The UK government is soliciting feedback from a handful of internet providers, but isn’t consulting the tech industry or the public.
The proposed measures would greatly benefit hackers and cyber criminals, as the UK government is secretly planning to push greater surveillance powers that would force UK internet providers to monitor communications in near-real-time and companies to build backdoors into their products, to enable intelligence agencies to read people’s private messages, according to a leaked document.
The document, leaked on Thursday by the Open Rights Group, appears to be part of a “targeted consultation” into the Investigatory Powers Act, brought into law last year, which critics called the “most extreme surveillance law ever passed in a democracy”. It details extreme new surveillance proposals that would enable government agencies to spy on one in 10,000 citizens – around 6,500 people – at any given time. The government actually plans to force mobile operators and internet service providers to provide real-time communications of customers to the government “in an intelligible form”, and within one working day.
To that end, UK internet providers will have no choice but to introduce a backdoor point on their networks in order to allow intelligence agencies to read anyone’s communications. This would effectively ban encryption in the UK, an important security measure used by a wide range of companies, including WhatsApp and major banks, to keep people’s private data private, and to protect them from hackers and cyber criminals. This “backdoor” capability was heavily criticized last year when it was floated as part of the draft law’s proposal. At the time, Apple chief executive Tim Cook warned of “dire consequences” if the legislation required internet providers or companies to put backdoors into their systems, and described them as “the software equivalent of cancer”. The provision would effectively prohibit companies operating in the UK from introducing end-to-end encryption, a feature now commonplace in many messaging apps, including Facebook Messenger, WhatsApp, and Apple’s own messaging platform iMessage.
The executive director of Open Rights Group, Jim Killock, who obtained this document, declared in an email that these proposals, if passed, would “make security products a lot easier to break into, and that means companies may be obliged to lie to the customers about their privacy and about the security that is applied to their communications.”
“The government doesn’t think it has any legal or moral obligation to consult anyone outside of industry partners and the security services,” he added.
The only slightly reassuring aspect to the situation is that approval from a judge appointed by the Prime Minister would be required before an individual could be targeted by government agencies, and the proposals outlined in the document also need to be approved by both Houses of Parliament before being pushed into law. However, even if the government has good intentions, backdoors expose everyone to cyber criminals too. Encryption, block chains and other security measures will prove more and more necessary in the future, especially when it comes to the e-commerce industry. A law that forces backdoors to be included in code would create opportunities for hackers to bypass security and exploit the said backdoors.
What is perhaps most alarming is the lack of transparency around the draft powers, and the proposals and the way they are currently being discussed have been heavily criticized.
To this day, they are only being discussed with members of the UK’s Technical Advisory Board, which are BSkyB, BT, Cable and Wireless, O2, Virgin Media and Vodafone, as well as representatives from government agencies, believed to include GCHQ and MI5. The short, four-week consultation ends on 19 May, and the document isn’t readily available to access on the government’s website by the public, neither was it communicated to partners in the tech industry who would be directly affected by the provisions if passed into law.
It is definitely unclear if the Home Office was planning a public consultation, but anyone can send their views on the matter to the government by emailing them at: [email protected].
A spokesperson for the Home Office did not respond to a request for comment at the time of writing.
It’s not clear either exactly how the provision would be enforced — or if it would only affect companies operating or based in the UK.
