Slashdot Banner
Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 134 +-   UK Law Enforcement Is Against "3-Strikes" on Tuesday October 27, @02:32PM

Posted by kdawson on Tuesday October 27, @02:32PM
from the swing-and-a-miss dept.
encryption
Now that the UK is discussing plans for some form of 3-strikes regime to discourage file-sharing, TechDirt reports that the fans of due process have picked up unlikely allies: the law enforcement and spying establishments fear that a 3-strikes policy would result in far more encryption on the Net, greatly complicating their jobs. "Of course, they're not as concerned about due process and civil rights, as they are about making it more difficult to track down criminals online: 'Law enforcement groups, which include the Serious and Organized Crime Agency and the Metropolitan Police's e-crime unit, believe that more encryption will increase the costs and workload for those attempting to monitor internet traffic. ... A source involved in drafting the Bill said that the intelligence agencies, MI5 and MI6, had also voiced concerns about disconnection. "The spooks hate it," the source said.'" The Times (UK) Online has more details.
story

Related Stories

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Of course... (Score:3, Insightful)

    by click2005 (921437) on Tuesday October 27, @02:36PM (#29887829)

    They dont want people to have any excuse to use encryption other than if you've got something to hide.

    Besides.. linking terrorists to filesharers is a stretch despite how much easier it would make the UK RIAA's job.

    • Re: (Score:3, Insightful)

      I encrypt all my HDDs in both my laptop and my computers. With Truecrypt it is as easy as a few clicks, so really there is no reason /not/ to do it.

      There are also numerous benefits. I can "wipe" the drive before selling/binning it by simply deleting the encryption key which takes seconds instead of hours for a full format. If my laptop is stolen or my house burgled then my private data will still be safe. Even my USB flash drives are protected that way.

      The argument that anyone who uses encryption must have

  • LAWL (Score:2, Funny)

    by Anonymous Coward
    The Serious and Organised Crime Agency, as opposed to what, the Laid-back and Disheveled Crime Buddies?
  • by fantomas (94850) on Tuesday October 27, @02:42PM (#29887917)

    Never really understood this "3 strikes and you're out" theory. Law enforcement is too complex to be modelled after the rules of a US sports game. Can somebody explain how this idiotic idea came about, the thinking behind it?

    What next? You don't go to jail if you say "Simon says" before committing an offence? Police can't arrest you if you're not touching the ground when they catch up with you?

    • by Shagg (99693) on Tuesday October 27, @02:52PM (#29888051)

      Can somebody explain how this idiotic idea came about

      It comes from the music industry executives.

      the thinking behind it?

      There isn't any.

      Well, other than the fact that taking people to court, not to mention the whole annoying thing about having to come up with evidence/proof, is too difficult. So they thought it would be a good idea if they could just bypass the legal system. All that "due process" stuff is too much trouble. It's much easier if they can just kick people off based on accusations.

      • by TimHunter (174406) on Tuesday October 27, @03:10PM (#29888323)

        Can somebody explain how this idiotic idea came about

        It comes from the music industry executives.

        Well, actually, no. Close, but no. It got started by the only group capable of giving the music industry executives competition in the stupidity race, politicians. Politicians learn very quickly that you can't go wrong by being tough on crime, so every year they enact increasingly medieval laws designed to make the populace think "there, that'll get those criminals off the street!" "Three strikes" originally meant "if you get convicted of three felonies then we'll put you in jail forever."

        "Three strikes" sounds good until you fill up the jails and you have to ask the voters for money to build more jails. (The only thing voters hate more than criminals is taxes.) Of course your average politician is unable think past the next election, so the jails filling up with struck-out felons naturally came as a surprise to them.

        And of course, once you've made a crime law you can't undo it, no matter how stupid and counter-productive it is, because then your opponent in the next election will accuse you of "being soft on crime."

        There, now I've gone and gotten off-topic. Damn hot-button topics.

        • psychopathology (Score:5, Interesting)

          by Onymous Coward (97719) on Tuesday October 27, @05:23PM (#29890345) Homepage

          This simplistic and damaging law-making gets traction because of the people who are overly punitive.

