Saturday, 3 February 2018

How to manage Internet Content Blocking: some practicalities






“The Internet contains some deeply troublesome and harmful material. The main commercial players are both immensely rich and immensely clever – they must be able to do more to find solutions. If they don’t we politicians will prosecute/fine/tax them until they behave responsibly.” So goes the refrain but what can we reasonably expect of the available technologies? Here is a guide for campaigners.

Issue 1: what criteria are you applying for blocking “undesirable” material?
To those who haven’t thought about the issue it seems obvious what needs to be blocked. Almost anyone other than the most extreme libertarian will point to material which they find distressing or harmful – and be able to produce justifying arguments. But if you are asking a computer program or a human being to make decisions there has to be greater clarity. In almost all circumstances there will be countervailing arguments about freedom of speech,  freedom of expression and censorship.  
The easiest policy to implement is where one can point to existing legislation defining specifically illegal content. For example in the United Kingdom possession of indecent images of children is a strict liability offence[i]. Published guidelines from the Sentencing Council describe in detail three levels of offence in terms of age and specific activities[ii]. Similarly “extreme pornography” is clearly defined – essentially animals,  dead people and absence of consent[iii]. But outside that particular context there is no definition of “extremism” still less of “harmful”.[iv] Successive would-be legislators have struggled because so often the appearance of a particular document or file depends not only on its content but on its context. 
A simple example: let’s take two statements: “the state of Israel is a theft from Palestinians” and “the state of Israel is entitled to occupy all the territories mentioned in the Bible”. Are these statements, which many people would label “extreme”,  simply expressions of history and religious belief? Do we have a different view of them if they are accompanied by a call to action – push all the Jews out, push out all the Arabs? The boundaries are unclear and it seems unreasonable that if legislators are unwilling to provide assistance that somehow Internet companies should be forced to make those decisions. There is a separate further issue for the biggest of the global companies in that judgements about extremism and harmfulness vary across jurisdictions and cultures.
It gets more difficult with “grooming” whether for a sexual purpose or to incite terrorist acts.  The whole point of grooming is that its starts low key and then builds. It is  easy enough to identify grooming after a successful exercise[v] but how do you distinguish the early stages from ordinary conversation?  And how do you do so via a computer program or a human monitor? 
Finally, it is even more difficult to think what the evidence would look like where the enforceable law simply says: social media sites should keep children safe.


Issue 2: what is the legal framework within which material gets uploaded?
Material gets uploaded to the Internet via a variety of legal frameworks and this has an impact on where potential legal enforcement can be directed.  An individual might buy web space from an Internet service provider and create their own website. That same individual may provide facilities for third parties to post comments which will then be automatically instantly seen by all visitors. A social media service will almost certainly require a specific sign up from their subscribers/members and at that time inform them of an “acceptable use” or “community standards” policy but will thereafter allow postings without prior approval or initial restraint.
The position currently taken by most Internet service companies, bolstered by various directives and laws is that they are not publishers in the same sense as traditional media such as newspapers magazines and broadcast television stations. They say that they are providing facilities but are not editors. Or that they are “data processors” as opposed to “data controllers”[vi].  The claim is that they are “intermediaries” for the purpose of the E-Commerce Directive and Regulations. These arguments are currently being hotly debated. But even under their interpretation there is a significant impact on what one can reasonably expect them to do in terms of attempting to block before publication.
The main business of Google is to index world wide web content which has been originated by others with whom it has no contractual relationship. It has a series of “crawler” programs which scavenge the open part of the World Wide Web; the findings are then indexed and that is what visitors to Google’s main pages see. The contractual relationship that is most important in the basic Google framework is with those who use the indexes – essentially the service is paid for by allowing Google to harvest information about individuals which can be turned into targeted advertising. But Google is not under any compulsion or contractual obligation to index anything;  it can block at will.   The main policy reason for refusing to block is that it has decided that it favours completeness and freedom of speech and expression; it blocks only when there is an overwhelming reason to do so. 
By contrast for Facebook, Twitter, and many similar services the contractual relationship is with their customers/subscribers/members. It is consists of saying “we will let you see what others have posted and we will let you post provided you will allow us to harvest information about you and send you targeted advertisements”.  As part of the contract there is usually an Acceptable Use or Community Standards provision which are the basis for blocking. But here again as companies headquartered in the United States they are concerned about observing First Amendment rights[vii]
There are important differences in terms of what one can expect if some of this material is to be blocked. In the case of Google they have no opportunity to prevent material from being uploaded; the earliest point at which they could intervene is when their crawler comes across material which has already been published.  Their choice is to refuse to index.  But for the social media sites and where the acceptable use policy is part of the customer agreement the earliest opportunity for blocking is when the customer uploads material.

