The British IP Bill & Protection From Government Snoopers

The UK has just passed the Investigatory Powers Act 2016, at the third attempt, and it will become law by the end of the year. The bill was instigated by the then Home Secretary, Theresa May, in 2012. It is better known as the snooper’s charter.

Jim Killock, the director of Open Rights Group, described it as the “most extreme surveillance law ever passed in a democracy”. It more or less removes your right to online privacy.

The law forces Internet service providers to keep a record of all the websites, not the actual pages, you visit for up to a year. It also obliges companies to decrypt data on demand and gives government security services the power to hack your computers, tablets, mobile phones and other devices.

To some extent, the new law merely legalises the current “custom and practice” as revealed by Edward Snowden. The most obvious difference is that it makes your web history readily available to almost 50 assorted police forces and government departments. These include the British Transport Police, the Department of Health, the Food Standards Agency, the Gambling Commission, and the Welsh Ambulance Services NHS Trust.

Web Tracking and Proxies

When you sign up with an ISP, the traffic from your PCs and other devices goes to your ISP’s servers, which feed most of it, except various blocked websites, on to the Internet. You can track this process yourself using TraceRoute.

Your ISP therefore knows where you are going online. You can avoid this by using one or more anonymous “proxy servers” between your PC and your eventual destination. Your ISP will then know you visited the proxy server, but, if the anonymising is done properly, it won’t know where you went from there.

Enter the VPN

There are two big problems with using free proxies. First, you may not know who’s running them. They could be helpful hackers or criminals, or even CIA honeypots. Second, they may be unreliable and slow. It’s better to use a Virtual Private Network or VPN.

Multinational corporations have long used VPNs as a way of extending their private networks across the public Internet. If they encrypt all the traffic between computers in their British, American and other offices, they can send their traffic securely over the Internet without paying for expensive leased lines. VPN service providers offer the same facilities to ordinary users for a small monthly fee.

The traffic from your PC is automatically encrypted and sent to the VPN supplier’s server, so your ISP can’t see the final destination. The ISP’s records should only contain the VPN company’s server addresses.
Choosing a VPN

Dozens of companies sell VPN services, and you can find plenty of reviews to help you choose. The things to look for include the number of servers and where they are located, their privacy policies, the applications they support (Tor, BitTorrent etc.), speed and price. Some have applications for different devices. For example, NordVPN has them for Windows, MacOS, iPhone, iPad and Android.

If your motivation includes the snooper’s charter, choose a VPN that is not UK-based, and that does not keep any logs. If they don’t keep any logs, they can’t hand them over to government raiders. 

Web Tracking

A VPN stops your ISP from logging your web visits, but they may still be logged. For starters, your own web browser is keeping a history. You’re also being tracked by dozens of advertising services, including Google’s. You can block trackers with a browser extension such as Ghostery or the EFF’s Privacy Badger, but note that Privacy Badger only blocks trackers from third-party sites.

GRC has a “forensics” page, which checks whether you are being tracked by cookies. For increased privacy, you could access the Internet from a “virtual computer” loaded in your operating system, and then throw it away after use. VirtualBox is a good free example. VMware Workstation Player is also free for non-commercial use.

Mail, Messaging and Smartphones

You can’t make smartphone use private because you’re always being tracked by the cellular network. However, you can turn off Wi-Fi and Bluetooth when you’re not using them, they can also be used to track you, and use a VPN for web access. Remember also that many smartphone apps request permissions that enable them to track you.

Last Words

As an ordinary citizen with a life, you can’t hide from the security services, any more than you can defend your house against a tank regiment. If they want to hack your devices, they will. If you’re an investigative journalist, human rights campaigner, one of Snowden’s collaborators etc., you need a higher level of security.

But if they are not out to get you, why act as though they should be? It’s probably better to be as inconspicuous as possible, while limiting the amount of data that might turn up in some bored agency’s random fishing expeditions.

There are already plenty of reasons for using a VPN, to protect yourself in a world of hostile Wi-Fi hotspots and other online threats. That’s why many large businesses use VPNs. The fact that they may also shield you from some State Snooping is a bonus.

Guardian:            MI5's Uncontrolled Bulk Data Collection:     UK Investigatory Powers Bill Will Cost £1bn To Implement:

 

 

 

« Google & Facebook Ban Fake News Sites
Facebook Will Double UK Employees »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

FireEye

FireEye

FireEye delivers unmatched detection, protection and response technology through an extensible and flexible cloud-based XDR platform.

SecuTech Solutions

SecuTech Solutions

SecuTech is a global leader in providing strong authentication and software licensing management solutions.

Modux

Modux

Modux focus on a number of core competencies across cyber security including; cyber intelligence & analytics, penetration testing and training.

ReSec Technologies

ReSec Technologies

ReSec provides total protection against all types of known and unknown malware threats including viruses, Trojans, ransomware and phishing, regardless of their delivery method.

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI) is recognized as Thailand’s leader in cyber investigations and digital forensics.

Miradore

Miradore

Miradore is a software company specializing in effective, cloud-based device management. Our goal is to help IT Service Providers and IT departments secure and control devices.

Perseus Cyber Security

Perseus Cyber Security

Perseus provides all-around digital protection for small and medium-sized businesses through state-of-the-art software solutions, flexible online training and emergency response.

ShorePoint

ShorePoint

ShorePoint is an elite cybersecurity firm dedicated to improving the cyber resilience of Federal agencies and their missions.

Brighterion

Brighterion

Brighterion solutions stop payment and acquirer fraud, reduce credit risk and delinquency, fight financial crime, prevent healthcare fraud, waste and abuse, and more.

KSOC Labs

KSOC Labs

KSOC is an event-driven SaaS platform built to automatically remediate Kubernetes security risks.

Saiflow

Saiflow

SaiFlow provides a tailor-made cybersecurity solution for Electric Vehicles Charging Infrastructure (EVCI), Distributed Energy Resources (DERs) and energy networks and assets.

Nullify

Nullify

Nullify is your automated security sentry that continuously finds and fixes security issues across your codebase.

DV Cyber Security

DV Cyber Security

DV Cyber (formerly A76) is an innovative cyber security company vertically focused on Threat Intelligence and Cyber Security Research.

Judy Security

Judy Security

Judy provides smart, simple, effective, all-in-one cybersecurity for SMBs. Get the 24/7 protection and support you deserve, at a price you can afford.

GitLab

GitLab

GitLab is a complete DevOps platform, delivered as a single application, fundamentally changing the way Development, Security, and Ops teams collaborate and build software.

CloudBees

CloudBees

CloudBees is building the world’s first end-to-end automated software delivery system, enabling companies to balance governance and developer freedom.