Security

Third Committee Report Critical Of UK’s “Sloppy” Draft Surveillance Bill

Comment

Image Credits: Harshil Shah (opens in a new window) / Flickr (opens in a new window) under a CC BY-ND 2.0 (opens in a new window) license.

A third UK parliamentary committee has now published a report on the government’s draft surveillance legislation.

The report of the joint select committee, which is made up of a majority of Conservative MPs and Peers, takes a more supine approach than the ISC committee report earlier this week, with many statements where the committee accepts the government’s position, while still suggesting it should publish, for example, fuller justification for each of the so-called “bulk capabilities” (aka mass surveillance powers) to be set out in the legislation.

The committee does recommend a raft of specific changes to the draft bill, although its general tone is more supportive than the ISC report. Cambridge University security researcher Ross Anderson, one of the expert witnesses who gave evidence to the committee, dubs the report “deeply disappointing“.

That said, one of the committee members, the Lib Dem Peer Lord Strasburger, summing up the report for Wired, calls for the bill to be “fundamentally rethought and rebuilt”, branding it “sloppy in its wording and short on vital details”. Albeit, at times Lord Strasburger has stood out as something of a lone dissenting voice speaking up for privacy and civil liberties on the committee.

“[The report] tells the government to make clear that it does not expect companies to provide decrypted copies of end-to-end encrypted information. It finds the proposed Internet Connection Records, essentially a log of everything that everyone does on the internet, to be largely undefined, difficult and costly to deliver, and risky for the ISPs to store safely for 12 months. It says that there should be strong protections to prevent journalists’ sources from being exposed and for legally privileged communications,” writes Strasburger.

“So this Bill is a long way from the finished article,” he adds. “It needs more than mere tweaking, it needs to be fundamentally rethought and rebuilt. The Home Office should stop rushing to push it through and take its time to get it right.”

The Investigatory Powers Bill (IP bill) was introduced by the UK government this fall, with the aim of — in its words — plugging “capability gaps” for domestic intelligence and law enforcement agencies operating in an increasing technological context by expanding state surveillance powers, such as laying out a requirement that ISPs must log details of all the websites visited by citizens over a 12 month period. Hence critics dubbing it another ‘Snoopers’ Charter’.

The government wants the IP bill passed by the end of this year when existing emergency surveillance powers, passed under DRIPA in 2014, are set to expire. Which gives a relatively short timeframe for the parliamentary scrutiny process. So all the committee reports are key steps and will steer the wider response of MPs and Peers in Parliament and the Lords when they begin to look in earnest at the proposals.

Talking of expiring, the joint select committee is at least pushing for a review of the new powers after five years. When the Home Secretary gave evidence to the committee last month she rejected the idea put to her by the committee of including a sunset clause in the legislation, arguing that ISPs will need certainty that the provisions are permanent.

The committee notes this but says: “We are of the view that some form of review after five years would be merited. We believe that a review provision of this sort, which would require the next Parliament to revisit the powers which are in the draft Bill, would go some way to provide assurance to those who have expressed concerns over the operational case for some of these powers. The evidence of several years’ operation will inform the debate.”

“A provision which asked Parliament to revisit the intrusive powers it gives to the Executive after a period would, in our view, be a healthy way to fulfil the welcome aspirations for greater openness and legitimacy which underpin the draft Bill,” it adds.

It is also recommending “detailed post-legislative scrutiny” of the bill after “an appropriate period” — suggesting this should be another joint select committee and should start six months after the end of the five-year operational period. (Albeit, that’s a rather ‘shutting the door after the horse has bolted’ type of provision.)

Other key suggestions of the committee include that the language around encryption should be clarified, as noted by Lord Strasburger — and in line with calls from other critics.

“We agree with the intention of the Government’s policy to seek access to protected communications and data when required by a warrant, while not requiring encryption keys to be compromised or backdoors installed on to systems. The drafting of the Bill should be amended to make this clear,” writes the committee.