Issue 3: technical means for blocking material (a) that that has already been identified as “undesirable”.
We must now look at the various blocking technologies and see how far they are practical to implement. There is a significant difference between situations where material has already been identified by some method or other as requiring blocking and material which no one has so far seen and passed judgement on.
Blocking of known “undesirable” material (I am using the word “undesirable” to avoid the problems raised in Issue 1 above) is relatively straightforward though there are questions of how to do so at the speed and quantity of uploads. For example on Facebook, it is said  that every 60 seconds 510,000 comments are posted, 293,000 statuses are updated and 136,000 photos uploaded[viii].

It is trivially easy to block an entire website. The block is on the URL  -  www.nastysite.com -and this is the method traditionally used by such bodies as the Internet Watch Foundation and the National Center for Missing and Exploited Children. It is also possible, again by URL, to block part of the website -  www.harmlesssite.com /nastymaterial  - though here the blocking will fail if the folder containing the undesirable material is given a different name or location in the file structure of the website as a whole. One can extend this method to specific pages and pictures on the website – www.harmlesssite.com/harmless/nastyfile.jpg -  but here too simple name changes will render the blocking ineffective.
Blocking on the basis of keyword is impossibly crude.  “Sex” eliminates the counties of Sussex, Essex, Middlesex etc as well as much useful material on health, education, law enforcement and more. 
In order to overcome these problems one must revert to a different technology – file hashing. A file hash or fingerprint of a file is created using a simple program[ix] which is applied to the totality of a file – photo, picture, documents, software program – to produce a unique short sequence of numbers and letters. The program is clever enough so that the most purposes no two dissimilar files will ever produce the same hash or signature. A database of these hashes is built up and when a file is presented for examination a hash is created and compared with the database. If there is a match the newly uploaded file is then blocked. File hashing is used elsewhere throughout computing in order, for example, to demonstrate that a file has not been altered or that it has.
This method only works to identify absolutely identical files so that if an “undesirable” file has been slightly altered there will be a different hash and so blocking will not take place. To a limited extent there is also a further technology which deals with slightly dissimilar files. For photo images the most popular of these is called photoDNA[x] which is promoted by Microsoft and given away to Internet service providers , social media services and to law enforcement. There are two typical situations where it is effective – when a file has been subject to a degree of compression to reduce its size and where are there are a series of adjacent clips taken from a video.

Issue 4: technical means for blocking material (b) that is new and hasn’t been seen before.
This leaves the situation where a wholly new material never seen before is uploaded or where previously seen material has been substantially altered for example by cropping or selection. Here many claims are made for “artificial intelligence” techniques.
But most computer scientists as opposed to marketing droids no longer use the phrase “artificial intelligence” or its contraction “AI” because concepts of what it is keep on changing in the light of developments in computer science and investigations by biological scientists in how the human brain actually works. Moreover AI consists of a number of separate techniques all with their own value but also limitations. It can include pattern recognition in images, the identification of rules in what initially appears to be random data, data mining,  neural networks, and machine learning in which a program follows the behaviour of an individual or event and identifies patterns and linkages.  And there are more and there are also many overlaps in definitions and concepts. 
Much depends on what sort of results are hoped for. A scientist either operating in the physical or social sciences and possessed of large volumes of data may wish to have drawn to their attention possible patterns from which rules can be derived.  They may want to extend this into making predictions.  A social media company or retailer may wish to scan the activity of a customer in order to make suggestions for future purchases – but here high levels of accuracy are not particularly required. If an intelligence agency or law enforcement agency uses similar techniques to scan the activities of individual the level of inaccuracy may have unfortunate consequences – the decision to prevent that person from boarding an aeroplane or whether they secure future employment or whether they are arrested.
If one is scrutinising uploaded files, limitations become apparent. In the first place the context in which a file is being uploaded may be critical. Field Manuals from the United States Army[xi] were produced as part of the training mechanism for that organisation but they are also found on the computers of people suspected of terrorism. Terrorist manuals may be reproduced on research and academic websites on the basis that experts need to be able to refer and analyse them. The same photo may appear on a site promoted by a terrorist group and by a news organisation.  Some sexually explicit photos may be justified in the context of medical and educational research – or law enforcement. 
Beyond that, as we have already discussed, telling the difference between a document which merely advances an argument and one which incites may be beyond what is currently possible via AI. My favourite example of linguistic ambiguity is “I could murder an Indian” which might mean no more than one person is inviting another to a meal in an Indian restaurant. In terms of photos, how does one tell the difference between the depiction of a murderous terrorist act and a clip from a movie or computer game?  AI can readily identify a swasitka in an image - but is the photo historic and of Germany in the 1930s and during World War II,  or a still from a more modern war movie, or is it on a website devoted to neo-Nazi anti-semitism?    How do you reliably distinguish a 16-year-old from an 18-year-old, and for all ethnicities?  How does an AI system distinguish the artistic from the exploitative or when in a sexual situation there is an absence of consent?  What exactly is "fake news" and where are the generally-accepted guidelines to recognise it?
The role of AI techniques therefore is less that they can make fully automated decisions of their own and more that they can provide alerts for which human monitors will make a final arbitration. Even here there is a problem because as with most alert systems it is usually possible to set a threshold before something is brought to attention. A balance has to be struck between too many false positives – alerts which identify harmless events – and false negatives - failures to identify harmful activity.