          That trait of excessive eagerness to punish is often coupled with these other traits:

          • conventionalism
          • authoritarian submission
          • authoritarian aggression
          • anti-intraception (anti-{need to analyze behaviors and feelings of others})
          • superstition and belief stereotypy
          • power and "toughness"
          • destructiveness and cynicism
          • projectivity
          • exaggerated concerns over sexuality

          Authoritarian Personality WP article [wikipedia.org]

          "The Authoritarians" paper [umanitoba.ca]

      • Re: (Score:3, Informative)

        The three strikes idea comes out of of California. The basic idea was that after you committed 3 serious criminal offenses, they were able lock you up for an extended period of time. It first was passed in California, in 1994, long before the internet was popular.
    • They probably thought that a three strikes rule would be easier for people to remember. It's a rule that isn't based on justice but intimidation.

    • I think the notion is that if you have committed 3 crimes of a certain level, Felonies for example, you are likely to just be an habitual criminal and be locked up permanently for the good of society.

      Not saying it's right or wrong, just explaining were the idea came from.

    • Law enforcement is too complex to be modelled after the rules of a US sports game. Can somebody explain how this idiotic idea came about, the thinking behind it?

      If you're a music industry executive who's incapable of rethinking the music industry's failing business model, which do you think is easier - steal an idea from a common past-time or come up with your own idea?

      Given that music execs haven't come up with an original idea in decades, the answer should be obvious...

    • It's nice because instead of using the Chewbacca defense I can use the foul ball defense.

    • Re: (Score:3, Interesting)

      In some US jurisdictions, being convicted of three felony offenses raises the penalty to life imprisonment, as by this point supporters argue that the criminal has repeatedly not rehabilitated and just keeps on committing more crimes. Music executives apparently want something analogous for punishing intellectual property "criminals". A noteworthy difference between the situations, however, is that in the criminal justice case, the penalty kicks in after three felony convictions in a court of law, whereas

      • Re: (Score:3, Insightful)

        Yes, the big idea of "three strikes" laws was that you were dealing with a repeat offender who wasn't at all rehabilitatable, and so the solution was to lock them up for an extended period of time. It was never completely clear if the extended period of time was to give them greater time to rehabilitate, if people were hoping that great prison sentences would serve as an increased deterrent (i.e. "I can't do anything bad because I already have 2 strikes!"), or if the idea was to get dangerous criminals off

    • 3 strikes became a cause in the US, during the rise in violent crime as various street gangs warred for control of the crack trade. Essentially cities saw huge increases in crime and policies of the time weren't doing enough to make citizens feel safe. So led by Western states (where voters almost always have some ability to directly pass laws) votors passed laws mandating that for certain types of crimes (normally murder, attempted murder, rape, and armed robbery sometimes others as well) a third convict
    • by bitt3n (941736) on Tuesday October 27, @04:34PM (#29889613)

      Never really understood this "3 strikes and you're out" theory. Law enforcement is too complex to be modelled after the rules of a US sports game. Can somebody explain how this idiotic idea came about, the thinking behind it?

      What next? You don't go to jail if you say "Simon says" before committing an offence? Police can't arrest you if you're not touching the ground when they catch up with you?

      Actually, maybe it should be more closely modeled. They should have 'balls' in there too. Like, say you try to download a torrent of Iron Man, and it turns out to be dubbed into Swedish. If that happens 4 times, the MPAA has to send you a free movie of your choice.

  • I'm guessing that one possible reason is whilst encryption is moderately rare - then they might assume that any encryption means a greater chance of something to hide and hence they can focus on it.

    And of course that unencrypted stuff is easier to track though less immediately suspicious.

    Anybody work in forensics and can give us an insider viewpoint?

  • E7J9D W34F6 (Score:5, Funny)

    by davebarnes (158106) on Tuesday October 27, @02:46PM (#29887963) Homepage

    LP098 5B6FR

  • Law enforcement groups, which include the Serious and Organised Crime Agency (Soca) and the Metropolitan Police's e-crime unit, believe that more encryption will increase the costs and workload for those attempting to monitor internet traffic. One official said: "It will make prosecution harder because it increases the workload significantly."

