privacy campaigners and most of the security industry have been up in arms about the Snooper's Charter, it has met largely with apathy from the general public. That's understandable; mass surveillance is a difficult concept to fully wrap one's head around, mainly due to the sheer size of it.</p><p>It's virtually impossible to comprehend this kind of issue without putting it in some kind of context. When John Oliver interviewed whistleblower Edward Snowden about similar US surveillance programmes, he used the analogy of whether or not the government was able to spy on people's "dick pics". I'll attempt to employ a similar, if less crude, analogy here.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/XEVlyP4_11M" allowfullscreen></iframe></div></div><p>Let's say, for example, that you decide to visit a porn website. Under the new laws, the government will be able to see:</p><ul><li>Which site you visited</li><li>What time you visited it</li><li>What kind of device you visited it from</li><li>Which browser or app you used to visit it</li><li>Your physical location when you visited it</li></ul><p>The same goes for any app that uses the internet. Made a Skype call? Government agents will be able to tell who you called, from where, for how long and much more. They can tell when you upload photos to iCloud, and when you open up Instagram. The only limit, an admittedly sizeable one, is that they can't directly read what you said or wrote.</p><p>We've all deleted our internet history at one point or another, but once these laws come into effect, your internet provider - as well as the provider of any communications service like WhatsApp, Snapchat, and Facebook - will have to store your entire history for a full year.</p><p>Another element of the incoming law now gives the government the right to hack into your devices. That means they can break into your laptop, tablet or smartphone, go through the data stored on it, or even install keylogger software that can tell them exactly what you're typing, as you're typing it.</p><p>While many (although not all) of the powers outlined in the act require a warrant, many people have raised questions about this process. For example, in order to access your internet connection records, most government bodies only need approval from an internal officer within the department, rather than a judge.</p><p>In order to hack your computer or phone, a warrant must be issued by a senior official - a chief constable in the case of the police, or a Secretary of State in the case of spy agencies - and then approved by a special judge. But that judge will be legally compelled to approve warrants in all but the most extremely unreasonable of circumstances.</p><p>One of the most common arguments is that the end justifies the means, and that this is a small price to pay for fighting terrorism. But what about fighting unpaid parking tickets? In order to access your internet records, agencies must show that they've got a good reason, but while the government lists issues of national security and public safety as acceptable reasons, it also says that public bodies can look at your internet history for the purposes of collecting taxes, duties, or any other financial contribution owed to the government. It can also look at your data in order to serve "the regulation of financial services and markets".</p><p>There's an argument that says if you've got nothing to hide, then you've got nothing to fear. The problem with that is, it's frighteningly easy for governments to move the goalposts, and the definition of 'something to hide' can change overnight. For example, a part of the Digital Economy Bill, currently being looked at by Parliament, would <a href="https://www.theguardian.com/technology/2016/nov/23/censor-non-conventional-sex-acts-online-internet-pornography" target="_blank">ban any websites showing videos of 'non-conventional' sex acts</a> - including spanking and female ejaculation.</p><p>If the government decided not only to ban this kind of content, but also to make viewing it a criminal offence, it would already have all the tools it needed to track down and arrest you in minutes - all for watching a bit of slap and tickle.</p><p>Systems like this are notoriously vulnerable to abuse, too. Not only would the agencies themselves have to trust that none of their employees will exploit their access to a vast and comprehensive database of their friends and families' secrets, they would also have to protect against the legions of hackers that would love nothing better than to get access to the entire country's internet records.</p><p>This is something that has proven notoriously difficult for them in the past; <a href="https://www.itpro.com/data-protection/27635/two-thirds-of-london-councils-have-suffered-data-breaches" target="_blank" data-original-url="https://www.itpro.com/data-protection/27635/two-thirds-of-london-councils-have-suffered-data-breaches">two-thirds of London councils have suffered data breaches in the last four years</a>, while in the last five years, <a href="https://www.itpro.com/data-leakage/26853/police-suffer-2315-data-breaches-in-five-years" target="_blank" data-original-url="https://www.itpro.com/data-leakage/26853/police-suffer-2315-data-breaches-in-five-years">the police have had more than 2,300</a>. This is not particularly encouraging when the government is essentially discussing creating a centralised database of all of our internet activity.</p><p>Theresa May is hoping that this bill will pass unnoticed into law; that you will be too busy worrying about Brexit, and Trump, and your own personal stresses to care about the monolithic and terrifying surveillance apparatus that is being assembled around you.</p><p>We don't have to let that happen. It may be too late to stop this bill from being passed, but it is not too late to show this government that we will not consent to having our every action monitored, our every movement filed and our every conversation logged.</p><p>If you believe that privacy is not a luxury, and that the government's surveillance powers can and should be tempered in a democracy, there are ways to fight back. <a href="http://www.cloudpro.co.uk/it-infrastructure/security/5663/best-vpn-services-for-2016-1" target="_blank">Use a VPN</a>. Donate to privacy groups. Write to your MPs and elected officials. Protest.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet</link>
                                                                            <description>
                            <![CDATA[ The Snooper's Charter may have been struck down - but it will be back ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iXQQAutQjAtofKChLDGdfc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Feb 2017 17:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>Update:</strong> it would appear that Theresa May et al's grasping hands may be kept away from our personal data after all. The Investigatory Powers bill has been struck down - sadly not by public outcry and concerted demonstrations that reinforced the country's resistance to dystopian state surveillance, but by the European Court of Justice.</p><p>The court ruled that the bulk data collection outlined by the Snooper's Charter in all cases other than when it was specifically related to "serious crime". Although it told <a href="https://arstechnica.co.uk/tech-policy/2017/02/investigatory-powers-law-missing-draft-communications-data-code" target="_blank"><em>Ars Technica</em></a> it has some ominously vague backup plans in place, the Home office has nevertheless confirmed that it has put the plan on hold, for now.</p><p>Privacy campaigners should not be resting on their laurels just yet, though. The government is likely to be exploring other options in order to reinstate bulk data collection. Worryingly, the political climate has now become so chaotic that any future versions run the risk of passing with even less scrutiny than the original.</p><p>The ECJ's decision is a heartening one for those of us who don't wish to surrender our online identities to the security services but, make no mistake, this fight is far from over.</p><p>---</p><p>Do you like to be watched?</p><p>If the answer is no, I've got some bad news for you. The Investigatory Powers Bill - commonly known as the Snooper's Charter - has been passed by Parliament, meaning the government now has the power to examine and dissect virtually every element of your online life.</p><p>Although privacy campaigners and most of the security industry have been up in arms about the Snooper's Charter, it has met largely with apathy from the general public. That's understandable; mass surveillance is a difficult concept to fully wrap one's head around, mainly due to the sheer size of it.</p><p>It's virtually impossible to comprehend this kind of issue without putting it in some kind of context. When John Oliver interviewed whistleblower Edward Snowden about similar US surveillance programmes, he used the analogy of whether or not the government was able to spy on people's "dick pics". I'll attempt to employ a similar, if less crude, analogy here.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/XEVlyP4_11M" allowfullscreen></iframe></div></div><p>Let's say, for example, that you decide to visit a porn website. Under the new laws, the government will be able to see:</p><ul><li>Which site you visited</li><li>What time you visited it</li><li>What kind of device you visited it from</li><li>Which browser or app you used to visit it</li><li>Your physical location when you visited it</li></ul><p>The same goes for any app that uses the internet. Made a Skype call? Government agents will be able to tell who you called, from where, for how long and much more. They can tell when you upload photos to iCloud, and when you open up Instagram. The only limit, an admittedly sizeable one, is that they can't directly read what you said or wrote.</p><p>We've all deleted our internet history at one point or another, but once these laws come into effect, your internet provider - as well as the provider of any communications service like WhatsApp, Snapchat, and Facebook - will have to store your entire history for a full year.</p><p>Another element of the incoming law now gives the government the right to hack into your devices. That means they can break into your laptop, tablet or smartphone, go through the data stored on it, or even install keylogger software that can tell them exactly what you're typing, as you're typing it.</p><p>While many (although not all) of the powers outlined in the act require a warrant, many people have raised questions about this process. For example, in order to access your internet connection records, most government bodies only need approval from an internal officer within the department, rather than a judge.</p><p>In order to hack your computer or phone, a warrant must be issued by a senior official - a chief constable in the case of the police, or a Secretary of State in the case of spy agencies - and then approved by a special judge. But that judge will be legally compelled to approve warrants in all but the most extremely unreasonable of circumstances.</p><p>One of the most common arguments is that the end justifies the means, and that this is a small price to pay for fighting terrorism. But what about fighting unpaid parking tickets? In order to access your internet records, agencies must show that they've got a good reason, but while the government lists issues of national security and public safety as acceptable reasons, it also says that public bodies can look at your internet history for the purposes of collecting taxes, duties, or any other financial contribution owed to the government. It can also look at your data in order to serve "the regulation of financial services and markets".</p><p>There's an argument that says if you've got nothing to hide, then you've got nothing to fear. The problem with that is, it's frighteningly easy for governments to move the goalposts, and the definition of 'something to hide' can change overnight. For example, a part of the Digital Economy Bill, currently being looked at by Parliament, would <a href="https://www.theguardian.com/technology/2016/nov/23/censor-non-conventional-sex-acts-online-internet-pornography" target="_blank">ban any websites showing videos of 'non-conventional' sex acts</a> - including spanking and female ejaculation.</p><p>If the government decided not only to ban this kind of content, but also to make viewing it a criminal offence, it would already have all the tools it needed to track down and arrest you in minutes - all for watching a bit of slap and tickle.</p><p>Systems like this are notoriously vulnerable to abuse, too. Not only would the agencies themselves have to trust that none of their employees will exploit their access to a vast and comprehensive database of their friends and families' secrets, they would also have to protect against the legions of hackers that would love nothing better than to get access to the entire country's internet records.</p><p>This is something that has proven notoriously difficult for them in the past; <a href="https://www.itpro.com/data-protection/27635/two-thirds-of-london-councils-have-suffered-data-breaches" target="_blank" data-original-url="https://www.itpro.com/data-protection/27635/two-thirds-of-london-councils-have-suffered-data-breaches">two-thirds of London councils have suffered data breaches in the last four years</a>, while in the last five years, <a href="https://www.itpro.com/data-leakage/26853/police-suffer-2315-data-breaches-in-five-years" target="_blank" data-original-url="https://www.itpro.com/data-leakage/26853/police-suffer-2315-data-breaches-in-five-years">the police have had more than 2,300</a>. This is not particularly encouraging when the government is essentially discussing creating a centralised database of all of our internet activity.</p><p>Theresa May is hoping that this bill will pass unnoticed into law; that you will be too busy worrying about Brexit, and Trump, and your own personal stresses to care about the monolithic and terrifying surveillance apparatus that is being assembled around you.</p><p>We don't have to let that happen. It may be too late to stop this bill from being passed, but it is not too late to show this government that we will not consent to having our every action monitored, our every movement filed and our every conversation logged.</p><p>If you believe that privacy is not a luxury, and that the government's surveillance powers can and should be tempered in a democracy, there are ways to fight back. <a href="http://www.cloudpro.co.uk/it-infrastructure/security/5663/best-vpn-services-for-2016-1" target="_blank">Use a VPN</a>. Donate to privacy groups. Write to your MPs and elected officials. Protest.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liberty hits crowdfunding goal to take on Snooper's Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Civil rights group Liberty has launched a crowdfunding campaign to take on the government's Snooper Charter, saying it's against our basic human rights to be monitored on such a large scale.</p><p>The organisation is seeking to challenge the law in the High Court and is inviting the public to support the action by donating money to the campaign using the CrowdJustice platform. With a month to go before the fund-raising initiative ends, it has already hit its 40,000 target, reaching 40,162 at the time of writing.</p><p>The Snooper's Charter, formally known as the Investigatory Powers Act (IPA), was devised by Theresa May while she was still Home Secretary and will allow the government to access web history and email, text and phone records. Liberty's appeal describes these powers as the ability to "hack computers, phones and tablets on an industrial scale".</p><p>"Last year, this Government exploited fear and distraction to quietly create the most extreme surveillance regime of any democracy in history," Martha Spurrier, director of Liberty, said. "Hundreds of thousands of people have since called for this Act's repeal because they see it for what it is an unprecedented, unjustified assault on our freedom."</p><p>Although the IPA gained Royal Assent in November last year and came into force at the end of December, Liberty is seeking to have it repealed, claiming it's unlawful and puts UK citizens' basic human rights at risk.</p><p>"We hope anybody with an interest in defending our democracy, privacy, press freedom, fair trials, protest rights, free speech and the safety and cybersecurity of everyone in the UK will support this crowdfunded challenge, and make 2017 the year we reclaim our rights," Spurrier added.</p><p>Liberty's campaign comes just a few weeks after the European Court of Justice upheld a legal challenge brought by Conservative MP David Davis and Labour MP Tom Watson, which claimed the Data Retention and Investigatory Powers Act the IPA's predecessor broke the law by indiscriminately collecting and analysing citizens' internet activity and phone records. That case has now reterned to the UK court of appeal.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter" data-original-url="/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter">House of Lords hits out at Snooper's Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/27900/liberty-hits-crowdfunding-goal-to-take-on-snoopers-charter</link>
                                                                            <description>
                            <![CDATA[ Campaign group raises £40,000 to finance legal challenge against the government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s2MFXk1tWepXw4cbSayA9w</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Jan 2017 09:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Civil rights group Liberty has launched a crowdfunding campaign to take on the government's Snooper Charter, saying it's against our basic human rights to be monitored on such a large scale.</p><p>The organisation is seeking to challenge the law in the High Court and is inviting the public to support the action by donating money to the campaign using the CrowdJustice platform. With a month to go before the fund-raising initiative ends, it has already hit its 40,000 target, reaching 40,162 at the time of writing.</p><p>The Snooper's Charter, formally known as the Investigatory Powers Act (IPA), was devised by Theresa May while she was still Home Secretary and will allow the government to access web history and email, text and phone records. Liberty's appeal describes these powers as the ability to "hack computers, phones and tablets on an industrial scale".</p><p>"Last year, this Government exploited fear and distraction to quietly create the most extreme surveillance regime of any democracy in history," Martha Spurrier, director of Liberty, said. "Hundreds of thousands of people have since called for this Act's repeal because they see it for what it is an unprecedented, unjustified assault on our freedom."</p><p>Although the IPA gained Royal Assent in November last year and came into force at the end of December, Liberty is seeking to have it repealed, claiming it's unlawful and puts UK citizens' basic human rights at risk.</p><p>"We hope anybody with an interest in defending our democracy, privacy, press freedom, fair trials, protest rights, free speech and the safety and cybersecurity of everyone in the UK will support this crowdfunded challenge, and make 2017 the year we reclaim our rights," Spurrier added.</p><p>Liberty's campaign comes just a few weeks after the European Court of Justice upheld a legal challenge brought by Conservative MP David Davis and Labour MP Tom Watson, which claimed the Data Retention and Investigatory Powers Act the IPA's predecessor broke the law by indiscriminately collecting and analysing citizens' internet activity and phone records. That case has now reterned to the UK court of appeal.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter" data-original-url="/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter">House of Lords hits out at Snooper's Charter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blow for Snoopers Charter as EU court bans mass data collection ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Snoopers Charter has a had a major setback with a court ruling saying that mass collection of emails and other communications data is illegal.</p><p>Last year, MP David Davis and MP Tom Watson -- respectively of the Conservatives and Labour -- brought a legal challenge regarding mass collection of data against the Data Retention and Investigatory Powers Act (DRIPA), which is set to expire at the end of the year and be replaced by the Investigatory Powers Act.</p><p>The duo won a <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">high court challenge against DRIPA</a>, but that was appealed by the government, leading the case to head to European courts. In the meantime, the government hurried to write a new law, ahead of the end-of-year sunset clause on DRIPA. Davis has since withdrawn from the case after being named Brexit minister.</p><p>That law was the Investigatory Power Act (IPA) -- commonly referred to as the Snoopers Charter -- that was <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">waved through parliament by the Tories and Labour last month</a>. The new laws included provisions requiring all communications firms to keep records of so-called metadata -- who we talk to online and when -- as well as a year of browsing history.</p><p>The European Court of Justice (CJEU) has ruled on the issue of bulk data collection in DRIPA, saying "general and indiscriminate retention" of such data is illegal, and traffic and location data can only be collected in a targeted manner to fight serious crime.</p><p>That ruling is bad news for the newly passed law. "The CJEU has sent a clear message to the UK Government: blanket surveillance of our communications is intrusive and unacceptable in a democracy," ORG executive director Jim Killock said. "The Government knew this judgment was coming but Theresa May was determined to push through her snoopers' charter regardless. The Government must act quickly to re-write the IPA or be prepared to go to court again."</p><p>The ruling highlights issues around the blanket collection of data, pointing out that the retained data is "liable to allow very precise conclusions to be drawn concerning the private lives of the persons whose data has been retained."</p><p>The judges conclude that fighting serious crime is the only justification for collecting such invasive data, saying "legislation prescribing a general and indiscriminate retention of data does not require there to be any relationship between the data which must be retained and a threat to public security."</p><p>"Such national legislation, therefore, exceeds the limits of what is strictly necessary and cannot be considered to be justified within a democratic society, as required by the directive, read in the light of the charter," the summary of the judgement reads.</p><p><strong>Ruling response</strong></p><p>Liberal Democrat Shadow Home Secretary Brian Paddick said: "This ruling proves that this Conservative Government has overstepped the mark. The legality of the Investigatory Powers Act - passed into law with Labour's full support - has now been called into question."</p><p>He added: "This dreadful piece of legislation will cost millions to implement and unless the Government reconsider, they will inevitably face further embarrassment in the courts."</p><p>A Home Office spokesperson said: "We are disappointed with the judgment from the European Court of Justice and will be considering its potential implications."</p><p>"It will now be for the court of appeal to determine the case. The government will be putting forward robust arguments to the court of appeal about the strength of our existing regime for communications data retention and access."</p><p>"Given the importance of communications data to preventing and detecting crime, we will ensure plans are in place so that the police and other public authorities can continue to acquire such data in a way that is consistent with EU law and our obligation to protect the public."</p><p>The MPs' legal challenge was backed by the Law Society, Liberty, Open Rights Group and Privacy International. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/snoopers-charter/27819/blow-for-snoopers-charter-as-eu-court-bans-mass-data-collection</link>
                                                                            <description>
                            <![CDATA[ A legal challenge brought against DRIPA could take out its successor ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8tk3xfEkj1FchAAq7FvWRu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fWXWTwWDVPjvmpVFH8EmUP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Dec 2016 11:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fWXWTwWDVPjvmpVFH8EmUP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fWXWTwWDVPjvmpVFH8EmUP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Snoopers Charter has a had a major setback with a court ruling saying that mass collection of emails and other communications data is illegal.</p><p>Last year, MP David Davis and MP Tom Watson -- respectively of the Conservatives and Labour -- brought a legal challenge regarding mass collection of data against the Data Retention and Investigatory Powers Act (DRIPA), which is set to expire at the end of the year and be replaced by the Investigatory Powers Act.</p><p>The duo won a <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">high court challenge against DRIPA</a>, but that was appealed by the government, leading the case to head to European courts. In the meantime, the government hurried to write a new law, ahead of the end-of-year sunset clause on DRIPA. Davis has since withdrawn from the case after being named Brexit minister.</p><p>That law was the Investigatory Power Act (IPA) -- commonly referred to as the Snoopers Charter -- that was <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">waved through parliament by the Tories and Labour last month</a>. The new laws included provisions requiring all communications firms to keep records of so-called metadata -- who we talk to online and when -- as well as a year of browsing history.</p><p>The European Court of Justice (CJEU) has ruled on the issue of bulk data collection in DRIPA, saying "general and indiscriminate retention" of such data is illegal, and traffic and location data can only be collected in a targeted manner to fight serious crime.</p><p>That ruling is bad news for the newly passed law. "The CJEU has sent a clear message to the UK Government: blanket surveillance of our communications is intrusive and unacceptable in a democracy," ORG executive director Jim Killock said. "The Government knew this judgment was coming but Theresa May was determined to push through her snoopers' charter regardless. The Government must act quickly to re-write the IPA or be prepared to go to court again."</p><p>The ruling highlights issues around the blanket collection of data, pointing out that the retained data is "liable to allow very precise conclusions to be drawn concerning the private lives of the persons whose data has been retained."</p><p>The judges conclude that fighting serious crime is the only justification for collecting such invasive data, saying "legislation prescribing a general and indiscriminate retention of data does not require there to be any relationship between the data which must be retained and a threat to public security."</p><p>"Such national legislation, therefore, exceeds the limits of what is strictly necessary and cannot be considered to be justified within a democratic society, as required by the directive, read in the light of the charter," the summary of the judgement reads.</p><p><strong>Ruling response</strong></p><p>Liberal Democrat Shadow Home Secretary Brian Paddick said: "This ruling proves that this Conservative Government has overstepped the mark. The legality of the Investigatory Powers Act - passed into law with Labour's full support - has now been called into question."</p><p>He added: "This dreadful piece of legislation will cost millions to implement and unless the Government reconsider, they will inevitably face further embarrassment in the courts."</p><p>A Home Office spokesperson said: "We are disappointed with the judgment from the European Court of Justice and will be considering its potential implications."</p><p>"It will now be for the court of appeal to determine the case. The government will be putting forward robust arguments to the court of appeal about the strength of our existing regime for communications data retention and access."</p><p>"Given the importance of communications data to preventing and detecting crime, we will ensure plans are in place so that the police and other public authorities can continue to acquire such data in a way that is consistent with EU law and our obligation to protect the public."</p><p>The MPs' legal challenge was backed by the Law Society, Liberty, Open Rights Group and Privacy International. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Porn site xHamster protests Snooper's Charter a week too late ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Porn site xHamster is appealing to users to sign a petition against theso-called Snooper's Charter,<a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">the Investigatory Powers Act</a>that will see communications providers forced to keep records of which websites Brits visit - something viewers of adult content may prefer their ISPs not to track.</p><p>The pop-up message comes a little late, however. The <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill has already been signed into law</a>, gaining Royal Assent on 29 November, and the petition itself long ago topped the <a href="https://petition.parliament.uk/petitions/173199" target="_blank">100,000 mark that triggers a response from the government</a>.</p><p>That response was a refusal for another debate on the issue, pointing out that "the Investigatory Powers Bill was debated on many occasions in Parliament before it became law".</p><p>A more detailed response claims that the Snooper's Charter was "subject to unprecedented scrutiny" and brings in necessary powers for security services, and includes privacy protections - a fact digital rights campaigners dispute.</p><p>"The IP Bill was debated and passed while the public, media and politicians were preoccupied by Brexit," Open Rights Group executive director Jim Killock told <em>IT Pro</em>when the <a href="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate">100,000 signature mark was passed last month</a>.</p><p>If you still want to sign the epetition - without visiting the adult site - you <a href="https://petition.parliament.uk/petitions/173199" target="_blank">can do so here</a>.</p><p>While xHamster's political posturing may be misspent in this instance, there's another target it can aim for: the Digital Economy Bill and its requirement that pornographic sites run age verification checks <a href="https://www.itpro.com/business/policy-and-legislation" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27683/digital-economy-bill-moves-to-the-house-of-lords">or risk being blocked across UK networks</a>. That will mean adult sites know the real identity of those visiting it, a honey pot which may well attract hackers looking for blackmail material similar to <a href="https://www.itpro.com/data-leakage/25003/ashley-madison-hack-steals-37-million-cheaters-details" target="_blank" data-original-url="https://www.itpro.com/data-leakage/25003/ashley-madison-hack-steals-37-million-cheaters-details">the Ashley Madison affair</a>.</p><p>The Digital Economy Bill has been waved through the House of Commons without argument from Labour, but now faces the House of Lords, which has previously raised concerns about it. The second reading in the House of Lords is 13 December, one of the last chances for digital campaigners and affected sites such as xHamster to attempt to stop it becoming law or force the government to build in safeguards.</p><p>Following the second reading, there will be a report and consideration of amendments, before it's signed into law via Royal Assent, expected to happen early next year.</p><p>A petition against <a href="https://petition.parliament.uk/petitions/174544" target="_blank">age verification on the government website has just 22 signatures so far</a>, though the anti-porn rules have <a href="http://metro.co.uk/2016/10/18/lingerie-clad-activists-want-you-to-know-about-a-law-that-will-change-the-way-you-watch-porn-6199990" target="_blank">already sparked protests</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Investigatory Powers 'will cost UK £1 billion'</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/digital-economy-bill/27756/porn-site-xhamster-protests-snoopers-charter-a-week-too</link>
                                                                            <description>
                            <![CDATA[ xHamster pushes visitors to sign anti-surveillance petition ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nggrtbonw1k232U4VcedEi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gjo9bKyzz24Lxpuh2BtHR8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Dec 2016 15:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gjo9bKyzz24Lxpuh2BtHR8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gjo9bKyzz24Lxpuh2BtHR8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Porn site xHamster is appealing to users to sign a petition against theso-called Snooper's Charter,<a href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" target="_blank" data-original-url="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">the Investigatory Powers Act</a>that will see communications providers forced to keep records of which websites Brits visit - something viewers of adult content may prefer their ISPs not to track.</p><p>The pop-up message comes a little late, however. The <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill has already been signed into law</a>, gaining Royal Assent on 29 November, and the petition itself long ago topped the <a href="https://petition.parliament.uk/petitions/173199" target="_blank">100,000 mark that triggers a response from the government</a>.</p><p>That response was a refusal for another debate on the issue, pointing out that "the Investigatory Powers Bill was debated on many occasions in Parliament before it became law".</p><p>A more detailed response claims that the Snooper's Charter was "subject to unprecedented scrutiny" and brings in necessary powers for security services, and includes privacy protections - a fact digital rights campaigners dispute.</p><p>"The IP Bill was debated and passed while the public, media and politicians were preoccupied by Brexit," Open Rights Group executive director Jim Killock told <em>IT Pro</em>when the <a href="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27661/investigatory-powers-bill-petition-forces-debate">100,000 signature mark was passed last month</a>.</p><p>If you still want to sign the epetition - without visiting the adult site - you <a href="https://petition.parliament.uk/petitions/173199" target="_blank">can do so here</a>.</p><p>While xHamster's political posturing may be misspent in this instance, there's another target it can aim for: the Digital Economy Bill and its requirement that pornographic sites run age verification checks <a href="https://www.itpro.com/business/policy-and-legislation" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27683/digital-economy-bill-moves-to-the-house-of-lords">or risk being blocked across UK networks</a>. That will mean adult sites know the real identity of those visiting it, a honey pot which may well attract hackers looking for blackmail material similar to <a href="https://www.itpro.com/data-leakage/25003/ashley-madison-hack-steals-37-million-cheaters-details" target="_blank" data-original-url="https://www.itpro.com/data-leakage/25003/ashley-madison-hack-steals-37-million-cheaters-details">the Ashley Madison affair</a>.</p><p>The Digital Economy Bill has been waved through the House of Commons without argument from Labour, but now faces the House of Lords, which has previously raised concerns about it. The second reading in the House of Lords is 13 December, one of the last chances for digital campaigners and affected sites such as xHamster to attempt to stop it becoming law or force the government to build in safeguards.</p><p>Following the second reading, there will be a report and consideration of amendments, before it's signed into law via Royal Assent, expected to happen early next year.</p><p>A petition against <a href="https://petition.parliament.uk/petitions/174544" target="_blank">age verification on the government website has just 22 signatures so far</a>, though the anti-porn rules have <a href="http://metro.co.uk/2016/10/18/lingerie-clad-activists-want-you-to-know-about-a-law-that-will-change-the-way-you-watch-porn-6199990" target="_blank">already sparked protests</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Investigatory Powers 'will cost UK £1 billion'</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers Bill passes through Parliament ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Investigatory Powers Bill is on track to becoming UK law after being approved by the House of Lords yesterday, despite facing strong opposition.</p><p>The controversial bill, also known as the Snooper's Charter, has now been passed by both houses of Parliament, and is expected to receive Royal Assent before the end of 2016.</p><p>It will force internet service providers (ISPs) to store people's web history data (known as Internet Connection Records, a list of websites you visit, but not the individual webpages you click on) for up to a year.</p><p>Spy agencies will also be granted the power to collect bulk personal datasets, including information of people not suspected of any criminal activity. They will also be permitted to undertake large scale hacking operations, though they must first obtain a warrant from the secretary of state.</p><p>It is set to become law before the end of the year, in order to replace the expiring Data Retention and Investigatory Powers Act (DRIPA), which came into force in 2014.</p><p><a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">DRIPA was ruled unlawful by the High Court last October</a>, which said it was incompatible with the European Human Rights Act, but the European Court of Justice subsequently issued guidance contradicting this.</p><p>While MPs and Lords have passed the Investigatory Powers Bill, privacy campaigners have railed against the would-be legislation.</p><p>Open Rights Group executive director Jim Killock said: "The IP Bill will put into statute the powers and capabilities revealed by Snowden as well as increasing surveillance by the police and other government departments. There will continue to be a lack of privacy protections for international data sharing arrangements with the US. Parliament has also failed to address the implications of the technical integration of GCHQ and the NSA.</p><p>"While parliamentarians have failed to limit these powers, the courts may succeed. A ruling by the Court of Justice of the European Union, expected next year, may mean that parts of the bill are unlawful and need to be amended."</p><p>Julian Huppert, the former Liberal Democrat MP for Cambridge, added: "Soon, a record will be kept of every website you ever go to. That should worry you."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/798934011951325184"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/798934011951325184"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Privacy action group Liberty, meanwhile, appeared to threaten court action.</p><p>Policy director Bella Sankey said: "The passage of the Snooper's Charter through Parliament is a sad day for British liberty. Under the guise of counter-terrorism, the state has achieved totalitarian-style surveillance powers the most intrusive system of any democracy in human history. It has the ability to indiscriminately hack, intercept, record, and monitor the communications and internet use of the entire population.</p><p>"Liberty has fought tooth and nail against this terrifying legislation, but the paucity of political opposition has been devastating. The fight does not end here. Our message to Government: see you in court."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27017/brits-fear-snoopers-charter-powers-that-already-exist" data-original-url="/public-sector/27017/brits-fear-snoopers-charter-powers-that-already-exist">Brits fear Snooper's Charter powers that already exist</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament</link>
                                                                            <description>
                            <![CDATA[ Now only Royal Assent is required to enshrine Snooper's Charter in UK law ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ydH4DYJqrov8sCwhPpcjG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Nov 2016 13:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Bill is on track to becoming UK law after being approved by the House of Lords yesterday, despite facing strong opposition.</p><p>The controversial bill, also known as the Snooper's Charter, has now been passed by both houses of Parliament, and is expected to receive Royal Assent before the end of 2016.</p><p>It will force internet service providers (ISPs) to store people's web history data (known as Internet Connection Records, a list of websites you visit, but not the individual webpages you click on) for up to a year.</p><p>Spy agencies will also be granted the power to collect bulk personal datasets, including information of people not suspected of any criminal activity. They will also be permitted to undertake large scale hacking operations, though they must first obtain a warrant from the secretary of state.</p><p>It is set to become law before the end of the year, in order to replace the expiring Data Retention and Investigatory Powers Act (DRIPA), which came into force in 2014.</p><p><a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">DRIPA was ruled unlawful by the High Court last October</a>, which said it was incompatible with the European Human Rights Act, but the European Court of Justice subsequently issued guidance contradicting this.</p><p>While MPs and Lords have passed the Investigatory Powers Bill, privacy campaigners have railed against the would-be legislation.</p><p>Open Rights Group executive director Jim Killock said: "The IP Bill will put into statute the powers and capabilities revealed by Snowden as well as increasing surveillance by the police and other government departments. There will continue to be a lack of privacy protections for international data sharing arrangements with the US. Parliament has also failed to address the implications of the technical integration of GCHQ and the NSA.</p><p>"While parliamentarians have failed to limit these powers, the courts may succeed. A ruling by the Court of Justice of the European Union, expected next year, may mean that parts of the bill are unlawful and need to be amended."</p><p>Julian Huppert, the former Liberal Democrat MP for Cambridge, added: "Soon, a record will be kept of every website you ever go to. That should worry you."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/798934011951325184"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/798934011951325184"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Privacy action group Liberty, meanwhile, appeared to threaten court action.</p><p>Policy director Bella Sankey said: "The passage of the Snooper's Charter through Parliament is a sad day for British liberty. Under the guise of counter-terrorism, the state has achieved totalitarian-style surveillance powers the most intrusive system of any democracy in human history. It has the ability to indiscriminately hack, intercept, record, and monitor the communications and internet use of the entire population.</p><p>"Liberty has fought tooth and nail against this terrifying legislation, but the paucity of political opposition has been devastating. The fight does not end here. Our message to Government: see you in court."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27017/brits-fear-snoopers-charter-powers-that-already-exist" data-original-url="/public-sector/27017/brits-fear-snoopers-charter-powers-that-already-exist">Brits fear Snooper's Charter powers that already exist</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade ]]></title>
                                                                                                <dc:content><![CDATA[ <p>UK spy agencies broke privacy rules and illegally collected data on UK citizens for over a decade without appropriate safeguards, according to a landmark ruling by the Investigatory Powers Tribunal (IBT) released today.</p><p>Complaints were brought forward in July by human rights organisation <a href="https://medium.com/privacy-international/press-release-new-court-judgment-finds-uk-surveillance-agencies-collected-everyones-e3f037a0b901#.khexdgay4" target="_blank">Privacy International</a>, claiming that GCHQ, MI5 and MI6 had breached Article 8 of the European Convention on Human Rights (ECHR).</p><p>The IBT <a href="http://www.ipt-uk.com/judgments.asp" target="_blank">ruling</a> today found that the three agencies (SIAs) had unlawfully collected communications data between 1998 and 2015. This data contains the "who, when, where and how", including telephone, internet, mobile communications and location information.</p><p>It also ruled that collections of "bulk personal data", such as "considerable volumes of biographical details, commercial and financial activities, and communications and travel", were unlawfully obtained between 2003 and 2015.</p><p>Official legislation on how to lawfully collect personal data came into force in February 2015 under the SIA Bulk Personal Data Policy. Before this however, the tribunal found that the absence of safeguards breached Article 8, making personal data collection "unlawful".</p><p>Article 8 of the ECHR guarantees the right to respect for a person's "private and family life, his home, and his correspondence" and that any attempts to breach this right should be "in accordance with law".</p><p>Security concerns were raised by the tribunal, including the discovery of an internal memo warning staff to not use the vast data systems to search for "other members of staff, neighbours, friends, acquaintances, family members and public figures".</p><p>Given the secretive nature of the data collection, it seems "difficult to conclude that the use of bulk communication data collection was foreseeable by the public when it was not explained to Parliament", according to the IBT.</p><p>GCHQ, MI6 and MI6 argued that the use of such powers is "lawful and essential for the protection of national security".</p><p>The tribunal has stated that following the additional oversight implemented in February, personal data collection is now lawfully carried out in the UK.</p><p>However Privacy International believes safeguards are still inadequate, with a spokesperson responding to the ruling by saying: "There is no requirement for judicial or independent authorization. Supervision by a member of the executive (ie a government minister) does not provide the necessary guarantees that surveillance operations that could impact on millions of people are necessary and proportionate."</p><p>Legal representative for Privacy International, Mark Scott of Bhatt Murphy solicitors, said: "This judgment confirms that for over a decade UK security services unlawfully concealed both the extent of their surveillance capabilities and that innocent people across the country have been spied on."</p><p>In response to the ruling, the Home Office stated it is "committed" to providing greater transparency and stronger safeguards.</p><p>"We are pleased the tribunal has confirmed the current lawfulness of the existing bulk communications data and bulk personal dataset regimes," said a Home Office spokesperson to the <em>BBC</em>.</p><p>The House of Lords is currently debating the final details of the Investigatory Powers Bill, aka the Snooper's Charter, which aims to create a legal framework for mass digital surveillance. This was spurred on by the Edward Snowden leaks in 2013, showing the extent of surveillance in the UK.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop" data-original-url="/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop">GCHQ VoIP software can be used to eavesdrop</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26999/high-profile-individuals-targeted-by-uk-security-services" data-original-url="/security/26999/high-profile-individuals-targeted-by-uk-security-services">“High-profile” individuals targeted by UK security services</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade</link>