Issue 5: the role and training of human monitors.
This takes us back to Issue 1. A human monitor has to make judgements based on criteria laid down by the organisation exercising blocking. That human monitor needs clear and consistent instructions and associated with them appropriate training. Among other things the blocking organisation will want to be able to demonstrate consistency in decisions.  As we have seen monitoring for illegality is easier than making judgements about “extremism” and “harm”. But even here the structure of many laws is that it is for a court to determine whether a crime has been committed. Where the test is purely of a factual nature – for example the age of a person in a sexual situation – the decision might be relatively simple. But whether somebody is to be convicted for disseminating terrorist material context may be critical – the academic researcher versus someone against whom there is also evidence of having sent funds to or has begun to accumulate the material necessary to build a bomb. 
As a result the human monitor can probably only block where they are absolutely sure that a court would convict – leaving a number of potential situations in which a court might possibly convict but the monitor decides that there is insufficient reason to block. At the Internet Watch Foundation which operates on a relatively limited remit  confined to illegal sexual material, decisions about marginal photos and files are usually taken by more than one person and may be referred upwards for special review.  
One policy problem in the counter-terrorism domain is that material which by itself is not illegal may nevertheless play a part in the radicalisation of an individual.  A striking recent example was a BBC drama based on events involving child abuse in the northern town of Rochdale which was said to have inspired a man to  murder a Muslim man and attack others in Finsbury Park, London.
Where are we to obtain appropriate human monitors? Facebook and similar organisations have announced that they plan to recruit 10,000 or more such persons. But there is no obvious source – this is not a role which exists in employment exchanges or in the universities. Almost inevitably a monitor will spend most of their day looking at deeply unpleasant and distressing material – even if you can persuade people to assume such a role it is plainly important to establish that they have the intellectual ability and psychological make up to be able to cope and perform.  Current indications are that monitors are recruited in countries that possess a population of graduates but where regular employment for them is very limited and hourly rates are low.  It also looks as though the monitors are not directly employed by the social media sites but by third-party out-sourcing companies such as Accenture.[xii]  If true this could be aimed at limiting the liability of the major social media sites.  Moreover, and again one looks at the experience of the Internet Watch Foundation, employers have a duty of care as damage to the monitor as well as their effectiveness may develop over time. One must also ask what sort of career progression such a monitor can expect.

Observations
Too often those who dislike what they see “on the Internet” spend all their energy in drawing attention to the various harms and neglect to consider in sufficient detail which remedies might have a practical impact. 
As this article has tried to show criteria for blocking have to be clear and unambiguous whether the blocking is carried out by human monitors, computer programs or a combination thereof. There will always be a substantial territory at the margins where there are disputes.
Fully automated computer-mediated blocking is high risk because AI is nowhere near sufficiently sophisticated to achieve results which most people will accept. There is a useful mantra: Blocking is good and censorship is bad.

So given that obvious harms exist on the Internet:  what practical routes are available now?
One of them,  popular with campaigners, is to emulate Germany and its Netzwerkdurchsetzungsgesetz - NetzDG for short. This requires the biggest social networks - those with more than two million German users - to take down "blatantly illegal" material within 24 hours of it being reported. For less obvious material, seven days’ consideration is allowed. Fines for violation could be up to 50 million euros.  At the time of writing there have been no cases.  But this law seems to be limited to situations where there is existing law describing illegality, not to further instances of extremism and harm.

There are a number of existing UK laws which address situations which are less than full-on sexual and terrorism offences, for example the sending by an adult of a sexually explicit picture to a child and the various preparatory terrorist activities in the Terrorist Act 2006 -  “encouragement”,  dissemination of materials,  raising funds, arranging and attending training events.

The NSPCC proposes a Code of Practice which it says should be mandatory[xiii] but many of  their detailed proposals lack the specificity which is required if there is to be legal enforcement – “safeguarding children effectively – including preventative measures to protect children from abuse” is simply the articulation of a desirable policy aim. However there is much to be said for campaigning for a voluntary code, violation of which would be an opportunity for public shaming.

This takes us to a proposal which is in some respects contentious but which merits further examination:  much higher personal identity verification standards before admitting people to accounts on social media.  This would involve processes similar to those required in opening an online bank account – birth certificates,  passports,  possibly signatures from trusted individuals to sign off on some-one’s identity.  Such an approach would do much to prevent under-age individuals from joining unsuitable services and stop others from seeking to post anonymously or via a fake identity.  Just as gun laws do not wholly stop the circulation of illegal firearms such measures would reduce though not eliminate grooming, hate speech and fake news.  At the least higher personal identity verification standards would make it much easier to identify fake identities and identities which are bots as opposed to real people. But there will be opposition from privacy advocates who will argue that in some countries dissent is difficult to publish unless there is anonymity.

