Showing posts with label Rule of law. Show all posts
Showing posts with label Rule of law. Show all posts

Monday, 9 November 2015

From Oversight to Insight - Hidden Surveillance Law Interpretations

The focus of my posts on RIPA, DRIPA and now the Investigatory Powers Bill has been on the scope and extent of the powers – what exactly they enable law enforcement and the agencies to do – rather than on oversight and safeguards, important though those are.

One aspect of oversight, however, bears directly on the scope of the surveillance powers granted by legislation. It relates to an issue that has perhaps not received as much attention in the UK as it has in the USA: secret interpretations of the law.

The problem arose in the USA partly as a result of the secret FISA court system. C
ontroversial previously secret interpretations of the law came to light following the Snowden disclosures. This led to, for instance, the Electronic Frontier Foundation's Secret Law is Not Law campaign.

We have a similar problem on this side of the Atlantic. Here, though, it is about interpretations conceived and acted upon by government without any court involvement.

The clearest example to date is the government’s interpretation of ‘external communications’ under RIPA. This was revealed by senior Home Office official Charles Farr in a witness statement filed in the Investigatory Powers Tribunal case brought by Liberty and others. The background is that GCHQ can intercept in bulk if its objective is to intercept external communications. So the meaning of 'external communications' is significant. The Home Office interpretation was controversial. It also had implications for who (or what) could be regarded as a sender or intended recipient of a communication, a foundational building block of RIPA. (See further paragraphs 6.52 and 12.25 of the Anderson Report ‘A Question of Trust’ and paragraphs 31 to 54 of my submission to Anderson.)

The Home Office’s interpretation, which underpinned the agencies’ operations under RIPA S.8(4) warrants, would not have seen the light of day had the NGOs not brought the IPT legal challenge. That occurred because of the Snowden disclosures. The interpretation was a significant, but previously hidden, aspect of the law under which the agencies were operating.

Another example was The Data Retention and Investigatory Powers Act (DRIPA), rushed through Parliament in four days in July 2014. The Home Office argued that amendments to RIPA’s territoriality provisions and to the definition of telecommunications services did no more than reflect what the legislation had always meant. The claim was untestable, since the public had no way of knowing how the Home Office might have interpreted the provisions either in the minds of its officials or in its previous dealings with communications service providers.

A similar issue is boiling up over the effect on end to end encryption of the Investigatory Powers Bill. The Home Office says, with some justification (although a debate is taking place around possible knock-on effects of other changes), that the draft Bill mirrors existing law. Clause 189(4)(c) of the draft Bill is very similar to paragraph 10 of the Schedule to the 2002 Maintenance of Interception Capability Order. On the face of it neither affects end to end encryption where the protection is applied not by the service provider but by the user. However the public is in no position to know whether the Home Office has adopted some other interpretation or, if so, whether it might be as open to debate as its view of external communications.

The Investigatory Powers Bill provides an opportunity to ensure that the proposed new oversight body proactively seeks out and brings to public attention material legal interpretations on the basis of which powers are exercised or asserted. Service providers might also be able to bring a legal interpretation asserted against them to the attention of the oversight body. This may be all the more necessary in the light of the new disclosure offences built into the draft Bill.

Such mechanisms would enable material legal interpretations to be publicly debated and if appropriate challenged. None of this would require to be made public any legal advice that the government had received, nor any factual matters that should properly remain secret, but only the substance of the legal interpretations themselves.

This could be an important protection against the possibility of groupthink, the tendency for members of a closed group to convince themselves of the rightness of a consensus position and to resist contrary views. It would contribute to the new standards for openness, transparency and oversight that the government has promised in the new legislation. Most fundamentally, by providing not only oversight but insight it would help to satisfy the basic rule of law tenet that the law should be foreseeable and accessible.


[Amended 7 pm 9 November 2015 to include reference to possible knock-on effects of other changes on end to end encryption]

Sunday, 21 December 2014

A Cheltenham Carol

On the Twelfth Day of Christmas my true love sent to me:

Twelve Zettabytes

Eleven Encryption Layers

Ten Coders Coding

Nine Hackers Hacking

Eight Routers Routing

Seven Inspected Packets

Six Spies-a-Spying

Five Back Doors

Four Fishing Warrants

Three Haystacks

Two Secret Laws

And a Paean to Proportionality


Friday, 10 October 2014

Submissions to the Investigatory Powers Review

[Update 11 June 2015.  David Anderson's report 'A Question of Trust' has been published today and is available on his website, together with two volumes of submissions made to his review. My own submission is also available here (PDF).]

