I am a UK citizen who has worked developing software for computers and communication devices since the early 1980s. I was an “early adopter” of the internet for professional and private purposes, and have followed its development and take up with great interest.
My overall view of the Draft Investigatory Powers Bill is that it is unnecessary, disproportionate and technically ill-thought-out.
Thank you for this opportunity to comment. I am basing my response on the structure of the questions suggested by the Committee’s “Call for Written Evidence”
No, the case has not been made. No evidence has been presented as to how the powers made available under the draft bill will be used by security services to prevent terrorism or other criminal activity. The oft-quoted example of using ICRs (Internet Connection Records) to track a missing person is at best misleading, and maybe disingenuous: the missing person’s communication devices will simply indicate that they have been continually connected to a variety of social media sites, and investigators would far better direct their efforts to the organisations running those sites.
As a general point, a government should not collect potentially private and personal data on its citizens, even in bulk and anonymised, without unambiguous justification.
The loose and unworkable “definition” of ICRs in the Draft Bill will mean that a significant amount of legal testing in the courts will be needed to clarify the meaning and intention of the bill. This is bad for justice.
No. In particular the notion of an ICR is not adequately defined. See “Communications Data”, below.
No. As currently drafted, the Home Secretary is the primary supervisor. Retention and Interception Orders should only be issued with judicial authority. Whatever the stated intentions of the current Home Secretary, a future holder of that position may act differently. This is surely fundamental to the operation of a democracy.
Security, Intelligence and Law Enforcement services should have the powers for targeted surveillance and interception, with judicial oversight.
Whilst I believe there is sufficient justification for targeted interception, there is none for bulk interception of individuals’ personal private communications data.
Individuals will always be able to communicate in confidence using pre-agreed code signals, and with minor inconvenience will be able to continue to use the internet through VPNs https://en.wikipedia.org/wiki/Virtual_private_network or systems designed to avoid interception such as Tor https://en.wikipedia.org/wiki/Tor_(anonymity_network)
The idea of an ICR (Internet Connection Record” is not adequately defined (See written evidence from Adrian Kennard, Andrews & Arnold Ltd, 10th Dec 2015).
Because of the incomplete definitions of what is required, Service and Communications Providers are unable to adequately cost the development of the equipment and ongoing running costs necessary to satisfy the requirements of the bill.
Due to the way the internet works (again, see written evidence from Adrian Kennard, Andrews & Arnold Ltd, 10th Dec 2015), ICRs are unlikely to be consistent and will not be particularly useful.
Attempting to use IP addresses to identify individual “persons of interest” is not straightforward, due to shared use of IP addressed and complexities of “Carrier Grade NAT” (see https://en.wikipedia.org/wiki/Carrier-grade_NAT).
Powers to interfere with commercially available telecommunications equipment should not be given to government or their agents. This will harm commercial interests and will give the UK a reputation as a country that does not allow organisations or individuals to communicate confidentially.
The collection of vast quantities of communications data records is likely to create a hugely attractive target for hackers. With this data being captured, logged and maintained in a variety of different ways by different service providers, it is quite likely to be compromised at some point in the future (e.g. a “Snowden”-like individual leaking the data or a “Talk Talk“-style data breach).
The Draft Bill is inadequate in its description of "Request Filters" – it is sufficiently vague that the Home Office could subsequently change scope of information collated and returned. The idea of external programmatic access to intercepted data provides a weakness which will be a target of hacking.
The Draft Bill does not clearly define what will be collected, and for what purpose. The Code of Practice is not published. Retention Notices will be secret and cannot be shared between Communication Providers, so there will be little commonality about what data will be captured, and how.
The judiciary should be in overall charge of authorizing individual, targeted interception and retention orders before they occur. Post-act oversight is a poor compromise in a democracy.
20 December 2015