                                                                            <description>
                            <![CDATA[ Tribunal rules GCHQ, MI5 and MI6 surveillance breached Article 8 of the ECHR ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9pqLqQFvRR1Nj3CTxrG414</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Oct 2016 15:57:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Ministry of Defence]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An aerial shot of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[An aerial shot of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[An aerial shot of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK spy agencies broke privacy rules and illegally collected data on UK citizens for over a decade without appropriate safeguards, according to a landmark ruling by the Investigatory Powers Tribunal (IBT) released today.</p><p>Complaints were brought forward in July by human rights organisation <a href="https://medium.com/privacy-international/press-release-new-court-judgment-finds-uk-surveillance-agencies-collected-everyones-e3f037a0b901#.khexdgay4" target="_blank">Privacy International</a>, claiming that GCHQ, MI5 and MI6 had breached Article 8 of the European Convention on Human Rights (ECHR).</p><p>The IBT <a href="http://www.ipt-uk.com/judgments.asp" target="_blank">ruling</a> today found that the three agencies (SIAs) had unlawfully collected communications data between 1998 and 2015. This data contains the "who, when, where and how", including telephone, internet, mobile communications and location information.</p><p>It also ruled that collections of "bulk personal data", such as "considerable volumes of biographical details, commercial and financial activities, and communications and travel", were unlawfully obtained between 2003 and 2015.</p><p>Official legislation on how to lawfully collect personal data came into force in February 2015 under the SIA Bulk Personal Data Policy. Before this however, the tribunal found that the absence of safeguards breached Article 8, making personal data collection "unlawful".</p><p>Article 8 of the ECHR guarantees the right to respect for a person's "private and family life, his home, and his correspondence" and that any attempts to breach this right should be "in accordance with law".</p><p>Security concerns were raised by the tribunal, including the discovery of an internal memo warning staff to not use the vast data systems to search for "other members of staff, neighbours, friends, acquaintances, family members and public figures".</p><p>Given the secretive nature of the data collection, it seems "difficult to conclude that the use of bulk communication data collection was foreseeable by the public when it was not explained to Parliament", according to the IBT.</p><p>GCHQ, MI6 and MI6 argued that the use of such powers is "lawful and essential for the protection of national security".</p><p>The tribunal has stated that following the additional oversight implemented in February, personal data collection is now lawfully carried out in the UK.</p><p>However Privacy International believes safeguards are still inadequate, with a spokesperson responding to the ruling by saying: "There is no requirement for judicial or independent authorization. Supervision by a member of the executive (ie a government minister) does not provide the necessary guarantees that surveillance operations that could impact on millions of people are necessary and proportionate."</p><p>Legal representative for Privacy International, Mark Scott of Bhatt Murphy solicitors, said: "This judgment confirms that for over a decade UK security services unlawfully concealed both the extent of their surveillance capabilities and that innocent people across the country have been spied on."</p><p>In response to the ruling, the Home Office stated it is "committed" to providing greater transparency and stronger safeguards.</p><p>"We are pleased the tribunal has confirmed the current lawfulness of the existing bulk communications data and bulk personal dataset regimes," said a Home Office spokesperson to the <em>BBC</em>.</p><p>The House of Lords is currently debating the final details of the Investigatory Powers Bill, aka the Snooper's Charter, which aims to create a legal framework for mass digital surveillance. This was spurred on by the Edward Snowden leaks in 2013, showing the extent of surveillance in the UK.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop" data-original-url="/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop">GCHQ VoIP software can be used to eavesdrop</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26999/high-profile-individuals-targeted-by-uk-security-services" data-original-url="/security/26999/high-profile-individuals-targeted-by-uk-security-services">“High-profile” individuals targeted by UK security services</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">444 MPs push Investigatory Powers Bill forward into House of Lords</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Brits fear Snooper's Charter powers that already exist ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The British public does not trust the government to look after its data, and is scared the so-called Snooper's Charter will allow the police to secretly access people's computers - even though such powers already exist.</p><p>Security firm Venafi found that 69 per cent of UK citizens think the government already abuses its powers to access data on citizens, while 76 per cent are concerned the Snooper's Charter - formally known as the Investigatory Powers Bill - will increase its powers to gain access to the contents of private digital communications, such as emails and text messages.</p><p>Additionally, 70 per cent believe that powers such as those contained in the Snooper's Charter would be abused if they came into force, and the same percentage is against the government being allowed to force technology companies to put their customers' data at risk by creating encryption backdoors.</p><p>Despite this high level of mistrust, the majority of respondents (69 per cent) felt that they are better off in the UK than the US in terms of law enforcement's ability to access citizens' data.</p><p>However, this trust may be misplaced.</p><p>Under the existing UK legislation, the Regulation of Investigatory Powers Act 2000 (RIPA), law enforcement can already compel individuals, including the heads of companies that hold data on individuals, to hand over data without first having to get a warrant from a judge.</p><p>They can also isolate these people, preventing them from communicating with anyone except their solicitor. In the case of a CEO, this would include preventing them from communicating with their fellow board members.</p><p>These powers are far in excess of what US law enforcement is able to do - in <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">the recent case of the San Bernardino iPhone</a>, Apple CEO Tim Cook would have been prevented from making any public statements on the demands of the FBI, or would have faced three years in jail had he done so.</p><p>Despite this, 80 per cent of respondents to the Venafi survey had never heard of RIPA and were unaware of the powers it contains.</p><p>Kevin Bocek, VP of security strategy for Venafi, said: "Governments all over the world already have the power to do what the FBI could only ask a judge to do against Apple ... especially in the UK."</p><p>"RIPA has huge implications for UK businesses and the multi-nationals that operate here; particularly individuals in more senior positions within those organisations," he added. "There is no option to hide behind the corporate veil, it is the individual that is charged, not the company, and the individual that needs to make the difficult choice between protecting customer data or their personal freedom. Most citizens have no idea these powers even exist. This is a worrying state of affairs. Our freedoms and rights are slowly being eroded: government is gaining powers to hijack the Internet."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/27017/brits-fear-snoopers-charter-powers-that-already-exist</link>
                                                                            <description>
                            <![CDATA[ General public unaware of existing police powers to spy on the public ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWxStVrpXfMzL44ZwNRfhJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nmdNgk7qfudGfqRXXnsdZW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 Jul 2016 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nmdNgk7qfudGfqRXXnsdZW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nmdNgk7qfudGfqRXXnsdZW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The British public does not trust the government to look after its data, and is scared the so-called Snooper's Charter will allow the police to secretly access people's computers - even though such powers already exist.</p><p>Security firm Venafi found that 69 per cent of UK citizens think the government already abuses its powers to access data on citizens, while 76 per cent are concerned the Snooper's Charter - formally known as the Investigatory Powers Bill - will increase its powers to gain access to the contents of private digital communications, such as emails and text messages.</p><p>Additionally, 70 per cent believe that powers such as those contained in the Snooper's Charter would be abused if they came into force, and the same percentage is against the government being allowed to force technology companies to put their customers' data at risk by creating encryption backdoors.</p><p>Despite this high level of mistrust, the majority of respondents (69 per cent) felt that they are better off in the UK than the US in terms of law enforcement's ability to access citizens' data.</p><p>However, this trust may be misplaced.</p><p>Under the existing UK legislation, the Regulation of Investigatory Powers Act 2000 (RIPA), law enforcement can already compel individuals, including the heads of companies that hold data on individuals, to hand over data without first having to get a warrant from a judge.</p><p>They can also isolate these people, preventing them from communicating with anyone except their solicitor. In the case of a CEO, this would include preventing them from communicating with their fellow board members.</p><p>These powers are far in excess of what US law enforcement is able to do - in <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">the recent case of the San Bernardino iPhone</a>, Apple CEO Tim Cook would have been prevented from making any public statements on the demands of the FBI, or would have faced three years in jail had he done so.</p><p>Despite this, 80 per cent of respondents to the Venafi survey had never heard of RIPA and were unaware of the powers it contains.</p><p>Kevin Bocek, VP of security strategy for Venafi, said: "Governments all over the world already have the power to do what the FBI could only ask a judge to do against Apple ... especially in the UK."</p><p>"RIPA has huge implications for UK businesses and the multi-nationals that operate here; particularly individuals in more senior positions within those organisations," he added. "There is no option to hide behind the corporate veil, it is the individual that is charged, not the company, and the individual that needs to make the difficult choice between protecting customer data or their personal freedom. Most citizens have no idea these powers even exist. This is a worrying state of affairs. Our freedoms and rights are slowly being eroded: government is gaining powers to hijack the Internet."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers: Expect less scrutiny now Theresa May is Prime Minister ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With Theresa May becoming Prime Minister, the Investigatory Powers Bill (IP Bill), which she championed as Home Secretary, raises serious questions as it heads to becoming law.</p><p>The controversial plan to put surveillance on a stronger legal footing would compel internet service providers to store people's web browsing histories for up to one year, and force software providers to build backdoors into encryption.</p><p>The so-called 'Snooper's Charter' may be under the aegis of new Home Secretary Amber Rudd, <a href="https://www.itpro.com/it-legislation/26932/investigatory-powers-bill-s-security-backdoors-won-t-make-iphone-illegal" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26932/investigatory-powers-bill-s-security-backdoors-won-t-make-iphone-illegal">but plans have changed little</a>, and with an opposition in disarray, look unlikely to be questioned as much as it should.</p><p>"Theresa May is the poster girl for UK surveillance and she will no doubt continue this approach as Prime Minister," says Brian Spector, CEO at online identity firm Miracl. "When it comes to the IP Bill, we can only hope that the peers and lawyers who have final review can scupper its passage through Parliament with more scrutiny and conviction than our MPs did back in March [<a href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" target="_blank" data-original-url="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">when 444 MPs voted it through the House of Commons</a>]."</p><p>He says that given that most people now place all their personal data online, the IP bill would grant enormous surveillance capabilities to the government.</p><p>"If the legislation proceeds, it could undermine trust in the internet as a whole, from service providers, to device manufacturers, to the apps we use as part of our everyday lives," he adds.</p><p>Serious implications</p><p>There are also serious implications, warns Spector. "Under the proposals, [companies] would be legally bound to help UK police and security services access an individual's device. What's more, the current wording of the bill means that any software made by a British company could soon be perceived to be facilitating government spying on its customer's data."</p><p>This would have enormous repercussions by making it much harder for British technology and information security companies to compete globally, according to Spector.</p><p>Dave Levy, associate partner at IT advisory group Citihub Consulting, tells <em>IT Pro</em> that MPs were unlikely to give the bill the proper scrutiny it needs.</p><p>"I don't think the change in Prime Minister will make much difference except that May is the ex-Home Secretary and will have a much finer and more accurate judgement about the feasibility and political cost of getting the bill through," he says.</p><p>"Also, it's gone through the Commons and so it will only require to be considered again if the Lords make amendments, which given the majority it had in the Commons on the third reading because Labour supported it, I think it's unlikely."</p><p>One worrying aspect, much underestimated, is that the IP Bill proposes giving the intelligence services immunity from criminal liability for actions such as hacking that would be illegal if conducted by others, he points out.</p><p>"This throws up a civil liberties issue. Possibly, it will make IT security research harder to perform within the law. If so, researchers will move to a more conducive regulatory jurisdiction," says Levy.</p><p>Encryption issues</p><p>Jake Madders, director at managed cloud hosting company Hyve, believes the policies around data protection and encryption present particular challenges.</p><p>"Cybersecurity and data protection are core considerations for a huge range of digital businesses, with encryption of data being among the most pertinent," he says. "Removing encryption could mean that tech companies become an even bigger target for hackers. Organisations like ours adhere to the governance provided by the Data Protection Act, ISO 27001, PCI DSS standard, and via the government accreditation, G-Cloud, among others. This would all have to be reconsidered if the 'back door' to encryption the bill seeks was to appear."</p><p>Jacob Ginsberg, senior director at email encryption firm Echoworx, says that the bill undermines the fundamental right to privacy.</p><p>"There is a severe lack of clarity around encryption backdoors and bulk data collection in the bill, which will have far-reaching ramifications," he says. "Businesses need to be reassured that backdoors will not be built into encryption solutions.</p><p>"If this is not clearly defined, cloud and hosting companies will simply move their data to jurisdictions that the bill cannot influence. This could destroy the UK's data storage market, driving out over 10 billion worth of business."</p><p>Ginsberg adds that the speed at which the bill was rushed through parliament, and now through the House of Lords, undermines all of these concerns. "With Theresa May's recent appointment, further scrutiny and changes are extremely unlikely."</p><p>Handing our data to cybercriminals</p><p>Valuing anti-terrorism above encryption does not mean the government is making our data more susceptible to hacking, according to Jonathan Parker-Bray, CEO and founder of encryption app Pryvate.</p><p>"Business interests are quite selfish in this regard and will ensure that they have sufficient levels of protection in place for their customers to protect them from cyber attacks," he says.</p><p>The culpability in a breach falls on the company, not with the government, he adds, saying this means that companies have lots of incentive to defend their users from attacks or risk losing business.</p><p>"Whilst the government wishes to create a situation where data can be requested from companies with a warrant, the fact is that in many cases this won't be possible, and any attempt to weaken encryption will receive massive pushback from businesses throughout the country and their international partners," he says.</p><p>What next?</p><p>The issue of Brexit has grabbed most of the government's time now and for the foreseeable future. Lee Munson, security researcher at Comparitech.com, says he suspects that the IP Bill may not be quite as high on the agenda as it otherwise would have been.</p><p>"It may also no longer be a legacy the new PM wishes to associate with she has, after all, quickly demonstrated how she wishes to separate herself from the Cameronista policies of yesterday," he points out.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26936/investigatory-powers-expect-less-scrutiny-now-theresa-may-is-prime-minister</link>
                                                                            <description>
                            <![CDATA[ Experts predict Theresa May's rise to PM will give the Snooper's Charter an easier ride ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">63422cHMHG2dkesarPENJa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Jul 2016 13:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With Theresa May becoming Prime Minister, the Investigatory Powers Bill (IP Bill), which she championed as Home Secretary, raises serious questions as it heads to becoming law.</p><p>The controversial plan to put surveillance on a stronger legal footing would compel internet service providers to store people's web browsing histories for up to one year, and force software providers to build backdoors into encryption.</p><p>The so-called 'Snooper's Charter' may be under the aegis of new Home Secretary Amber Rudd, <a href="https://www.itpro.com/it-legislation/26932/investigatory-powers-bill-s-security-backdoors-won-t-make-iphone-illegal" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26932/investigatory-powers-bill-s-security-backdoors-won-t-make-iphone-illegal">but plans have changed little</a>, and with an opposition in disarray, look unlikely to be questioned as much as it should.</p><p>"Theresa May is the poster girl for UK surveillance and she will no doubt continue this approach as Prime Minister," says Brian Spector, CEO at online identity firm Miracl. "When it comes to the IP Bill, we can only hope that the peers and lawyers who have final review can scupper its passage through Parliament with more scrutiny and conviction than our MPs did back in March [<a href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" target="_blank" data-original-url="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">when 444 MPs voted it through the House of Commons</a>]."</p><p>He says that given that most people now place all their personal data online, the IP bill would grant enormous surveillance capabilities to the government.</p><p>"If the legislation proceeds, it could undermine trust in the internet as a whole, from service providers, to device manufacturers, to the apps we use as part of our everyday lives," he adds.</p><p>Serious implications</p><p>There are also serious implications, warns Spector. "Under the proposals, [companies] would be legally bound to help UK police and security services access an individual's device. What's more, the current wording of the bill means that any software made by a British company could soon be perceived to be facilitating government spying on its customer's data."</p><p>This would have enormous repercussions by making it much harder for British technology and information security companies to compete globally, according to Spector.</p><p>Dave Levy, associate partner at IT advisory group Citihub Consulting, tells <em>IT Pro</em> that MPs were unlikely to give the bill the proper scrutiny it needs.</p><p>"I don't think the change in Prime Minister will make much difference except that May is the ex-Home Secretary and will have a much finer and more accurate judgement about the feasibility and political cost of getting the bill through," he says.</p><p>"Also, it's gone through the Commons and so it will only require to be considered again if the Lords make amendments, which given the majority it had in the Commons on the third reading because Labour supported it, I think it's unlikely."</p><p>One worrying aspect, much underestimated, is that the IP Bill proposes giving the intelligence services immunity from criminal liability for actions such as hacking that would be illegal if conducted by others, he points out.</p><p>"This throws up a civil liberties issue. Possibly, it will make IT security research harder to perform within the law. If so, researchers will move to a more conducive regulatory jurisdiction," says Levy.</p><p>Encryption issues</p><p>Jake Madders, director at managed cloud hosting company Hyve, believes the policies around data protection and encryption present particular challenges.</p><p>"Cybersecurity and data protection are core considerations for a huge range of digital businesses, with encryption of data being among the most pertinent," he says. "Removing encryption could mean that tech companies become an even bigger target for hackers. Organisations like ours adhere to the governance provided by the Data Protection Act, ISO 27001, PCI DSS standard, and via the government accreditation, G-Cloud, among others. This would all have to be reconsidered if the 'back door' to encryption the bill seeks was to appear."</p><p>Jacob Ginsberg, senior director at email encryption firm Echoworx, says that the bill undermines the fundamental right to privacy.</p><p>"There is a severe lack of clarity around encryption backdoors and bulk data collection in the bill, which will have far-reaching ramifications," he says. "Businesses need to be reassured that backdoors will not be built into encryption solutions.</p><p>"If this is not clearly defined, cloud and hosting companies will simply move their data to jurisdictions that the bill cannot influence. This could destroy the UK's data storage market, driving out over 10 billion worth of business."</p><p>Ginsberg adds that the speed at which the bill was rushed through parliament, and now through the House of Lords, undermines all of these concerns. "With Theresa May's recent appointment, further scrutiny and changes are extremely unlikely."</p><p>Handing our data to cybercriminals</p><p>Valuing anti-terrorism above encryption does not mean the government is making our data more susceptible to hacking, according to Jonathan Parker-Bray, CEO and founder of encryption app Pryvate.</p><p>"Business interests are quite selfish in this regard and will ensure that they have sufficient levels of protection in place for their customers to protect them from cyber attacks," he says.</p><p>The culpability in a breach falls on the company, not with the government, he adds, saying this means that companies have lots of incentive to defend their users from attacks or risk losing business.</p><p>"Whilst the government wishes to create a situation where data can be requested from companies with a warrant, the fact is that in many cases this won't be possible, and any attempt to weaken encryption will receive massive pushback from businesses throughout the country and their international partners," he says.</p><p>What next?</p><p>The issue of Brexit has grabbed most of the government's time now and for the foreseeable future. Lee Munson, security researcher at Comparitech.com, says he suspects that the IP Bill may not be quite as high on the agenda as it otherwise would have been.</p><p>"It may also no longer be a legacy the new PM wishes to associate with she has, after all, quickly demonstrated how she wishes to separate herself from the Cameronista policies of yesterday," he points out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers bill’s security backdoors ‘won’t make iPhone illegal’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Accessing people's data via security backdoors will form a key part of the Investigatory Powers Bill, despite arguments it could make the new iPhone illegal, it emerged in Parliament this week.</p><p>The government's deputy leader in the House of Lords, Earl Howe, was adamant the bill must require telecoms companies to break or remove their own encryption to give government agencies access to people's personal data.</p><p>Debating the bill, he said: "If we do not provide for access to encrypted communications when it is necessary and proportionate to do so, we must simply accept that there can be areas online beyond the reach of the law, where criminals can go about their business unimpeded and without the risk of detection."</p><p>Howe added: "Enforcement and the intelligence agencies must retain the ability to require telecommunications operators to remove encryption in limited circumstancessubject to strong controls and safeguardsto address the increasing technical sophistication of those who would seek to do us harm."</p><p>He was defending the backdoor element of the bill from proposed amendments 92, 102 and 103, which would have removed this section of the legislation.</p><p>"They are an [sic] irresponsible proposals, which would remove the government's ability to give a technical capability notice to telecommunications operators requiring them to remove encryption from the communications of criminals, terrorists and foreign spies," Howe said.</p><p>However, one proponent of the amendments, the Liberal Democrats' Lord Paul Strasburger, suggested the Investigatory Powers' backdoors are incompatible with IT companies' use of end-to-end encryption.</p><p>"The implication of what he is saying is that no one may develop end-to-end encryption," he said. </p><p>"He seems to be implying that providers can use only encryption which can be broken and therefore cannot be end to end, so the next version of the Apple iPhone would, in theory, become illegal."</p><p>Howe denied this, instead insisting that "there will be circumstances where it is reasonably practicable for a company to build in a facility to de-encrypt the contents of communication".</p><p>None of the above amendments were made to the bill. Its passage through Parliament continues with debate in the House of Lords, after <a href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">the House of Commons voted it through with 444 MPs in favour</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/26932/investigatory-powers-bill-s-security-backdoors-won-t-make-iphone-illegal</link>
                                                                            <description>
                            <![CDATA[ Encryption backdoors survive proposed House of Lords amendments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GPVRjWoAJX3YNn2DiUvpk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Jul 2016 10:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of the UK houses of parliament]]></media:description>                                                            <media:text><![CDATA[Image of the UK houses of parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Image of the UK houses of parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Accessing people's data via security backdoors will form a key part of the Investigatory Powers Bill, despite arguments it could make the new iPhone illegal, it emerged in Parliament this week.</p><p>The government's deputy leader in the House of Lords, Earl Howe, was adamant the bill must require telecoms companies to break or remove their own encryption to give government agencies access to people's personal data.</p><p>Debating the bill, he said: "If we do not provide for access to encrypted communications when it is necessary and proportionate to do so, we must simply accept that there can be areas online beyond the reach of the law, where criminals can go about their business unimpeded and without the risk of detection."</p><p>Howe added: "Enforcement and the intelligence agencies must retain the ability to require telecommunications operators to remove encryption in limited circumstancessubject to strong controls and safeguardsto address the increasing technical sophistication of those who would seek to do us harm."</p><p>He was defending the backdoor element of the bill from proposed amendments 92, 102 and 103, which would have removed this section of the legislation.</p><p>"They are an [sic] irresponsible proposals, which would remove the government's ability to give a technical capability notice to telecommunications operators requiring them to remove encryption from the communications of criminals, terrorists and foreign spies," Howe said.</p><p>However, one proponent of the amendments, the Liberal Democrats' Lord Paul Strasburger, suggested the Investigatory Powers' backdoors are incompatible with IT companies' use of end-to-end encryption.</p><p>"The implication of what he is saying is that no one may develop end-to-end encryption," he said. </p><p>"He seems to be implying that providers can use only encryption which can be broken and therefore cannot be end to end, so the next version of the Apple iPhone would, in theory, become illegal."</p><p>Howe denied this, instead insisting that "there will be circumstances where it is reasonably practicable for a company to build in a facility to de-encrypt the contents of communication".</p><p>None of the above amendments were made to the bill. Its passage through Parliament continues with debate in the House of Lords, after <a href="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords" data-original-url="https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords">the House of Commons voted it through with 444 MPs in favour</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Police suffer 2,315 data breaches in five years ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Police have suffered 2,315 data breaches in the last five years, Big Brother Watch revealed today, leading it to question whether forces can be trusted to look after increasing amounts of people's personal data.</p><p>The privacy campaign group's <a href="https://www.bigbrotherwatch.org.uk/wp-content/uploads/2016/07/Safe-in-Police-Hands.pdf" target="_blank"><em>Safe in Police Hands?</em></a> report details UK police force data breaches from June 2011 to December 2015, sourced from Freedom of Information requests.</p><p>More than 800 members of police staff accessed people's personal information "without a policing purpose", adding that data was "inappropriately shared" with third parties 877 times.</p><p>However, police took no disciplinary action in 55 per cent of all breaches, Big Brother Watch found, and just 11 per cent ended in a verbal or written warning.</p><p>The data led Big Brother Watch to question whether police should have access to people's Internet Connection Records (ICRs), records of websites people visit, <a href="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter">as proposed by the Investigatory Powers Bill</a>.</p><p>Internet service providers would have to hold onto people's ICRs for up to a year, and decrypt it if law enforcement agencies request it.</p><p>But Big Brother Watch argued the ICR proposal should be removed from the bill, writing: "Police forces are already struggling to keep the personal information they can access secure. It is clear that the addition of yet more data may just lead to the risk of a data breach or of misuse."</p><p>The report added: "The power to collect, store and for the police to subsequently seek a warrant to access our online activity would create another vulnerability to our personal data and personal lives. The failure of the Government to demonstrate the need for the power means that there are no tangible benefits to set against the negative impact the power would have on our privacy."</p><p>Other recommendations made by the organisation included criminal records for those responsible for serious breaches, as well as the introduction of prison sentences, saying that existing penalties are not strong deterrants.</p><p>Police should also notify people whose data is leaked within 90 days of the breach being investigated, said Big Brother Watch.</p><p>West Midlands police force suffered by far the highest number of data breaches, at 488, with the next nearest being Surrey Police with 202.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-leakage/26853/police-suffer-2315-data-breaches-in-five-years</link>
                                                                            <description>
                            <![CDATA[ Big Brother Watch argues police cannot be trusted with more personal data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pyDaCL8jEPw2b6X27v9hpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c2i2QxZxdxqBVNnKMxE8LS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Jul 2016 10:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/c2i2QxZxdxqBVNnKMxE8LS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Police]]></media:description>                                                            <media:text><![CDATA[Police]]></media:text>
                                <media:title type="plain"><![CDATA[Police]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c2i2QxZxdxqBVNnKMxE8LS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Police have suffered 2,315 data breaches in the last five years, Big Brother Watch revealed today, leading it to question whether forces can be trusted to look after increasing amounts of people's personal data.</p><p>The privacy campaign group's <a href="https://www.bigbrotherwatch.org.uk/wp-content/uploads/2016/07/Safe-in-Police-Hands.pdf" target="_blank"><em>Safe in Police Hands?</em></a> report details UK police force data breaches from June 2011 to December 2015, sourced from Freedom of Information requests.</p><p>More than 800 members of police staff accessed people's personal information "without a policing purpose", adding that data was "inappropriately shared" with third parties 877 times.</p><p>However, police took no disciplinary action in 55 per cent of all breaches, Big Brother Watch found, and just 11 per cent ended in a verbal or written warning.</p><p>The data led Big Brother Watch to question whether police should have access to people's Internet Connection Records (ICRs), records of websites people visit, <a href="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter">as proposed by the Investigatory Powers Bill</a>.</p><p>Internet service providers would have to hold onto people's ICRs for up to a year, and decrypt it if law enforcement agencies request it.</p><p>But Big Brother Watch argued the ICR proposal should be removed from the bill, writing: "Police forces are already struggling to keep the personal information they can access secure. It is clear that the addition of yet more data may just lead to the risk of a data breach or of misuse."</p><p>The report added: "The power to collect, store and for the police to subsequently seek a warrant to access our online activity would create another vulnerability to our personal data and personal lives. The failure of the Government to demonstrate the need for the power means that there are no tangible benefits to set against the negative impact the power would have on our privacy."</p><p>Other recommendations made by the organisation included criminal records for those responsible for serious breaches, as well as the introduction of prison sentences, saying that existing penalties are not strong deterrants.</p><p>Police should also notify people whose data is leaked within 90 days of the breach being investigated, said Big Brother Watch.</p><p>West Midlands police force suffered by far the highest number of data breaches, at 488, with the next nearest being Surrey Police with 202.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ House of Lords hits out at Snooper's Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Members of the House of Lords have raised concerns about the content of the Investigatory powers Bill, known also as the Snooper's Charter, which started being debated in the House yesterday.</p><p>Particular concerns have been raised around the protections for journalists and their sources, as well as the privacy of the general public.</p><p><a href="http://www.pressgazette.co.uk/fight-to-secure-better-source-safeguards-in-snoopers-charter-bill-moves-to-house-of-lords-this-is-about-protecting-the-public" target="_blank"><em>Press Gazette</em></a> reports that Lords Rosser and Strasburger spoke out against the bill's current wording.</p><p>Lord Rosser said: "We have already secured amendments to the bill providing that judicial commissioners, when considering a warrant, must give weight to the overriding public interest in a warrant being granted for the use of investigatory powers against journalist ... however, there are still matters outstanding on this point, including the extent to which the bill does or does not provide for the same level of protection for journalists as is currently the case under the Police and Criminal Evidence Act."</p><p>"There is also the question of the definition of who is and who is not a journalist now that we are in the digital world," he added. "This is not about preserving the special status of individuals who work in journalism or the legal profession, or indeed as parliamentarians, but about protecting the public and their ability to raise issues through these channels on a secure and confidential basis."</p><p>Lord Strasberger, meanwhile, said: "There needs to be much better protection in the Bill, as we have already heard, for privileged communications such as those between lawyers and their clients, journalists and their sources and MPs and their constituents."</p><p>He added that the provision for the indiscriminate bulk collection of data from internet users is "highly intrusive, difficult and expensive to implement".</p><p>He also pointed out that reviews of such policies in Denmark and the USA have revealed they had no significant impact on detecting and preventing crime. The former country therefore abandoned the practice in 2014, although the latter has not formally undertaken any such measures yet.</p><p>Lord Paddick sounded a similar note, with both him and Strasberger pointing out that the security services, who are supposed to benefit from this clause, had not actually asked for it.</p><p>Strasberger also hit out at the continued threat to encryption contained in the Bill, saying that it needs to be removed in its entirety, for both security and democratic reasons.</p><p>"Strong encryption, as the Government have recognised in this House, is vital to our personal security and the integrity of our finance and commerce sectors. If [the bill] were enacted unchanged, innocent UK citizens would not be far behind their North Korean and Chinese counterparts in a contest to be the most spied-on population in the world. The powers in the Bill are very broad and very intrusive--more so than in any of our democratic allies."</p><p>Although the House of Commons <a href="http://www.pressgazette.co.uk/fight-to-secure-better-source-safeguards-in-snoopers-charter-bill-moves-to-house-of-lords-this-is-about-protecting-the-public" target="_blank">has voted to pass</a> the IP Bill, the Lords could defeat it, particularly as there is a Conservative minority in the house.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/26806/house-of-lords-hits-out-at-snoopers-charter</link>
                                                                            <description>
                            <![CDATA[ Privacy and practicality worries could give the IP Bill a rough ride through the upper house ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">41UdTwCb1FdLCMTcDKhH2u</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Jun 2016 09:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Houses of Parliament]]></media:description>                                                            <media:text><![CDATA[Houses of Parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Houses of Parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Members of the House of Lords have raised concerns about the content of the Investigatory powers Bill, known also as the Snooper's Charter, which started being debated in the House yesterday.</p><p>Particular concerns have been raised around the protections for journalists and their sources, as well as the privacy of the general public.</p><p><a href="http://www.pressgazette.co.uk/fight-to-secure-better-source-safeguards-in-snoopers-charter-bill-moves-to-house-of-lords-this-is-about-protecting-the-public" target="_blank"><em>Press Gazette</em></a> reports that Lords Rosser and Strasburger spoke out against the bill's current wording.</p><p>Lord Rosser said: "We have already secured amendments to the bill providing that judicial commissioners, when considering a warrant, must give weight to the overriding public interest in a warrant being granted for the use of investigatory powers against journalist ... however, there are still matters outstanding on this point, including the extent to which the bill does or does not provide for the same level of protection for journalists as is currently the case under the Police and Criminal Evidence Act."</p><p>"There is also the question of the definition of who is and who is not a journalist now that we are in the digital world," he added. "This is not about preserving the special status of individuals who work in journalism or the legal profession, or indeed as parliamentarians, but about protecting the public and their ability to raise issues through these channels on a secure and confidential basis."</p><p>Lord Strasberger, meanwhile, said: "There needs to be much better protection in the Bill, as we have already heard, for privileged communications such as those between lawyers and their clients, journalists and their sources and MPs and their constituents."</p><p>He added that the provision for the indiscriminate bulk collection of data from internet users is "highly intrusive, difficult and expensive to implement".</p><p>He also pointed out that reviews of such policies in Denmark and the USA have revealed they had no significant impact on detecting and preventing crime. The former country therefore abandoned the practice in 2014, although the latter has not formally undertaken any such measures yet.</p><p>Lord Paddick sounded a similar note, with both him and Strasberger pointing out that the security services, who are supposed to benefit from this clause, had not actually asked for it.</p><p>Strasberger also hit out at the continued threat to encryption contained in the Bill, saying that it needs to be removed in its entirety, for both security and democratic reasons.</p><p>"Strong encryption, as the Government have recognised in this House, is vital to our personal security and the integrity of our finance and commerce sectors. If [the bill] were enacted unchanged, innocent UK citizens would not be far behind their North Korean and Chinese counterparts in a contest to be the most spied-on population in the world. The powers in the Bill are very broad and very intrusive--more so than in any of our democratic allies."</p><p>Although the House of Commons <a href="http://www.pressgazette.co.uk/fight-to-secure-better-source-safeguards-in-snoopers-charter-bill-moves-to-house-of-lords-this-is-about-protecting-the-public" target="_blank">has voted to pass</a> the IP Bill, the Lords could defeat it, particularly as there is a Conservative minority in the house.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI can hack computers with no warrant, US court rules ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A court in Virginia has ruled the FBI can hack computers without a warrant.</p><p>The decision was made in relation to an ongoing case in which 137 people were arrested on suspicion of having accessed a site hosting images of child abuse, Playpen, on the dark web.</p><p>In 2014, the FBI managed to take control of the site, however, and track down users by hacking their computers and secretly collecting their IP addresses.</p><p>While the law enforcement agency did obtain a warrant for its actions, one of the suspects argued nevertheless that the evidence was collected illegally.</p><p>The court, however, disagreed.</p><p><a href="https://www.eff.org/files/2016/06/23/matish_suppression_edva.pdf">In his ruling</a>, senior united states district judge Henry Coke Morgan said: "The court finds ... that probable cause supported the warrant issuance [and] that the warrant was sufficiently specific ... and that the magistrate judge did not exceed her jurisdiction or authority in issuing the warrant. Furthermore, the court finds ... the government did not need a warrant in this case."</p><p>Mark Rumold, writing for privacy organisation the Electonic Frontier Foundation (EFF), c<a href="https://www.eff.org/deeplinks/2016/06/federal-court-fourth-amendment-does-not-protect-your-home-computer">alled the decision "dangerously flawed"</a>. </p><p>"This decision is the latest in, and perhaps the culmination of, a series of troubling decisions in prosecutions stemming from the FBI's investigation of Playpen. The implications of the decision, if upheld, are staggering: law enforcement would be free to remotely search and seize information from your computer, without a warrant, without probable cause, or without any suspicion at all," Rumold said.</p><p>The decision comes just days after theUS Senate slapped down a motion from the FBI to amend the law to allow it to access a wide range of internet records without a warrant (see story dated 23/06/2016), and a month after the maker of the Firefox browser, Mozilla, <a href="https://www.itpro.com/security/26534/mozilla-s-bid-for-tor-hack-used-in-child-porn-case-rejected" data-original-url="https://www.itpro.com/security/26534/mozilla-s-bid-for-tor-hack-used-in-child-porn-case-rejected">was denied information on how the FBI was able to crack the Tor network</a> to track the alleged criminals.</p><p><strong>23/06/2016: US Senate defeats Snooper's Charter analogue</strong></p><p>The US Senate has voted down an attempt by the FBI to gain unfettered access to citizens' internet data.</p><p>The motion to amend the Commerce, Justice, Science, and Related Agencies Appropriations Act would have allowed the US government to "obtain a specified set of electronic communication transactional records under that section, and to make permanent the authority for individual terrorists to be treated as agents of foreign powers under the Foreign Intelligence Surveillance Act of 1978".</p><p>This electronic communication would have included a subject's name, email address, phone number, login history, methods of payment made to online services, including card or bank information, IP address and session duration, such as how long a person was connected to the internet.</p><p>Under the amendment, all this would have been possible through self-certification on the part of the FBI, rather than having to go through a judge and get a warrant.</p><p>The application was voted down by the Senate more by a technical issue than by majority vote - it failed to meet the 60-vote limit in order to proceed.</p><p>The disruption was welcomed by groups such as the American Civil Liberties Union (ACLU), although the motion could be revived for another vote within the next 24-48 hours.</p><p>Nevertheless, campaign groups in the UK are hopeful that the defeat could help sway the opinion of the Lords with regards to the <a href="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter" data-original-url="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter">Snooper's Charter</a> - more properly known as the Investigatory Powers Bill - which provides law enforcement here with powers similar to those the FBI hoped for.</p><p>Jim Killock, executive director of Open Rights Group, told <em>IT Pro</em>: "The Investigatory Powers Bill will give the police and even government departments access to British citizens' personal information, including their web-browsing history, app use, phone records and location data. Not only will they be able to get internal sign off to access this data, but a new 'request filter' will put all of this information into a population-wide police database, which can be analysed without a warrant."</p><p>"The Home Office insists these powers are necessary but this is not borne out by evidence. As we have seen, the US Senate has struck down similar proposals and many other European countries have ended data retention, without any apparent impact on criminal detection."</p><p>"We hope that members of the House of Lords will take note of the US Senate's ruling and amend the IP Bill to remove proposals for both recording our web browsing history and the request filter."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26781/fbi-can-hack-computers-with-no-warrant-us-court-rules</link>