    One would think that encryption would stop them in their tracks, not just "increase the costs and workload"

    • by sqlrob (173498) on Tuesday October 27, @02:53PM (#29888069)

      IIRC, you are required to turn over keys if asked by the government in the UK, jail time if you don't.

      If they're currently trying to figure out who to ask keys from, if everyone does it, workload on figuring out what is malicious and requires them to ask everyone or figure out some way to narrow it down.

    • Re: (Score:2, Interesting)

      Law enforcement groups, which include the Serious and Organised Crime Agency (Soca) and the Metropolitan Police's e-crime unit, believe that more encryption will increase the costs and workload for those attempting to monitor internet traffic. One official said: "It will make prosecution harder because it increases the workload significantly."

      One would think that encryption would stop them in their tracks, not just "increase the costs and workload"

      Those increased costs and workload are for actually doing "real" police work instead

    • Encryption requires the extra step of going to the hardware store and buying a $5 wrench.

    • Encryption simply forces them to tap your keyboard, and the costs of that are much higher than the costs of running Wireshark on a router somewhere.

      • Re: (Score:3, Interesting)

        Encryption simply forces them to tap your keyboard, and the costs of that are much higher than the costs of running Wireshark on a router somewhere.

        Not only that, but it usually requires a much more involved process of those troublesome warrents and all to get actual wire-tepping done (usually, not always). Curse that due process!

        Let's not be too disparaging here, the police sometimes have legitamte interests in information gathering, there really are some people who need to be taken down. It is not their job to just protect our rights politically, that's our job and the job of the politicians (who epically fail in internet law). It is their job to pr

      • Re: (Score:3, Insightful)

        Even keyboard logging isn't a shoe-in. 90% of the time they're not also monitoring the MOUSE as well. Some programs are now using on-screen keyboards for password entry to get around keyloggers. You can also on many systems pair a key-file with your password. The keyfile needn't necessarily stay on your computer if it's easily retrievable.

        For example, you could use a source file from the first release of the Linux kernel as a keyfile. It's easily remembered, and easily retrieved from tons of locations o

        • Re: (Score:3, Insightful)

          My point is, no amount of encryption adds to your physical security. If they bug your ceiling, they can see you entering the password and doing all the other things you do with your computer. Hence the encryption does not make spying impossible, only a lot more expensive, geographically isolated, and more subject to the due process, as Znork (31774) points out nearby. IMHO, all the more reasons to use the end-to-end encryption as much as possible.

    • If commerical encryption were truly unbreakable by these groups, then I'd assume that they would have outlawed their use by now. That is a troubling thought.

      • by Znork (31774) on Tuesday October 27, @03:28PM (#29888591)

        If commerical encryption were truly unbreakable by these groups, then I'd assume that they would have outlawed their use by now.

        They pretty much have. In the UK you are legally obligated to give up your keys if required.

        Of course, then comes the question of how they're going to determine if the keys were the real keys... or just to the first layer... or just to the first and second layer... or...

        The intelligence agencies would do well to object quite a lot; we still haven't the final mass migration to rubber hose protected encryption and f2f darknets, but it's well on the way. If three-strikes regulation becomes popular, then most of the internet will become pretty opaque to any form of snooping, and any real threats will happily tag along on the mass of ordinary citizens just out to protect their privacy from whatever lobbyist it tugging at the puppet strings of the politicians for the moment.

  • by tomtomtom (580791) on Tuesday October 27, @02:58PM (#29888157)

    I'd hazard a guess that the real issue these agencies have is about increased use of anonymous communication networks such as Tor rather than just "encryption" of the content. It's almost a given that widespread adoption of Tor will have two important effects: (1) there will be larger numbers of relay or exit nodes in the network - at present it is suspected that intelligence agencies control a large number of the exit nodes (and possibly relay nodes too) in the network; and (2) greater traffic through the network will make it significantly harder to perform timing attacks on entry and exit from the mix network to correlate traffic and thus break its anonymity.

    • I use openbsd. The latest version has tor in the ports tree. I expect to try it, but I hear that tor is presently sort of slow.

