Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.
Speaker B: Hello and welcome to Password on Resonance 104.4 FM, the technology program that plugs you into the issues in our high-tech world. This week, MPs debated the controversial Data Retention and Investigatory Powers Act. And last week, we told you how this could affect your lives because of incredible advances in technology that mean that incredibly intelligent and incredibly fast computer systems could be used to keep us in a semi-permanent state of surveillance. If you want to hear more about this fusion of quantum computers and artificial intelligence and how it could be used to look for patterns of abnormal behaviour on the internet, and using the Internet of Things on the high street, then log on to Mixcloud and search for the password programme of the 9th of March 2016. Now, under the DRIPA legislation, the government is allowed to store the data on the websites we have visited for over a year, and the police are allowed to hack into computers that form part of their investigations. But everything has to be done with the written permission of the Home Secretary and of a judge. In this week’s programme, we let the police and the intelligence agencies put their side of things and say why they want this. This is not about surveillance at all, they say. This is about coming to terms with the information age and keeping everyone safe. We speak to the head of the communications group on the National Police Chiefs’ Council on why the police want to have the DRIPA legislation. And to the former head of GCHQ about why we need it to prevent outrages like the Bataclan massacre in Paris. We also speak to an intelligence expert on what the developments in technology mean for the intelligence agencies and the insight that they offer. We also talk to the former head of the Met Police’s Computer Crime Unit on why we should start dropping the word cyber from our vocabulary, because technology is now embedded in our lives. In a world where everyone is hoarding data, including the criminals, it’s stupid to try to stop the police from doing the same. Now, in introducing the DRIPA legislation, Theresa May said that now some 85% of police investigations have a computer component. Here’s Richard Berry the Assistant Chief Constable of Gloucestershire and the National Policing Lead for Communications Data to tell us why the police need to have our internet data stored for over a year.
Speaker C: First thing to clear up, Peter, is that there are two pieces of legislation concerned here. DRIPA is the Data Retention Investigatory Powers Act, which was emergency legislation brought in as a result of a European Court ruling last year, and that’s around the legal basis for requiring organisations, communication service providers to retain data. In terms of the new legislation, that’s called the Investigatory Powers Bill. That essentially is bringing capabilities for law enforcement and the intelligence agencies into the internet age. In terms of police requirements, we have essentially 5 requirements. The first one is through investigations to link an individual, a person, to an account or an action. To establish a person’s whereabouts, so for example, a considerable percentage of our work is around tracing vulnerable suicidal missing persons. We need to establish their locations. The third purpose is to establish how suspects or victims are communicating, particularly pertinent, for example, in domestic abuse, stalking, that kind of scenario, as well as at extremes in homicide situations. The fourth purpose is to observe online criminality, and the fifth purpose is to exploit data to corroborate evidence and to identify further investigative leads, both during the initial investigation but also at the court stages, which could be perhaps 12 months later.
Speaker B: Okay, so what are the problems that you’re now facing that will be solved by this legislation? Some people will say that for some of those things they weren’t there before the internet or the mobile phone age.
Speaker C: Yeah, absolutely. So essentially, this is all brought about by internet-based communications. Can give an example. In 2008, I ran a national operation against human trafficking, and 80%— sorry, 85% of the actionable information— and these are about people involved in organized trafficking of women and children for the UK sex markets— 85% of the actionable intelligence and information came from communications data that was very much on the old GSM networks and not using internet-based communications. I couldn’t actually repeat that operation now because the technology has changed. IP-related communications, the use of apps and third-party providers across UK networks has proliferated. It’s driven by customer demand and we literally just need to bring those capabilities back up to date because of the technology driver.
Speaker B: Okay. One of the charges that’s been very frequently leveled against this legislation is that it will create a large pool of data that law and order officers will be able to trawl through and that they’ll be looking for data patterns. Is that— can that happen?
Speaker C: I would certainly say not. I think it’s really, really important at this point in time to draw a differentiation between the work of the intelligence agencies who deal in bulk data and law enforcement who are only permitted in this provisional legislation to conduct what we call targeted inquiries. So we need to build a case around conducting a particular inquiry around a particular individual or a particular organized crime group and only specifically draw back data which isn’t in a big pot. It’s distributed around the communication service providers in the UK, but to draw specific data back in relation in relation to that very targeted inquiry. The idea that we could go on fishing trips and obtain lots of data from lots of pots and conduct those kinds of inquiries just simply— we wouldn’t have the powers in this legislation.
Speaker B: Well, I mean, that’s an interesting point, isn’t it? Because it’s interesting that you’ve answered that in that way, because what you’ve said is that the— and I listened to the debate yesterday. What you’ve said is that the police will actually have to say what data they want, whereas there doesn’t seem to have been similar controls on, say, GCHQ, for example. So what you’re saying is the police have to target their searches.
