The British IP Bill & Protection From Government Snoopers

The UK has just passed the Investigatory Powers Act 2016, at the third attempt, and it will become law by the end of the year. The bill was instigated by the then Home Secretary, Theresa May, in 2012. It is better known as the snooper’s charter.

Jim Killock, the director of Open Rights Group, described it as the “most extreme surveillance law ever passed in a democracy”. It more or less removes your right to online privacy.

The law forces Internet service providers to keep a record of all the websites, not the actual pages, you visit for up to a year. It also obliges companies to decrypt data on demand and gives government security services the power to hack your computers, tablets, mobile phones and other devices.

To some extent, the new law merely legalises the current “custom and practice” as revealed by Edward Snowden. The most obvious difference is that it makes your web history readily available to almost 50 assorted police forces and government departments. These include the British Transport Police, the Department of Health, the Food Standards Agency, the Gambling Commission, and the Welsh Ambulance Services NHS Trust.

Web Tracking and Proxies

When you sign up with an ISP, the traffic from your PCs and other devices goes to your ISP’s servers, which feed most of it, except various blocked websites, on to the Internet. You can track this process yourself using TraceRoute.

Your ISP therefore knows where you are going online. You can avoid this by using one or more anonymous “proxy servers” between your PC and your eventual destination. Your ISP will then know you visited the proxy server, but, if the anonymising is done properly, it won’t know where you went from there.

Enter the VPN

There are two big problems with using free proxies. First, you may not know who’s running them. They could be helpful hackers or criminals, or even CIA honeypots. Second, they may be unreliable and slow. It’s better to use a Virtual Private Network or VPN.

Multinational corporations have long used VPNs as a way of extending their private networks across the public Internet. If they encrypt all the traffic between computers in their British, American and other offices, they can send their traffic securely over the Internet without paying for expensive leased lines. VPN service providers offer the same facilities to ordinary users for a small monthly fee.

The traffic from your PC is automatically encrypted and sent to the VPN supplier’s server, so your ISP can’t see the final destination. The ISP’s records should only contain the VPN company’s server addresses.
Choosing a VPN

Dozens of companies sell VPN services, and you can find plenty of reviews to help you choose. The things to look for include the number of servers and where they are located, their privacy policies, the applications they support (Tor, BitTorrent etc.), speed and price. Some have applications for different devices. For example, NordVPN has them for Windows, MacOS, iPhone, iPad and Android.

If your motivation includes the snooper’s charter, choose a VPN that is not UK-based, and that does not keep any logs. If they don’t keep any logs, they can’t hand them over to government raiders. 

Web Tracking

A VPN stops your ISP from logging your web visits, but they may still be logged. For starters, your own web browser is keeping a history. You’re also being tracked by dozens of advertising services, including Google’s. You can block trackers with a browser extension such as Ghostery or the EFF’s Privacy Badger, but note that Privacy Badger only blocks trackers from third-party sites.

GRC has a “forensics” page, which checks whether you are being tracked by cookies. For increased privacy, you could access the Internet from a “virtual computer” loaded in your operating system, and then throw it away after use. VirtualBox is a good free example. VMware Workstation Player is also free for non-commercial use.

Mail, Messaging and Smartphones

You can’t make smartphone use private because you’re always being tracked by the cellular network. However, you can turn off Wi-Fi and Bluetooth when you’re not using them, they can also be used to track you, and use a VPN for web access. Remember also that many smartphone apps request permissions that enable them to track you.

Last Words

As an ordinary citizen with a life, you can’t hide from the security services, any more than you can defend your house against a tank regiment. If they want to hack your devices, they will. If you’re an investigative journalist, human rights campaigner, one of Snowden’s collaborators etc., you need a higher level of security.

But if they are not out to get you, why act as though they should be? It’s probably better to be as inconspicuous as possible, while limiting the amount of data that might turn up in some bored agency’s random fishing expeditions.

There are already plenty of reasons for using a VPN, to protect yourself in a world of hostile Wi-Fi hotspots and other online threats. That’s why many large businesses use VPNs. The fact that they may also shield you from some State Snooping is a bonus.

Guardian:            MI5's Uncontrolled Bulk Data Collection:     UK Investigatory Powers Bill Will Cost £1bn To Implement:

 

 

 

« Google & Facebook Ban Fake News Sites
Facebook Will Double UK Employees »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Digital Detective

Digital Detective

Digital Detective offer a range of products and services for digital forensic analysis and advanced data recovery.

ControlScan

ControlScan

ControlScan is a Managed Security Services Provider (MSSP) - our primary focus is protecting your business and securing your sensitive data.

Prim'X Technologies

Prim'X Technologies

Prim'X Technologies provides information protection solutions to prevent unauthorised access to sensitive data.

tietoevry

tietoevry

Tietoevry creates digital advantage for businesses and society. We are a leading digital services and software company with local presence and global capabilities.

i-Sprint Innovations

i-Sprint Innovations

i-Sprint is a leader in Securing Identity and Transactions in the Cyber World for industries that are security sensitive.

Ecubel

Ecubel

Ecubel is the market leader in Belgium in buying and selling used IT harware guaranteed by a certified data erasure.

Perimeter 81

Perimeter 81

Perimeter 81 is a Zero Trust Network as a Service designed to simplify secure network, cloud and application access for the modern and distributed workforce.

UMBRA

UMBRA

UMBRA is solely concerned with protecting governments against Nation State attacks. We are not a consumer or enterprise company.

Pixm

Pixm

Pixm’s computer vision based approach offers a truly unique and effective means to protect organizations from web-based phishing attacks.

IDX

IDX

IDX is the leading consumer privacy platform built for agility in the digital age.

InfoSystems Inc

InfoSystems Inc

InfoSystems provides reliable IT solutions to build and maintain strong and secure systems for both SMB and enterprise organizations.

Guardio

Guardio

Guardio develop tools and products to combat modern web and browser threats.

Privacy Compliance Hub

Privacy Compliance Hub

Privacy Compliance Hub provide an easy to use platform with a comprehensive data protection compliance programme including training, information, templates and reporting.

IDECSI

IDECSI

IDECSI delivers cutting-edge technology and engages all employees in the security system for effective and cost-efficient data protection.

Beetles Cyber Security

Beetles Cyber Security

Beetles is a crowdsourced penetration testing platform designed to build a trusted, hacker-centric approach to protectan organization’s digital attack surface.

Ionize

Ionize

Ionize offers solutions to help you uplift your capability across the full-spectrum of cyber security - assessment, remediation, monitoring, governance and ongoing education.