Speaker A: Hello and welcome to the Password Radio Show on Resonance 104.4 FM with me, Peter Warren. In today’s show, we look at how our real world is being drawn inexorably into the new digital world of the internet, how NATO is now saying that there will be no-go zones in cyberspace, and the new digital markets that Brexit is locking us out of, and how the EU is just like Hotel California. You can check out anytime you want, but you can never leave. A point reinforced by the news that the EU has just signed the US up to its digital shield legislation that we are likely to also have to comply with. We also look into the technology that is being used to monitor traffic over the web to help the police and intelligence communities and the computer networks. And finally, Pokémon Go. The start of a new trend that will see the games that we play involving more than sitting on a couch. Computer games are getting active. But first, last month NATO announced that it was going to enforce borders in cyberspace. Oddly, 20 years ago Commodore Patrick Tyrrell recommended this to the MOD. We talked to him about why he saw the need then and why it is being done now. And about discussions that are taking place in London at the Royal United Services Institute about the need to stop an arms race in space that is seeing satellites potentially fighting each other with grappling arms, missiles, and electromagnetic pulses.
Speaker B: I was exposed to it initially in the 1990s when it was quite clear that information technology was developing at an ever-increasing pace. This meant that it was going to be easier to deal with large quantities of data. We were getting the early hackers and the hackers conferences coming in. One or two people were writing stories about attacks on infrastructure systems. And so I became interested and looked at it from the perspective of how would a country defend itself from a cyberattack. And when I produced the report, there was a considerable body of people who thought, yes, this is clearly the way we’re going, particularly amongst information technologists. There were one or two of the very famous ones, you know, Toffler and Schwartau. These are all people who were saying this is going to happen one day. So it wasn’t as though I was the one with the original ideas. I was building on work being done by others.
Speaker D: What is a cyber board?
Speaker B: Well, that’s the difficult point because there is no frontier for a cyber attack. And indeed, some of the cyber attacks that we’ve had, that we’ve experienced over the past few years— there was one in Estonia It’s very difficult when you have an attack to know exactly who is attacking you because they use, they camouflage their tracks if you like. They come in through other people’s computer servers. They make sure that you don’t know who is directing it. Although we are now getting very much better at being able to look at the fingerprints, that electronic fingerprint of an attack, so they actually know where the thing has originated from.
Speaker D: We are now so dependent on technology that we will say that there are places that— or systems that cannot, cannot be attacked. Is that something that you agreed with? I think the report that you presented said that elements of the economy would be considered to be no-go zones, like banks for example.
Speaker B: Well, yes, I mean I think that each government will decide what its strategic priorities are.
Speaker D: Which is one of the issues, isn’t it? Because a lot of people have pointed out that in both the American and the Chinese new war doctrine that cyber is a large component of that and knowing whether somebody whether somebody’s on a fishing trip or whether they’re actually beginning to launch a war is going to be a very, very difficult exercise.
Speaker C: It is, it is.
Speaker B: I mean, these are going to be the new problems that we are going to have to develop, you know, the necessary procedures and reactions. In the Cold War, we knew exactly what we were going to do if if the Soviet armies went across the inner German border. You know, we were trained to do that. Now we are going to have to train people who are going to look at what happens if cyber war starts to happen and is targeted against things that are affect the way we can conduct our defence. So for example, if you had a highly targeted cyber attack against NATO’s logistic chain, that might be considered a precursor to actual military operations. Anything that links in with the information infrastructure is going to be a target, and, um, and anything else can be used as a weapon. So we’re going to have to change our way of looking at things.
Speaker D: It’s an interesting point, isn’t it? Because, you know, in terms of the future, people would actually think that, uh, conflicts between, um, spacecraft are far-fetched and that’s the stuff of sci-fi. Yet oddly, today we find that there is a conference going on at the Royal United Services Institute, an organization set up by Duke of Wellington, actually. And one of the things that they’re looking at is satellites attacking each other and attacks on satellites.
Speaker B: Absolutely. Satellites are so integral to our, in our basic lifestyles. These days. When we, you know, don’t know where we’re going, we automatically look at the sat nav and we let it guide us. If you’re looking at aircraft flying across the globe, they’re using global positioning. If war is a disruption of individuals’ lives so that one nation can obtain something it wouldn’t otherwise obtain. These are all targets.
Speaker A: That was Commodore Patrick Tyrrell on cyberspace, the new frontier. Now, other frontiers have been foisted on us by the Brexit debate, most notably the barriers that will prevent us accessing the €415 million a year single digital market. Ironically, it would appear that despite leaving the EU, we will still have to abide by European laws if we want to take advantage of the big data opportunities of people who are very similar to us. I asked Natalie Marinho of the lawyers Lewis Silkin on why leaving might only be a form of words, and more importantly, about the elephant in the room, the Data Regulation and Investigatory Powers Act, that could mean that our intelligence agencies could lock us out of Europe.