David Anderson QC (@terrorwatchdog) is the UK's Independent Reviewer of Terrorism Legislation. He is tasked under the Data Retention and Investigatory Powers Act 2014 (DRIPA) with conducting a review of investigatory powers. This includes interception of communications (e.g. by GCHQ and law enforcement) and powers to compel retention and production of communications data. His Call for Evidence closed on 3 October 2014.  Here are some of the submissions to the Review now being made public.

AccessNow

Bingham Centre for the Rule of Law

Centre for Democracy and Technology

Dr Andrew Defty and Professor Hugh Bochel (University of Lincoln)

Equality and Human Rights Commission

Global Network Initiative

Human Rights Watch

Interception of Communications Commissioner

ISPA

The Law Society of England and Wales

Liberty

The Newspaper Society

UCL LLM Students

Vodafone

And although not strictly speaking a submission to the Review, GCHQ Director Sir Iain Lobban's valedictory speech.

More to follow.



Thursday, 22 May 2014

Everyman and the data inspector

[Now dedicated to the memory of John Blundell, who died on 22 July 2014. Find out the connection here.]

Everyman is dreaming of a future.

Data Inspector: Good morning, citizen. We have reason to believe you have data in this house.

Everyman: Who told you that?

DI: Someone who knows.

Everyman: It would be a strange house that didn’t have data in it, wouldn’t it?

DI: All the same, we have to act on reports received.

Everyman: At dawn?

DI: You heard us. We require entry to inspect the data on these premises. We suspect it may be inaccurate, incomplete or irrelevant to the purposes for which it was collected or further processed.

Everyman: This is my private house. It’s my personal information.

DI: Your personal information? We’ve heard it names other people. That makes it their information.

Everyman: It’s still my private house.

DI: From which you run a little business on eBay.  No household exception for you.

Everyman: I don’t have to answer your questions.

DI: Ah, but you do.  How else can we perform our duty to the public?

Everyman: What about my privacy?

DI: Privacy begins at home. So that's where we start.

Everyman: By invading my privacy?

DI: We protect privacy, we don’t invade it.

Everyman: You seem to be about to invade my home.

DI: Sometimes you have to sacrifice privacy to preserve privacy.

Everyman: So what do you want to know?

DI: Who is the data controller in this house?

Everyman: How should I know that?

DI: You are required to know that. The data controller should have notified us.

Everyman: Well you’ve got me there, haven’t you?

DI: When did you last clean your data?

Everyman: Clean?

DI: Scrub it - remove excessive, irrelevant or out of date data. We like to see hygienic data practices, citizen.  Dirty data is a menace.

Everyman: Sounds like the last public health campaign.

DI: Exactly.  Unclean data spreads.  We could have a national data contamination crisis on our hands.  You know our motto: “Healthy data makes a healthy mind”.

Everyman: So you think I’ve got a secret store of mouldy old data hidden away here, do you? 

DI: I’m sure of it.  We have a duty to discharge and you’re starting to be obstructive.

Everyman: What else do you want?

DI: Do all your appliances conform to privacy design standards?

Everyman: And if they don’t?

DI: You’ll be put on our list.

Everyman: What list is that?

DI: The privacy offenders register. Everyone should know who can and can’t be trusted with their data.

Everyman: How long would I be on it?

DI: Permanently.

Everyman: No right to be forgotten, then?

DI: Not where privacy breaches are concerned, my friend. Far too serious.

Everyman: Well, thank you for your interest. Now please leave.

DI: Not that simple, citizen.  Sledgehammer, please.

Everyman: (wakes up).


Wednesday, 1 January 2014

Cyberlaw memes and themes for 2014

[Updated as at 20 December 2014]
Following my hard law roundup of legislation and pending court cases in the EU/UK pipeline, here are some rather more amorphous cyberlaw themes to look out for in 2014. This is the realm of soft law, inter-government negotiations, NGOs, lobbyists, op-ed writers, bloggers and policy wonks. I have also thrown in some concrete items that were too speculative to qualify for the hard law survey.