Speaker C: Yes, absolutely. I mean, there are lots of additional protections in the draft legislation. So we have a role we call a single point of contact, a trained person, an experienced person who can advise investigators. Investigators the best way of going about obtaining a piece of information. And in fact, today I’m at a conference this morning, and we are launching a whole range of measures to ensure that these people, to tie in with this new legislation, are tested, accredited, and if you could use the term, have a license to operate.
Speaker B: That was Assistant Chief Constable Richard Berry. The National Police Chiefs’ Council’s lead on communications data. Now, as we heard, the activities of the police are going to be very closely monitored, and there is a crime included in the bill for the misuse of data, which is aimed at keeping them in line. It’s one of the sticking points in the bill and one of the reasons cited by the Labour Party for its abstaining from voting for the bill in the House of Commons. As we’ve heard from Richard Berry, while the police’s activities are tightly controlled, GCHQ would appear to have a lot more freedom. Here’s Sir David Oman, the former head of the listening agency, talking to Password ahead of a debate on Security LSE in 2014. He says why GCHQ needs to have the legislation.
Speaker A: It’s the job of the security and intelligence agencies and the police to try and keep us safe. They’re doing the right things. They are finding it increasingly hard for reasons, you know, which I think you know, but which we can discuss. But they are doing the right things. I don’t see any need for any dramatic shift in what they’re doing. But as has been pointed out many times, there are a significant number of people who mean us harm, and uncovering who they are, and which of, for example, the returnees from Syria and Iraq want to settle back down into a normal life, and which want to continue their struggle, and violent struggle, is a very difficult exercise in security. The problem that’s come up is that As more and more communications travel across the internet—Skype, iChat, those sort of applications—it is harder and harder for the authorities to know who is communicating with whom. They can do that with more traditional telephone calls, and they have the legal authority to do that. The companies retain the data of who called whom for telephone calls, perfectly legally, and that can be accessed so that suspects can be investigated. But that’s not available for the more advanced internet-based communications because the companies have no need of their own to retain the data. And the big argument there’s been over the last year is should Parliament legislate to make that a requirement for those providing that service in the UK, and if so, what are the safeguards?
Speaker B: Okay, I mean, we interviewed the former head of legal affairs for GCHQ, Michael Drury, and Michael Drury was saying that really basically the need is for the legislation to essentially come to terms with the internet age. Is that what you’re saying? Is that because there are these logs that aren’t available or logs that aren’t kept, that really the logs that were kept in the old telephone age now need to be kept in the internet age? That’s the argument.
Speaker A: I’m very sympathetic to that argument. There have to be safeguards. You wouldn’t want that kind of information retained for for too long, just in case it comes in handy in some future era. So you would want very careful legal constraints on it, but something has to be done to help the police and the security authorities in that space.
Speaker B: One of the points that Mr. Huppert made, he was saying currently what was happening in these searches for people is that you’re looking for a needle in the haystack, and the solution seems to be that the intelligence agencies are asking for is to pour in more hay.
Speaker A: I mean, that’s a rather glib soundbite, but when you think about it, what actually they’re saying is we want the right haystack, and at the moment there are several haystacks they can’t even approach because the hay is not accessible. So it’s not that they want more hay. They certainly need and want better magnets to pull out the needles. And the key to this is not in the amount of hay, it’s in the nature of the discriminator. In other words, how do you program the computer to pull out what is warranted to be pulled out, the communications or the data on the suspect and not everything else. And that is the question they should be asking, not about hay, it’s about the quality of the magnet. Now Snowden has revealed some quite clever ways in which they are doing that, which is fine, but I’m sure the agencies would like to improve their ability to be discriminating because this is the other point. That has lost sight of, but the Charlie Hebdo attacks have kind of reinforced, which is that there is a real threat out there, but there aren’t that many people to address it. We don’t want a police state. We don’t want very, very large intelligence agencies. So those who are there need to focus on the real threats. They are not interested in you or they are going to be going after the people who’ve been in contact with known terrorists. So they just simply wouldn’t have the time, even if it was legal for them to do this, which it isn’t, or they were so disposed, which clearly they’re not. As the director of GCHQ said, the last one, his staff would walk out if you asked them to conduct the kind of mass surveillance which gets towards talked about. So I’ve got confidence in that. But a final thought on that, which is that this debate is not about the tools that these agents— that’s what you need to keep even reasonably safe in today’s world. The real debate is about oversight. It’s about how can we have confidence that even under a future government, and who knows in the long term, a future government, could they misuse this system? And that’s where you want Parliament to be building in some strong constraints, law, and the right kind of oversight mechanisms. And I’m all for kind of examining that and seeing improvements, but don’t deprive them of the tools they need. Otherwise, we’ll discover that not only domestically but internationally, the world becomes a rather more dangerous place.