Speaker D: Where on earth is the UK left if it passes DRIPA and it is outside of the EU? Because the DRIPA legislation allows bulk collection of data, yet that wouldn’t actually mean that we meet the adequacy requirements.
Speaker E: There’s been a lot of debate that not where part of the EU, that the UK will meet the adequacy requirement. But as I mentioned, it’s not something that I am— I think is ultimately will not be the case. It’s just any type of negotiation process takes time, and what will happen between the time where the Commission grants that adequacy decision to the UK will create so much uncertainty and flux that it cannot be productive for the UK economy. So, and also the fact that there is no reason for the EU to make it easy for the UK to grant that decision.
Speaker D: Would the EU be that commercially? Would it, would it, would it, some people have suggested that that wouldn’t be in the EU’s interest, that just because the UK had pulled out that they wouldn’t be vindictive. What do you think?
Speaker E: I think based on, it’s difficult to say because obviously the UK government will have to put in place national law, which I suspect will be as close as possible to the current Data Protection Act. Based on that, it’s true that the current Data Protection Act does not meet the requirements of the GDPR, of the new General Data Protection Regulation. So we’re talking 2 years down the line because the UK will not have been out of the EU before 2018, which is also the time when the GDPR will become effective and applicable directly. So I think what will happen is if the UK government is reasonable and is prepared to put into place a UK Data Protection Act which is as close as possible to the— then I don’t think there would be any impediments. To the UK having— benefiting from an adequacy decision. Now, if for some reason they believe, and it’s possible, that the GDPR, for instance, is putting in place fines which are too high, or they’re not happy with the fact that companies will need to put in place data protection officers in certain cases, or they’re not happy to implement the right to be forgotten, et cetera, then that might delay negotiations. And beyond that, it’s difficult to know what— how long it could take. But it’s the closest, basically, the UK will mirror the legislation enforced in the EU, the easiest it will be for the UK to have— to facilitate the trading, the trade between the two blocks.
Speaker D: Which does make it seem a little silly, doesn’t it? It seems odd. You say we want to pull out of this organization because we don’t like them telling us what to do, but by the way, we’re going to do what they’re telling us to anyway.
Speaker E: It is senseless for lawyers to consider what’s happening. Yes. So obviously it’s not from a legal regulatory point of view that the exit of the UK would make sense. It has to be looked into other reasons, but certainly not from the respect of law economic interest of the countries. Like I mentioned earlier, I think that the reasons and motivations are rooted somewhere else.
Speaker A: Natalie Marinho of Lewis Silkin. Now here’s another lawyer, Sarah Thompson of London law firm McGuire Woods, on the Digital Shield, the EU law that the US has had to comply with to use EU citizens’ data. Ironically, not only will we have to adopt the EU’s law, but she tells us we’ll have to develop another one, possibly similar to the Digital Shield, to work with the US.
Speaker F: So the Privacy Shield is effectively a new agreement that’s been reached between the US and the EU, and it effectively legalises the transfer of personal data from the EU to US companies that have signed up to the framework.
Speaker D: Okay, so what is the point of the exercise?
Speaker F: In October last year, the European Court had a hearing which basically invalidated a framework called the Safe Harbor framework, which was put in place to legalize the transfer of personal data from the EU to US companies. And in light of that decision, the US and the EU governments have negotiated over the past few months to put in place a replacement framework, which has been formally approved today, which is obviously termed the EU-US Privacy Shield.
Speaker D: Okay, and they’re doing that why? Because why are they after data from, say, the EU? What’s the value of that? Surely they’re just our names and addresses, and what do they want?
Speaker F: We have a fundamental right to privacy in the EU, so each European citizen has a fundamental right to their personal data. So be it their names, be it their email addresses, be it their telephone numbers, they have a right to protect that data. And we have laws in place in the EU that ensures that our data is protected. So the purpose of the Privacy Shield is to effectively allow the transfer of data between companies, and so from the EU to US companies that sign up to the framework, to ensure effectively that those companies that have signed up to to the framework put in place adequate protections. So effectively, they, they agree to adhere to the standards of EU data protection laws.
Speaker D: I see. And obviously the reason that everybody wants to do this is because they want to take advantage of these huge markets in data that are beginning to emerge. So that it’s not just knowing who I am for the purposes of going onto a website, it’s also knowing what I’ve bought and perhaps what socioeconomic group I come from so that they can extract some value from Yeah, absolutely.