      I have a couple dedicated servers at hosting companies. I have thought about making them tor "nodes", but as best I can figure out, it is a bit of a hassle for the full tor server to coexist with lots of server protocols.

      Still, it seems like the "right" thing to do.

  • ....and oops. I just showed this article to a friend who was resistant to using OTR to encrypt his IM communications, even though he had pidgin and could easily turn on OTR. Now he has seen the light and switched on OTR. Thanks UK Police!

    -Steve

  • by Yvan256 (722131) on Tuesday October 27, @03:21PM (#29888475) Homepage Journal

    I didn't know they made three more movies, but MI3 sure sucked.

    • Re:MI5 and MI6? (Score:4, Informative)

      by nelsonal (549144) on Tuesday October 27, @03:35PM (#29888733) Journal
      Military Intelligence Division 5 and Divsion 6, I believe. MI5 is the UK's version of the FBI, while MI-6 is the UK's version of the CIA. If you listen to bond carefully, you'll usually hear some references to MI6.
      • Re:MI5 and MI6? (Score:4, Informative)

        by Timosch (1212482) on Tuesday October 27, @04:14PM (#29889279)
        Although, to be precise, the MI6 is nowadays called Secret Intelligence Service (SIS) and in contrast to the FBI, the MI5 does not have police-like powers like arresting etc.
  • As a privacy advocate I recommend that, whenever possible, one should encrypt everything regardless of the sensitivity of the particular data.

    This will effectively keep law enforcement from tagging encrypted network traffic as being suspicious because encrypted network traffic will become the norm.

    How will the police track down dangerous criminals using the Internet you may ask? My answer would be who cares? In my book criminals have just as much right to privacy as do any law abiding citizen. Plus more

  • At least this hints that there isn't a trivial way of breaking RSA, AES, or the other popular systems.
    • Re: (Score:3, Interesting)

      Not really necessary when you can lock someone up for two years for refusing to divulge keys.

    • Re: (Score:3, Interesting)

      Maybe that's what they want you to think. You *have* read Cryptonomicon, haven't you? Sometimes having the information can be more of a pain than not having it.
  • by Eil (82413) on Tuesday October 27, @05:55PM (#29890779) Homepage Journal

    'Law enforcement groups, which include the Serious and Organized Crime Agency and the Metropolitan Police's e-crime unit, believe that more encryption will increase the costs and workload for those attempting to monitor internet traffic.

    I like this. In reality, properly-implemented encryption will completely prevent even the most well-funded government agency from monitoring your Internet traffic. But Police and Three Letter Agencies would never admit as much in a press release. Instead, encryption just "increases their costs and workload." Feh.

    I think one of the reasons that the average person doesn't care enough about encryption to use it is because they have no idea how effective it is.

    • Re:UK (Score:5, Insightful)

      by wizardforce (1005805) on Tuesday October 27, @02:46PM (#29887969) Journal

      They are not concerned for what is good for the people. They don't want the law solely because they are afraid that it will lead to citizens making use of encryption that makes it harder for them to snoop. Pure selfish interest.

      • Re:UK (Score:4, Insightful)

        by spydabyte (1032538) on Tuesday October 27, @02:59PM (#29888179)
        Sure, it makes sense. Make it such a PR issue that everyone and their grandmother is concerned with security so that they use Tor. It's simply an arms race [wikipedia.org].
      • Re:UK (Score:4, Interesting)

        by DaveGod (703167) on Tuesday October 27, @04:10PM (#29889245)

        To be fair the "UK law enforcement and intelligence services" should not be commenting on due process and civil rights, other than to confirm that they uphold them. It is their job to track criminals, it is our job to dictate the rules they must follow in doing so.

        It's not really fair to apportion them with blame for the laziness, apathy and short-sightedness of voters and their elected officials. They're probably even more surprised than we are when their more outlandish proposals actually get approved.

      • Ummmm yeah... that's pretty much exactly what the article summary said. Being able to read is now +5 insightful? Oh well, I'm here to witness the dying days of /. I guess.
    • Don't be surprised. They're not considering what's good for _people_ they're considering what's good for them. It's bad for big brother if all the internets are encrypted.
When I left you, I was but the pupil. Now, I am the master. - Darth Vader