But higher personal identity verification standards would have to be imposed globally and not just in the UK in order to close off obvious evasion routes – and both the public and the major social media sites would need to be persuaded that the advantages outweigh the loss of convenience and privacy. 





[i] S 160 Criminal Justice Act 1988
[ii] https://www.sentencingcouncil.org.uk/offences/item/possession-of-indecent-photograph-of-child-indecent-photographs-of-children/
[iii] sections 63-67 of the Criminal Justice and Immigration Act 2008
[iv] https://www.theguardian.com/uk-news/2017/sep/17/paralysis-at-the-heart-of-uk-counter-extremism-policy
[v] Indeed under s 67 Serious Crime Act 2015 it is an offence for an adult to send a sexually explicit message to a child
[vi] See for example:  https://inforrm.org/2017/11/12/cjeu-advocate-general-opines-on-the-definition-of-a-data-controller-applicable-national-law-and-jurisdiction-under-data-protection-law-henry-pearce/
[vii] http://constitutionus.com/; https://www.law.cornell.edu/constitution/first_amendment
[viii] Cited by https://zephoria.com/top-15-valuable-facebook-statistics/ though there are other statistics and it is difficult to know which to credit.
[ix] Such as MD5 or from the SHA family
[x] https://www.microsoft.com/en-us/photodna;  https://en.wikipedia.org/wiki/PhotoDNA
[xi] https://www.loc.gov/rr/frd/Military_Law/pamphlets_manuals.html
[xii] https://www.thetimes.co.uk/article/facebook-fails-to-delete-hate-speech-and-racism-hwrzw0qzn; https://www.thetimes.co.uk/article/meet-the-internet-moderators-b86t2lrlv; ttps://www.washingtonpost.com/news/the-intersect/wp/2017/05/04/the-work-of-monitoring-violence-online-can-cause-real-trauma-and-facebook-is-hiring/?utm_term=.4d0a47b56d12; https://www.wsj.com/articles/the-worst-job-in-technology-staring-at-human-depravity-to-keep-it-off-facebook-1514398398;http://www.dailymail.co.uk/news/article-4548898/Facebook-young-Filipino-terror-related-material-Manchester.html
[xiii] https://www.nspcc.org.uk/what-we-do/news-opinion/more-than-1300-cases-sexual-communication-with-child-recorded-after-change-law/

Monday, 3 April 2017

CIA's Marble Framework

Another leaked document via Wikileaks this time about the CIA's Marble Framework obfuscation tool.
I am rather puzzled. The aim of the tools is to obscure the authorship of a cyber attack. Let's wind back a little. Large numbers of entities that mount cyber attacks want the attack to succeed but to be able to deny authorship. For the analyst and investigator this is "the problem of attribution".
One route for the attacker is to avoid mounting the attack from a computer that can be associated with them via its IP address. This is done by hijacking one of the several million unprotected computers and other devices and launching the attack from there. Or maybe they'll set up a chain of such devices. So investigators move on to code analysis - looking for clues in the use of structures and strings. Are there words in a specific language? Has the code been used before - and by some-one already known? The problem with this is that there is no enforceable copyright in attack code and it is relatively easy for a hacker to steal some-one else's code and hence point the finger of blame at them. This is known in espionage circles as a "false flag" action.
Marble Framework, if it works,  automates the process.  The CIA write their attack code and then run it through their Marble software so that any "English" references either are deleted or "foreign language" references added. 
So we move on to two other attribution routes - "resource required" and "motivation". Judgements about the level of resource required to mount the attack - the difficulty of creating the code, the amount of research required into accurately focusing the attack on the target - give clues about the nature of the attacker - lone recreational hacker or large national security agency or somewhere in between. Judgements about motivation take us away from technical matters into politics. Who would want to mount the attack? The attribution of Stuxnet is based on a combination of resource required and motivation.
Where does Marble Framework fit in? Well presumably in defeating code analysis by attempting to remove indications of authorship. Will it actually do so? If future analysts come across code that looks suspiciously anonymous, will they not say to themselves: "This looks as though it has been carefully cleaned - I wonder if this is the result of CIA's Marble tool?"
And of course there will still be the "resource required" and "motivation" tests.
I cover nearly all of these points in my Digital Evidence Handbook Kindle ebook. http://www.digital-evidence.expert.

Monday, 14 October 2013

Madeleine McCann and Cellphone Evidence

Mobile phone evidence is apparently highly significant in the re-examined case of Madeleine McCann, the three-year old who disappeared on 3 May 2007 while on holiday in Portugal’s Algarve and whose story has had an incredible hold on the UK media ever since. 