The Government still needs to make explicit on the face of the Bill that CSPs offering end-to-end encrypted communication or other un-decryptable communication services will not be expected to provide decrypted copies of those communications if it is not practicable for them to do so. We recommend that a draft Code of Practice should be published alongside the Bill for Parliament to consider.”

The encryption point is especially key, given that earlier this week the FT newspaper reported that UK intelligence agencies have apparently warned Silicon Valley tech giants the UK government intends to press ahead with plans to force companies to decrypt encrypted private messages sent between their customers — contrary to statements made by the Home Secretary to the joint select committee on this very point — with spooks said to be intending to rely on overly broad clauses in the current draft bill to enable them to force companies to decrypt user data (clauses such as one that requires “electronic protection applied by a relevant operator to any communications or data” to be removed).

The UK government has been cooking up a pretty fudge on encryption for more than a year, with senior politicians such as the Prime Minister appearing to call for a ban on encryption then apparently rowing back and saying they are not calling for anything of the sort. The mixed messaging is unsurprisingly reflected in the opaque language of the draft legislation on encryption. But if the government’s intention is to legislate to outlaw end-to-end encryption that should at least be made clear in the language of the bill — so it can be quite rightly opposed in parliament.

The committee is also uncomfortable with so-called thematic bulk warrants, asserting that “the current wording of the provisions for targeted interception and targeted equipment interference warrants is too broad” and recommending that the language of the bill “be amended so that targeted interception and targeted equipment interference warrants cannot be used as a way to issue thematic warrants concerning a very large number of people”.

Another area the committee wants to see changes is on so-called ‘urgent’ warrants, where the legislation affords for a Secretary of State to be the sole authorization mechanism in such urgent situations — and judicial approval (the “double lock” authorization mechanism) only carried out in retrospect (so, at times, only a single lock in practice).

The committee wants the period afforded for back-checking by a judge to be shortened from the current five days to within 24 hours. It is also calling for greater clarity on the term “urgent” in this context.

It also specifically warns the government that operation of some of the bulk capabilities set out in the bill could infringe European human rights law. “It is possible that the bulk interception and equipment interference [hacking] powers contained in the draft Bill could be exercised in a way that does not comply with the requirements of Article 8 as defined by the Strasbourg court. It will be incumbent upon the Secretary of State and judicial commissioners authorising warrants, and the Investigatory Powers Commissioner’s oversight of such warrants, to ensure that their usage is compliant with Article 8,” it notes.

The committee is also critical of the bill’s position on intelligence sharing and flags up the risks of potential workarounds to safeguards via agreements with foreign intelligence services — so it is directly calling for “more safeguards” to be put on the face of the bill.

“These should address concerns about potential human rights violations in other countries that information can be shared with,” it notes, adding specifically that “the Bill should make it illegal for UK bodies to ask overseas agencies to undertake intrusion which they have not been authorised to undertake themselves”.

With so many detailed criticisms of the draft bill, one of the specialist advisors to the joint select committee — Martin Hoskins — is today suggesting there may not be enough parliamentary time this year to pass even a narrower bill.

“Should Parliament concentrate on passing a Bill that is narrower in scope this year, say one that just addresses the data retention and oversight provisions? Is there really sufficient time to consider other elements — such as overhauling the bulk data and equipment interference provisions in 2016? A second Bill, containing the remaining provisions, could always be considered in 2017,” he writes, noting constraints on the parliamentary calendar this year such as the EU referendum campaign and the various holidays and recesses scheduled in 2016. “That doesn’t leave a lot of time for legislating.”

“So, a new bill needs to be ready and tabled within weeks,” he adds. “And, if it is to get through both Houses of Parliament unscathed, it really does needs to take full account of each of the 123 recommendations that have been made by the scrutiny Committees. There will be no rest for the Home Secretary, her officials and the Parliamentary draftsmen for the foreseeable future.”

More TechCrunch

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

17 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?