Security

Third Committee Report Critical Of UK’s “Sloppy” Draft Surveillance Bill

Comment

Image Credits: Harshil Shah (opens in a new window) / Flickr (opens in a new window) under a CC BY-ND 2.0 (opens in a new window) license.

A third UK parliamentary committee has now published a report on the government’s draft surveillance legislation.

The report of the joint select committee, which is made up of a majority of Conservative MPs and Peers, takes a more supine approach than the ISC committee report earlier this week, with many statements where the committee accepts the government’s position, while still suggesting it should publish, for example, fuller justification for each of the so-called “bulk capabilities” (aka mass surveillance powers) to be set out in the legislation.

The committee does recommend a raft of specific changes to the draft bill, although its general tone is more supportive than the ISC report. Cambridge University security researcher Ross Anderson, one of the expert witnesses who gave evidence to the committee, dubs the report “deeply disappointing“.

That said, one of the committee members, the Lib Dem Peer Lord Strasburger, summing up the report for Wired, calls for the bill to be “fundamentally rethought and rebuilt”, branding it “sloppy in its wording and short on vital details”. Albeit, at times Lord Strasburger has stood out as something of a lone dissenting voice speaking up for privacy and civil liberties on the committee.

“[The report] tells the government to make clear that it does not expect companies to provide decrypted copies of end-to-end encrypted information. It finds the proposed Internet Connection Records, essentially a log of everything that everyone does on the internet, to be largely undefined, difficult and costly to deliver, and risky for the ISPs to store safely for 12 months. It says that there should be strong protections to prevent journalists’ sources from being exposed and for legally privileged communications,” writes Strasburger.

“So this Bill is a long way from the finished article,” he adds. “It needs more than mere tweaking, it needs to be fundamentally rethought and rebuilt. The Home Office should stop rushing to push it through and take its time to get it right.”

The Investigatory Powers Bill (IP bill) was introduced by the UK government this fall, with the aim of — in its words — plugging “capability gaps” for domestic intelligence and law enforcement agencies operating in an increasing technological context by expanding state surveillance powers, such as laying out a requirement that ISPs must log details of all the websites visited by citizens over a 12 month period. Hence critics dubbing it another ‘Snoopers’ Charter’.

The government wants the IP bill passed by the end of this year when existing emergency surveillance powers, passed under DRIPA in 2014, are set to expire. Which gives a relatively short timeframe for the parliamentary scrutiny process. So all the committee reports are key steps and will steer the wider response of MPs and Peers in Parliament and the Lords when they begin to look in earnest at the proposals.

Talking of expiring, the joint select committee is at least pushing for a review of the new powers after five years. When the Home Secretary gave evidence to the committee last month she rejected the idea put to her by the committee of including a sunset clause in the legislation, arguing that ISPs will need certainty that the provisions are permanent.

The committee notes this but says: “We are of the view that some form of review after five years would be merited. We believe that a review provision of this sort, which would require the next Parliament to revisit the powers which are in the draft Bill, would go some way to provide assurance to those who have expressed concerns over the operational case for some of these powers. The evidence of several years’ operation will inform the debate.”

“A provision which asked Parliament to revisit the intrusive powers it gives to the Executive after a period would, in our view, be a healthy way to fulfil the welcome aspirations for greater openness and legitimacy which underpin the draft Bill,” it adds.

It is also recommending “detailed post-legislative scrutiny” of the bill after “an appropriate period” — suggesting this should be another joint select committee and should start six months after the end of the five-year operational period. (Albeit, that’s a rather ‘shutting the door after the horse has bolted’ type of provision.)

Other key suggestions of the committee include that the language around encryption should be clarified, as noted by Lord Strasburger — and in line with calls from other critics.

“We agree with the intention of the Government’s policy to seek access to protected communications and data when required by a warrant, while not requiring encryption keys to be compromised or backdoors installed on to systems. The drafting of the Bill should be amended to make this clear,” writes the committee.

The Government still needs to make explicit on the face of the Bill that CSPs offering end-to-end encrypted communication or other un-decryptable communication services will not be expected to provide decrypted copies of those communications if it is not practicable for them to do so. We recommend that a draft Code of Practice should be published alongside the Bill for Parliament to consider.”

The encryption point is especially key, given that earlier this week the FT newspaper reported that UK intelligence agencies have apparently warned Silicon Valley tech giants the UK government intends to press ahead with plans to force companies to decrypt encrypted private messages sent between their customers — contrary to statements made by the Home Secretary to the joint select committee on this very point — with spooks said to be intending to rely on overly broad clauses in the current draft bill to enable them to force companies to decrypt user data (clauses such as one that requires “electronic protection applied by a relevant operator to any communications or data” to be removed).