At the beginning of October 2013 the team of UK police set up and specially funded to re-investigate - Operation Grange - briefed the  press that mobile phone records appeared to provide a break-through.  I have no particular knowledge of the McCann story but various media outlets decided they wanted some brief technical explanations for their audiences. BBC Radio 4’s Today programme was first to contact me, closely followed by BBC’s Radio 5Live.  Once in New Broadcasting House I was whisked into the BBC NewsChannel studio and then asked to pre-record a clip for the main BBC1 News bulletins.  Later I did the same for ITN and Channel 5 News.  One clip was shown in the US on ABC’s Good Morning America. 

It is flattering (and to be honest, commercially useful in marketing terms) to be asked,  but radio and tv news while good at quick reporting is not good at detail.  The purpose of this posting is to set out the potential value of cellphone evidence but also its limitations.  As it happens, the McCann case provides rather a useful way of understanding these.

We are talking here of the communications data collected by mobile phone companies – it is also sometimes referred to as metadata – not what can be retrieved from a physical examination of a mobile phone and its SIM.

Potentially there are two sorts of evidence available – who was talking to whom, when and for how long; and location data – where a phone was at a particular time. Given that 94% of the UK population now have a mobile phone (and 49% use a mobile phone to access the Internet) and there are now 83 million mobile phone subscriptions for a population of 63.7 million it is easy to see why mobile phone evidence is so important in very many types of criminal investigation.  Pop into a sample of Crown Courts and look at the bundles of evidence and it won’t take you long before you will find exhibits of Call Data Records and maps of Cell Site Analysis.

Data Retention

It was for this reason that the police in 2000 or so started to demand laws requiring mobile phone companies to retain these classes of data.  Data Protection legislation treats call data and location records as personal data with the result that once a mobile phone company no longer has a business need for the data it should be destroyed.  The two business justifications for retaining the data are:  to settle bill disputes and to collect engineering information to improve the quality of the service.  Law enforcement lobbying to require the data to be held for much longer resulted in the EU Data Retention Directive of 2006.  The UK implementation occurred in the Data Retention (EC Directive) Regulations 2009.  The “communications” data is held for a year.  The mobile phone company yields information requested in the correct form and with appropriate detail  by a senior law enforcement officer under the Regulation of Investigatory Powers Act, 2000, Chapter 11.  The requesting officer has to justify using necessity and proportionality tests.


Available Records

Several types of record are available:

Call Data Record (CDR)   This refers to a single phone number and the calls in made and received over a given period.  It contains: number of  the counterparty's  phone;   whether call is in-coming or out-going; type of call (eg voice SMS, multi-media message)  time of call;  duration of call;   identity of SIM (IMSI), hardware identity of phone (IMEI),  identity of cell mast through which the call has taken place.   Although all CDRs contain this information, some mobile phone companies may have collected additional data.

Mobile Phone / Mast Registration Data    While it is switched on every mobile phone is monitoring the available signals and registering and re-registering itself to the mobile phone mast that is presenting as strongest.  As the phone moves with its owner across the landscape it will re-register.  The process is intrinsic to how mobile phones work – the system has to know to which mast to send a specific incoming call to the right phone.  The records are collected by mobile phone number, time and mast/cell site identity.   Levels of detail vary between different mobile phone companies.   In the UK these too are kept for a year.

Cell Dump  This record collects each phone number associated with a specific mast/cell site at a particular time.  It is also sometimes referred to as a “tower dump”.


Software Analysis

There are a variety of software aids to assist investigators:

Link Analysis is used on CDRs (and other communications data such as IP addresses and email headers) to indicate relationships between callers / participants.  The software shows frequencies of contact over time.  The results are usually rendered into graphics so that possible conspiracies can be identified, or a particular intensity of interaction at a particular time.

Cell Site Location Analysis  produces maps showing the movements of individuals, or rather their powered-up mobile phones,  as they move from one place to another.   Reasonably detailed maps of movements obviously require that the persons of interest are moving from one mast area to another.  The creation of the maps can require quite a bit of human input.  For example,  if movement is rapid it is a reasonable inference that some-one is travelling in a car or other vehicle and that this must be taking place on a proper road and not over fields or back-gardens.  At any given time a mobile phone may not necessarily be registered to the mast that is geographically closest.  That mast may be fully in use so that traffic is being handed over to an adjacent one;  phone signals can get attenuated through buildings or may be reflected off them;  there may be local anomalies of terrain – an unexpected open “path” to a more-distant mast.  

Cell Dumps by themselves don’t lend themselves to much further software analysis – they identify phone numbers present near a mast at a particular time.

Few of these techniques are used by themselves but are feeds into wider-based reconstruction of events,  other sources including statements from witnesses and, if available closed circuit tv.  In the UK a further source is data from Automatic Number Plate Recognition (ANPR) cameras which track and record movements of vehicle on major roads, data from which is kept for at least two years.

Limitations

The McCann case helps use see some of the limitations: What the Portuguese police collected in May 2007 was, I understand,  a cell dump.   It is not clear how much other cellphone data was collected then, subsequently or has been successfully acquired in the current new UK police investigation.  