Speaker F: I mean, as you say, the, you know, the big data is such a lucrative market nowadays. It’s to be able to target individuals and to be able to, you know, advertise goods and services to them on a large scale.
Speaker D: And to understand that, I mean, the market is allegedly worth €415 billion. I mean, that’s in the EU alone. It’s quite a massive market. Do you think that this will work? I mean, as you mentioned, that Maximilian Schrems, the Austrian, knocked down the Safe Harbor agreement agreement, and he did that because he said that it wasn’t protecting his data. Don’t you think that some other privacy expert will rise up and try to attack this one just for the sheer hell of it?
Speaker F: Yeah, I mean, I do. I mean, no doubt this will come before the European courts, and it’s just a matter of time before the privacy activists challenge the Privacy Shield. You know, you’ve got to remember that this has been born out of the Safe Harbor invalidation, and it does put in place stronger obligations on US companies. So I do think as and when this comes before the European courts, it hopefully will stand up to scrutiny.
Speaker C: Now, is there—
Speaker D: I mean, obviously post-Brexit, we’re going to be in the position at some point of actually needing a privacy shield of our own, aren’t we?
Speaker F: Yeah, absolutely. And it’s all going to depend on the relationship that the UK has with the EU following Brexit. But the likelihood is that we will need our own equivalent privacy shield in place. You know, that will run in parallel to the European Privacy Shield.
Speaker D: And we’ll need one with the US too?
Speaker F: Yes, exactly.
Speaker D: So we will have a— well, not a privacy— something that actually looks like the General Data Protection Regulations, and then we’ll have negotiated something different but perhaps similar with the US?
Speaker F: Yes, absolutely. I mean, in terms of anything between the UK and the EU, I said it’s all going to depend on whether we remain within the EEA and how the relations relationship, or, you know, will look following Brexit and whether or not the UK would be deemed adequate by the European Commission. But if it’s not, we’re going to need some form of mechanism in place to effectively allow the transfers to take place between the UK and the EU.
Speaker A: Sarah Thompson from law firm Maguire Woods on the digital shield. Ever wondered how such things will be enforced? How on earth do you know what is travelling where? The answer is technologies like deep packet inspection. A packet is a little container of data that holds information like what you were doing, who you are, etc., etc. Your conversations on the web are made up of these, and they form little trains so the networks know what you want to do, like watch a film, and verify that is what you were doing so they can fine-tune your experience. But they can also tell other people what you’re doing. Here’s Cam Cullen of Procera, a deep packet inspection company that helps networks and the authorities monitor traffic on a technology that has drawn some suspicion on why it’s needed on the fact that post-Snowden everyone is now encrypting data.
Speaker C: An estimate would be actually anywhere from 50 to 80% of the traffic is encrypted on the internet now depending on, you know, what the application is and maybe what part of the world you’re in. We actually did a— I did a study about 6 months after the Snowden revelations, and we saw encrypted traffic jump from maybe 5 to 10% in the US to almost 40%. And then the mobile network in Russia, believe it or not, the ratio was like 70% even 3 to 4 years ago.
Speaker D: So it was 40% in America 3 to 4 years ago. It jumped to that in Russia.
Speaker A: Yeah.
Speaker C: And now it’s more like 70 to 80% in most of the networks. And there’s a couple reasons for that. Is that all video traffic from Netflix and from YouTube is encrypted, and that alone is anywhere from 50% to 60% of the overall traffic. Applications, Facebook, Twitter, all the social networks all moved to encryption. So the vast majority of what consumers do on networks today is encrypted. So that really makes up the majority. There are things like Some of the IoT devices aren’t fully encrypted yet, and some email systems and such are not fully encrypted end-to-end when they’re sending. So there are still applications or websites that are not encrypted, but within the next 2 years, we expect that number to probably be 95% of traffic is encrypted end-to-end.
Speaker D: One of the points in the DRIPA legislation is that the police— and I know this because I went along to see the National Crime Agency 2 or 3 weeks ago— They’re saying they want metadata. They need it to be able to carry on their war against terrorism, their war against crime, their war against pedophilia. Doesn’t this encryption mean that they won’t be able to do that?