                                                                            <description>
                            <![CDATA[ No warrant was needed in child abuse case, even though one was obtained ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jCZaDeVm2t1RhxWe2gQvcs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jun 2016 09:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US Senate]]></media:description>                                                            <media:text><![CDATA[US Senate]]></media:text>
                                <media:title type="plain"><![CDATA[US Senate]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A court in Virginia has ruled the FBI can hack computers without a warrant.</p><p>The decision was made in relation to an ongoing case in which 137 people were arrested on suspicion of having accessed a site hosting images of child abuse, Playpen, on the dark web.</p><p>In 2014, the FBI managed to take control of the site, however, and track down users by hacking their computers and secretly collecting their IP addresses.</p><p>While the law enforcement agency did obtain a warrant for its actions, one of the suspects argued nevertheless that the evidence was collected illegally.</p><p>The court, however, disagreed.</p><p><a href="https://www.eff.org/files/2016/06/23/matish_suppression_edva.pdf">In his ruling</a>, senior united states district judge Henry Coke Morgan said: "The court finds ... that probable cause supported the warrant issuance [and] that the warrant was sufficiently specific ... and that the magistrate judge did not exceed her jurisdiction or authority in issuing the warrant. Furthermore, the court finds ... the government did not need a warrant in this case."</p><p>Mark Rumold, writing for privacy organisation the Electonic Frontier Foundation (EFF), c<a href="https://www.eff.org/deeplinks/2016/06/federal-court-fourth-amendment-does-not-protect-your-home-computer">alled the decision "dangerously flawed"</a>. </p><p>"This decision is the latest in, and perhaps the culmination of, a series of troubling decisions in prosecutions stemming from the FBI's investigation of Playpen. The implications of the decision, if upheld, are staggering: law enforcement would be free to remotely search and seize information from your computer, without a warrant, without probable cause, or without any suspicion at all," Rumold said.</p><p>The decision comes just days after theUS Senate slapped down a motion from the FBI to amend the law to allow it to access a wide range of internet records without a warrant (see story dated 23/06/2016), and a month after the maker of the Firefox browser, Mozilla, <a href="https://www.itpro.com/security/26534/mozilla-s-bid-for-tor-hack-used-in-child-porn-case-rejected" data-original-url="https://www.itpro.com/security/26534/mozilla-s-bid-for-tor-hack-used-in-child-porn-case-rejected">was denied information on how the FBI was able to crack the Tor network</a> to track the alleged criminals.</p><p><strong>23/06/2016: US Senate defeats Snooper's Charter analogue</strong></p><p>The US Senate has voted down an attempt by the FBI to gain unfettered access to citizens' internet data.</p><p>The motion to amend the Commerce, Justice, Science, and Related Agencies Appropriations Act would have allowed the US government to "obtain a specified set of electronic communication transactional records under that section, and to make permanent the authority for individual terrorists to be treated as agents of foreign powers under the Foreign Intelligence Surveillance Act of 1978".</p><p>This electronic communication would have included a subject's name, email address, phone number, login history, methods of payment made to online services, including card or bank information, IP address and session duration, such as how long a person was connected to the internet.</p><p>Under the amendment, all this would have been possible through self-certification on the part of the FBI, rather than having to go through a judge and get a warrant.</p><p>The application was voted down by the Senate more by a technical issue than by majority vote - it failed to meet the 60-vote limit in order to proceed.</p><p>The disruption was welcomed by groups such as the American Civil Liberties Union (ACLU), although the motion could be revived for another vote within the next 24-48 hours.</p><p>Nevertheless, campaign groups in the UK are hopeful that the defeat could help sway the opinion of the Lords with regards to the <a href="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter" data-original-url="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter">Snooper's Charter</a> - more properly known as the Investigatory Powers Bill - which provides law enforcement here with powers similar to those the FBI hoped for.</p><p>Jim Killock, executive director of Open Rights Group, told <em>IT Pro</em>: "The Investigatory Powers Bill will give the police and even government departments access to British citizens' personal information, including their web-browsing history, app use, phone records and location data. Not only will they be able to get internal sign off to access this data, but a new 'request filter' will put all of this information into a population-wide police database, which can be analysed without a warrant."</p><p>"The Home Office insists these powers are necessary but this is not borne out by evidence. As we have seen, the US Senate has struck down similar proposals and many other European countries have ended data retention, without any apparent impact on criminal detection."</p><p>"We hope that members of the House of Lords will take note of the US Senate's ruling and amend the IP Bill to remove proposals for both recording our web browsing history and the request filter."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 444 MPs push Investigatory Powers Bill forward into House of Lords  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Parliament <a href="https://hansard.parliament.uk/commons/2016-06-07/debates/16060732000001/InvestigatoryPowersBill">voted overwhelmingly in favour of the Investigatory Powers Bill yesterday</a>, with 444 MPs deciding to move it into the House of Lords.</p><p>Only the Scottish National Party, the Green Party, and the Liberal Democrats opposed the bill's third reading in the House of Commons with 69 votes.</p><p>It will now go through the same process in the Lords, and if passed, receive Royal Assent to become an act.</p><p>The bill, also known as the Snooper's Charter, proposes forcing internet service providers to store people's web browsing histories (a list of sites, not pages, they visit) for up to a year.</p><p>It would also see companies install backdoors' into their encryption to allow the government to access data a move much criticised by cybersecurity experts.</p><p>But Tory MP Dominic Grieve said: "The [Intelligence and Security Committee of Parliament] has always taken the collective view that this legislation is necessary, and that that necessity applies to bulk powers of collection."</p><p>While the majority of Labour MPs supported the bill, the SNP declined to back it over privacy fears.</p><p>Anne McLaughlin, SNP MP for Glasgow North East, said: "When we are dealing with proposals that are so broadthe proposal is effectively for bulk data harvesting from mainly innocent citizensit is incumbent on the Government to prove that there is an operational case and that the powers are necessary, and to ensure that the safeguards in place are rigorous. The Government have neither proven the operational case for the powers nor have they delivered safeguards and oversight of sufficient calibre to make the powers justifiable."</p><p>Critics of the bill claim the government is trying to rush the bill through Parliament, with Tory backbencher David Davis saying the 300-page bill <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">left MPs with five seconds to consider each line on the second reading</a>.</p><p>Independent QC David Anderson is conducting a review into the bill's proposals and is expected to publish a report before the House of Lords considers the measures.</p><p>Grieve said: "We look forward to and will accept David Anderson's report, and will consider whether there are indeed any alternatives that might be advanced, but I have to say that, on the basis of everything that we have seen up to now, we believe that bulk powers are needed, although sensible and proper safeguards are required to ensure that they cannot be abused."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26696/444-mps-push-investigatory-powers-bill-forward-into-house-of-lords</link>
                                                                            <description>
                            <![CDATA[ House of Commons passes Snooper’s Charter despite privacy concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8gZFDanyV3VfexN3Zc747B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2016 12:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwfxxkWEFLKg9Y2pADXqmY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Parliament <a href="https://hansard.parliament.uk/commons/2016-06-07/debates/16060732000001/InvestigatoryPowersBill">voted overwhelmingly in favour of the Investigatory Powers Bill yesterday</a>, with 444 MPs deciding to move it into the House of Lords.</p><p>Only the Scottish National Party, the Green Party, and the Liberal Democrats opposed the bill's third reading in the House of Commons with 69 votes.</p><p>It will now go through the same process in the Lords, and if passed, receive Royal Assent to become an act.</p><p>The bill, also known as the Snooper's Charter, proposes forcing internet service providers to store people's web browsing histories (a list of sites, not pages, they visit) for up to a year.</p><p>It would also see companies install backdoors' into their encryption to allow the government to access data a move much criticised by cybersecurity experts.</p><p>But Tory MP Dominic Grieve said: "The [Intelligence and Security Committee of Parliament] has always taken the collective view that this legislation is necessary, and that that necessity applies to bulk powers of collection."</p><p>While the majority of Labour MPs supported the bill, the SNP declined to back it over privacy fears.</p><p>Anne McLaughlin, SNP MP for Glasgow North East, said: "When we are dealing with proposals that are so broadthe proposal is effectively for bulk data harvesting from mainly innocent citizensit is incumbent on the Government to prove that there is an operational case and that the powers are necessary, and to ensure that the safeguards in place are rigorous. The Government have neither proven the operational case for the powers nor have they delivered safeguards and oversight of sufficient calibre to make the powers justifiable."</p><p>Critics of the bill claim the government is trying to rush the bill through Parliament, with Tory backbencher David Davis saying the 300-page bill <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">left MPs with five seconds to consider each line on the second reading</a>.</p><p>Independent QC David Anderson is conducting a review into the bill's proposals and is expected to publish a report before the House of Lords considers the measures.</p><p>Grieve said: "We look forward to and will accept David Anderson's report, and will consider whether there are indeed any alternatives that might be advanced, but I have to say that, on the basis of everything that we have seen up to now, we believe that bulk powers are needed, although sensible and proper safeguards are required to ensure that they cannot be abused."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy International challenges Snooper's Charter blanket hacking warrants in High Court ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Privacy International has appealed to the High Court to strike down a key part of the Investigatory Powers Bill that allows the government to issue blanket hacking warrants to GCHQ.</p><p>The so-called "thematic warrants" contained in the so-called Snooper's Charter allow the spy agency to hack into the computers and phones of people both inside and outside the UK.</p><p>Unlike normal warrants, they do not require a single target to be named and can instead be used to cover an entire class of unnamed property or persons, such as "all mobile phones in Nottingham" in the example given by the campaign group.</p><p>Privacy International initially raised a complaint about these general warrants in 2014, when it took its case to the Investigatory Powers Tribunal (IPT), which oversees agencies including GCHQ.</p><p>The campaign group had argued that such blanket warrants have no basis in UK law and also violate Articles 8 and 10 of the European Convention on Human Rights (ECHR) - the rights to privacy and freedon of speech. However, the IPT ruled in favour of the government in February this year.</p><p>Consequently, the organisation has taken its case to the High Court, seeking to overturn the IPT's ruling. As well as its claims that thematic warrants violate the ECHR, the group is also claiming that it undermines 250 years of English common law, which it claimed "has long rejected general warrants".</p><p>"The IPT's decision grants the government carte blanche to hack hundreds or thousands of people's computers and phones with a single warrant," said Privacy International's legal officer, Scarlet Kim. "General warrants permit GCHQ to target an entire class of persons or property without proving to a judge that each person affected is suspected of a crime or a threat to national security."</p><p>"By sanctioning this power, the IPT has upended 250 years of common law that makes clear such warrants are unlawful. Combined with the power to hack, these warrants represent an extraordinary expansion of state surveillance capabilities with alarming consequences for the security of our devices and the internet," Kim added.</p><p>Saying that these thematic warrants are a keystone of the Snooper's Charter, Privacy International claimed the entire bill could be called into question should it win its case in the High Court.</p><p>The group is not the only body to express concern over the inclusion of the warrants in the IP Bill. In February, <a href="https://www.itpro.com/public-sector/26015/snooper-s-charter-fails-to-protect-privacy-warn-mps" target="_blank" data-original-url="https://www.itpro.com/public-sector/26015/snooper-s-charter-fails-to-protect-privacy-warn-mps">the Intelligence and Security Committee (ISC) recommended "substantive amendments"</a> to the wording of the bill, adding that it was unconvinced by some of the legal frameworks for its implementation, including various hacking warrants.</p><p>The lawfulness of bulk data collection under DRIPA - the emergency stop-gap regulation the government hopes will be replaced by the Investigatory Powers Bill - has also been challenged by MPs Tom Watson and David Davis, with <a href="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter">the case currently progressing through the European Court of Justice (ECJ)</a>.</p><p>If DRIPA is found to break the rights to private and family life as defined in the Charter of Fundamental Rights of the European Union, it could scupper many of the plans laid out in the Snooper's Charter as well.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/26505/privacy-international-challenges-snoopers-charter-blanket-hacking-warrants-in</link>
                                                                            <description>
                            <![CDATA[ Campaign group files for judicial review of Investigatory Powers Bill's cornerstone policy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jSnEFKBdy2wfB4wGnNyhjp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 May 2016 09:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Statue of a woman holding the scales of justice]]></media:description>                                                            <media:text><![CDATA[Statue of a woman holding the scales of justice]]></media:text>
                                <media:title type="plain"><![CDATA[Statue of a woman holding the scales of justice]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EBJ5KbtbbaQH8TEPyhRcha-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy International has appealed to the High Court to strike down a key part of the Investigatory Powers Bill that allows the government to issue blanket hacking warrants to GCHQ.</p><p>The so-called "thematic warrants" contained in the so-called Snooper's Charter allow the spy agency to hack into the computers and phones of people both inside and outside the UK.</p><p>Unlike normal warrants, they do not require a single target to be named and can instead be used to cover an entire class of unnamed property or persons, such as "all mobile phones in Nottingham" in the example given by the campaign group.</p><p>Privacy International initially raised a complaint about these general warrants in 2014, when it took its case to the Investigatory Powers Tribunal (IPT), which oversees agencies including GCHQ.</p><p>The campaign group had argued that such blanket warrants have no basis in UK law and also violate Articles 8 and 10 of the European Convention on Human Rights (ECHR) - the rights to privacy and freedon of speech. However, the IPT ruled in favour of the government in February this year.</p><p>Consequently, the organisation has taken its case to the High Court, seeking to overturn the IPT's ruling. As well as its claims that thematic warrants violate the ECHR, the group is also claiming that it undermines 250 years of English common law, which it claimed "has long rejected general warrants".</p><p>"The IPT's decision grants the government carte blanche to hack hundreds or thousands of people's computers and phones with a single warrant," said Privacy International's legal officer, Scarlet Kim. "General warrants permit GCHQ to target an entire class of persons or property without proving to a judge that each person affected is suspected of a crime or a threat to national security."</p><p>"By sanctioning this power, the IPT has upended 250 years of common law that makes clear such warrants are unlawful. Combined with the power to hack, these warrants represent an extraordinary expansion of state surveillance capabilities with alarming consequences for the security of our devices and the internet," Kim added.</p><p>Saying that these thematic warrants are a keystone of the Snooper's Charter, Privacy International claimed the entire bill could be called into question should it win its case in the High Court.</p><p>The group is not the only body to express concern over the inclusion of the warrants in the IP Bill. In February, <a href="https://www.itpro.com/public-sector/26015/snooper-s-charter-fails-to-protect-privacy-warn-mps" target="_blank" data-original-url="https://www.itpro.com/public-sector/26015/snooper-s-charter-fails-to-protect-privacy-warn-mps">the Intelligence and Security Committee (ISC) recommended "substantive amendments"</a> to the wording of the bill, adding that it was unconvinced by some of the legal frameworks for its implementation, including various hacking warrants.</p><p>The lawfulness of bulk data collection under DRIPA - the emergency stop-gap regulation the government hopes will be replaced by the Investigatory Powers Bill - has also been challenged by MPs Tom Watson and David Davis, with <a href="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter">the case currently progressing through the European Court of Justice (ECJ)</a>.</p><p>If DRIPA is found to break the rights to private and family life as defined in the Charter of Fundamental Rights of the European Union, it could scupper many of the plans laid out in the Snooper's Charter as well.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Campaigners reveal government's secret spying regime ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The scale of mass data surveillance in the UK is far more sweeping than the government's official proposals currently being considered by Parliament, documents have revealed.</p><p>Security services MI5, MI6 and GCHQ have used Section 94 of the Telecommunications Act 1984 to justify gathering hundreds of millions of records onBritish citizens and other UK residents for the last 15 years, Privacy International found.</p><p>Spy agency analysts can then link together these records using filters such as telephone numbers or other values, the campaign group said, after receiving the documents as it prepares for a tribunal ontheInvestigatory Powers Bill.</p><p>Section 94 has also enabled them to access data outside the protection of the existing Regulation of Investigatory Powers Act (RIPA), and even goes beyond the powers proposed in the Investigatory Powers Bill,the government's proposed legislation that would force internet service providers to collect and hold certain data on people's web browsing histories for up to a year.</p><p>This is because section 94potentially allowed for the collection of medical and biometric data, such as blood type and hair and eye colour, though there is no indication that these kinds of information have been collected.</p><p>The existence of Bulk Personal Datasets (BPDs), as they are called, was first revealed in March 2015 in an Intelligence & Security Committee (ISC) report, however, they have existed for the past 15 years without the knowledge of the public or Parliament.</p><p>Millie Graham Wood, legal officer at Privacy International said: "The information revealed by this disclosure shows the staggering extent to which the intelligence agencies hoover up our data.</p><p>"This can be anything from your private medical records, your correspondence with your doctor or lawyer, even what petitions you have signed, your financial data, and commercial activities."</p><p>"The agencies have been doing this for 15 years in secret and are now quietly trying to put these powers on the statute book for the first time, in the Investigatory Powers Bill," she added.</p><p>Jacob Ginsberg, senior director of encryption software company Echoworx and outspoken opponent of Investigatory Powers, said: "The UK government and its intelligence agencies are watching UK citizens as if they were criminals."</p><p>"The government should not be allowed to circumvent existing laws that have been put in place to protect law-abiding citizens from potentially harmful intrusion. Having the power to sweep someone's phone records, financial data, medical records and internet communications without a warrant during bulk data collection is morally wrong," he added.</p><p>The details of the case and associated documents can be read <a href="https://privacyinternational.org/node/843" target="_blank">here</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/26403/campaigners-reveal-governments-secret-spying-regime</link>
                                                                            <description>
                            <![CDATA[ Intelligence services have had access to people's health, financial and communication data for 15 years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9sPQnNFGYUCn8NBLARH93d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Apr 2016 14:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zv6gJJCikkHSn82qsd2n3B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The scale of mass data surveillance in the UK is far more sweeping than the government's official proposals currently being considered by Parliament, documents have revealed.</p><p>Security services MI5, MI6 and GCHQ have used Section 94 of the Telecommunications Act 1984 to justify gathering hundreds of millions of records onBritish citizens and other UK residents for the last 15 years, Privacy International found.</p><p>Spy agency analysts can then link together these records using filters such as telephone numbers or other values, the campaign group said, after receiving the documents as it prepares for a tribunal ontheInvestigatory Powers Bill.</p><p>Section 94 has also enabled them to access data outside the protection of the existing Regulation of Investigatory Powers Act (RIPA), and even goes beyond the powers proposed in the Investigatory Powers Bill,the government's proposed legislation that would force internet service providers to collect and hold certain data on people's web browsing histories for up to a year.</p><p>This is because section 94potentially allowed for the collection of medical and biometric data, such as blood type and hair and eye colour, though there is no indication that these kinds of information have been collected.</p><p>The existence of Bulk Personal Datasets (BPDs), as they are called, was first revealed in March 2015 in an Intelligence & Security Committee (ISC) report, however, they have existed for the past 15 years without the knowledge of the public or Parliament.</p><p>Millie Graham Wood, legal officer at Privacy International said: "The information revealed by this disclosure shows the staggering extent to which the intelligence agencies hoover up our data.</p><p>"This can be anything from your private medical records, your correspondence with your doctor or lawyer, even what petitions you have signed, your financial data, and commercial activities."</p><p>"The agencies have been doing this for 15 years in secret and are now quietly trying to put these powers on the statute book for the first time, in the Investigatory Powers Bill," she added.</p><p>Jacob Ginsberg, senior director of encryption software company Echoworx and outspoken opponent of Investigatory Powers, said: "The UK government and its intelligence agencies are watching UK citizens as if they were criminals."</p><p>"The government should not be allowed to circumvent existing laws that have been put in place to protect law-abiding citizens from potentially harmful intrusion. Having the power to sweep someone's phone records, financial data, medical records and internet communications without a warrant during bulk data collection is morally wrong," he added.</p><p>The details of the case and associated documents can be read <a href="https://privacyinternational.org/node/843" target="_blank">here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers 'will cost UK £1 billion' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Investigatory Powers Bill could end up costing the UK government more than 1 billion, according to campaigners.</p><p>While the Home Office has set aside 174 million over 10 years to reimburse internet service providers required to collect the web browsing histories of all UK citizens, one of the bill's proposals, the Don't Spy On Us coalition said today that the cost will exceed 1 billion.</p><p>Basing its figures on a similar scheme that was recently rejected on cost grounds in Denmark, the coalition scaled up the costs proportionally for the UK.</p><p>The Danish Government decided to scrap the monitoring plans when Enrst & Young confirmed it would cost 105 million to set up the necessary infrastructure to support the scheme.</p><p>With Denmark's population numbering 5.6 million, Don't Spy On Us pegged the costs for the UK's 64 million population at 10 times that figure.</p><p>Director of the campaign group, Eric King, called on the government to get an independent cost analysis, saying: "The government is trying to force internet service providers to collect all of our internet connection records but refuses to listen when they express concerns about the cost and feasibility of their proposals.</p><p>"As in Denmark, the government should commission an independent cost analysis to clarify the true cost of collecting Internet Connection Records (ICRs). There is no evidence that collecting ICRs makes us safer." </p><p>BT Security president Mark Hughes told the Joint Committee of Parliament looking into the Investigatory Powers Bill last December that the 174 million earmarked by the government would only cover BT's costs of creating the infrastructure necessary to comply with the bill, also dubbed the Snooper's Charter.</p><p>Virgin Media believes its owns costs will hit tens of millions of pounds.</p><p>Lord Paddick, Liberal Democrats spokesman on Home Affairs in the House of Lords, said: "Now that we have a professional estimate that it would cost well over 1 billion in set-up costs alone and could be easily circumvented by criminals for just a few pounds a week, apart from anything else, this represents appallingly bad value for money."</p><p>A Home Office spokesman said: ""There are a number of fundamental differences between our Bill and the Danish model, and the independent Joint Committee of Parliament acknowledged this. It is absolutely incorrect to suggest we are implementing the Danish model.</p><p>"We have worked closely with communications service providers (CSPs) to carefully estimate the cost of implementing a system to retain internet connection records. And we will continue to work with CSPs to refine that cost as the Bill progresses. </p><p>"We are determined to implement the legislation in a way that will deliver the maximum operational benefit for the police and law enforcement agencies. Our proposals provide a comprehensive and comprehensible framework for investigatory powers, with robust safeguards and world-leading oversight."</p><p><strong>01/03/2016: Home Office introduces Investigatory Powers bill to Parliament</strong></p><p>The Home Office introduced its controversial <a href="https://www.gov.uk/government/collections/investigatory-powers-bill" target="_blank">Investigatory Powers Bill</a> to Parliament today with a number of amendments, amid fears that it is trying to rush the bill through the House without subjecting it to democratic scrutiny.</p><p>The government claimed the latest version of the bill, also known as the Snooper's Charter, addresses concerns raised by three separate committees, the last of which, the Joint Select Committee, called it "flawed" and recommended 86 amendments.</p><p>"This is vital legislation and we are determined to get it right. Our proposals have been studied in detail by a Joint Committee of both Houses of Parliament established to provide rigorous scrutiny, and two further committees," <a href="http://www.parliament.uk/business/publications/written-questions-answers-statements/written-statement/Commons/2016-03-01/HCWS568" target="_blank">said Home Secretary Theresa May</a>.</p><p>"The revised bill we introduced today reflects the majority of the committees' recommendations we have strengthened safeguards, enhanced privacy protections and bolstered oversight arrangements.</p><p>"Terrorists and criminals are operating online and we need to ensure the police and security services can keep pace with the modern world and continue to protect the British public from the many serious threats we face."</p><p>However, the majority of the amendments do not change the bill itself, rather creating additional oversight for the proposed legislation.</p><p><strong>Key changes include:</strong></p><p>- The security agencies will be required to reapply for equipment interference warrants the power to hack computers and telephones every three days, rather than every five days.</p><p>- UK security and intelligence agencies cannot request foreign agencies to conduct intelligence for the UK government unless they have a warrant from a Secretary of State and judicial commissioner.</p><p>- The government will work with the tech industry to implement the retention of internet connection records (ICRs) by telecoms companies. Six draft statutory codes of practice related to "bulk powers" have also been published alongside the bill.</p><p>- It will allow for ICRs gathered by ISPs to be used in "the pursuit of investigative leads".</p><p>- Companies will be asked to remove encryption they have applied themselves and "where it is practical to do so".</p><p>- Extra protection for journalists' sources</p><p>- The Lord Chief Justice will have the power to inform people who have suffered as a result of the inappropriate use of powers.</p><p>The government claimed that recommendations that were not implemented were turned down because they "would compromise the capabilities of law enforcement and the security and intelligence agencies".</p><p><strong>Reaction</strong></p><p>Following the bill's publication this afternoon, Nigel Hawthorn, European spokesperson for cloud software company Skyhigh Networks, accused the government of risking the wellbeing of British businesses.</p><p>"Using the argument of national security as a battering ram, the government is once again taking an approach that will cause more harm than good for businesses," he said. "Encryption is a key capability that makes business traffic safe from prying eyes, and asking companies to weaken, restrict or introduce backdoors is a sure fire way to ensure that sensitive data will find its way into the wrong hands.</p><p>"Everyone has a right to privacy, but the government is doing its utmost to take that away."</p><p>Antony Walker, deputy CEO of business association TechUK, called for assurances that MPs would have enough time to debate the bill, saying: "The test now is to understand if this bill addresses the very serious concerns that have been laid out by the tech industry and three Parliamentary committees.</p><p>"This is a complex bill, with significance for all of us. Parliamentarians must have time necessary to subject it to the maximum parliamentary scrutiny' the Home Office has promised.</p><p>"As more details emerge, tech companies are urgently seeking to understand what is being asked of them and the implications for their business, their customers and the security of our digital economy."</p><p><strong>29/02/2016:</strong> <strong>Gov 'rushing Investigatory Powers bill through Parliament'</strong></p><p>The government is set to officially introduce the Investigatory Powers bill in Parliament tomorrow, amid claims it is rushing the bill through in order to avoid scrutiny.</p><p>The news comes just two weeks after the Joint Select Committee ripped apart the proposed Snooper's Charter, calling it "flawed" and recommending 86 changes to the legislation.</p><p>Were it passed in its latest form, the bill would require ISPs to hold details on people's web browsing history for up to 12 months, and force companies to build backdoors into their encryption to give spies access to users' data.</p><p>Despite the criticism the bill has received, Home Secretary Theresa May plans to publish it tomorrow, according to the <a href="http://www.independent.co.uk/news/uk/politics/investigatory-powers-bill-theresa-may-accused-of-rushing-snoopers-charter-into-law-to-avoid-scrutiny-a6900566.html"><em>Independent</em></a>.</p><p>A line-by-line debate will then take place on 14 March before the committee scrutinises it on 22 March. A final vote is expected by the end of April.</p><p>However, Tory backbencher David Davis accused the government of rushing the legislation through Parliament, giving MPs little time to properly debate the bill.</p><p>He told the <em>Independent</em>: "When you work it out, it's a 300-page bill so that's something like five seconds to consider each line on second reading.</p><p>"It all keeps with their strategy, which is to rush everything through. They know when they engage with experts they lose. This is the way they will try to get this through on the rush. There's no doubt about it."</p><p>The Joint Select Committee has delivered three damaging reports on the bill, criticising a perceived lack of clarity on key issues including encryption, internet connection records, bulk equipment interference powers and extraterritorial reach.</p><p>Chairman of the committee, Lord Murphy of Torfaen, said earlier this month: "The Home Office has a significant amount of further work to do before Parliament can be confident that the provisions have been fully thought through."</p><p><strong>11/02/2016: "Significant changes" needed in Investigatory Powers Bill</strong></p><p>The Investigatory Powers Bill needs a significant amount of work before it can become law, the Joint Select Committee set up to review the proposed legislation has found.</p><p>In <a href="http://www.publications.parliament.uk/pa/jt201516/jtselect/jtinvpowers/93/9302.htm">its report on the bill</a> he committee has made 86 detailed recommendations to the government for revisions to the bill "aimed at ensuring that the powers within [it] are workable, can be clearly understood by those affected by them and have proper safeguards"</p><p>These include making it clearer in the text of the bill that companies will not be required to install 'backdoors' in their encryption to enable law enforcement automatic access, which had been a major concern amongst technology firms and civil liberties groups alike.</p><p>Other key recommendations include fuller justification of bulk collection of data - an issue that was also raised by the Intelligence and Security Select Committee in its report at the beginning of February - and the need to properly define the Internet Connections Record provision as well as determining if it is, in its current form, actually feasible.</p><p>The Joint Select Committee also said it should be illegal for the UK to ask foreign intelligence agencies, such as the NSA, to undertake intrusion they do not have permission to do.</p><p>ISPs should also be given financial support by the government to safeguard the security of the data they are forced to retain, however, this should not cover 100 per cent of all the costs data storage.</p><p>"There is much to be commended in the draft Bill, but the Home Office has a significant amount of further work to do before Parliament can be confident that the provisions have been fully thought through," said Lord Murphy of Torfaen, the chairman of the Committee.</p><p>"In some important cases, such as the proposal for communications service providers to create and store users' internet connection records, the Committee saw the potential value of the proposal but also that the cost and other practical implications are still being worked out," he added.</p><p>The industry reaction has largely reacted positively to the report and the recommendations contained within it.</p><p>Antony Walker, deputy CEO of industry body techUK said: "We've now had three Parliamentary reports raising serious concerns with this draft Bill. On vital issues like encryption, internet connection records, bulk equipment interference powers and extraterritorial reach all three reports have said that there are still too many aspects that are unclear, poorly defined or just wrong. The Home Office must recognise this and address the fundamental concerns raised by expert witnesses, MPs and Lords."</p><p>"We fully support the concerns and recommendations raised by the Joint Committee in the latest parliamentary report. There is a severe lack of clarity around encryption and bulk data collection in the current proposal," said Jacob Ginsberg, senior director of security firm Echoworx.</p><p>He reiterated <a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed">comments made to <em>Cloud Pro</em></a> earlier in the year that a lack of clarity around backdoors in end-to-end encryption could drive businesses, particularly those involved in storage and the cloud, from the UK, costing the Treasury tens-of-millions of pounds.</p><p>Mike Weston, CEO of data science consultancy Profusion also welcomed the report but ultimately said the government "should tear up the IP Bill and start again, developing new legislation in partnership with the tech industry and privacy bodies" adding that the proposed legislation "is in stark contrast with the approach taken by the EU's new data protection legislation".</p><p>"While imperfect, [the EU legislation: is, at least, a step towards reinforcing data privacy tor European citizens," said Weston. "The Bill is in closer standing with America's approach to data protection, which is extremely worrying."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion</link>
                                                                            <description>
                            <![CDATA[ Setting up the Snooper's Charter will dwarf government estimates of £174m, warn campaigners ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wKUkQ9oCD24PUavoXvYQiT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K6eiJDRoxdY3RY4QZkKPW8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Mar 2016 15:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K6eiJDRoxdY3RY4QZkKPW8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethernet plug with fiber optic wire]]></media:description>                                                            <media:text><![CDATA[Ethernet plug with fiber optic wire]]></media:text>