Data is not kept indefinitely.  The EU Data Retention Directive was only just in force in 2007. 

All these records are of phone numbers (and SIMs and the handset hardware identities) not of individuals – for that you need what is known as “Subscriber Data”.  Subscriber Data is easy to obtain – provided you are dealing with events in which only one national jurisdiction is involved and all the individuals of interest are pay-monthly customers identifiable by the addresses they provided on sign-up and their banking information.  And, as with all the other data,  the police would have to ask for it within the “data retention” period of a year.  Obviously data subscriber requested outside that period may still be valid.  

But the Algarve is a tourist area and there are likely to have been many “foreign” mobile phones active.  British police will have had to contact many overseas mobile phone companies,  though almost certainly each application could not have taken place directly but would have had to go through a Mutual Legal Assistance or similar procedure.   If these requests were being made in 2011, 2012 and 2013 not  all subscriber data might have been available.

However this is for “pay monthly” subscriptions,  many are PAYG – Pay and You Go. In the UK approximately half of all mobile phone subscriptions are PAYG.    The numbers associated with PAYG SIMs which appear not be used / not topped-up are usually recycled to another, newer customer,  after 270 days.  It is not clear that old customer records are kept.     The PAYG phone and SIMs may have been bought for cash, in which case there will no means of identifying the subscriber.  If the purchase was by credit or debit card and/or if the subscriber registered to top-up online, they may then be identifiable.  But we are still left with the problem of how much information from 2007 was still valid and available by 2011, 2012 and 2013.  

The value of the location data depends on how many masts were serving the specific holiday area, Praia de Luz.  If there was just one mast in the area of interest then it may not be possible to draw a useful map.

Other Leads

There are obviously many other leads in the McCann case and some of the mobile phone data will undoubtedly help the complex reconstruction which has to be at the heart of the police investigation.  But things may not be as simple as hoping that such data unlocks the mystery of Madeline’s  disappearance.  Indeed one possibility is that her abductor, and we assume that such a person exists, may not have even have been a mobile phone user at the relevant time.  


The missingkids uk website currently lists 123 missing children; the oldest disappeared in December 1959 and would now be 70. 

Thursday, 10 October 2013

Oversight of GCHQ


“Stronger oversight” is the frequent reply to the concerns raised by the Snowden documents about NSA and GCHQ.  But in UK terms what would more rigorous scrutiny of GCHQ and for that matter, the other Agencies, actually look like?

I wrote a short piece for the Guardian’s Comment is Free but while that is a good platform to get attention, the 800-word limit isn’t enough for more complex nuanced arguments and background explanation.

Inevitably people approach these issues with certain assumptions; you need to know mine and also be able to assess the value of my commentary. 

Assumptions

While my long-term hopes for humankind include permanent world peace and universal honesty, the world in which I live is dominated by competitive, sometimes even aggressive, nation states and an increasing number of non-state global profit-seeking entities based on finance, the supply of ICT services and large-scale manufacture.  There are also many varieties of dishonest and corrupting persons.  That means, alas, the need for intelligence and law enforcement agencies.  In turn these need powers and resources – and much of the investigatory aspects of their work will have to be operationally covert.


As to my qualifications, apart from what you can read on my website,  I have never worked within the intelligence community but I have had many types of contact with various officers from the Agencies since the mid-1990s, largely as a result of my cyber security work.  Between 2003 and 2009 I was on a Panel on Emergency Response run by the then UK Government Chief Scientist during which there was frequent interaction with the Agencies and elements in the Cabinet Office.  I have acted as a Specialist Advisor to a Commons Select Committee and also frequently give evidence to such committees.  You will, I hope,  understand the relevance of all of these experiences later in this post. 


Lost Trust

Trust has been lost in the current mechanisms of oversight:  Interception and Intelligence Commissioners – too limited to simply testing compliance with the Regulation of Investigatory Powers and Intelligence Services Acts (RIPA and ISA);  elected warrant-signing senior politicians – unlikely to have the necessary background to ask the tough questions particularly in relation to the effects of changing technologies,    politically reluctant to challenge the spooks and not really democratically accountable to Parliament as much cannot be fully openly discussed;  the Intelligence and Security Committee (ISC)  - lacking in necessary knowledge and experience and woefully under-resourced to know the right questions. It is difficult to discern, from their published reports,  that they are testing the fundamental assumptions of Ministers and the Agencies about perceived threats and how strategically these are to be met.  There are few references to value-for-money in the various Agency activities.  Nor do they appear to be questioning the quality of the internal procedures of the Agencies.  And there is scant reference to judgements about the impact of changing technologies    

According to Chris Huhne, former Cabinet Minister, but more crucially also a member of the National Security Council, (on its website: “the main forum for collective discussion of the government’s objectives for national security”) he never knew about GCHQ’s Prism and Tempora programs.

