Gov't web monitoring plans unworkable, warns Linx

NEWS

Government proposals to monitor all web communications are technologically unworkable, according to the organisation that switches the majority of web traffic for the UK.

The London Internet Exchange (Linx), which counts ISPs among its 330-plus internet partners, on Tuesday severely criticised the government's plans, known as the Interception Modernisation Programme (IMP).

The dynamic nature of web protocols would make the interception of web traffic for the entirety of the UK impractical, Linx's head of public affairs, Malcolm Hutty, told ZDNet UK.

"Web-based protocols can change without notice," Hutty said. He added that while some protocols, such as email, are relatively stable, others are proprietary, change frequently, and are complex.

"It will often be extremely difficult to reverse-engineer web protocols," he said. "Almost every website is a sophisticated communications application."

Under the IMP, the government would require communications service providers (CSPs) to log all the websites people visit. That proposal is also unworkable, due to the scale of the task, said Hutty. While it is relatively trivial to reverse-engineer web-communications in order to pinpoint a single website that one individual has visited, monitoring the browsing habits of an entire country is a different matter, he noted.

Hutty also said that government plans to have communications service providers (CSPs) cross-reference all communications data will not work.

The government wants CSPs to store details of all communications, including voice, text, VoIP, instant messaging and email. This data would then be linked together to build a map of who is communicating with whom, then presented in a form accessible to law enforcement. However, the technological complexity of such a scheme makes it impractical, said Hutty.

"Linking that data implies a lot of data-mining," said Hutty. "To have the advance capability of calling up a profile is a big ask."

Hutty said that under the current data-retention directive, CSPs are required to store a limited number of details about communications, which can be made available to law enforcement upon request. However, he said that many CSPs have struggled to provide even this limited amount of information in one format, as each of their systems is different.

"The main telcos have found it difficult to standardise the format [of data] to hand over to law enforcement," said Hutty. "The level of complexity of standardising the format in linking [data as proposed under IMP] is orders of magnitude more difficult than under current data-retention law."

Hutty noted that the government does not know how much interception data is being collected and used by the public sector at present.

"The Home Office is not able to collect detailed information [about data use] under the existing regime," said Hutty. "The scale of access to communications data as a whole is not something the Home Office knows. They don't have a system of auditing across the board."

The government launched a consultation document outlining the IMP in April. Linx on Monday publicised its response to the consultation, lambasting the project. The organisation said CSPs would suffer "unreasonable" costs in a project that would intrude on people's privacy.

'Unprecedented' level of intrusion
"The volume of data the government now proposes CSPs should collect and retain will be unprecedented, as is the overall level of intrusion into the privacy of the citizenry," said the Linx response.

The government is also unclear about what it wants to achieve, Linx said.

"We do not believe sufficient information has been given to say with confidence whether we will support or oppose the government approach [to IMP]," Linx said in the document. "Following discussions with officials, we do not even have confidence that 'a government approach' even exists — it appears that even the basic conceptualisation of the Interception Modernisation Programme is in flux."

The Information Commissioner's Office (ICO) also expressed concerns about the scheme.

"The ICO recognises the value that communications data has for the prevention and detection of crime and the prosecution of offenders," the data watchdog said in a statement on Tuesday. "However, this in itself is not a sufficient justification for mandating the collection of all possible communications data on all subscribers by all communication service providers."

The Home Office on Tuesday declined to comment on the Linx and ICO criticisms of IMP. However, a Home Office spokesperson said that all responses to the consultation, which closed on 20 July, were in the process of being collated. The Home Office summary of the responses will then be published, said the spokesperson, who declined to give a timescale.

Experts from the London School of Economics criticised the IMP on technological grounds in June.

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

8 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

10 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

10 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

12 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

12 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

13 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

13 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

14 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

15 hours ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

16 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

16 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

17 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

17 hours ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

cybfor

US gov t considers undercover social networking: [zdnet.co.uk] The Obama administration has considered sending... http://dlvr.it/Kh3L

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now