                                <media:title type="plain"><![CDATA[Ethernet plug with fiber optic wire]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K6eiJDRoxdY3RY4QZkKPW8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Bill could end up costing the UK government more than 1 billion, according to campaigners.</p><p>While the Home Office has set aside 174 million over 10 years to reimburse internet service providers required to collect the web browsing histories of all UK citizens, one of the bill's proposals, the Don't Spy On Us coalition said today that the cost will exceed 1 billion.</p><p>Basing its figures on a similar scheme that was recently rejected on cost grounds in Denmark, the coalition scaled up the costs proportionally for the UK.</p><p>The Danish Government decided to scrap the monitoring plans when Enrst & Young confirmed it would cost 105 million to set up the necessary infrastructure to support the scheme.</p><p>With Denmark's population numbering 5.6 million, Don't Spy On Us pegged the costs for the UK's 64 million population at 10 times that figure.</p><p>Director of the campaign group, Eric King, called on the government to get an independent cost analysis, saying: "The government is trying to force internet service providers to collect all of our internet connection records but refuses to listen when they express concerns about the cost and feasibility of their proposals.</p><p>"As in Denmark, the government should commission an independent cost analysis to clarify the true cost of collecting Internet Connection Records (ICRs). There is no evidence that collecting ICRs makes us safer." </p><p>BT Security president Mark Hughes told the Joint Committee of Parliament looking into the Investigatory Powers Bill last December that the 174 million earmarked by the government would only cover BT's costs of creating the infrastructure necessary to comply with the bill, also dubbed the Snooper's Charter.</p><p>Virgin Media believes its owns costs will hit tens of millions of pounds.</p><p>Lord Paddick, Liberal Democrats spokesman on Home Affairs in the House of Lords, said: "Now that we have a professional estimate that it would cost well over 1 billion in set-up costs alone and could be easily circumvented by criminals for just a few pounds a week, apart from anything else, this represents appallingly bad value for money."</p><p>A Home Office spokesman said: ""There are a number of fundamental differences between our Bill and the Danish model, and the independent Joint Committee of Parliament acknowledged this. It is absolutely incorrect to suggest we are implementing the Danish model.</p><p>"We have worked closely with communications service providers (CSPs) to carefully estimate the cost of implementing a system to retain internet connection records. And we will continue to work with CSPs to refine that cost as the Bill progresses. </p><p>"We are determined to implement the legislation in a way that will deliver the maximum operational benefit for the police and law enforcement agencies. Our proposals provide a comprehensive and comprehensible framework for investigatory powers, with robust safeguards and world-leading oversight."</p><p><strong>01/03/2016: Home Office introduces Investigatory Powers bill to Parliament</strong></p><p>The Home Office introduced its controversial <a href="https://www.gov.uk/government/collections/investigatory-powers-bill" target="_blank">Investigatory Powers Bill</a> to Parliament today with a number of amendments, amid fears that it is trying to rush the bill through the House without subjecting it to democratic scrutiny.</p><p>The government claimed the latest version of the bill, also known as the Snooper's Charter, addresses concerns raised by three separate committees, the last of which, the Joint Select Committee, called it "flawed" and recommended 86 amendments.</p><p>"This is vital legislation and we are determined to get it right. Our proposals have been studied in detail by a Joint Committee of both Houses of Parliament established to provide rigorous scrutiny, and two further committees," <a href="http://www.parliament.uk/business/publications/written-questions-answers-statements/written-statement/Commons/2016-03-01/HCWS568" target="_blank">said Home Secretary Theresa May</a>.</p><p>"The revised bill we introduced today reflects the majority of the committees' recommendations we have strengthened safeguards, enhanced privacy protections and bolstered oversight arrangements.</p><p>"Terrorists and criminals are operating online and we need to ensure the police and security services can keep pace with the modern world and continue to protect the British public from the many serious threats we face."</p><p>However, the majority of the amendments do not change the bill itself, rather creating additional oversight for the proposed legislation.</p><p><strong>Key changes include:</strong></p><p>- The security agencies will be required to reapply for equipment interference warrants the power to hack computers and telephones every three days, rather than every five days.</p><p>- UK security and intelligence agencies cannot request foreign agencies to conduct intelligence for the UK government unless they have a warrant from a Secretary of State and judicial commissioner.</p><p>- The government will work with the tech industry to implement the retention of internet connection records (ICRs) by telecoms companies. Six draft statutory codes of practice related to "bulk powers" have also been published alongside the bill.</p><p>- It will allow for ICRs gathered by ISPs to be used in "the pursuit of investigative leads".</p><p>- Companies will be asked to remove encryption they have applied themselves and "where it is practical to do so".</p><p>- Extra protection for journalists' sources</p><p>- The Lord Chief Justice will have the power to inform people who have suffered as a result of the inappropriate use of powers.</p><p>The government claimed that recommendations that were not implemented were turned down because they "would compromise the capabilities of law enforcement and the security and intelligence agencies".</p><p><strong>Reaction</strong></p><p>Following the bill's publication this afternoon, Nigel Hawthorn, European spokesperson for cloud software company Skyhigh Networks, accused the government of risking the wellbeing of British businesses.</p><p>"Using the argument of national security as a battering ram, the government is once again taking an approach that will cause more harm than good for businesses," he said. "Encryption is a key capability that makes business traffic safe from prying eyes, and asking companies to weaken, restrict or introduce backdoors is a sure fire way to ensure that sensitive data will find its way into the wrong hands.</p><p>"Everyone has a right to privacy, but the government is doing its utmost to take that away."</p><p>Antony Walker, deputy CEO of business association TechUK, called for assurances that MPs would have enough time to debate the bill, saying: "The test now is to understand if this bill addresses the very serious concerns that have been laid out by the tech industry and three Parliamentary committees.</p><p>"This is a complex bill, with significance for all of us. Parliamentarians must have time necessary to subject it to the maximum parliamentary scrutiny' the Home Office has promised.</p><p>"As more details emerge, tech companies are urgently seeking to understand what is being asked of them and the implications for their business, their customers and the security of our digital economy."</p><p><strong>29/02/2016:</strong> <strong>Gov 'rushing Investigatory Powers bill through Parliament'</strong></p><p>The government is set to officially introduce the Investigatory Powers bill in Parliament tomorrow, amid claims it is rushing the bill through in order to avoid scrutiny.</p><p>The news comes just two weeks after the Joint Select Committee ripped apart the proposed Snooper's Charter, calling it "flawed" and recommending 86 changes to the legislation.</p><p>Were it passed in its latest form, the bill would require ISPs to hold details on people's web browsing history for up to 12 months, and force companies to build backdoors into their encryption to give spies access to users' data.</p><p>Despite the criticism the bill has received, Home Secretary Theresa May plans to publish it tomorrow, according to the <a href="http://www.independent.co.uk/news/uk/politics/investigatory-powers-bill-theresa-may-accused-of-rushing-snoopers-charter-into-law-to-avoid-scrutiny-a6900566.html"><em>Independent</em></a>.</p><p>A line-by-line debate will then take place on 14 March before the committee scrutinises it on 22 March. A final vote is expected by the end of April.</p><p>However, Tory backbencher David Davis accused the government of rushing the legislation through Parliament, giving MPs little time to properly debate the bill.</p><p>He told the <em>Independent</em>: "When you work it out, it's a 300-page bill so that's something like five seconds to consider each line on second reading.</p><p>"It all keeps with their strategy, which is to rush everything through. They know when they engage with experts they lose. This is the way they will try to get this through on the rush. There's no doubt about it."</p><p>The Joint Select Committee has delivered three damaging reports on the bill, criticising a perceived lack of clarity on key issues including encryption, internet connection records, bulk equipment interference powers and extraterritorial reach.</p><p>Chairman of the committee, Lord Murphy of Torfaen, said earlier this month: "The Home Office has a significant amount of further work to do before Parliament can be confident that the provisions have been fully thought through."</p><p><strong>11/02/2016: "Significant changes" needed in Investigatory Powers Bill</strong></p><p>The Investigatory Powers Bill needs a significant amount of work before it can become law, the Joint Select Committee set up to review the proposed legislation has found.</p><p>In <a href="http://www.publications.parliament.uk/pa/jt201516/jtselect/jtinvpowers/93/9302.htm">its report on the bill</a> he committee has made 86 detailed recommendations to the government for revisions to the bill "aimed at ensuring that the powers within [it] are workable, can be clearly understood by those affected by them and have proper safeguards"</p><p>These include making it clearer in the text of the bill that companies will not be required to install 'backdoors' in their encryption to enable law enforcement automatic access, which had been a major concern amongst technology firms and civil liberties groups alike.</p><p>Other key recommendations include fuller justification of bulk collection of data - an issue that was also raised by the Intelligence and Security Select Committee in its report at the beginning of February - and the need to properly define the Internet Connections Record provision as well as determining if it is, in its current form, actually feasible.</p><p>The Joint Select Committee also said it should be illegal for the UK to ask foreign intelligence agencies, such as the NSA, to undertake intrusion they do not have permission to do.</p><p>ISPs should also be given financial support by the government to safeguard the security of the data they are forced to retain, however, this should not cover 100 per cent of all the costs data storage.</p><p>"There is much to be commended in the draft Bill, but the Home Office has a significant amount of further work to do before Parliament can be confident that the provisions have been fully thought through," said Lord Murphy of Torfaen, the chairman of the Committee.</p><p>"In some important cases, such as the proposal for communications service providers to create and store users' internet connection records, the Committee saw the potential value of the proposal but also that the cost and other practical implications are still being worked out," he added.</p><p>The industry reaction has largely reacted positively to the report and the recommendations contained within it.</p><p>Antony Walker, deputy CEO of industry body techUK said: "We've now had three Parliamentary reports raising serious concerns with this draft Bill. On vital issues like encryption, internet connection records, bulk equipment interference powers and extraterritorial reach all three reports have said that there are still too many aspects that are unclear, poorly defined or just wrong. The Home Office must recognise this and address the fundamental concerns raised by expert witnesses, MPs and Lords."</p><p>"We fully support the concerns and recommendations raised by the Joint Committee in the latest parliamentary report. There is a severe lack of clarity around encryption and bulk data collection in the current proposal," said Jacob Ginsberg, senior director of security firm Echoworx.</p><p>He reiterated <a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed">comments made to <em>Cloud Pro</em></a> earlier in the year that a lack of clarity around backdoors in end-to-end encryption could drive businesses, particularly those involved in storage and the cloud, from the UK, costing the Treasury tens-of-millions of pounds.</p><p>Mike Weston, CEO of data science consultancy Profusion also welcomed the report but ultimately said the government "should tear up the IP Bill and start again, developing new legislation in partnership with the tech industry and privacy bodies" adding that the proposed legislation "is in stark contrast with the approach taken by the EU's new data protection legislation".</p><p>"While imperfect, [the EU legislation: is, at least, a step towards reinforcing data privacy tor European citizens," said Weston. "The Bill is in closer standing with America's approach to data protection, which is extremely worrying."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Home Office faces EU court battle over Snooper’s Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European Court of Justice (ECJ) is set to scrutinise the UK government's plans for bulk data collection and retention at an emergency hearing on 12 April.</p><p>Its intervention was demanded by the Court of Appeal of England and Wales to <a href="http://curia.europa.eu/juris/document/document.jsf?text=&docid=175038&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1&cid=450816" target="_blank">help decide</a>whether existing government spying measures are incompatible withthe Charter of Fundamental Rights of the European Union.</p><p>Depending on the outcome of the hearing, the ECJ could scupper the government's plans to pass the Investigatory Powers Bill into law.</p><p>The Court of Appeal asked the ECJ to examine a casebrought by MPs Tom Watson and David Davis and their co-claimants, Peter Brice and Geoffrey Lewis, against Home Secretary Theresa May'sData Retention and Investigatory Powers Act 2014 (DRIPA).</p><p>DRIPA is a piece of emergency legislation that came into force in July 2014 and expires on 31 December 2016 that governs the interception of electronic communications data.</p><p>Watson, Davis, and their fellow claimants argued that two sections of DRIPA - Section 1 (powers for retention of relevant communications data subject safeguards) and Section 2 (definitions of the terms used in section one) -<a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">were unlawful</a>because they are incompatible with EU Charter articles outlining respect for private and family life and the protection of personal data.</p><p>In mid-2015, the High Court of England and Wales ruled in the claimants' favour.The Home Secretary appealed this decision, which would have seen a time limit for the enforcement of the unlawful sections run out on Thursday of this week.</p><p>The government hopes that the Investigatory Powers Bill, which would compelinternet service providers to keep aspects of people's web browsing histories for 12 months, will replace DRIPA, but if the ECJ upholds the High Court's ruling, it could mean that the Investigatory Powers Bill is also incompatible with people's rights to privacy and data protection.</p><p>The bill <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">is currently making its way through Parliament</a>, under accusations that the government is trying to rush it into law.</p><p>It is now a three-way race to see which will happen first: Investigatory Powers receiving Royal Assent and becoming law, the ECJ issuing its ruling on the DRIPA case, or the EU referendum to decide whether or not the UK remains in the EU.</p><p><em><strong>Read more about the Investigatory Powers Bill and its potential effect on businesses, the tech industry and privacy.</strong></em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter</link>
                                                                            <description>
                            <![CDATA[ ECJ emergency hearing could shoot down Investigatory Powers Bill ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jLARq6eVpxiPvuCLbhmY7c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o9vpe4waR3GntsjrQnjCn7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Mar 2016 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o9vpe4waR3GntsjrQnjCn7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o9vpe4waR3GntsjrQnjCn7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Court of Justice (ECJ) is set to scrutinise the UK government's plans for bulk data collection and retention at an emergency hearing on 12 April.</p><p>Its intervention was demanded by the Court of Appeal of England and Wales to <a href="http://curia.europa.eu/juris/document/document.jsf?text=&docid=175038&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1&cid=450816" target="_blank">help decide</a>whether existing government spying measures are incompatible withthe Charter of Fundamental Rights of the European Union.</p><p>Depending on the outcome of the hearing, the ECJ could scupper the government's plans to pass the Investigatory Powers Bill into law.</p><p>The Court of Appeal asked the ECJ to examine a casebrought by MPs Tom Watson and David Davis and their co-claimants, Peter Brice and Geoffrey Lewis, against Home Secretary Theresa May'sData Retention and Investigatory Powers Act 2014 (DRIPA).</p><p>DRIPA is a piece of emergency legislation that came into force in July 2014 and expires on 31 December 2016 that governs the interception of electronic communications data.</p><p>Watson, Davis, and their fellow claimants argued that two sections of DRIPA - Section 1 (powers for retention of relevant communications data subject safeguards) and Section 2 (definitions of the terms used in section one) -<a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">were unlawful</a>because they are incompatible with EU Charter articles outlining respect for private and family life and the protection of personal data.</p><p>In mid-2015, the High Court of England and Wales ruled in the claimants' favour.The Home Secretary appealed this decision, which would have seen a time limit for the enforcement of the unlawful sections run out on Thursday of this week.</p><p>The government hopes that the Investigatory Powers Bill, which would compelinternet service providers to keep aspects of people's web browsing histories for 12 months, will replace DRIPA, but if the ECJ upholds the High Court's ruling, it could mean that the Investigatory Powers Bill is also incompatible with people's rights to privacy and data protection.</p><p>The bill <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">is currently making its way through Parliament</a>, under accusations that the government is trying to rush it into law.</p><p>It is now a three-way race to see which will happen first: Investigatory Powers receiving Royal Assent and becoming law, the ECJ issuing its ruling on the DRIPA case, or the EU referendum to decide whether or not the UK remains in the EU.</p><p><em><strong>Read more about the Investigatory Powers Bill and its potential effect on businesses, the tech industry and privacy.</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Encryption is a touchy subject for the Home Office ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The publication of the Modern Crime Prevention Strategy by the Home Office yesterday was meant to make clear how the government will tackle crime. Actually, it just knocked another couple of nails into the privacy coffin.</p><p>You can read the whole depressing thing <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/509831/6.1770_Modern_Crime_Prevention_Strategy_final_WEB_version.pdf" target="_blank">here</a>, though you can skip to chapter eight, about using data and tech to prevent crime.</p><p>This got off to a bad enough start with the opening paragraph, which read: "Data and technology are not drivers of crime in themselves. Rather, they are tools that are critical to successfully preventing crime."</p><p>Erm, really? So hackers are not driven to access databases in order to profit from the information contained within them then? The fact that we nearly all have mobile devices which unlock our bank accounts, for example, does not drive hackers to develop methods of attacking them?</p><p>Seriously, who wrote this drivel? "Finding and correcting weak spots in online banking systems will make fraud less profitable to organised criminals", they insist. Actually, patching vulnerabilities makes accessing those systems harder but it does not make successful fraud any less profitable.</p><p>The real driver behind the strategic thinking of the government is revealed soon enough in chapter eight though. "We need a culture change in which everyone recognises that, in a more connected society, we all have a part to play in preventing crime", it says.</p><p>Translated from spin to reality that would read: all your data belongs to us'.</p><p>How so? The Home Office is implementing the National Law Enforcement Data Programme, which is collecting all data from the Police National Computer, Police National Database and Automatic Number-Plate Recognition systems and putting it onto a single platform.</p><p>The ANPR datacentre has information on more than 22 billion car journeys, the vast majority of which will have been perfectly legal and not involved in any criminal activity at all, even after the Surveillance Camera Commissioner called into question the legality of collecting data on vehicles not known to be of interest to law enforcement last year.</p><p>It's all part of the predictive policing concept that sits at the heart of the strategy when it comes to the use of technology and data. Data that will be used to map criminal networks, identify trends, patterns and relationships. Remember that if you've done nothing wrong, you have nothing to fear, as you watch Minority Report once more.</p><p>The biggest load of drivel to emerge from chapter eight, however, is probably summed up in the paragraph that insists "members of the public... have a responsibility to follow some basic rules" such as "choosing the more secure products, installing security software on all our devices, downloading software updates (particularly on our smartphones) and using strong passwords".</p><p>No mention of using strong encryption on our smartphones, I note. Nor any mention of the government's desire to build backdoors into such encryption via the <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">Investigatory Powers Bill</a>, should spies need to access people's data.</p><p>Businesses, the report says, need to "take responsibility for ensuring their products and services don't create opportunities for criminals", which is as clear as very murky mud. So is the next line, which states they must do this "as well as protecting their own networks and making it as easy as possible for customers to avoid unnecessary risks".</p><p>The government fails to elaborate here on what kind of steps businesses should take outside of this vague guidance, steps as simple and necessary as encryption, for example.</p><p>Not that the strategy document ignores encryption altogether. It does recognise that it presents "opportunities for the public to protect their information from cyber criminals, and also for protecting government data, and making public services and communications with citizens secure" all of which is a good thing.</p><p>However, this is immediately followed by the big but: "Encryption also can present challenges, such as when the authorities want access to data that indicates criminal activity. We are monitoring the increasing sophistication of encryption techniques." </p><p>What it doesn't do, of course, is make any mention of the Investigatory Powers Bill and how the exact same government plans to weaken encryption so that actually <a href="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors" target="_blank" data-original-url="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors">it's of absolutely no use to anyone</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/26266/encryption-is-a-touchy-subject-for-the-home-office</link>
                                                                            <description>
                            <![CDATA[ Theresa May's Modern Crime Prevention Strategy: strong on rhetoric, light on security measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9QvVot4GHaHTqjmqr5kdHn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Mar 2016 14:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Magnifying glass inspecting computer code]]></media:description>                                                            <media:text><![CDATA[Magnifying glass inspecting computer code]]></media:text>
                                <media:title type="plain"><![CDATA[Magnifying glass inspecting computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The publication of the Modern Crime Prevention Strategy by the Home Office yesterday was meant to make clear how the government will tackle crime. Actually, it just knocked another couple of nails into the privacy coffin.</p><p>You can read the whole depressing thing <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/509831/6.1770_Modern_Crime_Prevention_Strategy_final_WEB_version.pdf" target="_blank">here</a>, though you can skip to chapter eight, about using data and tech to prevent crime.</p><p>This got off to a bad enough start with the opening paragraph, which read: "Data and technology are not drivers of crime in themselves. Rather, they are tools that are critical to successfully preventing crime."</p><p>Erm, really? So hackers are not driven to access databases in order to profit from the information contained within them then? The fact that we nearly all have mobile devices which unlock our bank accounts, for example, does not drive hackers to develop methods of attacking them?</p><p>Seriously, who wrote this drivel? "Finding and correcting weak spots in online banking systems will make fraud less profitable to organised criminals", they insist. Actually, patching vulnerabilities makes accessing those systems harder but it does not make successful fraud any less profitable.</p><p>The real driver behind the strategic thinking of the government is revealed soon enough in chapter eight though. "We need a culture change in which everyone recognises that, in a more connected society, we all have a part to play in preventing crime", it says.</p><p>Translated from spin to reality that would read: all your data belongs to us'.</p><p>How so? The Home Office is implementing the National Law Enforcement Data Programme, which is collecting all data from the Police National Computer, Police National Database and Automatic Number-Plate Recognition systems and putting it onto a single platform.</p><p>The ANPR datacentre has information on more than 22 billion car journeys, the vast majority of which will have been perfectly legal and not involved in any criminal activity at all, even after the Surveillance Camera Commissioner called into question the legality of collecting data on vehicles not known to be of interest to law enforcement last year.</p><p>It's all part of the predictive policing concept that sits at the heart of the strategy when it comes to the use of technology and data. Data that will be used to map criminal networks, identify trends, patterns and relationships. Remember that if you've done nothing wrong, you have nothing to fear, as you watch Minority Report once more.</p><p>The biggest load of drivel to emerge from chapter eight, however, is probably summed up in the paragraph that insists "members of the public... have a responsibility to follow some basic rules" such as "choosing the more secure products, installing security software on all our devices, downloading software updates (particularly on our smartphones) and using strong passwords".</p><p>No mention of using strong encryption on our smartphones, I note. Nor any mention of the government's desire to build backdoors into such encryption via the <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">Investigatory Powers Bill</a>, should spies need to access people's data.</p><p>Businesses, the report says, need to "take responsibility for ensuring their products and services don't create opportunities for criminals", which is as clear as very murky mud. So is the next line, which states they must do this "as well as protecting their own networks and making it as easy as possible for customers to avoid unnecessary risks".</p><p>The government fails to elaborate here on what kind of steps businesses should take outside of this vague guidance, steps as simple and necessary as encryption, for example.</p><p>Not that the strategy document ignores encryption altogether. It does recognise that it presents "opportunities for the public to protect their information from cyber criminals, and also for protecting government data, and making public services and communications with citizens secure" all of which is a good thing.</p><p>However, this is immediately followed by the big but: "Encryption also can present challenges, such as when the authorities want access to data that indicates criminal activity. We are monitoring the increasing sophistication of encryption techniques." </p><p>What it doesn't do, of course, is make any mention of the Investigatory Powers Bill and how the exact same government plans to weaken encryption so that actually <a href="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors" target="_blank" data-original-url="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors">it's of absolutely no use to anyone</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IPB still not fit for purpose, say tech firms ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The tech industry has once again hit out at the UK's Investigatory Powers Bill (IPB), ahead of its Second Reading in the House of Commons today.</p><p>The proposed legislation, <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">also known as the Snooper's Charter</a>, has come in for heavy criticism from tech companies and civil rights campaigners alike, who have claimed its powers are too broad, it is an invasion of privacy and that what it requires is not technically feasible.</p><p>While the Bill was revised following extensive investigations by two select committees, which heard from numerous witnesses across these groups, many are still unhappy with the current wording.</p><p>John Shaw, VP of product management at Sophos, said that while his company is supportive of the concept of the IPB, he and his colleagues are "disappointed to see that in the revised Investigatory Powers Bill, although the government has made some small improvements, all our fundamental concerns remain".</p><p>Shaw listed these concerns as weak definitions, leading to very broad interpretations of the bill; putting data at risk; the tech credentials of the proposed Judicial Commissioners; a continued potential for backdoors into encryption; and putting UK content service providers at a disadvantage, as the law will only apply to them.</p><p>"We agree it is critical that the government get this bill right. Rushing it through in its current form will be a mistake. We fear the Bill will be rejected, causing even greater delay to getting a proper regulatory framework in place, or even worse it will be passed into legislation. If it does become law, it will undermine both the security and privacy of UK citizens and impact the competitiveness of UK Internet Service Providers," said Shaw.</p><p>ISPA, the trade body representing ISPs in the UK, sounded a similar note of concern.</p><p>Chairman, James Blessing, said: "ISPA supports reform of investigatory powers through a new Bill, but we are a long way from having a Bill that is clear and workable.</p><p>"Government needs to address concerns around its intentions, definitions and costs to enable industry to make a proper assessment of the Bill and help Parliament scrutinise the complex proposals. Getting this right is essential for the UK digital economy and user trust in services."</p><p>ISPA said that, as it stands, the current bill "does not do what the Home Office says it does".</p><p>"On numerous occasions, there is a disconnect between what can be found on the face of the Bill and what the Government says the Bill will be used for. Given that the Bill is highly intrusive, the Government must put all of its intentions for how it plans to use the powers on to the face of the Bill," the organisation said.</p><p>"Reliance on speeches and non-legislative documents, such as codes of practice, to make clear what the Bill explicitly intends is unsatisfactory," it added.</p><p>ISPA also said significant questions remain over costs, definition of key terms and concepts, including Internet Connection Records and even data, how ISPs can recover costs from the government -- if, indeed, they can at all.</p><p>Parliament should be given sufficient time to scrutinise the Bill, ISPA said, as it is, in the words of the Prime Minister, "one of the most important bills [the House of Commons] will discuss".</p><p>Erka Koivunen, security advisor at F-Secure, took an even stronger tone, saying: "Let us be clear on the British Government's intentions and the consequences of those actions. 'Equipment interference' is hacking. There is a reason there is a very large security industry dedicated to protecting businesses and their digital assets -- because hacking damages businesses."</p><p>"No company wants their own government or government of a friendly partner to break into their systems or undermine the security of their services. We would encourage the Government to pause and consider the implications of its intentions before it irreparably damages British businesses," Koivunen concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/26213/ipb-still-not-fit-for-purpose-say-tech-firms</link>
                                                                            <description>
                            <![CDATA[ Companies and trade bodies reiterate their concerns on day of Second Reading ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6iFjPBbAX5rdat6aMRThao</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Mar 2016 10:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Houses of Parliament]]></media:description>                                                            <media:text><![CDATA[Houses of Parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Houses of Parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Sf28yd9wKrzpojuifa6hAB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The tech industry has once again hit out at the UK's Investigatory Powers Bill (IPB), ahead of its Second Reading in the House of Commons today.</p><p>The proposed legislation, <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">also known as the Snooper's Charter</a>, has come in for heavy criticism from tech companies and civil rights campaigners alike, who have claimed its powers are too broad, it is an invasion of privacy and that what it requires is not technically feasible.</p><p>While the Bill was revised following extensive investigations by two select committees, which heard from numerous witnesses across these groups, many are still unhappy with the current wording.</p><p>John Shaw, VP of product management at Sophos, said that while his company is supportive of the concept of the IPB, he and his colleagues are "disappointed to see that in the revised Investigatory Powers Bill, although the government has made some small improvements, all our fundamental concerns remain".</p><p>Shaw listed these concerns as weak definitions, leading to very broad interpretations of the bill; putting data at risk; the tech credentials of the proposed Judicial Commissioners; a continued potential for backdoors into encryption; and putting UK content service providers at a disadvantage, as the law will only apply to them.</p><p>"We agree it is critical that the government get this bill right. Rushing it through in its current form will be a mistake. We fear the Bill will be rejected, causing even greater delay to getting a proper regulatory framework in place, or even worse it will be passed into legislation. If it does become law, it will undermine both the security and privacy of UK citizens and impact the competitiveness of UK Internet Service Providers," said Shaw.</p><p>ISPA, the trade body representing ISPs in the UK, sounded a similar note of concern.</p><p>Chairman, James Blessing, said: "ISPA supports reform of investigatory powers through a new Bill, but we are a long way from having a Bill that is clear and workable.</p><p>"Government needs to address concerns around its intentions, definitions and costs to enable industry to make a proper assessment of the Bill and help Parliament scrutinise the complex proposals. Getting this right is essential for the UK digital economy and user trust in services."</p><p>ISPA said that, as it stands, the current bill "does not do what the Home Office says it does".</p><p>"On numerous occasions, there is a disconnect between what can be found on the face of the Bill and what the Government says the Bill will be used for. Given that the Bill is highly intrusive, the Government must put all of its intentions for how it plans to use the powers on to the face of the Bill," the organisation said.</p><p>"Reliance on speeches and non-legislative documents, such as codes of practice, to make clear what the Bill explicitly intends is unsatisfactory," it added.</p><p>ISPA also said significant questions remain over costs, definition of key terms and concepts, including Internet Connection Records and even data, how ISPs can recover costs from the government -- if, indeed, they can at all.</p><p>Parliament should be given sufficient time to scrutinise the Bill, ISPA said, as it is, in the words of the Prime Minister, "one of the most important bills [the House of Commons] will discuss".</p><p>Erka Koivunen, security advisor at F-Secure, took an even stronger tone, saying: "Let us be clear on the British Government's intentions and the consequences of those actions. 'Equipment interference' is hacking. There is a reason there is a very large security industry dedicated to protecting businesses and their digital assets -- because hacking damages businesses."</p><p>"No company wants their own government or government of a friendly partner to break into their systems or undermine the security of their services. We would encourage the Government to pause and consider the implications of its intentions before it irreparably damages British businesses," Koivunen concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ boss denies Snooper’s Charter will weaken encryption ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Robert Hannigan, the director of UK spy agency GCHQ, has hit out at claims his agency and its counterparts in the USA are attempting to break strong encryption.</p><p>Speaking at MIT, Hannigan called the use of the term 'backdoor' in reference to encryption an overused and misapplied metaphor that "illustrates the confusion of the ethical debate in what is a highly-charged and technically complex area".</p><p>"I am not in favour of banning encryption. Nor am I asking for mandatory backdoors," he added. "I am puzzled by the caricatures in the current debate, where almost every attempt to tackle the misuse of encryption by criminals and terrorists is seen as a 'backdoor'."</p><p>Hannigan called on the memory of Turing and his Bletchley Park team who cracked the German enigma code during World War II to support his point.</p><p>"The exploitation of a few key flaws in the otherwise brilliant design of the commercial Enigma machine ... enabled Allied victory, and not only, as Eisenhower acknowledged, saved thousands of Allied lives, but also brought the Holocaust to an end before the Nazis could complete their task," said Hannigan.</p><p>"Even though it was very large scale, it would be hard to argue that this was not proportionate, particularly in wartime," he added.</p><p>Hannigan also denied that <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">the Investigatory Powers Bill, also known as the Snooper's Charter</a>, would give any new encryption-busting powers to intelligence agencies, which has been one of the key criticisms of the legislation.</p><p>Instead, he said it "tries to put in one place powers which were spread across numerous statutes".</p><p>"On encryption, it simply repeats the position of earlier legislation: where access to data is legally warranted, companies should provide data in clear where it is practicable or technically feasible to do so," said Hannigan. "No-one in the UK government is advocating the banning or weakening of encryption."</p><p>Hannigan did suggest, however, that the tech industry and the intelligence community should be working more closely together and try to find a workable solution to their differences.</p><p>"We need a new relationship between the tech sector, academia, civil society and government agencies. We should be bridging the divide, sharing ideas and building a constructive dialogue in a less highly-charged atmosphere," said Hannigan.</p><p>Stating that the UK government is "fully committed" to such a collaborative approach, Hannigan added: "This will be a dialogue that starts from the position I've set out today - that the government and its agencies support, and want to actively promote, effective encryption."</p><p>"For my part my promise today is to engage in that process with the tech industry openly, respectfully, and in good faith," he concluded.</p><p><em><strong>Read Next: <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">Apple vs FBI</a></strong></em></p><p><em>Image Credit: By Ministry of Defence (http://www.defenceimagery.mod.uk/) [<a href="http://www.nationalarchives.gov.uk/doc/open-government-licence/version/1">OGL</a>], <a href="https://commons.wikimedia.org/wiki/File%3AGCHQ-aerial.jpg">via Wikimedia Commons</a></em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/26182/gchq-boss-denies-snooper-s-charter-will-weaken-encryption</link>
                                                                            <description>
                            <![CDATA[ Head of GCHQ claims encryption is not under attack, but urges tech industry co-operation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">scMaMnQJuyXfBmBpC5dwcQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Mar 2016 11:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg">
                                                            <media:credit><![CDATA[Ministry of Defence]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An aerial shot of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[An aerial shot of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[An aerial shot of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Robert Hannigan, the director of UK spy agency GCHQ, has hit out at claims his agency and its counterparts in the USA are attempting to break strong encryption.</p><p>Speaking at MIT, Hannigan called the use of the term 'backdoor' in reference to encryption an overused and misapplied metaphor that "illustrates the confusion of the ethical debate in what is a highly-charged and technically complex area".</p><p>"I am not in favour of banning encryption. Nor am I asking for mandatory backdoors," he added. "I am puzzled by the caricatures in the current debate, where almost every attempt to tackle the misuse of encryption by criminals and terrorists is seen as a 'backdoor'."</p><p>Hannigan called on the memory of Turing and his Bletchley Park team who cracked the German enigma code during World War II to support his point.</p><p>"The exploitation of a few key flaws in the otherwise brilliant design of the commercial Enigma machine ... enabled Allied victory, and not only, as Eisenhower acknowledged, saved thousands of Allied lives, but also brought the Holocaust to an end before the Nazis could complete their task," said Hannigan.</p><p>"Even though it was very large scale, it would be hard to argue that this was not proportionate, particularly in wartime," he added.</p><p>Hannigan also denied that <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">the Investigatory Powers Bill, also known as the Snooper's Charter</a>, would give any new encryption-busting powers to intelligence agencies, which has been one of the key criticisms of the legislation.</p><p>Instead, he said it "tries to put in one place powers which were spread across numerous statutes".</p><p>"On encryption, it simply repeats the position of earlier legislation: where access to data is legally warranted, companies should provide data in clear where it is practicable or technically feasible to do so," said Hannigan. "No-one in the UK government is advocating the banning or weakening of encryption."</p><p>Hannigan did suggest, however, that the tech industry and the intelligence community should be working more closely together and try to find a workable solution to their differences.</p><p>"We need a new relationship between the tech sector, academia, civil society and government agencies. We should be bridging the divide, sharing ideas and building a constructive dialogue in a less highly-charged atmosphere," said Hannigan.</p><p>Stating that the UK government is "fully committed" to such a collaborative approach, Hannigan added: "This will be a dialogue that starts from the position I've set out today - that the government and its agencies support, and want to actively promote, effective encryption."</p><p>"For my part my promise today is to engage in that process with the tech industry openly, respectfully, and in good faith," he concluded.</p><p><em><strong>Read Next: <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">Apple vs FBI</a></strong></em></p><p><em>Image Credit: By Ministry of Defence (http://www.defenceimagery.mod.uk/) [<a href="http://www.nationalarchives.gov.uk/doc/open-government-licence/version/1">OGL</a>], <a href="https://commons.wikimedia.org/wiki/File%3AGCHQ-aerial.jpg">via Wikimedia Commons</a></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ RSA 2016: Weakened encryption compromises national security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Tech leaders have hit out at government snooping and attempts to break encryption on the first day of RSA Conference 2016.</p><p>On the same day that <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">Apple once again came face-to-face with the FBI</a> in a court hearing in LA, down the coast in San Francisco, Amit Yoran, president of RSA, used his opening keynote to criticise governments for allowing intelligence and law enforcement agencies to dominate the security conversation.</p><p>"We need governments to enact policies that help, rather than hinder security, providing opportunities for talent development," he told delegates.</p><p>Yoran said that the aims and perspectives of such agencies are "radically different" to those of people trying to defend networks, and said policy proposals such as weakening encryption "boggle the mind".</p><p>"In an era when cybersecurity is consistently cited as the single greatest threat to our way of life - above terrorism and all else - how can we possible justify a policy that would catastrophically weaken our infrastructures?" asked Yoran.</p><p>"Weakening encryption is solely for the ease and convenience of law enforcement when they are pursuing petty criminals. No credible terrorist or nation state actor would ever use technology that is knowingly weakened. However, if you weaken our encryption you can sure bet that the bad guys will use that and exploit it against us," he added.</p><p>These thoughts were echoed by Brad Smith, general legal counsel at Microsoft, who took to the stage after Yoran for his own keynote.</p><p>Smith reflected on not just the big hacks of the past few years but also the terrorist attacks that hit Paris and San Bernardino in late 2015.</p><p>"People went to work [the day after these attacks] debating whether this meant new steps needed to be taken for technology, for surveillance, for encryption," said Smith. "We live in a world where every week there is a pendulum and the question is, which way will the pendulum swing on these issues that affect us?"</p><p>Smith argued that it was impossible to ensure people's security in real life if their security cannot be ensured online.</p><p>"The internet started out two decades ago as something people talked about as a different space - cyberspace, as if it were disconnected from real space and the real world. Well, what we've learnt today is that if people want to shape and impact what happens in the real world, they go to the internet," said Smith.</p><p>"This has affected everybody - governments around the world studied <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony case</a> and they realised that there is no such thing as national security in this decade without cyber security. We've realised that hence we need to keep information secure. One thing is clear above all else - people will not use technology they do not trust and hence trust is the absolute foundation for our entire industry and it needs to remain that way," Smith concluded.</p><p>Smith and Yoran's comments also come on the same day <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Theresa May introduced a new draft of the Investigatory Powers Bill to Parliament</a>. The new text still contains a controversial provision that would oblige companies, including RSA, Microsoft and Apple, to remove encryption at the request of law enforcement agencies.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/26150/rsa-2016-weakened-encryption-compromises-national-security</link>