Some react with outrage that there should be any issue of questioning the ethics and integrity of the intelligence community.  There are several responses.  First, the main remit of the Agencies is spying and they are assessed on the basis of the value of the “product” and associated assessments.   It is an impossibility that they can simultaneously be the sole arbiter in deciding how far they should go in an intrusion.  Second, however ethical and well-run they are it is inevitable that mistakes in operations and judgements will be made – and with them the temptation to suppress knowledge that they have occurred, if only in the mistaken belief that “trust” would be undermined if imperfections became public.  If we compare the Agencies with the police, who for the most part are believed to behave properly, nevertheless currently there are concerns about Hillsborough, South Wales Police, and undercover policing of demonstrators.  And if we also look at the regular Ministries – the Agencies are part of the civil service – we can also see many mistakes:  Department of Transport in costing the West Coast franchise,  Ministry of Defence with cost over-runs too numerous to mention, Department of Health’s mismanagement and prolonged concealment of the failures of the Connecting for Health system,   Home Office failures in processing immigration requests,  and managing the UK’s borders.  Why would we think that the Agencies are entirely free from these sorts of problems? You have only to read Peter Wright’s Spycatcher to see that in the not-too-distant past very strange views were allowed to feaster in MI5.   Wouldn’t stronger oversight reduce their likelihood or at least publicise them so that corrective action becomes possible?


No Perfect Solution

There is no perfect oversight solution – any new regime will still lack total transparency – and will involve individuals, almost certainly with high levels of security clearance, sitting in secret.


Some specific law reform may be desirable, even necessary - some tightening of  UK and EU Data Protection law and of RIPA and ISA but in this arena, as in many others, clarity in policy aims should precede formulation of wordings for laws.    After a while “law” gives way to “politics”. Even at their best, these laws are only OK for protecting domestic citizens but not foreign individuals, businesses and governments – discovered state spying results in letters of complaint and the expulsion of diplomats, not prosecution.  

In the end who wants to be going to the courts all the time?  The key bits of  RIPA and ISA, to do with Agency remit, will always require flexible interpretation.   Sturdy plausible oversight mechanisms are what are really required.


What are the aims of an oversight mechanism?

Before looking at specific points in the system where oversight can be introduced or developed, we need to think what we want it to do.  The element that appears to be already in place is scrutiny of specific routine operations.  It is the bigger issues that are not covered. 
First among these must be testing current views of “What is the threat?” as everything else, levels of intrusion and expenditure on resources and people, follow.  With fewer than 60 mainland deaths from domestic terrorism since 1989 compared with the 3201 who died in traffic accidents in the single year, 2005, when 52 people died in 7/7, questions must be asked whether terrorism is the persistent existential threat so often used to justify whole-population surveillance.  Or whether, in view of the low evidential requirements to secure prosecutions under the Terrorism Act 2006 – dissemination of terrorist materials, “encouragement”, providing training – there are really large numbers of foiled plots which never come to public attention.  Plainly the traditional diplomatic and military targets of espionage and counter-espionage persist along with their newer cyber variants.   

Next, there is the impact of changing technology.  Yes, one wants GCHQ  to “Master the Internet” but the range and extent of material now available for harvesting plus the ease of large-scale data mining changes the intrusion equation.  Is “you never know all this data might be useful someday” a good enough reason to initiate large schemes for mass collection?  Do we really think that intrusion only occurs when globally collected data is actually searched?  Yes, too there are circumstances when encryption must be broken, but, after Snowden’s revelations,  trust in e-commerce, e-banking and routine business confidentiality precautions, all reliant on crypto and all essential to the economy,  is under threat.     Who understands and tests GCHQ’s judgements on the balance of risk in these matters?

GCHQ cannot be considered apart from its ultra-close relationship with NSA.  But here too there are judgements which can go by the board.  The national interests of the UK and USA are not completely intertwined and there remains the concern that NSA can monitor UK citizens  and businesses as foreigners and pass the results to GCHQ who would otherwise be bound by RIPA – and vice versa.  Should the UK be using US-based cloud services?
Beyond that there is our relationship with other countries – the risks involved in being caught spying on them, or having covert agreements for the siting of Internet probes.
Finally, the public needs re-assurance against abuse.

Scope for improvements exist throughout and beyond the current oversight regime . The Justice and Security Act 2013 already gives some more powers to the ISC  while the Intelligence Services Commissioner’s remit  is extended to cover “any aspect of the functions” of an intelligence service and refers to the implementation or effectiveness of particular policies.



Oversight Agenda

In the agenda for debate set out below I have deliberately designed for some overlap of functions so that there are several semi-competing oversight functions which should act as a mutual check.