Nudging and bludgeoning You could describe the UK government’s campaign to persuade ISPs to introduce default content filters as a variety of nudging, the idea being that a householder subscriber has to make an active selection to disable the filter. Aside from the inevitable coarseness of the filters, if this is nudging it is nudging with sharp elbows. Like many nudging ideas, changing the behavioural environment of the end user requires the co-operation, voluntary or enforced, of an intermediary. Call it what you like – private-public partnership, co-regulation, nudging, bludgeoning, backdoor armtwisting – we can expect more of it in 2014. [Here is David Cameron claiming that internet companies will Agree to do More to Filter Extremist Material Online, though the details of the supposed agreement seem a mite fuzzy.]

Magic wand politics Mention of filtering leads on to magic wand politics: the collective delusion of the governing class that the Good Fairy of the Internet can wave her magic wand and cure whatever perceived internet ill is troubling the PM and his advisers today. Steel yourselves for more in 2014. [The Intelligence and Security Committee Report on the Lee Rigby murder. If only Facebook had waved its magic wand.]

Understanding the internet Ill-considered political interventions provoke wailing from geeky quarters that politicians don’t understand the internet. But is the problem a lack of technical knowledge, or is it a deeper failure to embrace the liberal values that we like to think are embodied in the internet? If they did understand the consequences of their actions how many politicians would care? Given what politicians have shown themselves already capable of, tremble for the day (unlikely to be in 2014) when they do understand the internet. [
Clause 17 of the Counter Terrorism and Security Bill is about so-called IP address resolution. MPs can hardly be blamed for not understanding it when every government explanation adds to the confusion.]

The Internet Wild West It is impossible to debate behaviour on the internet without somebody painting a picture of the internet as a lawless Wild West and casting themselves in the role of Sheriff come to bring order to the chaos. No matter that the internet is beset with more laws than the offline world and that many of those impose stricter rules (often inappropriately so) than offline. It is depressingly safe to predict that the Wild West meme will continue to flourish in 2014. [Perhaps less of the Wild West than expected (examples here and here), but we did get 
'the beautiful dream of the internet as a totally ungoverned space' from Sir Iain Lobbanshortly followed by another Wild West in the Parliament Intelligence and Security Committee here (11:28). Then almost at the end of the year we had this corker from President Obama (with "rules of the road" thrown in for good measure).] 

Doctorow’s Warning Two years ago Cory Doctorow identified "the coming war on general purpose computing". He worried about the future lobbyists who would ask:




"Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?" The answer (see Magic Wand Politics) is ‘No’, but serious damage can be done in trying and failing. Doctorow again:
"Reality asserts itself. Like the nursery rhyme lady who swallows a spider to catch a fly, and has to swallow a bird to catch the spider, and a cat to catch the bird, so must these regulations, which have broad general appeal but are disastrous in their implementation. Each regulation begets a new one, aimed at shoring up its own failures." With each new round of regulation aimed at preventing wrongdoing, the greater the temptation to rectify the failure of the previous round by throwing a wider regulatory net over non-culpable actors engaged in general purpose activities. Site blocking injunctions against online intermediaries is an obvious example. Co-option of payment processors, advertising networks, domain name registrars and search engines is another, as would be action against VPN. 

These are not the only examples. Traditionally liability for wrongdoing has applied to doing, participating in and procuring wrongful acts, but stopped short of facilitating and enabling them. One reason for drawing that dividing line is that acts of facilitation and enablement are by their nature general purpose. As such, damnifying them always carries a high risk of damage to legitimate activity, whether present or future, known or unknown. There will in 2014 be continued pressure to extend all sorts of online liability and obligations to facilitation and enablement. [The amendment to the RIPA definition of 'telecommunications service' by the Data Retention and Investigatory Powers Act 2014 (DRIPA) is a classic example.  It now includes "facilitating" the creation, management or storage of communications transmitted, or that may be transmitted, by means of a telecommunication system.]  

At a deeper level, the concern about co-opting law-abiders, facilitators and enablers represents the difference between a society in which each is free to set and pursue his or her own goals and allocate their own resources accordingly, and one in which anyone can be conscripted into an online army and commanded to crusade against the government’s designated enemy of the day.

Doctorow’s Warning is as relevant at the start of 2014 as it was two years ago.

Technological neutrality. Everyone loves technological neutrality and will appeal to it in support of whatever legal or policy position they are advocating. Laws should obviously be technologically neutral, shouldn’t they? Not necessarily. In fact resort to technological neutrality is dangerous without understanding (a) which version of technological neutrality you are invoking (b) when it is safe or appropriate to deploy it and (c) when other principles (e.g. fundamental human rights) should outweigh it. These were my slides on the topic at the Society of Legal Scholars conference in September. A full paper is in the works. [Now published.]