Speaker B: Sir David Oman, the former head of GCHQ, on why we need better magnets to find the criminal needles in the massive haystacks of data. Now, Commodore Patrick Tyrrell, the government’s first advisor on cybersecurity issues and a former senior naval intelligence officer with intimate knowledge on the workings of GCHQ, tells us just what sort of magnets that the intelligence agencies want to make out of the technology that is coming and what this will mean to the public. Some 60% of people say that they are in favor of surveillance so long as it keeps them safe. And Commodore Tyrrell says that that is the point.
Speaker D: Well, we live in a world where one of the big threats is terrorist and small terrorist operations. People who have not come on the radar before, who decide that they want to do something that is threatening members of the public. Now, what the security services want to be able to do is to be able to look at who is potentially liable to do bad things. And I think it can only be in the interests of the public that we reduce the number of car bombs in London or bombs on the Tube or whatever it might be, shooting on Tunisian beaches. So that’s why they want it.
Speaker B: So they’re essentially after the people like those people in the San Bernardino case that is so sort of controversial at the moment. Because of the FBI and Apple, who weren’t on the radar before, like the guy at the Boston Marathon, you know, neither of whom were known to the authorities. It’s those people that you really want to try to stop.
Speaker D: Well, you certainly want to stop them. And if, if they are completely unknown and, and are acting and are not showing any of the initial things, perhaps what you want to do post-analysis is be able to have a look and say, ah, there is a common denominator here. They’ve both been watching certain videos on the internet that have radicalized them, or whatever it may be. Because it’s only by looking at this very big data and looking at it very quickly that we can remain ahead of the curve, that we can actually preempt some of these things happening. I have to say, there are a large number of families who lost people in Paris or lost people in Tunisia who would be saying, yes, that’s what we ought to do.
Speaker B: Right. So in that case then, but to do that and to use the big data in the way that you’re talking about, As we heard in the last program that we made about this, what you have to do is go through your, your big data pool and find those patterns of activity that seem to indicate that somebody may be about to embark on this sort of terrorism or, or a crime, because it’s not necessarily just terrorism. But isn’t that then, in a sense, You’re putting everybody under suspicion to be able to get that information.
Speaker D: Well, I mean, I think to a limited extent. I mean, it very quickly becomes— having done an analysis of one event, you start to target particular activities that may give you a good indication of other events, which allows you to be slightly more proactive. And then it’s an iterative process. And I think that if you look at the British population, which is extremely well-versed in common sense, they accept that there is a certain level of surveillance that is going to be in their interest.
Speaker B: Okay, now how about another, another point then? One of the things that the Prime Minister’s been very, very keen to try to head off is websites or social media sites that radicalize young people and send them off to Syria or to get involved in incidents like the Backland Massacre. But surely people are allowed to actually go onto websites to find information about religion and things things like that, aren’t you in a sense trying to change social behavior? Isn’t this one of the things that will happen as a result of this? Because people will become aware that they are being monitored and that will stop a certain amount of curiosity.
Speaker D: Well, I think that if you look at all the websites in all the world and then look at the websites that are, let’s just call them extremely antisocial, so it’s the websites that are extolling sexual perversion, radicalization, jihadism, whatever it might be.
Speaker B: Yeah, and not just, not just for Muslims. I mean, there’s far-right sites, there’s far-left sites, lots and lots of unpleasant stuff.
Speaker D: People who tend to go into those sites and go into them a number of times have in the main got criminal tendons. They go into radical jihadist sites to watch prisoners having their heads cut off with a view to believing this the way ahead. You know, this is something to be encouraged and enjoyed, just like certain people go on to extreme pornographic sites because they want to view pedophile imagery. Now, I don’t have a difficulty, and I think most of the British people would have no difficulty, with those sites being taken down.
Speaker B: Commodore Patrick Tyrrell on why the intelligence agencies want to be able to access our data. Something that many are very relaxed about. In a recent One poll survey, 42% said they did not care. Oddly, according to Charlie McMurdy, the former head of the Met Police’s Computer Crime Unit, who is now an advisor on data security at the accountants PricewaterhouseCoopers, they’re wrong. Charlie McMurdy says that it is essential that the public wake up to where their data is and start looking after it. We are all in the information age and we should start recognising that fact and understand the need for the police to store data on us.
Speaker E: People will do things online that they would never ever dream of doing in the real world. So simple examples of sharing inappropriate images. They wouldn’t run up and down the high street or physically share or do a certain action, but they’re more likely to do that online. Committing cybercrime, so individuals, when we’ve seen the likes of some of the Anonymous attacks, hack this bank or attack that company because we don’t like what they’ve done or what they’re talking about, and when some of the tools were previously published so you could join in, members of the public could join in attacks, and we’ve seen tens of thousands of members of the public from all sectors of the community joining in on attacks.