Speaker C: Well, so what it means is the level of metadata that you have access to has changed. So as I mentioned, in the past when traffic wasn’t encrypted, I could actually tell you which— not just which website you’re going to, but actually which page. So I could look in and see you’re watching YouTube video for Gangnam Style on YouTube. I could be very much specific about all of the high-level information on a particular subscriber. Now what I’ll get is that Party A is talking to Party B, and that’s really the level, and they’re using this application. That’s all I can do. What it means is that other intelligence mechanisms will need to be used to get the detail that they want, whether that’s human intelligence or basically big data analytics to kind of combine the conversations you’re seeing with other patterns that may be happening for a particular person that they’re surveilling. So they can still get metadata, but the amount of metadata they can collect goes down dramatically as traffic is encrypted. To be fair, it’s not that they can’t see anything. They just can’t see the same level of data that they could in previous times.
Speaker D: So then essentially when the police say that they want metadata, then they’re not really foiled by encryption because the police officers who were presenting to us were saying, “We want this metadata. We just want to know what sites people were going to and, you know, how long they were there.” And you can still get some level of information with solutions that, you know, like RSA would deploy. That.
Speaker C: But what it couldn’t tell you is that everyone from this terrorist group, for example, went to this page on that site. You could have a large site that has maybe just one little page that’s doing something bad. And in the past, we could identify which page that was. Now we can just tell you they went to that site, and you have to use other solutions or systems to figure out maybe what specifically they’re looking at on that particular site.
Speaker A: That was Cam Cullen of Pressera. Now, love it or loathe it, Pokémon has suddenly risen up again as the must-play game of choice for those who game. Pokémon Go, an interactive version of the console game that involved training little creatures to fight on your behalf, has come up with the idea of making the old game locational. You have to get up off your couch and go out into the real world and find your creature now. And go to a particular map location. We tracked down David Wortley, an expert on computer games for the Gamification and Enabling Technologies Strategic Solutions Company, to a campsite with poor phone reception in Provence and asked him about what was behind Pokémon Go.
Speaker G: It’s really not a new concept. Locational gaming, you could argue, in a manual form has been around been with us for years with things like car treasure hunts, which are designed to encourage people to socialize and discover things together. So yeah, it’s— geocaching is a very similar facility, but of course now as our technologies have matured, GPS capability and the amount of content that’s available available on the web today, as far as creating visual imagery of physical places. All of these things have sort of combined to make it possible that you can have a reliable detection of where you are, and you can overlay on top of that virtual characters like Pokémon.
Speaker A: I suppose there’s another point here though, too, isn’t there? This has quite a lot of value because you know where particular people are. You could sell that information, for example, to people who were selling pizzas or, or fast food so that they would know that at certain times people were around and then they could basically take advantage of that.
Speaker G: Yeah, well, yeah, again, that is not new. Uh, I mean, many years ago, uh, We were involved at the Serious Games Institute in a project called Stratford Unplugged, and the idea behind that was that people would take a mobile device and use augmented reality in Stratford-on-Avon to be able to interact with Shakespeare-related virtual characters, and that would also lend the opportunity to prompt you when you were near a restaurant, say, where you could get a good deal with a local meal. I think this is something which is intended to go a little bit beyond that, because the level of gaming, as I understand it anyway, because it’s not available in the UK, is a little bit more sophisticated. So you’ve not only got to find these virtual characters, you’ve also got to train them to fight.— and that’s a new level.
Speaker A: Right. You’re an expert on gamification. Is this another element of gamification? Is this another way of actually getting people engaged and creating some sort of stickiness for them with either a game or with web pages or things like that?
Speaker G: Yeah, I think it is very much— it uses gamification. Principles and practices. They’re using the experiential part of Pokémon GO to give people something of extra value beyond being in a physical place. They will also link that to rewards and incentives. So it’s bringing together a number of gamification principles, and I don’t think you can lose sight of the the commercial potential of this, because one of the, I think, the real values or important points about gamification is about creating win-win scenarios so that you can bring a number of people together with different agendas. So you talk about retailers, they will want to be selling stuff to people who are nearby. You’re talking about making social connections between people. I know there’s been connections between Pokémon Go and Tinder and dating apps and similar kind of apps which are based on letting you know where there is somebody you might be interested in nearby. So I think they’re trying to bring all of these things together. I know it’s added a huge amount of value onto the share price. What that’s based on largely is a notion that this is something that’s going to be a phenomenon that will last for a reasonable amount of time and will bring together a good number of people with common interests. I’d be interested to see whether that actually works out in practice.
Speaker A: David Wortley on why Pokémon Go is now valued at $1 billion. You’re listening to Password on Resonance FM with me, Peter Warren. And if you’ve just joined us, you’ve missed it and will have to tune in again next week or find us on Mixcloud. Password is brought to you by Future Intelligence and the Cybersecurity Research Institute. And if you want to know more about the issues we’ve been talking about, go to our relaunched website at www.futureintelligence.co.uk. And www.csri.info. Thanks for listening and goodbye.
