Speaker A: Hello and welcome to Password. In today’s show, the government grapples with terrorist threats online, and David Cameron has provoked an online storm by saying that if his government returns to power, that it will outlaw encryption. We have the views of the former head of GCHQ, Sir David Oman. The scientific advisor to the new sci-fi thriller Ex Machina tells us why he signed an open letter calling for a more cautious approach to the development of artificial intelligence. And top cybersecurity expert Mike Loginoff joins us in the studio to discuss the crisis in online security. First, the Prime Minister David Cameron is being widely ridiculed in the technology community for saying in a speech that he intends to outlaw encrypted messaging to prevent it being used by terrorists or criminals.
Speaker B: Ways of communicating develop. Now, I have a very simple principle to apply here, which should be at the heart of the legislation that will be necessary. And the simple principle is this: in our country, do we want to allow a means of communication between people which, even in extremis, with a signed warrant from the Home Secretary personally, that we cannot read? Now, up until now, Governments of this country have said, “No, we must not have such a means of communication.” That is why in Extremis it’s been possible to read someone’s letter. That is why in Extremis it’s been possible to listen in to someone’s telephone call. That is why the same applies with mobile communications. Let me stress again, this cannot happen unless the Home Secretary personally signs a warrant. We have a better system for safeguarding this very intrusive power than probably any other country I can think of. But the question remains: are we going to allow a means of communication where it simply isn’t possible to do that? And my answer to that question is no, we must not.
Speaker A: Well, that was David Cameron saying that there will be no no-go zones on the internet for the intelligence agencies. Professor Sir David Oman, the former head of the UK listening centre GCHQ, and until recently he was the permanent secretary at the Home Office and the UK Security and intelligence coordinator. He’s now sharing his insider knowledge of espionage with the Department of War Studies at King’s College London. He’s been talking to me about his thoughts on the latest terrorist outrages— murders in Paris, kidnappings and beheadings. Prime Minister David Cameron has said there should be no dark places on the internet where conspiracists can plot, as we’ve heard. So what does Sir David Oman think? He thinks he’s missing the point.
Speaker C: I wouldn’t oversimplify what they’re saying. It’s the job of the security and intelligence agencies and the police to try and keep us safe. They’re doing the right things. They are finding it increasingly hard for reasons which I think you know, but which we can discuss. But they are doing the right things. I don’t see any need for any dramatic shift in what they’re doing. But as has been pointed out many times, there are a significant number of people who mean us harm, and uncovering who they are and which of, for example, the returnees from Syria and Iraq want to settle back down into a normal life and which want to continue their struggle and violent struggle is a very difficult exercise in security. The problem that’s come up is that as more and more communications travel across the internet— Skype, iChat, those sort of applications— it is harder and harder for the authorities to know who is communicating with whom. They can do that with more traditional telephone calls, and they have the legal authority to do that. The companies retain the data of who called whom for telephone calls, perfectly legally, and that can be accessed so that suspects can be investigated. But that’s not available for the more advanced internet-based communications because the companies have no need of their own to retain the data, and the big argument there’s been over the last year is should Parliament legislate to make that a requirement for those providing that service in the UK, and if so, what are the safeguards? And that debate will have to be had after the election. Okay.
Speaker A: I mean, we interviewed the former head of legal affairs for GCHQ, Michael Drury. Michael Drury was saying that really basically the need is for the legislation to essentially come to terms with the internet age. Is that what you’re saying? Is that because there are these logs that aren’t available or logs that aren’t kept, that really the logs that were kept in the old telephone age now need to be kept in the internet age?
Speaker C: That’s the argument. I’m very sympathetic to that argument. There have to be safeguards. You wouldn’t want that kind of information retained for too long, just in case it comes in handy in some future era. So you would want very careful legal constraints on it. But as I understand it, the political parties have been talking about that, and they should be ready to come forward with proposals once we’re through the election and we can see who’s actually in the government seat. But something has to be done to help the police and the security authorities in that space. It’s never going to be perfect. There are always going to be ways around it, but we’re talking about can we improve the chances of our— of theirs successfully detecting and preventing attacks.
Speaker A: Now, the Prime Minister suggested that we should be doing away with encryption. Do you think that’s desirable?
Speaker C: I don’t think that was what he was suggesting for one moment, because we need powerful encryption to keep our normal internet use, financial transactions, and all the rest of it secure. So there’s no way that we’re going to get rid of encryption, nor should we. But that doesn’t mean that internet-based conversations or communications via the various apps that they’re there are, should be a totally private space where law enforcement has no chance of getting in there, and there’s no law, as it were, providing the basic information which would give them a chance. So I think you just have to balance those. This is a very difficult issue in public policy. We’ve got to have security in the internet, It’s essential for our future. We’ve got at the same time to give law enforcement a fighting chance of trying to catch not just terrorists but pedophile groups, people smugglers, drug smugglers, you name it. And we’ve got to give our national intelligence agencies a chance of obtaining intelligence on the serious foreign policy issues that they are looking at. Are there Russian paramilitaries in eastern Ukraine? Vital to know that if you’re going to put sanctions on Russia. Is Iran going to comply and dismantle some of its nuclear program? Is North Korea going to test another nuclear weapon? These are the sorts of issues that intelligence agencies get asked to illuminate. And if we shut them out because we’re so worried about personal privacy here in the UK, we’ll have done ourselves a great disservice.