                                                                            <description>
                            <![CDATA[ Terrorists will move to other platforms, while criminals will exploit the flaws, claim speakers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5jXRnFbYZnc49wkCNmjjdf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EZDkWva5SLYHpjuTyHNrVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Mar 2016 02:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EZDkWva5SLYHpjuTyHNrVF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue padlocks with one red padlock representing security hole]]></media:description>                                                            <media:text><![CDATA[Blue padlocks with one red padlock representing security hole]]></media:text>
                                <media:title type="plain"><![CDATA[Blue padlocks with one red padlock representing security hole]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EZDkWva5SLYHpjuTyHNrVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tech leaders have hit out at government snooping and attempts to break encryption on the first day of RSA Conference 2016.</p><p>On the same day that <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">Apple once again came face-to-face with the FBI</a> in a court hearing in LA, down the coast in San Francisco, Amit Yoran, president of RSA, used his opening keynote to criticise governments for allowing intelligence and law enforcement agencies to dominate the security conversation.</p><p>"We need governments to enact policies that help, rather than hinder security, providing opportunities for talent development," he told delegates.</p><p>Yoran said that the aims and perspectives of such agencies are "radically different" to those of people trying to defend networks, and said policy proposals such as weakening encryption "boggle the mind".</p><p>"In an era when cybersecurity is consistently cited as the single greatest threat to our way of life - above terrorism and all else - how can we possible justify a policy that would catastrophically weaken our infrastructures?" asked Yoran.</p><p>"Weakening encryption is solely for the ease and convenience of law enforcement when they are pursuing petty criminals. No credible terrorist or nation state actor would ever use technology that is knowingly weakened. However, if you weaken our encryption you can sure bet that the bad guys will use that and exploit it against us," he added.</p><p>These thoughts were echoed by Brad Smith, general legal counsel at Microsoft, who took to the stage after Yoran for his own keynote.</p><p>Smith reflected on not just the big hacks of the past few years but also the terrorist attacks that hit Paris and San Bernardino in late 2015.</p><p>"People went to work [the day after these attacks] debating whether this meant new steps needed to be taken for technology, for surveillance, for encryption," said Smith. "We live in a world where every week there is a pendulum and the question is, which way will the pendulum swing on these issues that affect us?"</p><p>Smith argued that it was impossible to ensure people's security in real life if their security cannot be ensured online.</p><p>"The internet started out two decades ago as something people talked about as a different space - cyberspace, as if it were disconnected from real space and the real world. Well, what we've learnt today is that if people want to shape and impact what happens in the real world, they go to the internet," said Smith.</p><p>"This has affected everybody - governments around the world studied <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony case</a> and they realised that there is no such thing as national security in this decade without cyber security. We've realised that hence we need to keep information secure. One thing is clear above all else - people will not use technology they do not trust and hence trust is the absolute foundation for our entire industry and it needs to remain that way," Smith concluded.</p><p>Smith and Yoran's comments also come on the same day <a href="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion" target="_blank" data-original-url="https://www.itpro.com/it-legislation/26034/investigatory-powers-will-cost-uk-1-billion">Theresa May introduced a new draft of the Investigatory Powers Bill to Parliament</a>. The new text still contains a controversial provision that would oblige companies, including RSA, Microsoft and Apple, to remove encryption at the request of law enforcement agencies.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snooper's Charter could lead to Apple vs FBI-style case in UK ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Electronic Frontier Foundation (EFF) has warned the Snooper's Charter contains three clauses that could compel companies to hack their own technology while preventing them from revealing to the public what is going on.</p><p>The campaign group's comments come in the midst of <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">an ongoing court battle in the US between Apple and the FBI</a>, where the law enforcement agency is trying to force the company to build custom code to bypass security measures on an iPhone.</p><p>The EFF, however, has warned that the Investigatory Powers Bill (IPB), as the Snooper's Charter is properly called, could be even more of a threat to privacy and security than what is being asked of Apple by the FBI.</p><p>In a blog post, EFF's international director Danny O'Brien claimed the IPB already contains clauses that could force tech companies to re-engineer their own technology, as the FBI is requesting of Apple, and that these would be accompanied by a gag order.</p><p>"If the law passes ... not only would Apple be expected to comply, but the IPB would insist that Tim Cook could not tell the public what was going on without breaking UK law," said O'Brien. "At least in the current fight between Apple and the US government, we're having the debate out loud and in public."</p><p>O'Brien has identified three parts of the Snooper's Charter that could allow what he has described at "unchecked hacking powers".</p><p>The first of these is the Technical Capability Notice, which O'Brien describes as "a secret order that the UK would be able to serve on a telecommunications operator ... to force it to 'remov[e] electronic protection applied ... to any communications or data [and] provide facilities or services of a specified description'."</p><p>According to O'Brien, the wording of the bill is currently so broad that the term telecommunications operator "would include companies like Apple".</p><p>O'Brien also draws attention to the provision for the issuing of a National Security Notice, which he claims is "another secret instrument, even more vaguely drawn, that would require operators to 'carry out any conduct, including the provision of services of facilities,' which the British government 'considers necessary in the interests of national security'." Once again, this element includes a gag order.</p><p>His third and final point of contention is equipment interference orders, which he said "would allow the UK to break into private devices and insert new code for the purposes of surveillance or extracting data ... [including] a requirement (S.101) that <em>any</em> communications provider (again, this includes Apple) take <em>any</em> 'reasonably practicable' steps in effecting a hacking warrant".</p><p>Referencing <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26341.html">the company's submission to the Draft Investigatory Powers Bill Committee</a>, O'Brien said: "Apple saw in the IPB's provisions exactly what it now sees in the FBI's demands: the government asking it to undermine the trust of its own customers."</p><p>"The IPB needs to be taken back to the drawing board, and rewritten to limit these blanket powers - and to give companies and technologists a chance to speak up, and fight back," he concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/26117/snoopers-charter-could-lead-to-apple-vs-fbi-style-case-in-uk</link>
                                                                            <description>
                            <![CDATA[ Electronic Frontier Foundation warns of backdoor provisions in IPB ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qLs8sQaUTcNWAEXaoBhgVu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Feb 2016 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Apple]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Electronic Frontier Foundation (EFF) has warned the Snooper's Charter contains three clauses that could compel companies to hack their own technology while preventing them from revealing to the public what is going on.</p><p>The campaign group's comments come in the midst of <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">an ongoing court battle in the US between Apple and the FBI</a>, where the law enforcement agency is trying to force the company to build custom code to bypass security measures on an iPhone.</p><p>The EFF, however, has warned that the Investigatory Powers Bill (IPB), as the Snooper's Charter is properly called, could be even more of a threat to privacy and security than what is being asked of Apple by the FBI.</p><p>In a blog post, EFF's international director Danny O'Brien claimed the IPB already contains clauses that could force tech companies to re-engineer their own technology, as the FBI is requesting of Apple, and that these would be accompanied by a gag order.</p><p>"If the law passes ... not only would Apple be expected to comply, but the IPB would insist that Tim Cook could not tell the public what was going on without breaking UK law," said O'Brien. "At least in the current fight between Apple and the US government, we're having the debate out loud and in public."</p><p>O'Brien has identified three parts of the Snooper's Charter that could allow what he has described at "unchecked hacking powers".</p><p>The first of these is the Technical Capability Notice, which O'Brien describes as "a secret order that the UK would be able to serve on a telecommunications operator ... to force it to 'remov[e] electronic protection applied ... to any communications or data [and] provide facilities or services of a specified description'."</p><p>According to O'Brien, the wording of the bill is currently so broad that the term telecommunications operator "would include companies like Apple".</p><p>O'Brien also draws attention to the provision for the issuing of a National Security Notice, which he claims is "another secret instrument, even more vaguely drawn, that would require operators to 'carry out any conduct, including the provision of services of facilities,' which the British government 'considers necessary in the interests of national security'." Once again, this element includes a gag order.</p><p>His third and final point of contention is equipment interference orders, which he said "would allow the UK to break into private devices and insert new code for the purposes of surveillance or extracting data ... [including] a requirement (S.101) that <em>any</em> communications provider (again, this includes Apple) take <em>any</em> 'reasonably practicable' steps in effecting a hacking warrant".</p><p>Referencing <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26341.html">the company's submission to the Draft Investigatory Powers Bill Committee</a>, O'Brien said: "Apple saw in the IPB's provisions exactly what it now sees in the FBI's demands: the government asking it to undermine the trust of its own customers."</p><p>"The IPB needs to be taken back to the drawing board, and rewritten to limit these blanket powers - and to give companies and technologists a chance to speak up, and fight back," he concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snooper’s Charter fails to protect privacy, warn MPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Investigatory Powers Bill would fail to protect UK citizens from mass surveillance, according to a Parliamentary committee's damning <a href="https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/20160209_ISC_Rpt_IPBill%28web%29.pdf?attachauth=ANoY7cr97obVXAd3SqbB6sWimG0Veq8z5i_MhcrV2fUS9_7lGK7x4dO1Lmm6yCn_yXa1WWgjqoFHMsI6oMR0Ys1i4rLkrrXToKOWThieYnDbMxBlya8g8DnTfa4-_Wp0JRRB80dTfO3ShijCCU29aHwPoFoa6GxUM9GidePi6i0AvUwFXpmHbTR19Vuobi3atEyQx7sGdLK5IUc1DgX4gZV5gqjEzWDBoDPGmskLXarM2jTWBPepcDqYrwc_t3BmExo-XJmuSIxR&attredirects=0" target="_blank">report</a> on the government's proposed new law.</p><p>The Intelligence and Security Committee (ISC) today demanded "substantive amendments" to the bill, also known as <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">the Snooper's Charter</a>.</p><p>If passed in its current guise, the bill would see internet service providers forced to store people's internet connection records (ICRs) for 12 months, while security products would have compulsory backdoors built in for government spies to access data.</p><p>MPs and peers on the committee claimed that those behind the legislation appeared not to know what the bill is meant to achieve.</p><p>"Overall, the privacy protections are inconsistent and in our view need strengthening," said the report, adding that the bill itself was a "significant missed opportunity" and took a "piecemeal" approach to protecting privacy.</p><p>The committee said that privacy should be "an integral part of the legislation rather than an add-on".</p><p>It added that checks and balances must be set up to oversee security services' powers to collect bulk data from internet users. </p><p>The report also focused on rules that force companies to build backdoors into encrypted services, saying the bill was unclear on how warrants to access the backdoors might work, and that the committee was "not convinced as to the requirement for them".</p><p>Dominic Grieve, the Conservative chairman of the ISC, said: "Taken as a whole, the draft bill fails to deliver the clarity that is so badly needed in this area."</p><p>"The issues under consideration are undoubtedly complex, however, it has been evident that even those working on the legislation have not always been clear as to what the provisions are intended to achieve."</p><p>He added: "The draft bill appears to have suffered from a lack of sufficient time and preparation."</p><p>Antony Walker, deputy CEO of industry trade body techUK, said that the bill lacks clarity on fundamental issues, such as core definitions of key terms, encryption, and equipment interference.</p><p>"Our members are unsure exactly what is meant by internet connection records (ICRs), how they will be gathered, stored and accessed. This kind of detail is crucial to understanding the impact of the proposed bill," he said.</p><p>Walker said anything that forces companies to create or allow vulnerabilities in their systems is a huge concern and could damage public trust and have a direct impact on global perception of the UK as a home for innovation and investment.</p><p>"These concerns are reinforced by the ISC report, which calls for clarity on the effect on end to end encryption, and we urge the Home Office to take its findings on board," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26015/snooper-s-charter-fails-to-protect-privacy-warn-mps</link>
                                                                            <description>
                            <![CDATA[ Intelligence and Security Committee criticises Investigatory Powers Bill ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bWrbPj89NLKMRbGJ5MvNik</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Feb 2016 13:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of the UK houses of parliament]]></media:description>                                                            <media:text><![CDATA[Image of the UK houses of parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Image of the UK houses of parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Bill would fail to protect UK citizens from mass surveillance, according to a Parliamentary committee's damning <a href="https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/20160209_ISC_Rpt_IPBill%28web%29.pdf?attachauth=ANoY7cr97obVXAd3SqbB6sWimG0Veq8z5i_MhcrV2fUS9_7lGK7x4dO1Lmm6yCn_yXa1WWgjqoFHMsI6oMR0Ys1i4rLkrrXToKOWThieYnDbMxBlya8g8DnTfa4-_Wp0JRRB80dTfO3ShijCCU29aHwPoFoa6GxUM9GidePi6i0AvUwFXpmHbTR19Vuobi3atEyQx7sGdLK5IUc1DgX4gZV5gqjEzWDBoDPGmskLXarM2jTWBPepcDqYrwc_t3BmExo-XJmuSIxR&attredirects=0" target="_blank">report</a> on the government's proposed new law.</p><p>The Intelligence and Security Committee (ISC) today demanded "substantive amendments" to the bill, also known as <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products">the Snooper's Charter</a>.</p><p>If passed in its current guise, the bill would see internet service providers forced to store people's internet connection records (ICRs) for 12 months, while security products would have compulsory backdoors built in for government spies to access data.</p><p>MPs and peers on the committee claimed that those behind the legislation appeared not to know what the bill is meant to achieve.</p><p>"Overall, the privacy protections are inconsistent and in our view need strengthening," said the report, adding that the bill itself was a "significant missed opportunity" and took a "piecemeal" approach to protecting privacy.</p><p>The committee said that privacy should be "an integral part of the legislation rather than an add-on".</p><p>It added that checks and balances must be set up to oversee security services' powers to collect bulk data from internet users. </p><p>The report also focused on rules that force companies to build backdoors into encrypted services, saying the bill was unclear on how warrants to access the backdoors might work, and that the committee was "not convinced as to the requirement for them".</p><p>Dominic Grieve, the Conservative chairman of the ISC, said: "Taken as a whole, the draft bill fails to deliver the clarity that is so badly needed in this area."</p><p>"The issues under consideration are undoubtedly complex, however, it has been evident that even those working on the legislation have not always been clear as to what the provisions are intended to achieve."</p><p>He added: "The draft bill appears to have suffered from a lack of sufficient time and preparation."</p><p>Antony Walker, deputy CEO of industry trade body techUK, said that the bill lacks clarity on fundamental issues, such as core definitions of key terms, encryption, and equipment interference.</p><p>"Our members are unsure exactly what is meant by internet connection records (ICRs), how they will be gathered, stored and accessed. This kind of detail is crucial to understanding the impact of the proposed bill," he said.</p><p>Walker said anything that forces companies to create or allow vulnerabilities in their systems is a huge concern and could damage public trust and have a direct impact on global perception of the UK as a home for innovation and investment.</p><p>"These concerns are reinforced by the ISC report, which calls for clarity on the effect on end to end encryption, and we urge the Home Office to take its findings on board," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snooper's Charter 'could destroy customer trust in UK products' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Investigatory Powers Bill risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies.</p><p>The bill, also known as the Snooper's Charter, could have a serious negative effect on UK business and the economy, in addition to potentially damaging the country's reputation for democracy and human rights, various parties warned <em>IT Pro</em>.</p><p>Proposals included in the bill range from compelling internet service providers to hold onto users' website data for 12 months, to forcing cybersecurity firms to build backdoors into their encryption, but making it illegal for them to warn customers of such backdoors.</p><p>Erka Koivunen, a cybersecurity advisor at security firm F-Secure, said this would mean that customers of his company's Freedome VPN who accessed the internet via a UK exit node "would know that somebody else, and in this context it would be the UK government, is doing their utmost to undermine that privacy promise that we as a company try to provide".</p><p>"That itself should be a strong argument for the UK government to consider, because this same smell, if you will, will stick to other businesses that operate from the UK," added Koivunen. "If you are providing cryptography products and you say that the company originated in the UK, nobody in the future is going to believe that this is not backdoored."</p><p>Chris Boyd, malware intelligence analyst at security firm Malwarebytes, added: "Asking companies to ensure they can 'remove electronic protection' is going to cause a huge rift between product makers and consumers. They may feel that the tools they trust and use on a daily basis are somehow booby-trapped in a way that potentially works against their best interests."</p><p>Koivunen and Boyd's comments come after the publication of the House of Commons Science and Technology Committee's third report on the bill, this time addressing technological issues.</p><p>Nicola Blackwood MP, the chair of the Science & Technology Committee, said the UK's growing tech sector would be stifled by the cost burden of meeting such demands.</p><p>She said: "We need our security services to be able to do their job and prevent terrorism, but as legislators we need to be careful not to inadvertently disadvantage the UK's rapidly growing Tech sector."</p><p>"The current lack of clarity within the draft Investigatory Powers Bill is causing concern amongst businesses. There remain questions about the feasibility of collecting and storing Internet Connection Records (ICRs), including concerns about ensuring security for the records from hackers.</p><p>"The Bill was intended to provide clarity to the industry, but the current draft contains very broad and ambiguous definitions of ICRs, which are confusing communications providers. This must be put right for the Bill to achieve its stated security goals."</p><p>Similar concerns were raised by numerous other bodies who spoke with <em>IT Pro</em>.</p><p>Antony Walker, deputy CEO of trade body techUK, said: "There are several important recommendations in this report that we urge the Home Office to take on board. In particular we need more clarity on fundamental issues, such as core definitions, encryption and equipment interference.</p><p>"Without that additional detail, too much of the bill will be open to interpretation, which undermines trust in both the legislation and the reputation of companies that have to comply with it."</p><p>Jim Killock, executive director of civil liberties organisation the Open Rights Group, added: "David Cameron needs to consider whether he wants to be the Conservative Prime Minister that jeopardised the success of the UK tech industry. As it stands, the Investigatory Powers Bill will be bad for business, bad for citizens and bad for UK democracy."</p><p>Lack of trust in the UK tech industry is only one way in which the Snooper's Charter could damage the UK economy, <em>IT Pro</em> has been told.</p><p><a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed" target="_blank">Speaking to sister title <em>Cloud Pro</em></a>, Michael Ginsberg, CEO of cloud-based encryption service Echoworx, said his company is ready to abandon its UK datacentres and move to Ireland if the bill becomes law.</p><p>He added that his business is not unique in this regard and that the Snooper's Charter could cost the UK $15 billion a year by driving hosting businesses abroad.</p><p>"Apart from any moral problems about snooping on its citizens and enterprises, there's some real financial risk," he said. "It has already activated us so we can imagine what larger hosting companies plans are [doing] in anticipation of this legislation, and once that data moves it won't come back. That's a real problem."</p><p><strong>Security concerns</strong></p><p>One of the most serious concerns around the Snooper's Charter, is the possibility that the massive amounts of data ISPs will be required to hold onto could be a very attractive target for cyber criminals.</p><p>In its report, the Commons Science and Technology Committee said: "It is essential that the integrity and security of legitimate online transactions is maintained if we are to trust in, and benefit from, the opportunities of an increasingly digital economy."</p><p>But Matthew Rice, advocacy officer at civil rights organisation Privacy International, warned: "The committee's report shows that the safety and security of users' data may be threatened."</p><p>"The draft Bill must be substantially revised or it will put the UK economy, as well as our privacy and security, at risk," he added.</p><p>Putting a finer point on the matter, Malwarebytes' researcher, Boyd, told <em>IT Pro</em>: "I would be very concerned that a large dump of internet records would be an immediately attractive proposition for those with the talent to compromise a database. The only real question is who would get there first - someone who did it for bragging rights and no real interest in the data, or somebody with more malicious intent."</p><p><strong>Counting the cost</strong></p><p>Much has been made of the potential cost ISPs would face by having to store the vast amounts of data required by the Snooper's Charter.</p><p>But the Committee's report said that the government should bear these costs.</p><p>It read: "While we well understand the security challenges of communications data, we strongly believe UK businesses must not be placed at a commercial disadvantage by measures to tackle security risks and that the full costs of implementing the additional measures in the draft bill should be met by government."</p><p>"Given that the cost of being able to do this is directly related to any future changes or developments in technology, we recognise this makes predicting accurately the cost of these measures difficult," it added. "This therefore raises concerns over any assessment of the costs of this scheme, which could increase or decrease, and so the value for money of this proposed legislation."</p><p>While the government pegs the cost of meeting the bill's requirements in the range of 250,000, previous attempts at this type of dragnet surveillance, such as the now abandoned Draft Communications Data Bill (also known as the Snooper's Charter), have carried an estimated cost of 2 billion.</p><p>Requiring that the government foot the bill for ISPs' costs could significantly increase this figure, particularly because ISPs such as BT have claimed in evidence submitted to the committee that it would cost "many tens of millions of pounds" to implement the technology.</p><p>The committee's latest report about the Investigatory Powers Bill <a href="http://www.publications.parliament.uk/pa/cm201516/cmselect/cmsctech/573/573.pdf" target="_blank">can be read in full here (PDF)</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products</link>
                                                                            <description>
                            <![CDATA[ Investigatory Powers Bill would taint UK firms with security backdoor fears, say experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4CXTpfPR3uqYXzaqRJRb4G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Feb 2016 15:08:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of the UK houses of parliament]]></media:description>                                                            <media:text><![CDATA[Image of the UK houses of parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Image of the UK houses of parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vKHvgCVvtBkcQbBmPFkkyL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Bill risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies.</p><p>The bill, also known as the Snooper's Charter, could have a serious negative effect on UK business and the economy, in addition to potentially damaging the country's reputation for democracy and human rights, various parties warned <em>IT Pro</em>.</p><p>Proposals included in the bill range from compelling internet service providers to hold onto users' website data for 12 months, to forcing cybersecurity firms to build backdoors into their encryption, but making it illegal for them to warn customers of such backdoors.</p><p>Erka Koivunen, a cybersecurity advisor at security firm F-Secure, said this would mean that customers of his company's Freedome VPN who accessed the internet via a UK exit node "would know that somebody else, and in this context it would be the UK government, is doing their utmost to undermine that privacy promise that we as a company try to provide".</p><p>"That itself should be a strong argument for the UK government to consider, because this same smell, if you will, will stick to other businesses that operate from the UK," added Koivunen. "If you are providing cryptography products and you say that the company originated in the UK, nobody in the future is going to believe that this is not backdoored."</p><p>Chris Boyd, malware intelligence analyst at security firm Malwarebytes, added: "Asking companies to ensure they can 'remove electronic protection' is going to cause a huge rift between product makers and consumers. They may feel that the tools they trust and use on a daily basis are somehow booby-trapped in a way that potentially works against their best interests."</p><p>Koivunen and Boyd's comments come after the publication of the House of Commons Science and Technology Committee's third report on the bill, this time addressing technological issues.</p><p>Nicola Blackwood MP, the chair of the Science & Technology Committee, said the UK's growing tech sector would be stifled by the cost burden of meeting such demands.</p><p>She said: "We need our security services to be able to do their job and prevent terrorism, but as legislators we need to be careful not to inadvertently disadvantage the UK's rapidly growing Tech sector."</p><p>"The current lack of clarity within the draft Investigatory Powers Bill is causing concern amongst businesses. There remain questions about the feasibility of collecting and storing Internet Connection Records (ICRs), including concerns about ensuring security for the records from hackers.</p><p>"The Bill was intended to provide clarity to the industry, but the current draft contains very broad and ambiguous definitions of ICRs, which are confusing communications providers. This must be put right for the Bill to achieve its stated security goals."</p><p>Similar concerns were raised by numerous other bodies who spoke with <em>IT Pro</em>.</p><p>Antony Walker, deputy CEO of trade body techUK, said: "There are several important recommendations in this report that we urge the Home Office to take on board. In particular we need more clarity on fundamental issues, such as core definitions, encryption and equipment interference.</p><p>"Without that additional detail, too much of the bill will be open to interpretation, which undermines trust in both the legislation and the reputation of companies that have to comply with it."</p><p>Jim Killock, executive director of civil liberties organisation the Open Rights Group, added: "David Cameron needs to consider whether he wants to be the Conservative Prime Minister that jeopardised the success of the UK tech industry. As it stands, the Investigatory Powers Bill will be bad for business, bad for citizens and bad for UK democracy."</p><p>Lack of trust in the UK tech industry is only one way in which the Snooper's Charter could damage the UK economy, <em>IT Pro</em> has been told.</p><p><a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed" target="_blank">Speaking to sister title <em>Cloud Pro</em></a>, Michael Ginsberg, CEO of cloud-based encryption service Echoworx, said his company is ready to abandon its UK datacentres and move to Ireland if the bill becomes law.</p><p>He added that his business is not unique in this regard and that the Snooper's Charter could cost the UK $15 billion a year by driving hosting businesses abroad.</p><p>"Apart from any moral problems about snooping on its citizens and enterprises, there's some real financial risk," he said. "It has already activated us so we can imagine what larger hosting companies plans are [doing] in anticipation of this legislation, and once that data moves it won't come back. That's a real problem."</p><p><strong>Security concerns</strong></p><p>One of the most serious concerns around the Snooper's Charter, is the possibility that the massive amounts of data ISPs will be required to hold onto could be a very attractive target for cyber criminals.</p><p>In its report, the Commons Science and Technology Committee said: "It is essential that the integrity and security of legitimate online transactions is maintained if we are to trust in, and benefit from, the opportunities of an increasingly digital economy."</p><p>But Matthew Rice, advocacy officer at civil rights organisation Privacy International, warned: "The committee's report shows that the safety and security of users' data may be threatened."</p><p>"The draft Bill must be substantially revised or it will put the UK economy, as well as our privacy and security, at risk," he added.</p><p>Putting a finer point on the matter, Malwarebytes' researcher, Boyd, told <em>IT Pro</em>: "I would be very concerned that a large dump of internet records would be an immediately attractive proposition for those with the talent to compromise a database. The only real question is who would get there first - someone who did it for bragging rights and no real interest in the data, or somebody with more malicious intent."</p><p><strong>Counting the cost</strong></p><p>Much has been made of the potential cost ISPs would face by having to store the vast amounts of data required by the Snooper's Charter.</p><p>But the Committee's report said that the government should bear these costs.</p><p>It read: "While we well understand the security challenges of communications data, we strongly believe UK businesses must not be placed at a commercial disadvantage by measures to tackle security risks and that the full costs of implementing the additional measures in the draft bill should be met by government."</p><p>"Given that the cost of being able to do this is directly related to any future changes or developments in technology, we recognise this makes predicting accurately the cost of these measures difficult," it added. "This therefore raises concerns over any assessment of the costs of this scheme, which could increase or decrease, and so the value for money of this proposed legislation."</p><p>While the government pegs the cost of meeting the bill's requirements in the range of 250,000, previous attempts at this type of dragnet surveillance, such as the now abandoned Draft Communications Data Bill (also known as the Snooper's Charter), have carried an estimated cost of 2 billion.</p><p>Requiring that the government foot the bill for ISPs' costs could significantly increase this figure, particularly because ISPs such as BT have claimed in evidence submitted to the committee that it would cost "many tens of millions of pounds" to implement the technology.</p><p>The committee's latest report about the Investigatory Powers Bill <a href="http://www.publications.parliament.uk/pa/cm201516/cmselect/cmsctech/573/573.pdf" target="_blank">can be read in full here (PDF)</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy and security clash on Data Protection Day ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As the world marks Data Protection Day, privacy experts say the UK is stuck in a state of conflict over personal data.</p><p>Data Privacy Day, as it is known outside Europe, is meant to raise awareness among businesses and individuals of the importance of protecting personal information online.</p><p>Butprivacy and security professionals have criticised the UK government's wish to introduce the <a href="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors" target="_blank" data-original-url="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors">Snooper's Charter</a>, saying it stands at cross-purposes with incoming EU legislation, the General Data Protection Regulation (GDPR), that is designed to strengthen people's rights over their personal data.</p><p>Nigel Hawthorn, chief European spokesman at cloud security company Skyhigh Networks, accused the UK of "failing to put privacy rhetoric into practice" with regard to the draft Investigatory Powers Bill, which wants to force ISPs to collect people's online browsing data for up to 12 months.</p><p>He said: "28 January is an iconic date because it marks the anniversary of the opening for signature of the Council of Europe's Convention 108 for the protection of individuals with regard to automatic processing of personal data.</p><p>"For 35 years the treaty has been considered the cornerstone of data protection. Yet, with a draft surveillance bill that doesn't specifically state that companies won't have to weaken their encryption for the authorities, consumers arguably have even less say today about how their data is being used."</p><p>For Raj Samani, EMEA CTO of Intel Security, the question is not just about data control, but also how well informed consumers are.</p><p>"As a society, we continue to be in a state of conflict when it comes to data. On the one hand, we're often outraged over regular news around <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" target="_blank" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">data breaches</a>, while on the other hand we think nothing about trading our identities for a chocolate bar or less," said Samani.</p><p>He also warned that people should be wary of giving up their data to companies.</p><p>"We need to be even more cautious and hard-nosed about entering into data transactions by driving harder bargains and asking ourselves smart questions such as 'who our data will be shared with and how it's going to be protected'," he said.</p><p>Lawrence Munro, director of EMEA and APAC at Trustwave, meanwhile, said Data Protection Day serves of a reminder this year of the incoming European General Data Protection Regulation(GDPR).</p><p>"Following on from a year of high profile security breaches ... there could hardly be a more pressing time for organisations to pay attention to Data Protection Day," said Munro.</p><p>"The mounting number of breaches involving consumer financial and private data means the public is increasingly aware of their information being at risk, and much less willing to forgive businesses who betray their trust. The upcoming regulations from the EU will also see harsh punishments for companies failing to protect customer data, with fines of up to four per cent of global revenue in some cases. With so much at stake, no organisation can afford to take any chances," he added.</p><p>The GDPR is expected to some into force within the coming weeks and months, while the Draft Investigatory Powers Bill, <a href="https://www.gov.uk/government/publications/draft-investigatory-powers-bill" target="_blank">which can be read in full here</a>, is <a href="http://www.parliament.uk/business/committees/committees-a-z/joint-select/draft-investigatory-powers-bill/timeline">currently under consideration by the Joint Committee on the Draft Investigatory Powers Bill</a>, which is preparing its report on the matter.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25949/privacy-and-security-clash-on-data-protection-day</link>
                                                                            <description>
                            <![CDATA[ Security experts say UK is in conflict over GDPR and Snooper's Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3S84ghMwWumtVp2nppPNoU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gh6hE9roTRxfbJgFgX8etW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Jan 2016 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gh6hE9roTRxfbJgFgX8etW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A map of Europe with nodes to represent data hotspots]]></media:description>                                                            <media:text><![CDATA[A map of Europe with nodes to represent data hotspots]]></media:text>
                                <media:title type="plain"><![CDATA[A map of Europe with nodes to represent data hotspots]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gh6hE9roTRxfbJgFgX8etW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the world marks Data Protection Day, privacy experts say the UK is stuck in a state of conflict over personal data.</p><p>Data Privacy Day, as it is known outside Europe, is meant to raise awareness among businesses and individuals of the importance of protecting personal information online.</p><p>Butprivacy and security professionals have criticised the UK government's wish to introduce the <a href="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors" target="_blank" data-original-url="https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors">Snooper's Charter</a>, saying it stands at cross-purposes with incoming EU legislation, the General Data Protection Regulation (GDPR), that is designed to strengthen people's rights over their personal data.</p><p>Nigel Hawthorn, chief European spokesman at cloud security company Skyhigh Networks, accused the UK of "failing to put privacy rhetoric into practice" with regard to the draft Investigatory Powers Bill, which wants to force ISPs to collect people's online browsing data for up to 12 months.</p><p>He said: "28 January is an iconic date because it marks the anniversary of the opening for signature of the Council of Europe's Convention 108 for the protection of individuals with regard to automatic processing of personal data.</p><p>"For 35 years the treaty has been considered the cornerstone of data protection. Yet, with a draft surveillance bill that doesn't specifically state that companies won't have to weaken their encryption for the authorities, consumers arguably have even less say today about how their data is being used."</p><p>For Raj Samani, EMEA CTO of Intel Security, the question is not just about data control, but also how well informed consumers are.</p><p>"As a society, we continue to be in a state of conflict when it comes to data. On the one hand, we're often outraged over regular news around <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" target="_blank" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">data breaches</a>, while on the other hand we think nothing about trading our identities for a chocolate bar or less," said Samani.</p><p>He also warned that people should be wary of giving up their data to companies.</p><p>"We need to be even more cautious and hard-nosed about entering into data transactions by driving harder bargains and asking ourselves smart questions such as 'who our data will be shared with and how it's going to be protected'," he said.</p><p>Lawrence Munro, director of EMEA and APAC at Trustwave, meanwhile, said Data Protection Day serves of a reminder this year of the incoming European General Data Protection Regulation(GDPR).</p><p>"Following on from a year of high profile security breaches ... there could hardly be a more pressing time for organisations to pay attention to Data Protection Day," said Munro.</p><p>"The mounting number of breaches involving consumer financial and private data means the public is increasingly aware of their information being at risk, and much less willing to forgive businesses who betray their trust. The upcoming regulations from the EU will also see harsh punishments for companies failing to protect customer data, with fines of up to four per cent of global revenue in some cases. With so much at stake, no organisation can afford to take any chances," he added.</p><p>The GDPR is expected to some into force within the coming weeks and months, while the Draft Investigatory Powers Bill, <a href="https://www.gov.uk/government/publications/draft-investigatory-powers-bill" target="_blank">which can be read in full here</a>, is <a href="http://www.parliament.uk/business/committees/committees-a-z/joint-select/draft-investigatory-powers-bill/timeline">currently under consideration by the Joint Committee on the Draft Investigatory Powers Bill</a>, which is preparing its report on the matter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud firms will leave UK if Snooper's Charter is passed ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Snooper's Charter risks removing billions of pounds from the UK economy by effectively forcing cloud and hosting companies to leave, rather than give in to demands to weaken encryption, it is claimed.</p><p><a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed" target="_blank">Speaking to <em>Cloud Pro</em></a>, Michael Ginsberg, CEO of cloud-based encryption service Echoworx, said his company is ready to abandon its two UK datacentres and migrate to other facilities abroad should the Snooper's Charter, formally known as the Investigatory Powers Bill, become law.</p><p>The bill proposes that internet service providers keep a list of websites their users visit for at least 12 months, and demands that hosting providers leave 'backdoors' in their encryption open for the government.</p><p>"If the [UK] government wants an encryption backdoor, we can move to a jurisdiction that doesn't have encryption back doors ... where this legislation doesn't exist," he said. "The bad news for the UK is $15 billion a year in hosting businesses and if my company can move out of the UK in a snap, how many other companies can?"</p><p>Ginsberg added: "Apart from any moral problems about snooping on its citizens and enterprises, there's some real financial risk. It has already activated us so we can imagine what larger hosting companies plans are [doing] in anticipation of this legislation, and once that data moves it won't come back. That's a real problem."</p><p>To illustrate his point, Ginsberg gave the example of "one of the largest commercial banks in Canada", which had all its commercial credit card processing done in Minnesota.</p><p>"Within two months of the original 9/11 US Patriot Act coming in, it was all back in Canada and it's never going to return," he said.</p><p><strong>Technical problems</strong></p><p>Ginsberg also accused the UK government of not having fully thought through the practical implications of the requirements in the Investigatory Powers Bill - an accusation that has been <a href="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter" target="_blank" data-original-url="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter">levelled before with regard to data storage demands</a>.</p><p>"As incredulous as it is to believe they're considering this, I don't know if the practicalities of it are going to allow them to enact it," said Ginsberg.</p><p>"We host a very large charity of yours here in the UK that deals with sensitive personal data and if the government comes to us and says 'We need a back door to your encryption' and I say, of course, 'no', and we snap our fingers and we're in Ireland or Romania - then what do they do? Do they go to the charity? What can the charity do? They're going to be asked to provide a backdoor and they're incapable of doing that technically - it's not their system, really."</p><p>"So the charity will say they can't and is the government going to say either use someone else's encryption, which isn't safe, or they can't use encryption? I don't know that it has followed the string of the logic of their own intent," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25919/cloud-firms-will-leave-uk-if-snoopers-charter-is-passed</link>
