The British IP Bill & Protection From Government Snoopers

The UK has just passed the Investigatory Powers Act 2016, at the third attempt, and it will become law by the end of the year. The bill was instigated by the then Home Secretary, Theresa May, in 2012. It is better known as the snooper’s charter.

Jim Killock, the director of Open Rights Group, described it as the “most extreme surveillance law ever passed in a democracy”. It more or less removes your right to online privacy.

The law forces Internet service providers to keep a record of all the websites, not the actual pages, you visit for up to a year. It also obliges companies to decrypt data on demand and gives government security services the power to hack your computers, tablets, mobile phones and other devices.

To some extent, the new law merely legalises the current “custom and practice” as revealed by Edward Snowden. The most obvious difference is that it makes your web history readily available to almost 50 assorted police forces and government departments. These include the British Transport Police, the Department of Health, the Food Standards Agency, the Gambling Commission, and the Welsh Ambulance Services NHS Trust.

Web Tracking and Proxies

When you sign up with an ISP, the traffic from your PCs and other devices goes to your ISP’s servers, which feed most of it, except various blocked websites, on to the Internet. You can track this process yourself using TraceRoute.

Your ISP therefore knows where you are going online. You can avoid this by using one or more anonymous “proxy servers” between your PC and your eventual destination. Your ISP will then know you visited the proxy server, but, if the anonymising is done properly, it won’t know where you went from there.

Enter the VPN

There are two big problems with using free proxies. First, you may not know who’s running them. They could be helpful hackers or criminals, or even CIA honeypots. Second, they may be unreliable and slow. It’s better to use a Virtual Private Network or VPN.

Multinational corporations have long used VPNs as a way of extending their private networks across the public Internet. If they encrypt all the traffic between computers in their British, American and other offices, they can send their traffic securely over the Internet without paying for expensive leased lines. VPN service providers offer the same facilities to ordinary users for a small monthly fee.

The traffic from your PC is automatically encrypted and sent to the VPN supplier’s server, so your ISP can’t see the final destination. The ISP’s records should only contain the VPN company’s server addresses.
Choosing a VPN

Dozens of companies sell VPN services, and you can find plenty of reviews to help you choose. The things to look for include the number of servers and where they are located, their privacy policies, the applications they support (Tor, BitTorrent etc.), speed and price. Some have applications for different devices. For example, NordVPN has them for Windows, MacOS, iPhone, iPad and Android.

If your motivation includes the snooper’s charter, choose a VPN that is not UK-based, and that does not keep any logs. If they don’t keep any logs, they can’t hand them over to government raiders. 

Web Tracking

A VPN stops your ISP from logging your web visits, but they may still be logged. For starters, your own web browser is keeping a history. You’re also being tracked by dozens of advertising services, including Google’s. You can block trackers with a browser extension such as Ghostery or the EFF’s Privacy Badger, but note that Privacy Badger only blocks trackers from third-party sites.

GRC has a “forensics” page, which checks whether you are being tracked by cookies. For increased privacy, you could access the Internet from a “virtual computer” loaded in your operating system, and then throw it away after use. VirtualBox is a good free example. VMware Workstation Player is also free for non-commercial use.

Mail, Messaging and Smartphones

You can’t make smartphone use private because you’re always being tracked by the cellular network. However, you can turn off Wi-Fi and Bluetooth when you’re not using them, they can also be used to track you, and use a VPN for web access. Remember also that many smartphone apps request permissions that enable them to track you.

Last Words

As an ordinary citizen with a life, you can’t hide from the security services, any more than you can defend your house against a tank regiment. If they want to hack your devices, they will. If you’re an investigative journalist, human rights campaigner, one of Snowden’s collaborators etc., you need a higher level of security.

But if they are not out to get you, why act as though they should be? It’s probably better to be as inconspicuous as possible, while limiting the amount of data that might turn up in some bored agency’s random fishing expeditions.

There are already plenty of reasons for using a VPN, to protect yourself in a world of hostile Wi-Fi hotspots and other online threats. That’s why many large businesses use VPNs. The fact that they may also shield you from some State Snooping is a bonus.

Guardian:            MI5's Uncontrolled Bulk Data Collection:     UK Investigatory Powers Bill Will Cost £1bn To Implement:

 

 

 

« Google & Facebook Ban Fake News Sites
Facebook Will Double UK Employees »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Blue Frost Security

Blue Frost Security

Blue Frost Security provides high-level IT security consulting, penetration testing services, ISO 27001 Solutions, PCI compliance solutions and training.

Perforce Software

Perforce Software

Perforce helps companies build complex software products more collaboratively, securely, and efficiently.

Seagate Technology

Seagate Technology

Seagate data storage systems are purpose-built for enterprise and data centre performance, scalability, reliability and security.

Organization for Security and Co-operation in Europe (OSCE)

Organization for Security and Co-operation in Europe (OSCE)

OSCE is the world's largest security-oriented intergovernmental organization. Areas of activity include Cyber/ICT security.

Miradore

Miradore

Miradore is a software company specializing in effective, cloud-based device management. Our goal is to help IT Service Providers and IT departments secure and control devices.

National Cybersecurity Society (NCSS) - USA

National Cybersecurity Society (NCSS) - USA

The National Cybersecurity Society is a non-profit organization focused on providing cybersecurity education, awareness and advocacy to small businesses.

Trusted CI

Trusted CI

Trusted CI, the NSF Cybersecurity Center of Excellence is comprised of cybersecurity experts who have spent decades working with science and engineering communities.

Quantum Security

Quantum Security

Quantum's game-changing approach to cybersecurity brings you performance and peace-of-mind, with a raft of additional benefits: it's non-proprietary, comprehensive, scalable, and affordable.

Stairwell

Stairwell

Stairwell is building a new approach to cybersecurity around a vision that all security teams should be able to determine what’s good, what’s bad, and why.

Digital Boundary Group (DBG)

Digital Boundary Group (DBG)

Digital Boundary Group (DBG) is an information technology security assurance services firm providing information technology security auditing and compliance assessment services to clients worldwide.

Great American Insurance Group

Great American Insurance Group

Great American's Cyber Risk Division offers cyber solutions for small and medium-sized businesses.

LaScala

LaScala

LaScala is an IT Managed Services provider delivering technical, security, and compliance solutions with dedication, compassion, and agility.

SPIE Switzerland

SPIE Switzerland

SPIE Switzerland AG, a subsidiary of the SPIE Group, is a Swiss full-service provider of ICT, multi-technical and integral facility services.

Sensity

Sensity

Sensity is a company that offers an AI-driven solution to detect and verify deepfakes and other forms of identity fraud.

Bell Canada

Bell Canada

Bell is the leading provider of network and communications services for Canadian businesses and the partner for delivering network, IoT, cloud, voice, collaboration and security solutions.

SITS Group

SITS Group

SITS Group excel in delivering a comprehensive range of Cyber Security consulting and managed services, from cloud transformation to risk management.