The rise of PIPCU Launched on 12 September 2013 with £2.6m of taxpayer funding over two years from the Intellectual Property Office and a special focus on offences committed online, the activities of the Police Intellectual Property Crime Unit, operated by the City of London Police, have perhaps so far attracted most attention in the pages of Torrentfreak.  With emphasis on preventative and deterrent action, including requesting suspensions from domain name registrars around the world, its activities will inevitably attract wider scrutiny. The Open Rights Group has requested a meeting with PIPCU to discuss its processes. Definitely one to watch in 2014. [PIPCU in the news already 11 Jan 2014.][As at 11 June 2014 PIPCU has suspended 2,359 .co.uk domains and achieved 19 website payment provision suspensions (IP Crime Highlight Report). It has also launched an unpublished Infringing Websites List to be shared with advertisers in an attempt to disrupt advertising revenue.][On 23 October 2014 the IP Minister announced that PIPCU would receive another £3 million government funding to take it through to 2017.  Meanwhile PIPCU has been putting replacement advertisements on infringing websites, including one making the at first sight curious claim that "Illegal Downloading is a Crime". Unauthorised downloading is of course a civil copyright infringement, but is not in itself a criminal offence under the UK Copyright Act. This is how PIPCU has explained it:


 So there you have it.]

Copyright wars The Piscean fishes swimming in opposite directions have nothing on the copyright wars. Historically there was pressure from rightsowner interests for stronger copyright, provoking largely reactive and patchy opposition. Now we can identify not just resistance to stronger copyright, but a coalescing agenda for digital copyright reform. In the UK the Hargreaves recommendations are going through. Ireland and Australia have completed significant reviews of copyright, with the Australian Law Reform Commission having recommended the adoption of a flexible fair use copyright exception and the Irish review a more limited version. Some EU MEPs have started to formulate an agenda for copyright reform. The courts have started to show interest in aligning digital copyright to its offline equivalent. The copyright wars will continue to be fought out in arenas such as TTIP. [The new European Commission has included copyright modernisation in its Work Programme for 2015. Expect a bloodbath.]

Blocking injunctions In my hard law piece I mentioned the pending CJEU reference in Constantin Films v UPC. In parallel there will almost certainly be more UK applications for blocking injunctions under S97A. In practice the court normally makes a determination on the basis of evidence and submissions from rightsowners alone - a less than ideal situation. Will 2014 be the year in which some public minded body tries to intervene in an application on a quasi-amicus basis? 
[Yes. The Open Rights Group obtained permission to intervene with written submissions in Cartier's application for a trade mark blocking injunction. The court adopted some of ORG's suggestions for further safeguards in the blocking order.] 

Privacy In a prediction at the end of 2012 for BNA I said that 2013 might be the year in which the privacy industry remembered that the state is more threatening than a cookie. And so it proved. But will we keep our eye on the ball? Will we let EU politicians turn PRISM, TEMPORA and Snowden into an excuse for an information trade war with the USA? Will they get away with suggesting that EU data protection laws have historically protected against surveillance by EU national governments? Or will we convince ourselves that it’s all the fault of US corporations for collecting data (as if Galileo should never have built a telescope)? We will find out in 2014. [No. Yes. Yes. Yes.]

See also: Internet Legal Developments to Look Out For in 2014




Tuesday, 20 August 2013

Everyman encounters Government

A dialogue for our times.

Government: We know what’s best for you.
Everyman: I think I’m the best judge of that.

G: Ah, but we know things that you don’t.

E: What things?

G: Can’t tell you, they are secret.

E: So how can I tell whether you are right?

G: You need to trust us on that.

E: Why should I trust you?

G: Because we are fighting your enemies.

E: Who are my enemies?

G: Can’t tell you, you might warn them.

E:  You don’t trust me?

G: No-one is above suspicion.

E: Am I a suspect?

G: We never comment on operational matters. But if you have nothing to hide, you have nothing to fear.

E: What do you know about me?

G: We never comment on intelligence matters.

E: Can you be trusted?

G: We always act proportionately and in accordance with the law.

E: Show me.

G: Don’t be silly, that’s secret.

E: How do I know you don’t think I’m your enemy?

G: You don’t.  But if you carry on asking questions we might put you on a list.

E: On what grounds?

G: That would be telling. 

E: When would you do it?

G: If it was necessary in the interests of national security.

E: Is that legal?

G: We always act proportionately and in accordance with the law.

E: How can I be sure of that?

G: Trust us.  We know best.