                                                                            <description>
                            <![CDATA[ Demands to weaken encryption 'will drive $15 billion worth of business out of the UK' ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kZG79AEcVT8aRUfedJVFur</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/An3FGxxAP2TKt5iNSYsjyh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Jan 2016 14:57:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/An3FGxxAP2TKt5iNSYsjyh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Encryption key ]]></media:description>                                                            <media:text><![CDATA[Encryption key ]]></media:text>
                                <media:title type="plain"><![CDATA[Encryption key ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/An3FGxxAP2TKt5iNSYsjyh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Snooper's Charter risks removing billions of pounds from the UK economy by effectively forcing cloud and hosting companies to leave, rather than give in to demands to weaken encryption, it is claimed.</p><p><a href="http://www.cloudpro.co.uk/leadership/risks/5761/cloud-firm-plans-to-leave-uk-if-snoopers-charter-is-passed" target="_blank">Speaking to <em>Cloud Pro</em></a>, Michael Ginsberg, CEO of cloud-based encryption service Echoworx, said his company is ready to abandon its two UK datacentres and migrate to other facilities abroad should the Snooper's Charter, formally known as the Investigatory Powers Bill, become law.</p><p>The bill proposes that internet service providers keep a list of websites their users visit for at least 12 months, and demands that hosting providers leave 'backdoors' in their encryption open for the government.</p><p>"If the [UK] government wants an encryption backdoor, we can move to a jurisdiction that doesn't have encryption back doors ... where this legislation doesn't exist," he said. "The bad news for the UK is $15 billion a year in hosting businesses and if my company can move out of the UK in a snap, how many other companies can?"</p><p>Ginsberg added: "Apart from any moral problems about snooping on its citizens and enterprises, there's some real financial risk. It has already activated us so we can imagine what larger hosting companies plans are [doing] in anticipation of this legislation, and once that data moves it won't come back. That's a real problem."</p><p>To illustrate his point, Ginsberg gave the example of "one of the largest commercial banks in Canada", which had all its commercial credit card processing done in Minnesota.</p><p>"Within two months of the original 9/11 US Patriot Act coming in, it was all back in Canada and it's never going to return," he said.</p><p><strong>Technical problems</strong></p><p>Ginsberg also accused the UK government of not having fully thought through the practical implications of the requirements in the Investigatory Powers Bill - an accusation that has been <a href="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter" target="_blank" data-original-url="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter">levelled before with regard to data storage demands</a>.</p><p>"As incredulous as it is to believe they're considering this, I don't know if the practicalities of it are going to allow them to enact it," said Ginsberg.</p><p>"We host a very large charity of yours here in the UK that deals with sensitive personal data and if the government comes to us and says 'We need a back door to your encryption' and I say, of course, 'no', and we snap our fingers and we're in Ireland or Romania - then what do they do? Do they go to the charity? What can the charity do? They're going to be asked to provide a backdoor and they're incapable of doing that technically - it's not their system, really."</p><p>"So the charity will say they can't and is the government going to say either use someone else's encryption, which isn't safe, or they can't use encryption? I don't know that it has followed the string of the logic of their own intent," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Theresa May refuses to say if UK spies access medical data ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Home Secretary Theresa May has refused to answer whether Britain's security services are accessing medical records and other sensitive data.</p><p>She was defending the Snooper's Charter to the draft Investigatory Powers Bill, and told the committee she would not "go down the route of giving information about the sort of data sets that are being acquired", according to the <em><a href="http://www.bbc.co.uk/news/uk-politics-35300671" target="_blank">BBC</a></em>.</p><p>Her comments come after it was revealed last year that GCHQ is downloading large amounts of personal data, which could include everything from the electoral register, to supermarket loyalty schemes or bank records.</p><p>This data would then be analysed to "join the dots" and draw conclusions about individuals, and such use of information is covered by old legislation.</p><p>But May said new safeguards would cover such powers - one was limited six-month warrants that give access to data and another was judicial oversight of such requests.</p><p>The controversial bill has been attacked by major technology companies, ISPs and campaign groups.</p><p>Central to the controversy is the mass collection and storage of sensitive data, which the bill in its current form says could be held for up to 12 months.</p><p>May said security minister, John Hayes, had written to the committee of MPs and peers to ask why the government did not want to reveal the kinds of data that investigators would access.</p><p>May, however, maintained that the practice of siphoning large amounts of web data does not amount to "mass surveillance".</p><p>"The UK does not undertake mass surveillance," she said.</p><p><strong>13/01/16:</strong> <strong>Information Commissioner attacks Snooper's Charter</strong></p><p>The Information Commissioner's Office (ICO) has attacked the Investigatory Powers Bill, AKA the Snooper's Charter, saying downgrading encryption could be dangerous for personal security.</p><p>Not only can the information be used maliciously by hackers if it falls into the wrong hands, but it could also be used as a weapon by nation states.</p><p>"The information commissioner has stressed the importance of encryption to guard against the compromise of personal information," the ICO said.</p><p>"Weakening encryption can have significant consequences for individuals. The constant stream of <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security breaches</a> only serves to highlight how important encryption is towards safeguarding personal information. Weakened encryption safeguards could be exploited by hackers and nation states intent on harming the UK's interests."</p><p>The privacy watchdog expressed its concerns to the parliamentary committee responsible for investigating the impact of the bill, saying there was also little justification for asking communications providers to store data for up to 12 months.</p><p><strong>11/01/16:</strong> Anonymous browser developer Tor has condemned the Snooper's Charter, saying it will "significantly harm" people's safety.</p><p>"The draft bill should not centre on the false tradeoff between civil liberty and security. While it is undoubtedly not the intention of the Home Office, this draft bill will significantly harm the safety of human rights activists," The Tor Project wrote in its <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26373.html">written evidence</a> presented to the government.</p><p>The group said the Investigatory Powers Bill storing the metadata the lw requires companies to store about people for up to 12 months could reveal sensitive information about people who are using its privacy browser and others who are purposefully protecting their identities, meaning their lives could potentially be in danger.</p><p>May of Tor's users are human rights campaigners and depend on anonymity for their safety. The new rules could mean information about these campaigners are accessible by the wider world.</p><p>"Although there are techniques to protect computer systems from large-scale attacks, there are no effective measures for protecting computer systems from targeted attack by a capable adversary, especially when an adversary with state backing is a possible threat," Tor wrote.</p><p>"The discussion of the draft bill thus can be framed as a tradeoff between giving additional powers to law enforcement in exchange for taking away the ability of human rights activists and human rights organisations to protect themselves,"</p><p><strong>07/01/2016:</strong> Four of the world's biggest tech companies have officially condemned the so-called Snooper's Charter'.</p><p>Google, Facebook, Microsoft, Twitter and Yahoo have joined the chorus of industry voices condemning the Investigatory Powers Bill, alongside Apple and a roster of ISPs.</p><p>Their <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26367.pdf" target="_blank">official submission to Parliament</a> stated that "governments have a responsibility to protect people and their privacy".</p><p>According to the signatories, "the best way for countries to promote the security and privacy interests of their citizens is to ensure that surveillance is targeted, lawful, proportionate, necessary, jurisdictionally bounded, and transparent".</p><p>The companies had several key complaints with regards to the bill's current form, predominantly around the scope of the proposed powers, which would require ISPs to hold metadata on people's communication for at least a year.</p><p>For example, they argued that the wording is "vague" and "opaque", and caution that this could lead to confusion over how much power authorities are actually granted.</p><p>They also said that the bill may undermine trust in their technologies, as it "could involve the introduction of risks or vulnerabilities".</p><p>Another major concern regarded the implications of the new laws on foreign data legislation.</p><p>"Key elements of whatever legislation is passed by the UK are likely to be replicated by other countries," they wrote, "including with respect to UK citizens' data."</p><p>A pre-existing mess of contradictory data protection laws also runs the risk of leaving companies "in the impossible position of deciding whose laws to violate", the group said.</p><p><strong>18/11/2015 - ISPs tell Parliament they are "very concerned" about Snooper's Charter</strong></p><p>Parliament's Science and Technology Committee <a href="http://www.parliament.uk/business/committees/committees-a-z/commons-select/science-and-technology-committee/news-parliament-2015/investigatory-powers-bill-inquiry-launch-15-16" target="_blank">is due to examine</a> whether the technology exists to support Home Secretary Theresa May's <a href="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone" data-original-url="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone">Draft Investigatory Powers bill</a>. </p><p>MPs sitting on the committee will also assess the costs of the bill, its potential impact on communication providers, the consequences for citizens' use of IT services. </p><p>"More specific issues of interest to the Committee include the extent to which communications data and communications content can be separated and the extent to which this is reflected in the Draft Bill," it added. </p><p>The "short inquiry" will take place after <a href="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter" data-original-url="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter">industry experts questioned the actual scale of data storage required</a> by the so-called Snooper's Charter, which would force ISPs to keep a list of internet connection records (ICRS the websites people visit) for 12 months.</p><p>Such sensitive details of people's online activities would need to be protected by strong security measures, yet the bill is being proposed at a time when data breaches are becoming more and more common. </p><p>In <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/science-and-technology-committee/investigatory-powers-bill-technology-issues/oral/24378.html" target="_blank">oral evidence given to the committee last week</a>, the chair of the Internet Services Providers' Association said a solution that suits the bill's purposes will be hard to create because the bill's concept of an ICR does not accurately describe the data ISPs</p><p>"We are very concerned," James Blessing told the committee. "The whole idea of an internet connection record does not exist as far as internet service providers are concerned. We do not have an internet connection record." </p><p>"We do not store information about what our customers do online in this particular way. It is not clear from the bill what constitutes a connection record."</p><p>He added: "If you want to get at the URL someone is visiting, you need to open the packet, inspect it, take information out and then throw data away, which makes the whole processing of those records even more complicated and prone to mistakes."</p><p>The committee is welcoming written submissions on the issues until Friday, 27 November.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/government-it-strategy/25618/theresa-may-refuses-to-say-if-uk-spies-access-medical-data</link>
                                                                            <description>
                            <![CDATA[ Home Secretary says sweeping up large amounts of data is not “mass surveillance” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oE3K5cibmc4DuVeU7c2KeX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kuzAFeieV48y644ftdxTYQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jan 2016 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kuzAFeieV48y644ftdxTYQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Houses of Parliament]]></media:description>                                                            <media:text><![CDATA[Houses of Parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Houses of Parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kuzAFeieV48y644ftdxTYQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Home Secretary Theresa May has refused to answer whether Britain's security services are accessing medical records and other sensitive data.</p><p>She was defending the Snooper's Charter to the draft Investigatory Powers Bill, and told the committee she would not "go down the route of giving information about the sort of data sets that are being acquired", according to the <em><a href="http://www.bbc.co.uk/news/uk-politics-35300671" target="_blank">BBC</a></em>.</p><p>Her comments come after it was revealed last year that GCHQ is downloading large amounts of personal data, which could include everything from the electoral register, to supermarket loyalty schemes or bank records.</p><p>This data would then be analysed to "join the dots" and draw conclusions about individuals, and such use of information is covered by old legislation.</p><p>But May said new safeguards would cover such powers - one was limited six-month warrants that give access to data and another was judicial oversight of such requests.</p><p>The controversial bill has been attacked by major technology companies, ISPs and campaign groups.</p><p>Central to the controversy is the mass collection and storage of sensitive data, which the bill in its current form says could be held for up to 12 months.</p><p>May said security minister, John Hayes, had written to the committee of MPs and peers to ask why the government did not want to reveal the kinds of data that investigators would access.</p><p>May, however, maintained that the practice of siphoning large amounts of web data does not amount to "mass surveillance".</p><p>"The UK does not undertake mass surveillance," she said.</p><p><strong>13/01/16:</strong> <strong>Information Commissioner attacks Snooper's Charter</strong></p><p>The Information Commissioner's Office (ICO) has attacked the Investigatory Powers Bill, AKA the Snooper's Charter, saying downgrading encryption could be dangerous for personal security.</p><p>Not only can the information be used maliciously by hackers if it falls into the wrong hands, but it could also be used as a weapon by nation states.</p><p>"The information commissioner has stressed the importance of encryption to guard against the compromise of personal information," the ICO said.</p><p>"Weakening encryption can have significant consequences for individuals. The constant stream of <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security breaches</a> only serves to highlight how important encryption is towards safeguarding personal information. Weakened encryption safeguards could be exploited by hackers and nation states intent on harming the UK's interests."</p><p>The privacy watchdog expressed its concerns to the parliamentary committee responsible for investigating the impact of the bill, saying there was also little justification for asking communications providers to store data for up to 12 months.</p><p><strong>11/01/16:</strong> Anonymous browser developer Tor has condemned the Snooper's Charter, saying it will "significantly harm" people's safety.</p><p>"The draft bill should not centre on the false tradeoff between civil liberty and security. While it is undoubtedly not the intention of the Home Office, this draft bill will significantly harm the safety of human rights activists," The Tor Project wrote in its <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26373.html">written evidence</a> presented to the government.</p><p>The group said the Investigatory Powers Bill storing the metadata the lw requires companies to store about people for up to 12 months could reveal sensitive information about people who are using its privacy browser and others who are purposefully protecting their identities, meaning their lives could potentially be in danger.</p><p>May of Tor's users are human rights campaigners and depend on anonymity for their safety. The new rules could mean information about these campaigners are accessible by the wider world.</p><p>"Although there are techniques to protect computer systems from large-scale attacks, there are no effective measures for protecting computer systems from targeted attack by a capable adversary, especially when an adversary with state backing is a possible threat," Tor wrote.</p><p>"The discussion of the draft bill thus can be framed as a tradeoff between giving additional powers to law enforcement in exchange for taking away the ability of human rights activists and human rights organisations to protect themselves,"</p><p><strong>07/01/2016:</strong> Four of the world's biggest tech companies have officially condemned the so-called Snooper's Charter'.</p><p>Google, Facebook, Microsoft, Twitter and Yahoo have joined the chorus of industry voices condemning the Investigatory Powers Bill, alongside Apple and a roster of ISPs.</p><p>Their <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/draft-investigatory-powers-bill-committee/draft-investigatory-powers-bill/written/26367.pdf" target="_blank">official submission to Parliament</a> stated that "governments have a responsibility to protect people and their privacy".</p><p>According to the signatories, "the best way for countries to promote the security and privacy interests of their citizens is to ensure that surveillance is targeted, lawful, proportionate, necessary, jurisdictionally bounded, and transparent".</p><p>The companies had several key complaints with regards to the bill's current form, predominantly around the scope of the proposed powers, which would require ISPs to hold metadata on people's communication for at least a year.</p><p>For example, they argued that the wording is "vague" and "opaque", and caution that this could lead to confusion over how much power authorities are actually granted.</p><p>They also said that the bill may undermine trust in their technologies, as it "could involve the introduction of risks or vulnerabilities".</p><p>Another major concern regarded the implications of the new laws on foreign data legislation.</p><p>"Key elements of whatever legislation is passed by the UK are likely to be replicated by other countries," they wrote, "including with respect to UK citizens' data."</p><p>A pre-existing mess of contradictory data protection laws also runs the risk of leaving companies "in the impossible position of deciding whose laws to violate", the group said.</p><p><strong>18/11/2015 - ISPs tell Parliament they are "very concerned" about Snooper's Charter</strong></p><p>Parliament's Science and Technology Committee <a href="http://www.parliament.uk/business/committees/committees-a-z/commons-select/science-and-technology-committee/news-parliament-2015/investigatory-powers-bill-inquiry-launch-15-16" target="_blank">is due to examine</a> whether the technology exists to support Home Secretary Theresa May's <a href="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone" data-original-url="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone">Draft Investigatory Powers bill</a>. </p><p>MPs sitting on the committee will also assess the costs of the bill, its potential impact on communication providers, the consequences for citizens' use of IT services. </p><p>"More specific issues of interest to the Committee include the extent to which communications data and communications content can be separated and the extent to which this is reflected in the Draft Bill," it added. </p><p>The "short inquiry" will take place after <a href="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter" data-original-url="https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter">industry experts questioned the actual scale of data storage required</a> by the so-called Snooper's Charter, which would force ISPs to keep a list of internet connection records (ICRS the websites people visit) for 12 months.</p><p>Such sensitive details of people's online activities would need to be protected by strong security measures, yet the bill is being proposed at a time when data breaches are becoming more and more common. </p><p>In <a href="http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/science-and-technology-committee/investigatory-powers-bill-technology-issues/oral/24378.html" target="_blank">oral evidence given to the committee last week</a>, the chair of the Internet Services Providers' Association said a solution that suits the bill's purposes will be hard to create because the bill's concept of an ICR does not accurately describe the data ISPs</p><p>"We are very concerned," James Blessing told the committee. "The whole idea of an internet connection record does not exist as far as internet service providers are concerned. We do not have an internet connection record." </p><p>"We do not store information about what our customers do online in this particular way. It is not clear from the bill what constitutes a connection record."</p><p>He added: "If you want to get at the URL someone is visiting, you need to open the packet, inspect it, take information out and then throw data away, which makes the whole processing of those records even more complicated and prone to mistakes."</p><p>The committee is welcoming written submissions on the issues until Friday, 27 November.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers Bill: Hackers could access security backdoors ]]></title>
                                                                                                <dc:content><![CDATA[ <p>While the UK government continues to push forward with the notion that encryption backdoors are a good thing and encryption is bad because terrorists and paedophiles use it, others have a slightly more informed opinion.</p><p>Take, for example, the Dutch government, which this week declared something approaching a passion for strong encryption.</p><p>In <a href="https://blog.cyberwar.nl/2016/01/full-translation-of-the-dutch-governments-statement-on-encryption" target="_blank">an English translation of the Dutch government's statement</a>, Dutch security and justice minister Ard van der Steur is clearly shown to have a much better understanding of technology than either Prime Minister David Cameron or Home Secretary Theresa May.</p><p>Arriving at the conclusion that "it is currently not appropriate to adopt restrictive legal measures against the development, availability and use of encryption" within the Netherlands, van der Steur shows that he gets how backdoors would make encrypted data vulnerable to not only criminals and foreign intelligence services but, yes, also to the very terrorists that Cameron and his cohorts argue they would protect us from.</p><p>Backdoor access is, simply put, not a one-way street. You cannot introduce such a weakness into a security product and expect it to only be exploitable by yourself. Well, Cameron obviously does expect exactly that, which means that he's either an idiot or has been getting very poor technical advice: most likely a bit of both, if you ask me.</p><p>Van der Steur, meanwhile, appears to be spot on when he notes that backdoors "could have undesirable consequences for the security of information communicated and stored" as well as the core integrity of IT systems which are "increasingly of importance for the functioning of the society".</p><p>We cannot forget, however, that this Dutch government statement is put together by politicians and so the language used is all important. Language such as "is currently not desirable" which implies that it could become so if there's a political will to change things.</p><p>What I do know is that, currently, the UK and US governments appear to be on a collision course with IT and I suspect will continue to use terrorist atrocities as emotional leverage to drive badly thought out, commercially damaging and privacy-harming policies as far as weakening encryption usage is concerned.</p><p>Cameron appears to have more of an appetite for this than President Obama, and while the draft Investigatory Powers Bill may have stopped short of banning end-to-end encryption services, it does require backdoor access for law enforcement officials.</p><p>If this becomes law, then I guarantee that UK PLC will suffer as business moves data out of the country and to locations where strong encryption without backdoors is available.</p><p>UK companies who make secure products have also spoken of relocating outside of the UK rather than have to bow to legal moves to build backdoors into them.</p><p>Of course, whether the UK stays in the EU could impact upon all of this: Privacy of communication is a fundamental right that the European Convention on Human Rights (and Charter of Fundamental Rights of the EU) protects.</p><p>The 'security soundbite' may win the popular vote among some, but the economy will surely suffer just as much as our right to privacy. Once the masses realise that any law weakening encryption is actually taking us down the exact same road as regimes with poor human rights records, then even the 'nothing to hide, nothing to fear' right-leaning brigade might start thinking twice...</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/firewalls/25818/investigatory-powers-bill-hackers-could-access-security-backdoors</link>
                                                                            <description>
                            <![CDATA[ Why David Cameron is wrong about backdoors, and the Netherlands is right ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jMHXh3hkyJq5bUZrVpT7Qo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WkbhCzKhvM3wNpHyoq7Lza-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Jan 2016 14:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Firewalls]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WkbhCzKhvM3wNpHyoq7Lza-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WkbhCzKhvM3wNpHyoq7Lza-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While the UK government continues to push forward with the notion that encryption backdoors are a good thing and encryption is bad because terrorists and paedophiles use it, others have a slightly more informed opinion.</p><p>Take, for example, the Dutch government, which this week declared something approaching a passion for strong encryption.</p><p>In <a href="https://blog.cyberwar.nl/2016/01/full-translation-of-the-dutch-governments-statement-on-encryption" target="_blank">an English translation of the Dutch government's statement</a>, Dutch security and justice minister Ard van der Steur is clearly shown to have a much better understanding of technology than either Prime Minister David Cameron or Home Secretary Theresa May.</p><p>Arriving at the conclusion that "it is currently not appropriate to adopt restrictive legal measures against the development, availability and use of encryption" within the Netherlands, van der Steur shows that he gets how backdoors would make encrypted data vulnerable to not only criminals and foreign intelligence services but, yes, also to the very terrorists that Cameron and his cohorts argue they would protect us from.</p><p>Backdoor access is, simply put, not a one-way street. You cannot introduce such a weakness into a security product and expect it to only be exploitable by yourself. Well, Cameron obviously does expect exactly that, which means that he's either an idiot or has been getting very poor technical advice: most likely a bit of both, if you ask me.</p><p>Van der Steur, meanwhile, appears to be spot on when he notes that backdoors "could have undesirable consequences for the security of information communicated and stored" as well as the core integrity of IT systems which are "increasingly of importance for the functioning of the society".</p><p>We cannot forget, however, that this Dutch government statement is put together by politicians and so the language used is all important. Language such as "is currently not desirable" which implies that it could become so if there's a political will to change things.</p><p>What I do know is that, currently, the UK and US governments appear to be on a collision course with IT and I suspect will continue to use terrorist atrocities as emotional leverage to drive badly thought out, commercially damaging and privacy-harming policies as far as weakening encryption usage is concerned.</p><p>Cameron appears to have more of an appetite for this than President Obama, and while the draft Investigatory Powers Bill may have stopped short of banning end-to-end encryption services, it does require backdoor access for law enforcement officials.</p><p>If this becomes law, then I guarantee that UK PLC will suffer as business moves data out of the country and to locations where strong encryption without backdoors is available.</p><p>UK companies who make secure products have also spoken of relocating outside of the UK rather than have to bow to legal moves to build backdoors into them.</p><p>Of course, whether the UK stays in the EU could impact upon all of this: Privacy of communication is a fundamental right that the European Convention on Human Rights (and Charter of Fundamental Rights of the EU) protects.</p><p>The 'security soundbite' may win the popular vote among some, but the economy will surely suffer just as much as our right to privacy. Once the masses realise that any law weakening encryption is actually taking us down the exact same road as regimes with poor human rights records, then even the 'nothing to hide, nothing to fear' right-leaning brigade might start thinking twice...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple mauls UK government over online surveillance ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple has called on the UK government to make changes to the Investigatory Powers Bill as the iPhone maker fears that if the law was enacted in its present state it would radically alter customers' security and privacy.</p><p>The bill is currently being scrutinised by a parliamentary committee. In a submission to the committee, Apple said that it believed "it would be wrong to weaken security for hundreds of millions of law-abiding customers so that it will also be weaker for the very few who pose a threat."</p><p>"In this rapidly evolving cyber threat environment, companies should remain free to implement strong encryption to protect customers," it added.</p><p>Apple underlined a number of areas where it wants to see changes. It said the bill would grant the government powers to demand Apple change the way iMessages works and this, the company claimed, would weaken its encryption and allow security services to eavesdrop on the service for the first time. At present, iMessage is set up so that even Apple cannot decrypt messages passing through the system. </p><p>The tech giant also claimed that the language in the bill could be interpreted widely and force it to create backdoors to allow security agencies access. Such a backdoor would make users' data less secure, Apple argued. </p><p>"The government does not know in advance which individuals will become targets of investigation, so the encryption system necessarily would need to be compromised for everyone," the statement said.</p><p>It continued: "The bill threatens to hurt law-abiding citizens in its effort to combat the few bad actors who have a variety of ways to carry out their attacks. The creation of backdoors and intercept capabilities would weaken the protections built into Apple products and endanger all our customers. A key left under the doormat would not just be there for the good guys. The bad guys would find it too."</p><p>Home Secretary Theresa May's bill would legally require companies, such as Apple, to hand over data on devices. Security agencies would also be allowed to tamper with equipment to extract data from a device.</p><p>Apple said that if companies were forced to comply with warrants for information, or snoop on their customers on behalf of governments, other countries would demand the same.</p><p>It added that the law would "force non-UK companies to take actions that violate the laws of their home countries".</p><p>Apple continued: "This would immobilise substantial portions of the tech sector and spark serious international conflicts. It would also likely be the catalyst for other countries to enact similar laws, paralysing multinational corporations under the weight of what could be dozens or hundreds of contradictory country-specific laws.</p><p>"Those businesses affected will have to cope with a set of overlapping foreign and domestic laws. When these laws inevitably conflict, the businesses will be left having to arbitrate between them, knowing that in doing so they might risk sanctions. That is an unreasonable position to be placed in."</p><p>Apple CEO Tim Cook last month warned that the bill would do nothing to stop criminals.</p><p>"We believe very strongly in end-to-end encryption and no back doors," Cook told The <em><a href="http://www.telegraph.co.uk/technology/apple/11984806/Apples-Tim-Cook-declares-the-end-of-the-PC-and-hints-at-new-medical-product.html">Telegraph</a></em>. "We don't think people want us to read their messages. We don't feel we have the right to read their emails."</p><p>Cook continued: "Any back door is a back door for everyone. Everybody wants to crack down on terrorists. Everybody wants to be secure. The question is how. Opening a back door can have very dire consequences."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/25767/apple-mauls-uk-government-over-online-surveillance</link>
                                                                            <description>
                            <![CDATA[ Cupertino urges changes to “Snooper’s Charter” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9CWygxYnz7xeTSRaEEzZLq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CbRtGYHhhckqk5tCPB2NKd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Dec 2015 11:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CbRtGYHhhckqk5tCPB2NKd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Snooping - confidential data]]></media:description>                                                            <media:text><![CDATA[Snooping - confidential data]]></media:text>
                                <media:title type="plain"><![CDATA[Snooping - confidential data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CbRtGYHhhckqk5tCPB2NKd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has called on the UK government to make changes to the Investigatory Powers Bill as the iPhone maker fears that if the law was enacted in its present state it would radically alter customers' security and privacy.</p><p>The bill is currently being scrutinised by a parliamentary committee. In a submission to the committee, Apple said that it believed "it would be wrong to weaken security for hundreds of millions of law-abiding customers so that it will also be weaker for the very few who pose a threat."</p><p>"In this rapidly evolving cyber threat environment, companies should remain free to implement strong encryption to protect customers," it added.</p><p>Apple underlined a number of areas where it wants to see changes. It said the bill would grant the government powers to demand Apple change the way iMessages works and this, the company claimed, would weaken its encryption and allow security services to eavesdrop on the service for the first time. At present, iMessage is set up so that even Apple cannot decrypt messages passing through the system. </p><p>The tech giant also claimed that the language in the bill could be interpreted widely and force it to create backdoors to allow security agencies access. Such a backdoor would make users' data less secure, Apple argued. </p><p>"The government does not know in advance which individuals will become targets of investigation, so the encryption system necessarily would need to be compromised for everyone," the statement said.</p><p>It continued: "The bill threatens to hurt law-abiding citizens in its effort to combat the few bad actors who have a variety of ways to carry out their attacks. The creation of backdoors and intercept capabilities would weaken the protections built into Apple products and endanger all our customers. A key left under the doormat would not just be there for the good guys. The bad guys would find it too."</p><p>Home Secretary Theresa May's bill would legally require companies, such as Apple, to hand over data on devices. Security agencies would also be allowed to tamper with equipment to extract data from a device.</p><p>Apple said that if companies were forced to comply with warrants for information, or snoop on their customers on behalf of governments, other countries would demand the same.</p><p>It added that the law would "force non-UK companies to take actions that violate the laws of their home countries".</p><p>Apple continued: "This would immobilise substantial portions of the tech sector and spark serious international conflicts. It would also likely be the catalyst for other countries to enact similar laws, paralysing multinational corporations under the weight of what could be dozens or hundreds of contradictory country-specific laws.</p><p>"Those businesses affected will have to cope with a set of overlapping foreign and domestic laws. When these laws inevitably conflict, the businesses will be left having to arbitrate between them, knowing that in doing so they might risk sanctions. That is an unreasonable position to be placed in."</p><p>Apple CEO Tim Cook last month warned that the bill would do nothing to stop criminals.</p><p>"We believe very strongly in end-to-end encryption and no back doors," Cook told The <em><a href="http://www.telegraph.co.uk/technology/apple/11984806/Apples-Tim-Cook-declares-the-end-of-the-PC-and-hints-at-new-medical-product.html">Telegraph</a></em>. "We don't think people want us to read their messages. We don't feel we have the right to read their emails."</p><p>Cook continued: "Any back door is a back door for everyone. Everybody wants to crack down on terrorists. Everybody wants to be secure. The question is how. Opening a back door can have very dire consequences."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts question sheer scale of data storage required by Snooper's Charter ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Requirements in <a href="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption" target="_blank" data-original-url="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption">the proposed Investigatory Powers Bill, unveiled yesterday</a>, for ISPs to store the history of every website visited by every individual on every device in the UK have been called into question at a technical level.</p><p>Under the proposed law, ISPs and mobile networks would have to retain what the government has termed "Internet Connection Records", or "ICRs" for up to 12 months.</p><p>ICRs comprise details, including IP addresses, of the websites that individuals visit, although not necessarily what content they access there, nor what actions they perform.</p><p>While this has <a href="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone">caused concerns among privacy and security professionals and campaigners</a>, the practicality of this requirement is also now being called into question.</p><p>"Unfortunately, this legislation unlocks more questions than it answers," said Bharat Mistry, a cybersecurity consultant with Trend Micro.</p><p>"If a Communications Service Provider (CSP) is required to capture this data and store it, there is a question around who is going to fund the infrastructure costs? This isn't just about the physical infrastructure assets but environmental sucha as power, cooling and physical security costs have to be considered," Mistry said.</p><p>"CSPs are already saying that data storage repositories are growing at an unmanageable rate - so how can this quantity of data be managed and securely transferred and stored?" he added.</p><p>Tarkan Maner, CEO of software-defined storage firm Nexenta, struck a similar note.</p><p>"While politicians and privacy campaigners are likely to continue to debate the ethical implications of the findings, and subsequently the terms of the bill, the big question that the IT industry is asking is how will this add to the already unsolved challenge of Big Data collection," said Maner.</p><p>"From a business perspective, we already find ourselves in a position where data collection is overwhelming the technology being used to collect and store is - and storage is emerging as a bottleneck to address. The industry, and bodies affected by the draft charter must move now and prepare their infrastructure to cope with this explosion of data," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-centers/25555/experts-question-sheer-scale-of-data-storage-required-by-snoopers-charter</link>
                                                                            <description>
                            <![CDATA[ Who will foot bill for physical infrastructure to house UK's browsing histories? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kVvHkQVEWfLQEsz1NLVNBn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hidEKzwyeRp7wN8LRCWarD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Nov 2015 16:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Centres]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hidEKzwyeRp7wN8LRCWarD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data industry]]></media:description>                                                            <media:text><![CDATA[Data industry]]></media:text>