The UK government has been cooking up a pretty fudge on encryption for more than a year, with senior politicians such as the Prime Minister appearing to call for a ban on encryption then apparently rowing back and saying they are not calling for anything of the sort. The mixed messaging is unsurprisingly reflected in the opaque language of the draft legislation on encryption. But if the government’s intention is to legislate to outlaw end-to-end encryption that should at least be made clear in the language of the bill — so it can be quite rightly opposed in parliament.

The committee is also uncomfortable with so-called thematic bulk warrants, asserting that “the current wording of the provisions for targeted interception and targeted equipment interference warrants is too broad” and recommending that the language of the bill “be amended so that targeted interception and targeted equipment interference warrants cannot be used as a way to issue thematic warrants concerning a very large number of people”.

Another area the committee wants to see changes is on so-called ‘urgent’ warrants, where the legislation affords for a Secretary of State to be the sole authorization mechanism in such urgent situations — and judicial approval (the “double lock” authorization mechanism) only carried out in retrospect (so, at times, only a single lock in practice).

The committee wants the period afforded for back-checking by a judge to be shortened from the current five days to within 24 hours. It is also calling for greater clarity on the term “urgent” in this context.

It also specifically warns the government that operation of some of the bulk capabilities set out in the bill could infringe European human rights law. “It is possible that the bulk interception and equipment interference [hacking] powers contained in the draft Bill could be exercised in a way that does not comply with the requirements of Article 8 as defined by the Strasbourg court. It will be incumbent upon the Secretary of State and judicial commissioners authorising warrants, and the Investigatory Powers Commissioner’s oversight of such warrants, to ensure that their usage is compliant with Article 8,” it notes.

The committee is also critical of the bill’s position on intelligence sharing and flags up the risks of potential workarounds to safeguards via agreements with foreign intelligence services — so it is directly calling for “more safeguards” to be put on the face of the bill.

“These should address concerns about potential human rights violations in other countries that information can be shared with,” it notes, adding specifically that “the Bill should make it illegal for UK bodies to ask overseas agencies to undertake intrusion which they have not been authorised to undertake themselves”.

With so many detailed criticisms of the draft bill, one of the specialist advisors to the joint select committee — Martin Hoskins — is today suggesting there may not be enough parliamentary time this year to pass even a narrower bill.

“Should Parliament concentrate on passing a Bill that is narrower in scope this year, say one that just addresses the data retention and oversight provisions? Is there really sufficient time to consider other elements — such as overhauling the bulk data and equipment interference provisions in 2016? A second Bill, containing the remaining provisions, could always be considered in 2017,” he writes, noting constraints on the parliamentary calendar this year such as the EU referendum campaign and the various holidays and recesses scheduled in 2016. “That doesn’t leave a lot of time for legislating.”

“So, a new bill needs to be ready and tabled within weeks,” he adds. “And, if it is to get through both Houses of Parliament unscathed, it really does needs to take full account of each of the 123 recommendations that have been made by the scrutiny Committees. There will be no rest for the Home Secretary, her officials and the Parliamentary draftsmen for the foreseeable future.”

More TechCrunch

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only more…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

Google on Wednesday launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation

Samsung Medison, a medical device unit of Samsung Electronics that specializes in developing diagnostic imaging devices, said on Wednesday it plans to acquire Sonio, a Paris-based startup that makes AI-powered software…

Samsung Medison to acquire French AI ultrasound startup Sonio for $92.7M

Kyle Kuzma is a lot of things. He’s a forward for the Washington Wizards NBA team and a 2020 NBA champion. He’s also a style icon — depending on who…

NBA champion Kyle Kuzma looks to bring his team mentality to Scrum Ventures

Ofcom is cracking down on Instagram, YouTube and 150,000 other web services to improve child safety online. A new Children’s Safety Code from the U.K. Internet regulator will push tech…

Ofcom to push for better age verification, filters and 40 other checks in new online child safety code

Lipids are fatty, waxy or oily compounds that, for instance, typically come in the form of fats and oils. As a result they are heavily used in the production of…

After a $20M Series A funding, Germany’s Insempra plans eco-friendly lipid production

Tesla CEO Elon Musk has said that lidar sensors are a “crutch” for autonomous vehicles. But his company has bought so many from Luminar that Tesla is now the lidar-maker’s…

Tesla is Luminar’s largest lidar customer

U.S. realty trust giant Brandywine Realty Trust has confirmed a cyberattack that resulted in the theft of data from its network. In a filing with regulators on Tuesday, the Philadelphia-based…

Brandywine Realty Trust says data stolen in ransomware attack

Rivian lost $1.45 billion in the first quarter, showing that its recent company-wide cost-cutting measures have a ways to go before it can approach profitability. The EV-maker brought in $1.2…

Rivian loses $1.45B as cost-cutting measures continue

Meta is rolling out an expanded set of generative AI tools for advertisers, after first announcing a set of AI features last October. Now, instead of only being able to…

Meta’s AI tools for advertisers can now create full new images, not just new backgrounds