Speaker A: Well, it will be interesting to see whether monitoring becomes a manifesto issue. That was Professor Sir David Oman, the former head of GCHQ. And joining us in the studio is Mike Logonov, Executive Director of the Information Systems Security Association, who’s no stranger to government systems, having worked on them and now with them. Mike, welcome to Password.
Speaker D: Thank you, Peter. It’s a pleasure to be here.
Speaker A: Now, Mike, encryption— can the government really get rid of it?
Speaker D: Well, I think the short answer is no. Encryption is now so well embedded into the internet and our systems, and really until some new form of technology comes along that perhaps provides a level of security that’s akin to that from which we get from encryption, then it’s highly unlikely that we would be able to get rid of it now.
Speaker A: Alright, so, but I mean, this doesn’t sort of reflect very well on the government, does it? It does sort of make it look as though it’s a little clueless about technology.
Speaker D: Well, I think that’s one viewpoint and one perspective. I think what it does suggest is that this is a big issue that governments, not just in the UK but around the world, are grappling with in terms of how do they manage encryption and access to areas that perhaps they feel is necessary to secure their environments. But, yeah, it certainly is an issue and, you know, encryption is definitely necessary to transact business on a normal daily basis, you know, for access to our bank accounts, even just in our day-to-day communications. Do we really want criminals and all those other faculties or threat vectors that the former speaker mentioned, Sir David Omrendt, actually looking at our data and our information? I don’t think so.
Speaker E: Right.
Speaker A: No, it’s a good point. Now, I mean, one of the things that everybody’s still talking about is metadata. What is this, the conversation about metadata? What is it? What is metadata? What does it do?
Speaker D: Well, metadata really is the information that surrounds the data held, for example, within an email or a communication. So it’s really the information that is attached to or tagged to a message, for example, the time it was sent, who it’s coming from, where it’s going to. When it was picked up, but it can even tell us things like the location, the geolocation of the individual that’s receiving or sending the information. So it can be used clearly for illegal purposes as well as legal purposes.
Speaker A: It can also give us the header, can’t it? So we can see actually what the title of the message was. So to a large extent, you can actually extract a huge amount of information from metadata.
Speaker D: Oh, undoubtedly. If metadata is as innocuous as certainly some government commentators and speakers would have us believe, then why is there such an interest from security services in capturing and collating that information? It gives an awful lot of information about what’s going on. So I totally agree. The header there, you don’t always need what’s in the information, the body of the information. To get a very clear signal about who’s talking to who and what’s going on.
Speaker A: Exactly. And it does seem to be the big push from all of those companies that are working with the intelligence agencies is to put together information systems that can actually interrelate metadata to extract even more meaning out of it. So what do you think the solution is then, Mike?
Speaker D: Well, I don’t think the solution, certainly from a society perspective, is necessarily about mass surveillance and mass data capture. I think we need to be working smarter, using technology and new technologies in a better way. So rather than mass collection, mass surveillance, we should really be targeting the bad guys. Quite often, certainly with the activities that took place in Paris, the people there were known to the authorities prior to that happening. So perhaps it’s more about better processes and execution of services rather rather than more data collection or more powers in the hands of the government or the security services.
Speaker A: Well, one of the things that— very briefly— but one of the things that Sir David Oman did say last night was that really what they’re not getting is access to the right information, or that they’re not getting access to what I know the technology industry call the right silos. But it seems to me that they’d had access to just about every silo that was around.
Speaker D: Well, apparently even, you know, if we’re reading the latest information, what was happening in North Korea prior to the Sony incidents, that security services were monitoring the networks there. So, you know, yes, it is interesting that there is a lot of information out there, and it would appear certainly that, you know, the access to that at the moment is fairly robust.
Speaker A: Yeah, no, well, thank you, Mike. I mean, I’ve also been talking to a lot of other people, and there does seem to be a very, very, very sort of constant call for better targeting. There’s a suggestion that some people could actually be working a little harder instead of sitting back and collecting information. One of those people I’ve been talking to is Richard Mulds at Thales, the French defense company which brought out the UK encryption company Encipher. Encipher provides encryption for most of the banks. Richard Moles was talking to me about how to prevent terrorists taking advantage of the many tools available to encrypt messages and hide the movement of money, people, and weapons.