                                <media:title type="plain"><![CDATA[Data industry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hidEKzwyeRp7wN8LRCWarD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Requirements in <a href="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption" target="_blank" data-original-url="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption">the proposed Investigatory Powers Bill, unveiled yesterday</a>, for ISPs to store the history of every website visited by every individual on every device in the UK have been called into question at a technical level.</p><p>Under the proposed law, ISPs and mobile networks would have to retain what the government has termed "Internet Connection Records", or "ICRs" for up to 12 months.</p><p>ICRs comprise details, including IP addresses, of the websites that individuals visit, although not necessarily what content they access there, nor what actions they perform.</p><p>While this has <a href="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone">caused concerns among privacy and security professionals and campaigners</a>, the practicality of this requirement is also now being called into question.</p><p>"Unfortunately, this legislation unlocks more questions than it answers," said Bharat Mistry, a cybersecurity consultant with Trend Micro.</p><p>"If a Communications Service Provider (CSP) is required to capture this data and store it, there is a question around who is going to fund the infrastructure costs? This isn't just about the physical infrastructure assets but environmental sucha as power, cooling and physical security costs have to be considered," Mistry said.</p><p>"CSPs are already saying that data storage repositories are growing at an unmanageable rate - so how can this quantity of data be managed and securely transferred and stored?" he added.</p><p>Tarkan Maner, CEO of software-defined storage firm Nexenta, struck a similar note.</p><p>"While politicians and privacy campaigners are likely to continue to debate the ethical implications of the findings, and subsequently the terms of the bill, the big question that the IT industry is asking is how will this add to the already unsolved challenge of Big Data collection," said Maner.</p><p>"From a business perspective, we already find ourselves in a position where data collection is overwhelming the technology being used to collect and store is - and storage is emerging as a bottleneck to address. The industry, and bodies affected by the draft charter must move now and prepare their infrastructure to cope with this explosion of data," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Investigatory Powers Bill: A Snooper's Charter in all but name alone ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Snooper's Charter, and despite all the efforts to try and distance it from that label by the government that is precisely what it remains, has finally been revealed in the form of the <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/473770/Draft_Investigatory_Powers_Bill.pdf" target="_blank">Draft Investigatory Powers Bill</a>.</p><p>The big question is, should we be worried?</p><p><a href="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption" target="_blank" data-original-url="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption">Industry reaction</a> so far has been alarmingly supportive. I was particularly concerned by the comments from Nicholas Lansman, general secretary of ISP industry body ISPA, who said it was preparing to work with the government to ensure the bill provides a framework that "balances necessary powers with oversight whilst minimising the impact on business." How about the impact on freedom, and the necessary power to go about our personal business without being spied upon?</p><p>I say 'our' but obviously I do not include MPs in that description as the draft bill clearly omits them from being subject to the surveillance that they would have us under; it will write 'the Wilson doctrine' into law, preventing surveillance of their communications. Journalists, who you might think require similar protection if they are to do their job of ensuring freedom of speech is a reality in the UK, don't get the same pass - police will be able to access their sources with the nod of a friendly judge.</p><p>There will be no requirement for the likes of Google to code backdoors into their services or <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">WhatsApp to stop runnign end-to-end encryption</a>, as has been feared.That is a good thing, obviously. That said, if you truly believe that this bill will prevent the security services from doing whatever they think is in the national interest, which may often translate into being their own interest, then you've obviously not taken an interest in Edward Snowden.</p><p>The lawyers, politicians, civil servants and spy masters who have drafted this latest proposed incarnation of the Snooper's Charter quite obviously do know all about Snowden. In fact, it reads like a direct response to his whistleblowing. When it comes down to it, after all, what this bill will do is give legal validity to most of the stuff that the security services were already doing secretly and without that legitimacy: the bulk collection of personal communication data, the hacking into computers and smartphones, the blanket storage of internet usage data.</p><p>The legal responsibility for storing such data is to be handed over to internet service providers (ISPs) rather than law enforcement and security agencies; they will just get the right to demand to see it. In fact the bill will require ISPs to store this data, of every internet user in the UK (apart from MPs of course), detailing every site that they visit, for a full 12 months. It's okay though, because a judge will have to sign off any request to access it as well as the Home Secretary herself. Unless it's urgent, in which case all bets are off and the data is revealed without the judge's nod or knowledge.</p><p>This is probably the most worrying aspect of the bill for me, quite apart from the privacy implications. Simply put, it leaves the door open for all kinds of insecurity scenarios. Home secretary Teresa May herself apparently failed to see the irony in her statement suggesting that high profile hacking attacks were one reason the bill needs to be introduced.</p><p>Put all that user data in one place, at every ISP, and it becomes a huge target. Let's hope there is a clause added to exclude TalkTalk from having to do this, <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" target="_blank" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">given its record</a>. Seriously though, can you imagine what will happen when this kind of data is hacked for the first time? And it is a matter of when, not if - of that you can be sure.</p><p>Hopefully this bill, or at least the browser history retention part of it, can follow DRIPA (the Data Retention and Investigatory Powers Act) into the unlawful bin. Earlier this year the High Court ruled that <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">parts of DRIPA were not compatible</a> with EU rights on privacy and the protection of personal data. I fail to see how the proposed new bill is any different, and would hope that the judiciary feels the same and follows the same route to throwing it out should it ever make it into law.</p><p>If not then I fear that Snowden was right when he tweeted that the "I don't need privacy, I've nothing to hide" line equates to "I don't need free speech, I've nothing to say". At the end of the day, as Snowden also noted, "your web records are not like an itemised phone bill, they're like a list of every book you've ever opened...".</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/25554/investigatory-powers-bill-a-snoopers-charter-in-all-but-name-alone</link>
                                                                            <description>
                            <![CDATA[ Edward Snowden is right to call this bill our biggest threat to freedom of speech ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bACjiBLeUA354ietgTrRDW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q2DWY5QeitXRHabHgB99DS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Nov 2015 14:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q2DWY5QeitXRHabHgB99DS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q2DWY5QeitXRHabHgB99DS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Snooper's Charter, and despite all the efforts to try and distance it from that label by the government that is precisely what it remains, has finally been revealed in the form of the <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/473770/Draft_Investigatory_Powers_Bill.pdf" target="_blank">Draft Investigatory Powers Bill</a>.</p><p>The big question is, should we be worried?</p><p><a href="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption" target="_blank" data-original-url="https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption">Industry reaction</a> so far has been alarmingly supportive. I was particularly concerned by the comments from Nicholas Lansman, general secretary of ISP industry body ISPA, who said it was preparing to work with the government to ensure the bill provides a framework that "balances necessary powers with oversight whilst minimising the impact on business." How about the impact on freedom, and the necessary power to go about our personal business without being spied upon?</p><p>I say 'our' but obviously I do not include MPs in that description as the draft bill clearly omits them from being subject to the surveillance that they would have us under; it will write 'the Wilson doctrine' into law, preventing surveillance of their communications. Journalists, who you might think require similar protection if they are to do their job of ensuring freedom of speech is a reality in the UK, don't get the same pass - police will be able to access their sources with the nod of a friendly judge.</p><p>There will be no requirement for the likes of Google to code backdoors into their services or <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">WhatsApp to stop runnign end-to-end encryption</a>, as has been feared.That is a good thing, obviously. That said, if you truly believe that this bill will prevent the security services from doing whatever they think is in the national interest, which may often translate into being their own interest, then you've obviously not taken an interest in Edward Snowden.</p><p>The lawyers, politicians, civil servants and spy masters who have drafted this latest proposed incarnation of the Snooper's Charter quite obviously do know all about Snowden. In fact, it reads like a direct response to his whistleblowing. When it comes down to it, after all, what this bill will do is give legal validity to most of the stuff that the security services were already doing secretly and without that legitimacy: the bulk collection of personal communication data, the hacking into computers and smartphones, the blanket storage of internet usage data.</p><p>The legal responsibility for storing such data is to be handed over to internet service providers (ISPs) rather than law enforcement and security agencies; they will just get the right to demand to see it. In fact the bill will require ISPs to store this data, of every internet user in the UK (apart from MPs of course), detailing every site that they visit, for a full 12 months. It's okay though, because a judge will have to sign off any request to access it as well as the Home Secretary herself. Unless it's urgent, in which case all bets are off and the data is revealed without the judge's nod or knowledge.</p><p>This is probably the most worrying aspect of the bill for me, quite apart from the privacy implications. Simply put, it leaves the door open for all kinds of insecurity scenarios. Home secretary Teresa May herself apparently failed to see the irony in her statement suggesting that high profile hacking attacks were one reason the bill needs to be introduced.</p><p>Put all that user data in one place, at every ISP, and it becomes a huge target. Let's hope there is a clause added to exclude TalkTalk from having to do this, <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" target="_blank" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">given its record</a>. Seriously though, can you imagine what will happen when this kind of data is hacked for the first time? And it is a matter of when, not if - of that you can be sure.</p><p>Hopefully this bill, or at least the browser history retention part of it, can follow DRIPA (the Data Retention and Investigatory Powers Act) into the unlawful bin. Earlier this year the High Court ruled that <a href="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful" target="_blank" data-original-url="https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful">parts of DRIPA were not compatible</a> with EU rights on privacy and the protection of personal data. I fail to see how the proposed new bill is any different, and would hope that the judiciary feels the same and follows the same route to throwing it out should it ever make it into law.</p><p>If not then I fear that Snowden was right when he tweeted that the "I don't need privacy, I've nothing to hide" line equates to "I don't need free speech, I've nothing to say". At the end of the day, as Snowden also noted, "your web records are not like an itemised phone bill, they're like a list of every book you've ever opened...".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snooper's Charter puts data at risk even with encryption ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Investigatory Powers Bill could leave UK citizens at risk of data theft even though end-to-end encryption has not been banned.</p><p>Home Secretary Theresa May presented the proposed legislation, known colloquially as <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Snooper's Charter</a>, to Parliament today, and if passed, it would require ISPs to store Internet Connection Records (ICRs - which domains people visit) for up to 12 months.</p><p>This includes details of which services a device has connected through, such as a website or instant messaging (IM) platform.</p><p>"An ICR is not a person's full internet browsing history," the preamble to <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/473770/Draft_Investigatory_Powers_Bill.pdf" target="_blank">the bill</a> reads. "It is a record of the services that they have connected to, which can provide vital investigative leads. It would not reveal every web page that they visit or anything that they do on that web page."</p><p>However, the data in question, which communications service providers will be required to store in bulk, is still sensitive, as pointed out by NSA whistleblower <a href="https://twitter.com/Snowden" target="_blank">Edward Snowden</a>.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Fj4UKofBQG9qVVZSzLvuMh" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/Fj4UKofBQG9qVVZSzLvuMh.png" mos="https://cdn.mos.cms.futurecdn.net/Fj4UKofBQG9qVVZSzLvuMh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>One tech vendor, Dell, warned that such a requirement opens up the risk that ISPs will leak sensitive user data.</p><p>"We have countless examples of how organisations' security systems have failed in the past as a result of insufficient security and access procedures, and [as] a result sensitive data has been misused," said Timothy Brown, executive director of security with Dell Software Group.</p><p>"If organisations are required to store more information on their customers for longer periods of time, there must be appropriate controls and audit measures in place. People consider their telecommunications and internet activity to be private and If ISPs and wireless providers are required to store data on their customers, this only creates larger and more attractive targets for hackers and leaks."</p><p>Jonathan Parker-Bray, CEO of Criptyque, which owns secure messaging platform Pryvate, voiced a similar concern, saying: "Threat actors will always find nefarious ways of using good-intentioned technology for their own means, and this law is a potential license for the invasion of the right to privacy on a scale this country cannot allow."</p><p>"Whilst we would agree strongly that there does need to be an updating and an expansion of legislation to account for the digital age, this should not override the hard-fought right to privacy that is owned by every citizen in the UK," he added.</p><h2 id="it-could-be-worse">It could be worse</h2><p>While there have been strong negative reactions, the draft of the bill published today does not include two of the clauses that had caused most concern: a ban on end-to-end encryption and the bypassing of the judiciary when issuing warrants to retrieve ICR data.</p><p>Instead for the first time in history, a judge must approve such warrants after the Home Secretary has signed off them, and the government will not require technology companies to weaken or water down encryption outside of RIPA's requirement for companies to be able to unencrypt communications data when authorities make such a request.</p><p>Mark Taylor, a partner with international law firm Osborne Clarke, said: "In regards to the authorisation of warrants, it's good to see that the Home Secretary has respected some separation of powers, with a degree of oversight from the judiciary as well as an independent commissioner."</p><p>"Businesses will breathe a sigh of relief that end-to-end encryption has not been banned. Many of their business models - and in particular payment transactions - are based on the trust that consumers place in their end-to-end encryption," he added.</p><h2 id="industry-reaction">Industry reaction</h2><p>It has also received qualified support from some quarters of the tech and telecoms industry.</p><p>Antony Walker, deputy CEO of techUK said: "On first impressions [the bill] looks like a step in the right direction to creating what is required here - a world-leading legal framework that balances the security needs with democratic values.</p><p>"Parliament must now judge whether the powers government is seeking, such as internet connection records, equipment interference and bulk collection, are necessary and proportionate and whether the safeguards being proposed to govern their use are sufficient. The importance of the task ahead of the Joint Parliamentary Scrutiny Committee cannot be overstated."</p><p>Nicholas Lansman, general secretary of ISP industry body ISPA, was more enthusiastic, adding: "ISPA welcomes the attempt to modernise and clarify the law. We will work with government to ensure that the bill provides ISPs with a clear and stable legal framework that balances necessary powers with oversight whilst minimising the impact on business."</p><p>The bill will now be scrutinised by the Lords and the Commons.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25550/snoopers-charter-puts-data-at-risk-even-with-encryption</link>
                                                                            <description>
                            <![CDATA[ The more data ISPs must store, the more there is to steal, warn experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vcsULdvrMjnKVvvUhaQxiX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Nov 2015 17:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Bill could leave UK citizens at risk of data theft even though end-to-end encryption has not been banned.</p><p>Home Secretary Theresa May presented the proposed legislation, known colloquially as <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Snooper's Charter</a>, to Parliament today, and if passed, it would require ISPs to store Internet Connection Records (ICRs - which domains people visit) for up to 12 months.</p><p>This includes details of which services a device has connected through, such as a website or instant messaging (IM) platform.</p><p>"An ICR is not a person's full internet browsing history," the preamble to <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/473770/Draft_Investigatory_Powers_Bill.pdf" target="_blank">the bill</a> reads. "It is a record of the services that they have connected to, which can provide vital investigative leads. It would not reveal every web page that they visit or anything that they do on that web page."</p><p>However, the data in question, which communications service providers will be required to store in bulk, is still sensitive, as pointed out by NSA whistleblower <a href="https://twitter.com/Snowden" target="_blank">Edward Snowden</a>.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Fj4UKofBQG9qVVZSzLvuMh" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/Fj4UKofBQG9qVVZSzLvuMh.png" mos="https://cdn.mos.cms.futurecdn.net/Fj4UKofBQG9qVVZSzLvuMh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>One tech vendor, Dell, warned that such a requirement opens up the risk that ISPs will leak sensitive user data.</p><p>"We have countless examples of how organisations' security systems have failed in the past as a result of insufficient security and access procedures, and [as] a result sensitive data has been misused," said Timothy Brown, executive director of security with Dell Software Group.</p><p>"If organisations are required to store more information on their customers for longer periods of time, there must be appropriate controls and audit measures in place. People consider their telecommunications and internet activity to be private and If ISPs and wireless providers are required to store data on their customers, this only creates larger and more attractive targets for hackers and leaks."</p><p>Jonathan Parker-Bray, CEO of Criptyque, which owns secure messaging platform Pryvate, voiced a similar concern, saying: "Threat actors will always find nefarious ways of using good-intentioned technology for their own means, and this law is a potential license for the invasion of the right to privacy on a scale this country cannot allow."</p><p>"Whilst we would agree strongly that there does need to be an updating and an expansion of legislation to account for the digital age, this should not override the hard-fought right to privacy that is owned by every citizen in the UK," he added.</p><h2 id="it-could-be-worse">It could be worse</h2><p>While there have been strong negative reactions, the draft of the bill published today does not include two of the clauses that had caused most concern: a ban on end-to-end encryption and the bypassing of the judiciary when issuing warrants to retrieve ICR data.</p><p>Instead for the first time in history, a judge must approve such warrants after the Home Secretary has signed off them, and the government will not require technology companies to weaken or water down encryption outside of RIPA's requirement for companies to be able to unencrypt communications data when authorities make such a request.</p><p>Mark Taylor, a partner with international law firm Osborne Clarke, said: "In regards to the authorisation of warrants, it's good to see that the Home Secretary has respected some separation of powers, with a degree of oversight from the judiciary as well as an independent commissioner."</p><p>"Businesses will breathe a sigh of relief that end-to-end encryption has not been banned. Many of their business models - and in particular payment transactions - are based on the trust that consumers place in their end-to-end encryption," he added.</p><h2 id="industry-reaction">Industry reaction</h2><p>It has also received qualified support from some quarters of the tech and telecoms industry.</p><p>Antony Walker, deputy CEO of techUK said: "On first impressions [the bill] looks like a step in the right direction to creating what is required here - a world-leading legal framework that balances the security needs with democratic values.</p><p>"Parliament must now judge whether the powers government is seeking, such as internet connection records, equipment interference and bulk collection, are necessary and proportionate and whether the safeguards being proposed to govern their use are sufficient. The importance of the task ahead of the Joint Parliamentary Scrutiny Committee cannot be overstated."</p><p>Nicholas Lansman, general secretary of ISP industry body ISPA, was more enthusiastic, adding: "ISPA welcomes the attempt to modernise and clarify the law. We will work with government to ensure that the bill provides ISPs with a clear and stable legal framework that balances necessary powers with oversight whilst minimising the impact on business."</p><p>The bill will now be scrutinised by the Lords and the Commons.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK government looks to ban strong encryption from devices ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK government is set to announce new laws that would force tech companies to hold a special key that unencrypts data held on devices, before passing it over to intelligence agencies.</p><p>Companies such as Apple, Google, Microsoft and others would no longer be able to offer "unbreakable" encryption in products sold in the UK, according to the <em><a href="http://www.telegraph.co.uk/news/uknews/terrorism-in-the-uk/11970391/Internet-firms-to-be-banned-from-offering-out-of-reach-communications-under-new-laws.html" target="_blank">Daily Telegraph</a>.</em></p><p>The <a href="https://www.itpro.com/public-sector/25525/gov-waters-down-investigatory-powers-bill-spying-measures" target="_blank" data-original-url="https://www.itpro.com/public-sector/25525/gov-waters-down-investigatory-powers-bill-spying-measures">Investigatory Powers Bill</a> (or Snooper's Charter in common parlance) would require technology firms and ISPs to provide unencrypted communications to law enforcement or intelligence agencies when they produce a warrant.</p><p>The bill would also require ISPs to retain the browsing history of customers - but not the specific pages they visit - for up to a year.</p><p>Devices with end-to-end encryption that is nearly impossible to break using current techniques provide a "safe space" for criminals, terrorists and paedophiles, the government believes.</p><p>Prime Minister David Cameron pleaded with the public and MPs to back the law, despite overwhelming criticism that it would violate user privacy and would essentially make many online tasks, such as online banking, impossible to fully secure.</p><p>"As Prime Minister I would just say to people please, let's not have a situation where we give terrorists, criminals, child abductors, safe spaces to communicate," he told <em>ITV</em>'s This Morning show. "It's not a safe space for them to communicate on a fixed line telephone or a mobile phone, we shouldn't allow the internet to be a safe space for them to communicate and do bad things."</p><p>Secret encryption keys have a terrible history of being discovered. In 2007, <a href="https://en.wikipedia.org/wiki/AACS_encryption_key_controversy">a number of encryption keys</a> were posted on the internet that allowed people to subvert the security around Blu-ray and HD DVD encryption.</p><p>Efforts to keep the keys under wraps led to a <a href="https://en.wikipedia.org/wiki/Streisand_effect" target="_blank">Streisand effect</a>, with many web pages, blogs and wikis spreading the encryption keys far beyond a coterie of techies.</p><p>Mike Weston, CEO of data science consultancy Profusion, said the Investigatory Powers Bill is a very concerning piece of legislation for both the tech industry and consumers.</p><p>"Limiting what encryption can be used is a victory for the security services, hackers and companies intent on misusing personal data," he said. "Not a week goes by when it isn't made readily apparent that the protection currently afforded to personal data is inadequate. Seeking to limit what companies can do to encrypt data is a stunningly short-sighted approach."</p><p>He added that the UK's position on data protection is in sharp contrast to the rest of Europe.</p><p>"Countries like Germany have recognised that greater emphasis needs to be placed on protecting the rights of users online and how personal information is collected and used," said Weston.</p><p>He added that the UK is taking a much more regressive path by seeking to increase oversight, the burden on businesses to collect, hold and make accessible personal information, and limit how companies protect data. "It will be an incredibly worrying situation if this Bill passes without any judicial oversight covering warrants," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25532/uk-government-looks-to-ban-strong-encryption-from-devices</link>
                                                                            <description>
                            <![CDATA[ Crypto ban could make internet activities, such as online banking, unsafe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mSQjVTFQmoLBXSedwCrfEp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Nov 2015 14:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Government]]></media:description>                                                            <media:text><![CDATA[Government]]></media:text>
                                <media:title type="plain"><![CDATA[Government]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government is set to announce new laws that would force tech companies to hold a special key that unencrypts data held on devices, before passing it over to intelligence agencies.</p><p>Companies such as Apple, Google, Microsoft and others would no longer be able to offer "unbreakable" encryption in products sold in the UK, according to the <em><a href="http://www.telegraph.co.uk/news/uknews/terrorism-in-the-uk/11970391/Internet-firms-to-be-banned-from-offering-out-of-reach-communications-under-new-laws.html" target="_blank">Daily Telegraph</a>.</em></p><p>The <a href="https://www.itpro.com/public-sector/25525/gov-waters-down-investigatory-powers-bill-spying-measures" target="_blank" data-original-url="https://www.itpro.com/public-sector/25525/gov-waters-down-investigatory-powers-bill-spying-measures">Investigatory Powers Bill</a> (or Snooper's Charter in common parlance) would require technology firms and ISPs to provide unencrypted communications to law enforcement or intelligence agencies when they produce a warrant.</p><p>The bill would also require ISPs to retain the browsing history of customers - but not the specific pages they visit - for up to a year.</p><p>Devices with end-to-end encryption that is nearly impossible to break using current techniques provide a "safe space" for criminals, terrorists and paedophiles, the government believes.</p><p>Prime Minister David Cameron pleaded with the public and MPs to back the law, despite overwhelming criticism that it would violate user privacy and would essentially make many online tasks, such as online banking, impossible to fully secure.</p><p>"As Prime Minister I would just say to people please, let's not have a situation where we give terrorists, criminals, child abductors, safe spaces to communicate," he told <em>ITV</em>'s This Morning show. "It's not a safe space for them to communicate on a fixed line telephone or a mobile phone, we shouldn't allow the internet to be a safe space for them to communicate and do bad things."</p><p>Secret encryption keys have a terrible history of being discovered. In 2007, <a href="https://en.wikipedia.org/wiki/AACS_encryption_key_controversy">a number of encryption keys</a> were posted on the internet that allowed people to subvert the security around Blu-ray and HD DVD encryption.</p><p>Efforts to keep the keys under wraps led to a <a href="https://en.wikipedia.org/wiki/Streisand_effect" target="_blank">Streisand effect</a>, with many web pages, blogs and wikis spreading the encryption keys far beyond a coterie of techies.</p><p>Mike Weston, CEO of data science consultancy Profusion, said the Investigatory Powers Bill is a very concerning piece of legislation for both the tech industry and consumers.</p><p>"Limiting what encryption can be used is a victory for the security services, hackers and companies intent on misusing personal data," he said. "Not a week goes by when it isn't made readily apparent that the protection currently afforded to personal data is inadequate. Seeking to limit what companies can do to encrypt data is a stunningly short-sighted approach."</p><p>He added that the UK's position on data protection is in sharp contrast to the rest of Europe.</p><p>"Countries like Germany have recognised that greater emphasis needs to be placed on protecting the rights of users online and how personal information is collected and used," said Weston.</p><p>He added that the UK is taking a much more regressive path by seeking to increase oversight, the burden on businesses to collect, hold and make accessible personal information, and limit how companies protect data. "It will be an incredibly worrying situation if this Bill passes without any judicial oversight covering warrants," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gov waters down Investigatory Powers Bill spying measures ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Home secretary Theresa May will drop some controversial elements from the Investigatory Powers Bill ahead of its appearance in Parliament on Wednesday.</p><p>The bill is a redrafted version of <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Communications Data Bill, dubbed the Snooper's Charter</a>, which was first introduced in 2012 but blocked by the Liberal Democrats during the coalition government. </p><p>A requirement for UK ISPs to keep data on third-parties will be scratched from the bill, as will the ability to access people's browsing histories, May told the <a href="http://www.bbc.co.uk/news/uk-34691956"><em>BBC</em></a>.</p><p>Speaking on the Andrew Marr show, she said: "It doesn't have some of the more contentious powers that were in that [Snooper's Charter] bill.</p><p>"So, for example, we won't be requiring communication service providers from in the UK to store third-party data, we won't be making the same requirements in relation to data retention on overseas CSPs.</p><p>"And crucially, we will not be giving powers to go through people's browsing history. That is not what the investigatory powers bill is about." </p><p>The changes come after consultation with civil liberties organisations as well as ISPs, May said, in time for the bill to be presented to Parliament on Wednesday.</p><p>The bill is intended to upgrade the UK's anti-terrorism measures, <a href="https://www.gov.uk/government/publications/queens-speech-2015-what-it-means-for-you/queens-speech-2015-what-it-means-for-you#investigatory-powers-bill">to address alleged surveillance gaps</a> the government believes are "severely degrading" intelligence agencies' ability to fight terrorists.</p><p>Despite May's promise about browsing histories, the bill is expected to require communications firms to hold data on website domains a person has visited for 12 months though only the main site, rather than the pages within the site, would be recorded.</p><p>With Labour arguing that only judges rather than ministers - should be able to issue warrants for spy agencies to access specific page visits, May said the government would reveal its decision on this matter on Wednesday.</p><p>"Encryption is important for people to be able to keep themselves safe when they are dealing with these modern communications in the digital age, but we will be setting out the current position, which does enable the authorities with proper authorisation to issue warrants," she said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/25525/gov-waters-down-investigatory-powers-bill-spying-measures</link>
                                                                            <description>
                            <![CDATA[ ISPs will no longer be required to hold data on third-parties, Theresa May confirms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gt1TxtZMPjruAxcsc8UcWB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Nov 2015 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Home secretary Theresa May will drop some controversial elements from the Investigatory Powers Bill ahead of its appearance in Parliament on Wednesday.</p><p>The bill is a redrafted version of <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Communications Data Bill, dubbed the Snooper's Charter</a>, which was first introduced in 2012 but blocked by the Liberal Democrats during the coalition government. </p><p>A requirement for UK ISPs to keep data on third-parties will be scratched from the bill, as will the ability to access people's browsing histories, May told the <a href="http://www.bbc.co.uk/news/uk-34691956"><em>BBC</em></a>.</p><p>Speaking on the Andrew Marr show, she said: "It doesn't have some of the more contentious powers that were in that [Snooper's Charter] bill.</p><p>"So, for example, we won't be requiring communication service providers from in the UK to store third-party data, we won't be making the same requirements in relation to data retention on overseas CSPs.</p><p>"And crucially, we will not be giving powers to go through people's browsing history. That is not what the investigatory powers bill is about." </p><p>The changes come after consultation with civil liberties organisations as well as ISPs, May said, in time for the bill to be presented to Parliament on Wednesday.</p><p>The bill is intended to upgrade the UK's anti-terrorism measures, <a href="https://www.gov.uk/government/publications/queens-speech-2015-what-it-means-for-you/queens-speech-2015-what-it-means-for-you#investigatory-powers-bill">to address alleged surveillance gaps</a> the government believes are "severely degrading" intelligence agencies' ability to fight terrorists.</p><p>Despite May's promise about browsing histories, the bill is expected to require communications firms to hold data on website domains a person has visited for 12 months though only the main site, rather than the pages within the site, would be recorded.</p><p>With Labour arguing that only judges rather than ministers - should be able to issue warrants for spy agencies to access specific page visits, May said the government would reveal its decision on this matter on Wednesday.</p><p>"Encryption is important for people to be able to keep themselves safe when they are dealing with these modern communications in the digital age, but we will be setting out the current position, which does enable the authorities with proper authorisation to issue warrants," she said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the CISA amendment further erodes our right to privacy ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A much-debated amendment to the 'Cybersecurity Information Sharing Act' (CISA) is splitting US authorities and the country's technology giants.</p><p>Last night <a href="http://www.theguardian.com/technology/2015/oct/22/cybersecurity-cisa-bill-amendment-foreign-nationals" target="_blank">the amendment passed through the first stages of a US Senate vote</a>by 83 to 14, and if it passes a full Senate vote next week it will allow US courts to pursue foreign nationals accused of cybercrimes, even if they were perpetrated against other foreign citizens.</p><p>In other words, it considerably lowers the barriers for prosecuting cybercrime committed abroad, and means the US could prosecute anyone who steals data from anyone or any entity, regardless of where that crime occurs or whether a US entity is involved.</p><p>Extradition treaties mean that those accused of such crimes could then be brought back to the US to stand trial and face possible jail time.</p><p>For many people, including politicians from both sides of the house and a broad sweep of the business community, the amendment is a positive, strengthening IT security.</p><p>Within the technology sector, however, the likes of Apple, Dropbox, Facebook, Google, Twitter and the Wikimedia Foundation have revolted against it, citing privacy concerns.</p><p>Not all tech companies are convinced that the amendment to CISA will actually improve security and many are concerned about the privacy implications it poses.</p><p>Here's the thing - while the internet means we all live in an ever-shrinking world, that does not translate into expanding the scope of national law enforcement and justice. Different countries have widely varying views on what is and isn't suitable punishment to fit a given crime.</p><p>This is why it's important to put this US attempt at becoming the world's cyberpolice and cybercourts into perspective: should a German national living in France who hacks the credit card of an Italian citizen be subject to the laws of the US and face prison time there? Most people, I suspect, would think not. People should be prosecuted for their crimes, but the justice they face should be home-grown and not outsourced to another country.</p><p>The message from the dissenting tech giants is clear - the sharing of threat data is important but should not be at the expense of users' privacy. The mantra for all companies should be if you can't protect it, don't collect it'.</p><p>However, proposed legislation such as CISA in the US and the <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">Snooper's Charter</a> here in the UK move the protection goalposts somewhat. You have to ask yourself the question of who companies be protecting our data from. It's increasingly clear that it's not just the cybercriminals, but governments as well who want our data.</p><p>Ironically, given <a href="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry" target="_blank" data-original-url="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry">the IT security record of government agencies in the US</a> over the last couple of years, once that information has been passed to them it's probably at greater risk of being hacked.</p><p>When it comes to privacy there is little room for much confusion or doubt. This part of the CISA bill should worry anyone: "Cyber threat indicators and defensive measures provided to the Federal Government under this Act shall be deemed voluntarily shared information and exempt from disclosure".</p><p>Yep, the Freedom of Information Act would not give anyone the right to know what data had been disclosed or by whom. Few corporates will actually take on 'the powers that be' when push comes to shove, which means that ultimately we can trust nobody but ourselves to protect our data from the grip of government surveillance.</p><p>At the end of the day my trust in both government and big business is already at a low, but this bill just drops it further down.</p><p>I am always being told whenever I rally against such moves as this that done nothing wrong, nothing to fear'. Well, I prefer to think in terms of done nothing wrong, deserve the right to a little privacy'...</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25485/why-the-cisa-amendment-further-erodes-our-right-to-privacy</link>
                                                                            <description>
                            <![CDATA[ Increasingly, governments are becoming the enemies of data protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jPTPTLoJtGJ84mMHVD6nnx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Oct 2015 12:26:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US Senate]]></media:description>                                                            <media:text><![CDATA[US Senate]]></media:text>
                                <media:title type="plain"><![CDATA[US Senate]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2MuTq2ny2jDKZfvStn7UR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A much-debated amendment to the 'Cybersecurity Information Sharing Act' (CISA) is splitting US authorities and the country's technology giants.</p><p>Last night <a href="http://www.theguardian.com/technology/2015/oct/22/cybersecurity-cisa-bill-amendment-foreign-nationals" target="_blank">the amendment passed through the first stages of a US Senate vote</a>by 83 to 14, and if it passes a full Senate vote next week it will allow US courts to pursue foreign nationals accused of cybercrimes, even if they were perpetrated against other foreign citizens.</p><p>In other words, it considerably lowers the barriers for prosecuting cybercrime committed abroad, and means the US could prosecute anyone who steals data from anyone or any entity, regardless of where that crime occurs or whether a US entity is involved.</p><p>Extradition treaties mean that those accused of such crimes could then be brought back to the US to stand trial and face possible jail time.</p><p>For many people, including politicians from both sides of the house and a broad sweep of the business community, the amendment is a positive, strengthening IT security.</p><p>Within the technology sector, however, the likes of Apple, Dropbox, Facebook, Google, Twitter and the Wikimedia Foundation have revolted against it, citing privacy concerns.</p><p>Not all tech companies are convinced that the amendment to CISA will actually improve security and many are concerned about the privacy implications it poses.</p><p>Here's the thing - while the internet means we all live in an ever-shrinking world, that does not translate into expanding the scope of national law enforcement and justice. Different countries have widely varying views on what is and isn't suitable punishment to fit a given crime.</p><p>This is why it's important to put this US attempt at becoming the world's cyberpolice and cybercourts into perspective: should a German national living in France who hacks the credit card of an Italian citizen be subject to the laws of the US and face prison time there? Most people, I suspect, would think not. People should be prosecuted for their crimes, but the justice they face should be home-grown and not outsourced to another country.</p><p>The message from the dissenting tech giants is clear - the sharing of threat data is important but should not be at the expense of users' privacy. The mantra for all companies should be if you can't protect it, don't collect it'.</p><p>However, proposed legislation such as CISA in the US and the <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">Snooper's Charter</a> here in the UK move the protection goalposts somewhat. You have to ask yourself the question of who companies be protecting our data from. It's increasingly clear that it's not just the cybercriminals, but governments as well who want our data.</p><p>Ironically, given <a href="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry" target="_blank" data-original-url="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry">the IT security record of government agencies in the US</a> over the last couple of years, once that information has been passed to them it's probably at greater risk of being hacked.</p><p>When it comes to privacy there is little room for much confusion or doubt. This part of the CISA bill should worry anyone: "Cyber threat indicators and defensive measures provided to the Federal Government under this Act shall be deemed voluntarily shared information and exempt from disclosure".</p><p>Yep, the Freedom of Information Act would not give anyone the right to know what data had been disclosed or by whom. Few corporates will actually take on 'the powers that be' when push comes to shove, which means that ultimately we can trust nobody but ourselves to protect our data from the grip of government surveillance.</p><p>At the end of the day my trust in both government and big business is already at a low, but this bill just drops it further down.</p><p>I am always being told whenever I rally against such moves as this that done nothing wrong, nothing to fear'. Well, I prefer to think in terms of done nothing wrong, deserve the right to a little privacy'...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ High Court rules DRIPA is unlawful ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Emergency surveillance legislation <a href="https://www.itpro.com/public-sector/22707/emergency-data-retention-bill-passed-through-parliament" target="_blank" data-original-url="https://www.itpro.com/public-sector/22707/emergency-data-retention-bill-passed-through-parliament">rushed through Parliament last year</a> was ruled unlawful by the High Court this morning.</p><p>Parts of the Data Retention and Investigatory Powers Act (DRIPA) are not compatible with EU rights on privacy and the protection of personal data, the court ruled.</p><p>It marks a victory for privacy campaigners and MPs Tom Watson and David Davis, who brought the case to court seeking the judicial review with human rights organisation <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/liberty-davis-and-watson-dripa-challenge-government-surveillance" target="_blank">Liberty</a> after DRIPA was introduced by the coalition government in 2014.</p><p><a href="https://www.itpro.com/business/policy-and-legislation" target="_blank" data-original-url="https://www.itpro.com/it-legislation/24750/mps-challenge-snooping-laws-in-high-court">The MPs argued the legislation was ill-thought out</a> and pointed out MPs had just one day to discuss it before it was rushed through with Royal Assent a year ago today.</p><p>DRIPA forces communications companies to record and keep user data for one year, covering correspondence including emails, calls and texts.</p><p>Public bodies like spy agency GCHQ, but also councils, can authorise their own access to this data, with human rights group Liberty claiming half a million access requests were granted last year.</p><p>However, the High Court today found that DRIPA fails to provide clear and precise rules ensuring data can only be accessed to prevent and detect serious offences.</p><p>It also found that courts or an independent body should decide on any data access requests.</p><p>The ruling stated: "The need for that approval to be by a judge or official wholly independent of the force or body making the application should not, provided the person responsible is properly trained or experienced, be particularly cumbersome."</p><p>DRIPA will remain in force until the end of March 2016, at which time it will be scrapped and the government forced to introduce revised laws.</p><p>MP David Davis said: "The court has recognised what was clear to many last year, that the government's hasty and ill-thought through legislation is fatally flawed. They will now have to rewrite the law to require judicial or independent approval before accessing innocent people's data."</p><p>Watson added: "There must be independent oversight of the Government's data-collection powers and there must be a proper framework and rules on the use and access of citizens' communications data."</p><p>The news comes as Home Secretary Theresa May plans to revive the Snooper's Charter, a permanent piece of legislation to compel ISPs and web firms to hold meta data on customers for at least a year.</p><p>The Investigatory Powers Bill, dubbed Snooper's Charter, blocked by the Liberal Democrats during the coalition, to bolster security services' abilities to intercept information.</p><p>But following the decision on DRIPA, Liberty's legal director, James Welch, said May must now commit to surveillance that respects privacy and democracy.</p><p>The Open Rights Group, which also worked on the judicial review, added its weight behind this argument, saying the High Court ruling means <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Investigatory Powers Bill (the new Snooper's Charter bill)</a> must respect human rights.</p><p>Executive director Jim Killock said: "Now that the High Court has agreed that DRIPA does not comply with EU law, we hope that the Government will listen to these concerns.</p><p>"In autumn, the Government will present the Investigatory Powers Bill to parliament. This should not be, as rumoured, an attempt by the Home Secretary to re-introduce the Snoopers' Charter, but an opportunity to introduce an effective surveillance law that is compatible with human rights."</p><p>The Home Office told <em>IT Pro</em> the government will appeal against the review's findings.</p><p>Security Minister John Hayes said: "We disagree absolutely with this judgment and will seek an appeal.</p><p>"Communications data is not just crucial in the investigation of serious crime. It is also a fundamental part of investigating other crimes which still have a severe impact, such as stalking and harassment, as well as locating missing people, including vulnerable people who have threatened to commit suicide.</p><p>"The effect of this judgment would be that in certain cases, communications data that could potentially save lives would only be available to the police and other law enforcement if a communications company had decided to retain it for commercial reasons. We believe that is wrong."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/24998/high-court-rules-dripa-is-unlawful</link>