  • Government to publish annual fact-based national threat assessment rather than the current simplistic references to “moderate”, “substantial” and “severe”
The obvious originator of such a publication appears to be the National Security Council, which in so far as it is not doing so already could borrow ideas from the US National Intelligence Council, responsible for the US Estimates  At the moment the UK  Cabinet Offices publishes a National Risk Register of Civil Emergencies which deals with various threats, natural and deliberate.  It is the public version of a more extensive classified document, the National Risk Assesement.  Something similar,  with historic statistics of terrorism threats in particular would form the basis of public discussion of what counter-measures appeared to be necessary and proportionate.  As an alternative or additional author there is also the Joint Intelligence Committee (JIC) though this entity, once very important, may be being wound down.



  • Ministers to retain operational authorisation for Agency activities but warrants for interception, including the broad-based  s 8(4) RIPA “certificated” warrants to be passed for approval to a court; with short-term provision for retrospective warrant-granting in emergencies 
Although Ministers are, in practical terms, not immediately accountable to Parliament as there are nearly always reasons not to make public statements, in a democracy there is no alternative but to have elected individuals responsible for policy. But it seems a mistake to say those persons should necessarily also sign off on warrants. A separate entity, a judge or group of judges, should be tasked with deciding on the necessity and proportionality of specific acts of intrusion within the ministerial policy framework. Such an approach is an improvement on what we have, though there may still be circumstances in which a court over-favours the Agencies – see for example current concerns that the US FISC is misinterpreting the law




  • ISC to be a proper Select Committee of Commons and Lords with no pre-nomination by the Prime Minister and preferably with a robust Chair; to have extended semi-permanent staff including a privacy advocate and academic technical experts  not drawn from the intelligence community.   
At the moment the ISC is described as a “Committee of Parliament”, its members are Parliamentarians, members of the Commons and Lords. They are nominated by the Prime Minister in consultation with the Leader of the Opposition and then appointed by Parliament. It is not a Select Committee. The ISC’ s remit: “includes oversight of operational activity and the wider intelligence and security activities of Government. … Other than the three intelligence and security Agencies, the ISC examines the intelligence-related work of the Cabinet Office including: the Joint Intelligence Committee (JIC); the Assessments Staff; and the National Security Secretariat. The Committee also provides oversight of Defence Intelligence in the Ministry of Defence and the Office for Security and Counter-Terrorism in the Home Office.”

The problem with the ISC is not remit but resource and capability. Only two of the current nine members would have had any serious experience of dealing with the Intelligence community, none has much knowledge of changing surveillance and computer technologies. Regular Select Committees rely heavily on the advice of Specialist Advisors, usually recruited from academia to support specific inquiries. In the case of the ISC there is no need for all Specialist Advisors to see everything the Committee sees. Select Committees prefer to have sessions that are open but also frequently have meetings where the public are excluded.

A reformed and extended ISC should also cover the activities of Ministers – as do the departmental Select Committees. It should hold at least one public session a year with the heads of the Agencies and also key Ministers. Ministers as well as the Agencies to provide full candid information in secret sessions. Ministers hould lose their power of vetoing the appearance of Agency Staff before the ISC. All future Annual Reports to cover changing strategic objectives of Agencies, transparency, value for money, impact of technological change, and commentary on intrusion limitation.  The ISC should declare its budget and resources so that they can be seen to be adequate.  There should be powers to demand access without the current limitation of potential ministerial veto. And no-notice visits would also be useful.



  • Intelligence Service Commissioner’s remit to extend to reviewing the work of warrant-signing ministers (if that role is retained), to report annually on quality of internal audit within the Agencies, the impact of changing technological facilities and on Agencies’ role in intrusion limitation.  Proper permanent staff resourcing required.  Publication of detail about the types,  purpose and quantity of interception warrants. The Commissioner should declare the size of his budget and resources - so that adequacy can be judged.
  • Information Commissioner to have specific role to report on intrusion limitation policies of Agencies and comment on impact on Data Protection policy. 
  • GCHQ to review its internal audit facilities so that each intrusive search is recorded together with the justification/authorisation – this facility is essential for any proper external inspection
  • ISC,  Intelligence Services Commissioner and Heads of Agencies to adopt a more public profile, engaging in debate both fully in public and at Chatham House Rule-type events
  • Better protection for whistle-blowers from within the intelligence community - right of direct access to the ISC.
  • The Investigatory Powers Tribunal, currently the ultimate appeal mechanism, to be more transparent and to be made subject to judicial review of its work. 

Some of these are easier to achieve than others – a UK supervising court will need to learn the defects of the US’s FISC, for example.




Snowden’s documents provided detail and confirmation of what had long been suspected by anyone who had read the published books about NSA and GCHQ and then gone onto speculate what those organisations might now be seeking to  do.  Now that some of that detail is in the public domain GCHQ can, paradoxically, be more candid in discussing some of its activities and judgements.  And, rather than concentrating on Snowden’s “traitorous” nature, perhaps achieve greater public support and legitimacy, a view supported by David Omand, one its former Directors and Intelligence Co-ordinator and Stella Rimington, a former MI5 Director.