Speaker F: So essentially what you’re saying is if I went up, if I went along this street here knocking on doors saying, I want to go and throw a stone at a bank, will you join me? What you’re saying is no, they wouldn’t.
Speaker E: No, you wouldn’t dream of it. But somebody gives you a tool which you just push this button on your computer and you are part of that attack. Then we saw tens of thousands of people downloading and joining in that attack. We’ve seen youngsters hacking into companies and networks. They would never dream of climbing over the fence and smashing a window and breaking into premises, but because it’s online, it seems to be almost— there isn’t that same code of conduct, if you like.
Speaker F: Okay, so then, and you were talking about grooming earlier, see, then you’ve also got this, this sort of behavior whereby somebody will say, can you take your clothes off and take a picture and let me watch, let me have a look at it? And as you’re saying, you wouldn’t do that on the street.
Speaker E: No, you wouldn’t do that in this, on the street. And a lot of youngsters, they wouldn’t do it if they were in the same room together, but to take that image and send it or share it with friends. But then there’s also the lack of appreciation that you share it with that one individual. If you then have a fallout with that individual the following day or the following month, that individual still has that image. And that can go around the world in seconds. That can be shared and shared and shared. It— once it’s out on the internet, it can go viral and everybody’s now got that image. And whereas physical hard copies you can grab hold of and destroy, that is almost a nigh-on impossibility once it goes online. And you can’t walk away from it.
Speaker F: This is one of the very interesting points, wasn’t it? We were speaking to somebody who was on the program, I think it was 2 years ago, and it was a police officer who’d been investigating the case of a young man who had had pictures taken of him, was being blackmailed by a Russian crime gang, and then threw himself off the Forth Road Bridge as a result.
Speaker E: With youngsters particularly, with, you know, cyberbullying or where images have been shared, sexting taking place, You cannot walk away from it. When they leave school, if it was bullying, physical bullying in the playground, they leave school, they go home, they’ve got distance, they’ve walked away from it. But now when it’s online, there is no escape. Their phone, their computer is with them wherever they go. They’re constantly receiving messages. So it’s a very, very difficult one, that cybercrime in all shapes and forms. And we put cyber in front of everything now, whether it’s bullying, cyberbullying, whether it’s blackmail, cyberblackmail, cyber is just the means of sending that transaction. But it’s far more impact, it causes far more harm.
Speaker F: It’s an interesting point, isn’t it? Just as a final summation on this. But as you’ve said, you do something like that, there is that image of you, it is with you forever. That your device follows you around, it is with you forever.. And in a sense, there has been this debate in Parliament this week and that debate is about wanting to make that data stay with you forever. Is this just, should it just be that we should recognize that we’re in an information age and that this is going to happen? And so what we need to do is to say, yeah, we want to define the way that this actually works. We want to define what a crime is, and we also want to define what those freedoms are, or what rules should govern our data. Is that really where we are now? Are we on the cusp of this move into the information age where we’ve just got to basically recognize it? I mean, you say cyber’s everywhere. Well, cyber just denotes when you’re online, really, doesn’t it?
Speaker E: I just think, you know, technology is now embedded in everything we do— work, social, whatever. And I think ultimately in a few years’ time, cyber will be a non-existent word because it’s just crime is crime, data is data, theft is theft, bullying is bullying. How it happens is just painting a picture around that. I think what the message is though is that we need to increase, constantly increase awareness across all sectors about how technology can be used for causing harm, how to protect ourselves better, and that’s part of the legislation that’s going through. You say about keeping all data. Cyber investigations are complex. Cyber moves technology, the data moves around at a great pace, but also through various different networks and systems. And more often than not, cyber criminals, they like to move their communications through different proxies. So they are complex investigations, and the bill that is being put through at the moment is to enable that data to be retained for a sufficient period of time so that law enforcement can access it where it’s proportionate and where it’s necessary for them to do so. So You may find in certain examples where we’ve had in the past where we’re looking at a trail for a cybercriminal and when we actually go to the service providers and say, okay, we know there’s the data that we actually need to obtain to track that cybercriminal and it’s already, it’s gone. So a large part of it is about retention of the data so we can identify the cybercriminals trail. So it’s not the content so much, it’s not who said what, it’s point A to point B, so we can follow that track.
Speaker B: Charlie McMurdy of PricewaterhouseCoopers: without a data pool on what’s happened, the criminals are getting away. You’re listening to Password on Resonance 104.4 FM, where we have been talking to the police and intelligence experts on why they think We need legislation to store our internet records for over a year. I’m afraid if you’ve just tuned in, then you’ve missed us, but you can join us at the same time next week. Password is a joint production between Future Intelligence and the Cybersecurity Research Institute. Thanks for listening.
Speaker A: Goodbye. This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.