                                                                            <description>
                            <![CDATA[ Government must scrap emergency surveillance legislation as it does not comply with human rights ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7UxUvpisBJiQT7GoQ21tB5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2015 11:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Emergency surveillance legislation <a href="https://www.itpro.com/public-sector/22707/emergency-data-retention-bill-passed-through-parliament" target="_blank" data-original-url="https://www.itpro.com/public-sector/22707/emergency-data-retention-bill-passed-through-parliament">rushed through Parliament last year</a> was ruled unlawful by the High Court this morning.</p><p>Parts of the Data Retention and Investigatory Powers Act (DRIPA) are not compatible with EU rights on privacy and the protection of personal data, the court ruled.</p><p>It marks a victory for privacy campaigners and MPs Tom Watson and David Davis, who brought the case to court seeking the judicial review with human rights organisation <a href="https://www.liberty-human-rights.org.uk/news/press-releases-and-statements/liberty-davis-and-watson-dripa-challenge-government-surveillance" target="_blank">Liberty</a> after DRIPA was introduced by the coalition government in 2014.</p><p><a href="https://www.itpro.com/business/policy-and-legislation" target="_blank" data-original-url="https://www.itpro.com/it-legislation/24750/mps-challenge-snooping-laws-in-high-court">The MPs argued the legislation was ill-thought out</a> and pointed out MPs had just one day to discuss it before it was rushed through with Royal Assent a year ago today.</p><p>DRIPA forces communications companies to record and keep user data for one year, covering correspondence including emails, calls and texts.</p><p>Public bodies like spy agency GCHQ, but also councils, can authorise their own access to this data, with human rights group Liberty claiming half a million access requests were granted last year.</p><p>However, the High Court today found that DRIPA fails to provide clear and precise rules ensuring data can only be accessed to prevent and detect serious offences.</p><p>It also found that courts or an independent body should decide on any data access requests.</p><p>The ruling stated: "The need for that approval to be by a judge or official wholly independent of the force or body making the application should not, provided the person responsible is properly trained or experienced, be particularly cumbersome."</p><p>DRIPA will remain in force until the end of March 2016, at which time it will be scrapped and the government forced to introduce revised laws.</p><p>MP David Davis said: "The court has recognised what was clear to many last year, that the government's hasty and ill-thought through legislation is fatally flawed. They will now have to rewrite the law to require judicial or independent approval before accessing innocent people's data."</p><p>Watson added: "There must be independent oversight of the Government's data-collection powers and there must be a proper framework and rules on the use and access of citizens' communications data."</p><p>The news comes as Home Secretary Theresa May plans to revive the Snooper's Charter, a permanent piece of legislation to compel ISPs and web firms to hold meta data on customers for at least a year.</p><p>The Investigatory Powers Bill, dubbed Snooper's Charter, blocked by the Liberal Democrats during the coalition, to bolster security services' abilities to intercept information.</p><p>But following the decision on DRIPA, Liberty's legal director, James Welch, said May must now commit to surveillance that respects privacy and democracy.</p><p>The Open Rights Group, which also worked on the judicial review, added its weight behind this argument, saying the High Court ruling means <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the Investigatory Powers Bill (the new Snooper's Charter bill)</a> must respect human rights.</p><p>Executive director Jim Killock said: "Now that the High Court has agreed that DRIPA does not comply with EU law, we hope that the Government will listen to these concerns.</p><p>"In autumn, the Government will present the Investigatory Powers Bill to parliament. This should not be, as rumoured, an attempt by the Home Secretary to re-introduce the Snoopers' Charter, but an opportunity to introduce an effective surveillance law that is compatible with human rights."</p><p>The Home Office told <em>IT Pro</em> the government will appeal against the review's findings.</p><p>Security Minister John Hayes said: "We disagree absolutely with this judgment and will seek an appeal.</p><p>"Communications data is not just crucial in the investigation of serious crime. It is also a fundamental part of investigating other crimes which still have a severe impact, such as stalking and harassment, as well as locating missing people, including vulnerable people who have threatened to commit suicide.</p><p>"The effect of this judgment would be that in certain cases, communications data that could potentially save lives would only be available to the police and other law enforcement if a communications company had decided to retain it for commercial reasons. We believe that is wrong."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Theresa May is 2015 Internet Villain of the year ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Theresa May is the internet industry's "villain of the year" after attempting to pass the <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">Snooper's Charter</a>, legislation handing spies more powers, without adequate consultation.</p><p>The Home Secretary was named the Internet Services Providers' Association (ISPA)'s Internet Villain yesterday at the annual ISPA Awards.</p><p>The organisation said she won "for forging ahead with communications data legislation without fully consulting industry. With an Investigatory Powers Bill due before parliament in the coming months, it is essential that ISPs are consulted".</p><p>Privacy International accepted the award on her behalf.</p><p>May tried to pass the Communications Data Bill under the Coalition, but Nick Clegg's Liberal Democrats blocked her attempt.</p><p>However, the bill returned in a different guise as the Investigatory Powers Bill in the Queen's Speech following the Conservative election victory.</p><p>The legislation would extend security services' powers to collect communication data on citizens from ISPs, something privacy groups have railed against.</p><p>Elsewhere, ISPA awarded Labour MP Tom Watson and Conservative MP David Davis as Internet Heros "for their legal challenge to guarantee the privacy of their constituents and their efforts to raise the level of debate in Parliament on communications data issues".</p><p>ISPA secretary general Nick Lansman said: "Congratulations to all the winners. With ISPA celebrating its 20th anniversary, the ISPAs show the continued strength and diversity of the UK Internet industry as the UK economy moves ever more online.</p><p>"The Hero and Villain Awards also show that industry needs to be included in the surveillance debate."</p><p>More winners can be found at <a href="http://www.ispa.org.uk/ispa-awards" target="_blank">www.ispaawards.org.uk</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/24928/theresa-may-is-2015-internet-villain-of-the-year</link>
                                                                            <description>
                            <![CDATA[ Home secretary recognised for inadequate consultation over Snooper’s Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hmPf34SPsbPoh2CMKq3wmF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jul 2015 16:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xxTGqZySLMnBGSWPUXXBaT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Theresa May is the internet industry's "villain of the year" after attempting to pass the <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_blank" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">Snooper's Charter</a>, legislation handing spies more powers, without adequate consultation.</p><p>The Home Secretary was named the Internet Services Providers' Association (ISPA)'s Internet Villain yesterday at the annual ISPA Awards.</p><p>The organisation said she won "for forging ahead with communications data legislation without fully consulting industry. With an Investigatory Powers Bill due before parliament in the coming months, it is essential that ISPs are consulted".</p><p>Privacy International accepted the award on her behalf.</p><p>May tried to pass the Communications Data Bill under the Coalition, but Nick Clegg's Liberal Democrats blocked her attempt.</p><p>However, the bill returned in a different guise as the Investigatory Powers Bill in the Queen's Speech following the Conservative election victory.</p><p>The legislation would extend security services' powers to collect communication data on citizens from ISPs, something privacy groups have railed against.</p><p>Elsewhere, ISPA awarded Labour MP Tom Watson and Conservative MP David Davis as Internet Heros "for their legal challenge to guarantee the privacy of their constituents and their efforts to raise the level of debate in Parliament on communications data issues".</p><p>ISPA secretary general Nick Lansman said: "Congratulations to all the winners. With ISPA celebrating its 20th anniversary, the ISPAs show the continued strength and diversity of the UK Internet industry as the UK economy moves ever more online.</p><p>"The Hero and Villain Awards also show that industry needs to be included in the surveillance debate."</p><p>More winners can be found at <a href="http://www.ispa.org.uk/ispa-awards" target="_blank">www.ispaawards.org.uk</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watchdog says “intolerable” terror laws must be scrapped ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK must redraft its "intolerable" terror laws from scratch, a watchdog recommended today.</p><p>Parts of RIPA, and DRIPA 2014, must be scrapped by the government as it returns to the drawing board, said David Anderson, Britain's independent reviewer of anti-terrorism laws, in his report published today.</p><p>The report <em>'A Question of Trust'</em> also said the government must outline the need for new surveillance powers such as the Snooper's Charter.</p><p>Writing in his report, Anderson said: "RIPA, obscure since its inception, has been patched up so many times as to make it incomprehensible to all but a tiny band of initiates. This state of affairs is undemocratic, unnecessary and in the long run intolerable.</p><p>"But trust requires verification. Each intrusive power must be shown to be necessary, clearly spelled out in law, limited in accordance with international human rights standards and subject to demanding and visible safeguards."</p><p>RIPA, which allows police and spies to intercept emails, phone calls and snoop on people's online movements, should be overseen by a law that bolsters safeguards to prevent abuses of power.</p><p>One measure the report recommended was to strip ministers' powers to approve surveillance warrants, giving these responsibilities to judges, instead.</p><p>A new law should be easy to understand, too, while any extra surveillance powers must be justified by strong cases for their introduction, Anderson added.</p><p>He called for a new easily understood, comprehensive law with improved safeguards, and judges, not ministers, approving warrants to allow access to the content of emails, phone calls and other communications.</p><p>It should also comply with human rights standards, despite the Conservatives' proposal to ditch the Human Rights Act</p><p>Any further powers, such as forcing service providers to keep details of all individuals' internet use, should only be allowed after a compelling case was made, he added.</p><p>Shami Chakrabarti, director of human rights organisation Liberty, said: "This thoughtful report is in sharp contrast with the defensive whitewash from the discredited Intelligence and Security Committee of the last Parliament. </p><p>"Whilst we don't agree with all his conclusions, Mr Anderson's intervention could be the beginning of re-building public trust in surveillance conducted with respect for privacy, democracy and the law. It is further vindication of Edward Snowden's courage."</p><p>The part Chakrabarti does not agree with is Anderson's support that mass surveillance should continue, if the right safeguards can be introduced.</p><p>He wrote: "The capability of the security and intelligence agencies to practise bulk collection of intercepted material and associated data should be retained ... but used only subject to strict additional safeguards."</p><p>These cover judicial authorisation and a tighter definition of the reasons it is required.</p><p>Reacting to the report, Home Secretary Theresa May suggested she would push the Snoopers' Charter through Parliament regardless of the report's advice.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/server/24786/watchdog-says-intolerable-terror-laws-must-be-scrapped</link>
                                                                            <description>
                            <![CDATA[ Adds that stronger reasons required to introduce Snoopers' Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qsZZkr69Hinh9FdCZoHgJJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2015 15:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[surveillance]]></media:description>                                                            <media:text><![CDATA[surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK must redraft its "intolerable" terror laws from scratch, a watchdog recommended today.</p><p>Parts of RIPA, and DRIPA 2014, must be scrapped by the government as it returns to the drawing board, said David Anderson, Britain's independent reviewer of anti-terrorism laws, in his report published today.</p><p>The report <em>'A Question of Trust'</em> also said the government must outline the need for new surveillance powers such as the Snooper's Charter.</p><p>Writing in his report, Anderson said: "RIPA, obscure since its inception, has been patched up so many times as to make it incomprehensible to all but a tiny band of initiates. This state of affairs is undemocratic, unnecessary and in the long run intolerable.</p><p>"But trust requires verification. Each intrusive power must be shown to be necessary, clearly spelled out in law, limited in accordance with international human rights standards and subject to demanding and visible safeguards."</p><p>RIPA, which allows police and spies to intercept emails, phone calls and snoop on people's online movements, should be overseen by a law that bolsters safeguards to prevent abuses of power.</p><p>One measure the report recommended was to strip ministers' powers to approve surveillance warrants, giving these responsibilities to judges, instead.</p><p>A new law should be easy to understand, too, while any extra surveillance powers must be justified by strong cases for their introduction, Anderson added.</p><p>He called for a new easily understood, comprehensive law with improved safeguards, and judges, not ministers, approving warrants to allow access to the content of emails, phone calls and other communications.</p><p>It should also comply with human rights standards, despite the Conservatives' proposal to ditch the Human Rights Act</p><p>Any further powers, such as forcing service providers to keep details of all individuals' internet use, should only be allowed after a compelling case was made, he added.</p><p>Shami Chakrabarti, director of human rights organisation Liberty, said: "This thoughtful report is in sharp contrast with the defensive whitewash from the discredited Intelligence and Security Committee of the last Parliament. </p><p>"Whilst we don't agree with all his conclusions, Mr Anderson's intervention could be the beginning of re-building public trust in surveillance conducted with respect for privacy, democracy and the law. It is further vindication of Edward Snowden's courage."</p><p>The part Chakrabarti does not agree with is Anderson's support that mass surveillance should continue, if the right safeguards can be introduced.</p><p>He wrote: "The capability of the security and intelligence agencies to practise bulk collection of intercepted material and associated data should be retained ... but used only subject to strict additional safeguards."</p><p>These cover judicial authorisation and a tighter definition of the reasons it is required.</p><p>Reacting to the report, Home Secretary Theresa May suggested she would push the Snoopers' Charter through Parliament regardless of the report's advice.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Infosec 2015: Has GCHQ lost the cyber security plot? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Infosecurity 2015 has been a great place to be if you care about IT security either from the vendor or enterprise perspective. The biggest event of its type in Europe, you would have expected a big-hitter to open things and that's what you got in the shape of Ciaran Martin, Director General of Cyber Security at GCHQ.</p><p>Or at least that's what you might think you were getting, until the actual point that Martin started talking that is and you realised that what you actually got was a spin-doctor. The key theme of the <a href="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief" data-original-url="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief">keynote presentation</a> was how cyber attacks are driven by power, money and propaganda, and how apt that turned out to be seeing as Mr Martin used his position of power to push the government privacy argument position of you have nothing to fear from us'.</p><p>An odd mix of vendors going for the hard sell alongside technical workshops and roundtable discussions pretty much sums up Infosecurity. I attended one of those roundtable events an hour or so after the GCHQ presentation, which included our very own occasional contributor Tom Brewster asking whether vendors control the narrative when it comes to media reporting of IT security. You may not categorise GCHQ as a vendor, but I would argue that Mr Martin was certainly trying to sell a product; namely the ability to pry on our private communications wrapped up in the packaging of protecting us from evil.</p><p>Vendor-esque overtones or not, Mr Martin certainly attempted to control the narrative by not only stating from the get go that he wouldn't be talking about the so-called Snoopers' Charter but also ended things by only having time for one question from the floor. A question asking about <a href="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws" data-original-url="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws">tech firms leaving the UK over the likelihood of forced encryption back doors</a>, I hasten to add, that was answered by quoting someone else confirming that GCHQ was no threat to our privacy.</p><p>None of this should come as any great shock of course, what with Mr Martin previously having been the lead negotiator on the referendum for Scottish independence for the Prime Minister in his role as Constitution Director' at the Cabinet Office. Something of a career civil servant with roles as Head of the Cabinet Secretary's Office and Director of Security and Intelligence behind him, I wasn't that surprised when his speech ended up like something from Sir Humphrey out of Yes Minister.</p><p>Now it would be disingenuous of me to suggest that Mr Martin, given both that Director of Security role and his current one, knows nothing about IT security. Just like it would be disingenuous of the government to suggest there is no political motivation behind speeches such as this one.</p><p>A speech entitled Building Cyber Security for Tomorrow' with Sir Humphrey, sorry I mean Mr Martin, spelling out right from the start that he would be focusing his comments on who is attacking us and how, what defensive and response strategies are most effective to combat them and what the role of GCHQ is in all of this.</p><p>Needless to say we never really discovered the who or how, and the combat strategies were just a repeat of usual broad sweep basics of business IT security 101. He did, however, take some time to explain why he wouldn't be talking about the Snoopers' Charter, which he didn't mention by name.</p><p>Here's exactly what Mr Martin said:</p><p>"Our role only really works because we have a world class intelligence capability to draw on. If we want to protect the UK from the darkest aspects of cyber space, we have to be able to understand how that works. That intelligence role has been the source of well-known controversy around privacy.</p><p>"I won't and can't talk about that in any detail today. The Queen's speech set out a process for considering legislation on the proper powers for national security and law enforcement bodies and it is for Ministers to propose and for Parliament to debate. All I would say is that everyone in GCHQ is acutely conscious that we are entrusted with significant power under the law, and we use it extremely carefully.</p><p>"Just over a year ago, the Interception Commissioner, Sir Anthony May, who was formerly one of England's three most senior judges and had ruled against the intelligence services in the past, compiled a report on the various allegations. He had full access to the papers and staff of GCHQ. He asked the question: "does GCHQ engage in the random mass intrusion into the private lives of law-abiding citizens?" The answer was "emphatically no".</p><p>"To get back to cyber, one of the things that has almost flippantly been said in our defence is that even if we wanted to do such things we don't have enough people to engage in such unlawful mass intrusion. And size naturally affects our role on cyber. We're simply not big enough to put a big cyber umbrella over the UK: no single organisation could possibly do that over any country."</p><p>The clue is at the end of all of that, of course, in that the bill which the Home Secretary and Prime Minister want passed into law would mean that it's the Internet Service Providers which would be forced into both collecting and storing the vast amounts of data required to snoop on users, and then handing over the bits (no pun intended) to GCHQ that relate to specific users upon request.</p><p>Which puts quite a different perspective upon it. David Cameron has also made it quite clear that he wants encrypted messaging services banned, and/or back doors put into encryption services.</p><p>Quite how an ability to devalue the ability to encrypt data serves to help British business in the fight against cyber crime, which was the main thrust of the Martin presentation remember, is frankly beyond me. Just as all the themes of Intelligent Security' as set out by Infosecurity Europe appear to be beyond Mr Martin, GCHQ and this government. Those themes were Protect - Defend - Respond - Recover. Mr Martin certainly achieved the first two with his presentation, and when he responds properly we might be able to tell if GCHQ can recover...</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/24830/infosec-2015-has-gchq-lost-the-cyber-security-plot</link>
                                                                            <description>
                            <![CDATA[ It's more about what GCHQ doesn't say about the Snooper's charter than what it does, according to Davy Winder ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mq63dwzFN9aJ1X912bEesq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2015 08:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber spy]]></media:description>                                                            <media:text><![CDATA[Cyber spy]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber spy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Infosecurity 2015 has been a great place to be if you care about IT security either from the vendor or enterprise perspective. The biggest event of its type in Europe, you would have expected a big-hitter to open things and that's what you got in the shape of Ciaran Martin, Director General of Cyber Security at GCHQ.</p><p>Or at least that's what you might think you were getting, until the actual point that Martin started talking that is and you realised that what you actually got was a spin-doctor. The key theme of the <a href="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief" data-original-url="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief">keynote presentation</a> was how cyber attacks are driven by power, money and propaganda, and how apt that turned out to be seeing as Mr Martin used his position of power to push the government privacy argument position of you have nothing to fear from us'.</p><p>An odd mix of vendors going for the hard sell alongside technical workshops and roundtable discussions pretty much sums up Infosecurity. I attended one of those roundtable events an hour or so after the GCHQ presentation, which included our very own occasional contributor Tom Brewster asking whether vendors control the narrative when it comes to media reporting of IT security. You may not categorise GCHQ as a vendor, but I would argue that Mr Martin was certainly trying to sell a product; namely the ability to pry on our private communications wrapped up in the packaging of protecting us from evil.</p><p>Vendor-esque overtones or not, Mr Martin certainly attempted to control the narrative by not only stating from the get go that he wouldn't be talking about the so-called Snoopers' Charter but also ended things by only having time for one question from the floor. A question asking about <a href="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws" data-original-url="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws">tech firms leaving the UK over the likelihood of forced encryption back doors</a>, I hasten to add, that was answered by quoting someone else confirming that GCHQ was no threat to our privacy.</p><p>None of this should come as any great shock of course, what with Mr Martin previously having been the lead negotiator on the referendum for Scottish independence for the Prime Minister in his role as Constitution Director' at the Cabinet Office. Something of a career civil servant with roles as Head of the Cabinet Secretary's Office and Director of Security and Intelligence behind him, I wasn't that surprised when his speech ended up like something from Sir Humphrey out of Yes Minister.</p><p>Now it would be disingenuous of me to suggest that Mr Martin, given both that Director of Security role and his current one, knows nothing about IT security. Just like it would be disingenuous of the government to suggest there is no political motivation behind speeches such as this one.</p><p>A speech entitled Building Cyber Security for Tomorrow' with Sir Humphrey, sorry I mean Mr Martin, spelling out right from the start that he would be focusing his comments on who is attacking us and how, what defensive and response strategies are most effective to combat them and what the role of GCHQ is in all of this.</p><p>Needless to say we never really discovered the who or how, and the combat strategies were just a repeat of usual broad sweep basics of business IT security 101. He did, however, take some time to explain why he wouldn't be talking about the Snoopers' Charter, which he didn't mention by name.</p><p>Here's exactly what Mr Martin said:</p><p>"Our role only really works because we have a world class intelligence capability to draw on. If we want to protect the UK from the darkest aspects of cyber space, we have to be able to understand how that works. That intelligence role has been the source of well-known controversy around privacy.</p><p>"I won't and can't talk about that in any detail today. The Queen's speech set out a process for considering legislation on the proper powers for national security and law enforcement bodies and it is for Ministers to propose and for Parliament to debate. All I would say is that everyone in GCHQ is acutely conscious that we are entrusted with significant power under the law, and we use it extremely carefully.</p><p>"Just over a year ago, the Interception Commissioner, Sir Anthony May, who was formerly one of England's three most senior judges and had ruled against the intelligence services in the past, compiled a report on the various allegations. He had full access to the papers and staff of GCHQ. He asked the question: "does GCHQ engage in the random mass intrusion into the private lives of law-abiding citizens?" The answer was "emphatically no".</p><p>"To get back to cyber, one of the things that has almost flippantly been said in our defence is that even if we wanted to do such things we don't have enough people to engage in such unlawful mass intrusion. And size naturally affects our role on cyber. We're simply not big enough to put a big cyber umbrella over the UK: no single organisation could possibly do that over any country."</p><p>The clue is at the end of all of that, of course, in that the bill which the Home Secretary and Prime Minister want passed into law would mean that it's the Internet Service Providers which would be forced into both collecting and storing the vast amounts of data required to snoop on users, and then handing over the bits (no pun intended) to GCHQ that relate to specific users upon request.</p><p>Which puts quite a different perspective upon it. David Cameron has also made it quite clear that he wants encrypted messaging services banned, and/or back doors put into encryption services.</p><p>Quite how an ability to devalue the ability to encrypt data serves to help British business in the fight against cyber crime, which was the main thrust of the Martin presentation remember, is frankly beyond me. Just as all the themes of Intelligent Security' as set out by Infosecurity Europe appear to be beyond Mr Martin, GCHQ and this government. Those themes were Protect - Defend - Respond - Recover. Mr Martin certainly achieved the first two with his presentation, and when he responds properly we might be able to tell if GCHQ can recover...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Infosec 2015: Power, money and propaganda are main aims of cyberattacks, says GCHQ chief ]]></title>
                                                                                                <dc:content><![CDATA[ <p>GCHQ's cyber security chief warned that the nation's businesses are at risk of being attacked by criminals and terrorists whose main motivations are money, power and propaganda.</p><p>Giving a keynote speech at the Infosec conference held in London this week, the intelligence agency's Director General for Cyber Security, Ciaran Martin, said that organisations should take their lead from GCHQ and render them as "irrelevant as possible".</p><p>He said that in the last 10 years, the security industry has moved from talking about "what might happen" to what is now happening on a daily basis". He told delegates that it had fallen to the agency to be the UK's "top scarer". He explained that the three main motives in cyber-attacks were money, power and propaganda - particularly as intellectual property and corporate reputation gain increasing importance to organisations.</p><p>"We're genuinely surprised at the variety of UK organisations that can been subject to intrusion," he said. He urged firms to think about what would make them "attractive as a target" to criminals as a good way of approaching IT security.</p><p>Martin said that organisations faced too many incidents to be concerned about "stopping attacks everywhere" and now the main aim in IT security was to protect "what you care about most".</p><p>But the UK market, despite increased awareness of attacks, displayed a "relative immaturity of norms and practices", even in supposedly secure institutions, said Martin. He hoped that new GCHQ standards would prevent the sorts of attacks that wiped bank drives in Asia and affected a Saudi Arabian oil firm in 2012.</p><p>Martin distanced his agency from the controversial allegations that it conducted mass surveillance of British citizens and said that GCHQ's powers were "strictly circumscribed" and "needed clear justifications as laid down by parliament".</p><p>When questioned on <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_self" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the upcoming Investigatory Powers Bill</a>, or 'Snooper's Charter', that the government plans to enact, Martin refused to give an answer but added that the agency's roles only worked "because we have an intelligence capability".</p><p>"If we want to protect the UK from the darkest reaches of cyberspace, we have to know how it all works."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief</link>
                                                                            <description>
                            <![CDATA[ Spook avoids talk of Snooper’s Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">24H66g3CWnfhxCNBafejHZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jun 2015 15:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ's cyber security chief warned that the nation's businesses are at risk of being attacked by criminals and terrorists whose main motivations are money, power and propaganda.</p><p>Giving a keynote speech at the Infosec conference held in London this week, the intelligence agency's Director General for Cyber Security, Ciaran Martin, said that organisations should take their lead from GCHQ and render them as "irrelevant as possible".</p><p>He said that in the last 10 years, the security industry has moved from talking about "what might happen" to what is now happening on a daily basis". He told delegates that it had fallen to the agency to be the UK's "top scarer". He explained that the three main motives in cyber-attacks were money, power and propaganda - particularly as intellectual property and corporate reputation gain increasing importance to organisations.</p><p>"We're genuinely surprised at the variety of UK organisations that can been subject to intrusion," he said. He urged firms to think about what would make them "attractive as a target" to criminals as a good way of approaching IT security.</p><p>Martin said that organisations faced too many incidents to be concerned about "stopping attacks everywhere" and now the main aim in IT security was to protect "what you care about most".</p><p>But the UK market, despite increased awareness of attacks, displayed a "relative immaturity of norms and practices", even in supposedly secure institutions, said Martin. He hoped that new GCHQ standards would prevent the sorts of attacks that wiped bank drives in Asia and affected a Saudi Arabian oil firm in 2012.</p><p>Martin distanced his agency from the controversial allegations that it conducted mass surveillance of British citizens and said that GCHQ's powers were "strictly circumscribed" and "needed clear justifications as laid down by parliament".</p><p>When questioned on <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_self" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the upcoming Investigatory Powers Bill</a>, or 'Snooper's Charter', that the government plans to enact, Martin refused to give an answer but added that the agency's roles only worked "because we have an intelligence capability".</p><p>"If we want to protect the UK from the darkest reaches of cyberspace, we have to know how it all works."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snooper's Charter returns as the Investigatory Powers Bill  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Snoopers Charter is officially back, after plans to update communications data laws were introduced in the Queen's Speech today. </p><p>Full details of the proposed Investigatory Powers Bill have yet to be revealed, with the speech merely mentioning that "new legislation will modernise the law on communications data". </p><p>However, the Conservative party has previously tried to push through the Communications Data Bill that would have required ISPs and web firms to hold meta data on customer communications for at least a year, among other changes.</p><p>That bill had been repeatedly blocked by the Liberal Democrat party during the last administration's coalition, but now that the Tories have a majority, the changes are expected to be pushed through. </p><p>Lobbying group Big Brother Watch suggested there may be little difference between the Communciations Data Bill and the Investigatory Powers Bill other than the names, with CEO Renate Samson saying "it will be interesting to see whether the content has radically changed". </p><p>A report from the <em><a href="http://www.bbc.co.uk/news/uk-politics-32896921" target="_blank">BBC</a></em> reveals that the new bill would give police "the tools to keep you and your family safe" and would "address gaps" in existing laws that put "lives at risk" by not giving authorities access to such data. </p><p>Number 10 told the BBC that the bill would "address ongoing capability gaps that are severely degrading the ability of law enforcement and intelligence agencies to combat terrorism and other serious crime".</p><p>"The legislation covers all investigatory powers including communications data, where the government has long maintained that the gap in capabilities is putting lives at risk," the spokesperson continued, adding the law would "enable the continuation of the targeting of terrorist communications and other capabilities".</p><p>A report in the <a href="http://www.theguardian.com/uk-news/2015/may/27/security-services-investigatory-powers-bill" target="_blank"><em>Guardian</em></a> suggested the Conservative government plans to extend the scope of the bill beyond the previous version by strengthening the security services' powers to intercept communications in bulk - the very sort of activity highlighted by Edward Snowden's NSA whistleblowing. </p><p><strong>More criticism</strong></p><p>The bill faces the same criticism as its predecessor. Big Brother Watch's Samson said that there's as yet been no evidence shown that "there's a gap in the capability" of authorities to access communications data.</p><p>"We are also yet to see any concrete evidence that access to communications data has, and indeed will, make the country safer," Samson said. "The only evidence we have is of numerous failures to make effective use of the data already available."</p><p>"Any new draft legislation must acknowledge that the bigger the haystacks the harder it will be to find the needles," Samson added. </p><p>Yesterday, 38 prominent legal experts published an <a href="https://www.itpro.com/data-protection/24670/legal-scholars-plead-with-mps-over-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/data-protection/24670/legal-scholars-plead-with-mps-over-snooper-s-charter">open letter urging MPs to take care with the new law</a>. </p><p>"We hope that MPs, especially those newly elected to the Commons, will take heed of our warning that surveillance powers must be subject to Parliamentary scrutiny and must be proportionate," Signatory Andrew Murray, professor of law at the London School of Economics, told <em>IT Pro </em>at the time. </p><p>The Open Rights Group is asking supporters to contact MPs, saying "the Conservative majority is <em>tiny</em>, and we have allies within the Tory party such as David Davis who has been outspoken in his opposition". </p><p>It has a <a href="https://www.thunderclap.it/projects/26340-stopsnooping-oppose-cdb" target="_blank">tool</a> here to help you contact your MP to send a message about the forthcoming bill. </p><p>"By highlighting failings in the previous Parliament we hope MPs will be aware of the risks of failings in Parliamentary scrutiny and will take steps to educate themselves in this area," Murray said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill</link>
                                                                            <description>
                            <![CDATA[ The bill gets a facelift in the Queen's Speech, but proposes new powers over communications data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iDHynxDQyKCKrRfdkL42m3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EGuvNyws6ygKcAWeFcSVdN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 May 2015 11:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EGuvNyws6ygKcAWeFcSVdN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Parliament building at night]]></media:description>                                                            <media:text><![CDATA[Parliament building at night]]></media:text>
                                <media:title type="plain"><![CDATA[Parliament building at night]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EGuvNyws6ygKcAWeFcSVdN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Snoopers Charter is officially back, after plans to update communications data laws were introduced in the Queen's Speech today. </p><p>Full details of the proposed Investigatory Powers Bill have yet to be revealed, with the speech merely mentioning that "new legislation will modernise the law on communications data". </p><p>However, the Conservative party has previously tried to push through the Communications Data Bill that would have required ISPs and web firms to hold meta data on customer communications for at least a year, among other changes.</p><p>That bill had been repeatedly blocked by the Liberal Democrat party during the last administration's coalition, but now that the Tories have a majority, the changes are expected to be pushed through. </p><p>Lobbying group Big Brother Watch suggested there may be little difference between the Communciations Data Bill and the Investigatory Powers Bill other than the names, with CEO Renate Samson saying "it will be interesting to see whether the content has radically changed". </p><p>A report from the <em><a href="http://www.bbc.co.uk/news/uk-politics-32896921" target="_blank">BBC</a></em> reveals that the new bill would give police "the tools to keep you and your family safe" and would "address gaps" in existing laws that put "lives at risk" by not giving authorities access to such data. </p><p>Number 10 told the BBC that the bill would "address ongoing capability gaps that are severely degrading the ability of law enforcement and intelligence agencies to combat terrorism and other serious crime".</p><p>"The legislation covers all investigatory powers including communications data, where the government has long maintained that the gap in capabilities is putting lives at risk," the spokesperson continued, adding the law would "enable the continuation of the targeting of terrorist communications and other capabilities".</p><p>A report in the <a href="http://www.theguardian.com/uk-news/2015/may/27/security-services-investigatory-powers-bill" target="_blank"><em>Guardian</em></a> suggested the Conservative government plans to extend the scope of the bill beyond the previous version by strengthening the security services' powers to intercept communications in bulk - the very sort of activity highlighted by Edward Snowden's NSA whistleblowing. </p><p><strong>More criticism</strong></p><p>The bill faces the same criticism as its predecessor. Big Brother Watch's Samson said that there's as yet been no evidence shown that "there's a gap in the capability" of authorities to access communications data.</p><p>"We are also yet to see any concrete evidence that access to communications data has, and indeed will, make the country safer," Samson said. "The only evidence we have is of numerous failures to make effective use of the data already available."</p><p>"Any new draft legislation must acknowledge that the bigger the haystacks the harder it will be to find the needles," Samson added. </p><p>Yesterday, 38 prominent legal experts published an <a href="https://www.itpro.com/data-protection/24670/legal-scholars-plead-with-mps-over-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/data-protection/24670/legal-scholars-plead-with-mps-over-snooper-s-charter">open letter urging MPs to take care with the new law</a>. </p><p>"We hope that MPs, especially those newly elected to the Commons, will take heed of our warning that surveillance powers must be subject to Parliamentary scrutiny and must be proportionate," Signatory Andrew Murray, professor of law at the London School of Economics, told <em>IT Pro </em>at the time. </p><p>The Open Rights Group is asking supporters to contact MPs, saying "the Conservative majority is <em>tiny</em>, and we have allies within the Tory party such as David Davis who has been outspoken in his opposition". </p><p>It has a <a href="https://www.thunderclap.it/projects/26340-stopsnooping-oppose-cdb" target="_blank">tool</a> here to help you contact your MP to send a message about the forthcoming bill. </p><p>"By highlighting failings in the previous Parliament we hope MPs will be aware of the risks of failings in Parliamentary scrutiny and will take steps to educate themselves in this area," Murray said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>