Speaker F: Last time I checked, we live in a fairly connected universe these days, and, you know, the idea that somehow messages to the UK would have to be handled differently than not— I mean, this is the sort of thing that happens in China and Iran and Syria. They block messages, they block websites, they force things to be different. And last time I checked, they weren’t very successful at doing that. So I think, you know, if this was a worldwide initiative that every government could get behind, then, you know, maybe. But the idea of any one geography, I think these days, trying to somehow extricate itself from this sort of global environment seems to me to be rather naive.
Speaker E: It does point to another inconsistency, doesn’t it? Because on Monday of this week, President Obama was calling for disclosure of data breach. The European Union data protection regulations, the update to those is widely being telegraphed that that too will have very, very strong measures on data breach. What’s been proposed is to take away a significant way for people to protect against that?
Speaker F: Well, data breaches are very important. Data breach disclosure is very important, and they’ve been, they’ve been part of the landscape in America for 5 or 6 years now. And I think, I think there’s a, there’s a strong logic behind them. You know, the data breach disclosure is not there to protect banks or merchants, it’s there to protect the consumer. If somebody loses my personal data, then I, I want to be told about it so that I can, you know, change my passwords or change my credit cards or whatever it might be. In fact, most data breach disclosure law in the world talks about encryption as a way of avoiding to have to disclose. If a bank, for example, loses a bunch of passwords and those passwords are encrypted, then they do not fall foul of data breach disclosure laws. So encryption at the moment, you know, is a positive for most— in most legislation around this area in that it removes the need to disclose because the presumption is that if data was encrypted, then the fact that it was disclosed is of no interest because the data itself is useless. And so it would expand the scope of data breach disclosure laws because, you know, because data wouldn’t be protected. So therefore it would be even more important to disclose the fact it had been lost.
Speaker E: And of course the other point too is that it’s very easy to get hold of encryption, isn’t it? And the bad guys know that they need to encrypt. I can remember speaking to somebody in 1996 who was telling me about a gang of drug smugglers who were aware that the police had infiltrated their operations and they knew that somebody was making mobile phone calls from the grounds of the building that they were in. And they were trying to hack into the mobile phone company to find out who that person was who owned that phone. So that shows that they were very, very technologically competent back in 1996. Now, they would have been aware of the possibilities of encryption for them.
Speaker F: [Speaker] Well, that’s right. I think this is the big, big difference between the discussion we’re having now about the cybersecurity arms race versus historic arguments have been heard about the physical arms race, if you like. Back in the olden days, you could only build nuclear bombs if you knew how to and if you could get your hands on nuclear material. It’s very different now. This is digital weaponry and digital defenses. And encryption, of course, is a digital defense and in some cases can be used as a weapon. But because it’s digital, you know, it’s like music these days. It can be copied and shared, you know, almost without restriction. The vast majority of the encryption software that we all use day to day— when you log on to a shopping website and type in your password, that’s going over an encrypted connection. And more chances than not is the software that that merchant is using to encrypt that connection was free to them. So encryption, even very strong encryption, is available for free on the internet to the good guys and to the bad guys. The idea that somehow it’s hard to get your hands on this type of technology is really a myth. Unfortunately, the bad guys have just as much access to it as we do, and trying to take it away from them retrospectively is probably even harder than trying to take it away from the good guys.
Speaker E: So what you’re saying is that the genie is out of the bottle and that it’s the equivalent of banning the MP3. CD player.
Speaker F: Yeah, that’s right, trying to pretend that digital music doesn’t exist to try and protect, you know, the LP is an interesting coffee table discussion, but it’s not practical.
Speaker A: Well, that was Richard Moldes of Thales. Now, sadly joining us on the line from Bexhill is Robert Shafrin to talk about the death of Steve Gold. Back in 1985, Robert and Steve passed into computing history when they hacked into the Prestel mailbox of Prince Philip and provoked outrage coverage in the Daily Mail, among other papers. Their actions led to another milestone in industry mythology, the writing of the Hacker’s Handbook. And since then, both Robert and Steve have worked to bring the topic of computer security to the mainstream. Hello, Robert.
Speaker G: Hello there.
Speaker A: Robert, obviously a sad, sad time. There’s been a lot of tributes to Steve. Tell us a little bit about him.
Speaker H: Um, he was a multi-talented guy, started off in the health service as a nurse of some sort. No one’s quite sure, no one quite remembers. He then moved into accountancy, and he was quite a senior person in accountancy and audit with the NHS. And following our court case with myself and Steve and being arrested in connection with hacking, although there wasn’t any law against hacking at the time, we were actually charged with forgery, the NHS said to Steve We don’t really want you here at the moment as an accountant and in charge of our audit because you’ve got a forgery conviction hanging over you. So you might want to go and do something else for a while. And he got into IT journalism and writing and talking and broadcasting about security, which I do as well. And he obviously did, you know, did very well at it and made his name there and was very well known for the 20 or so years he was doing that.
Speaker A: Now, obviously, you know, the incident that so many people remember was that hacking incident with Prince Philip. 1985. You and Steve achieved, I think it’d be fair to say, a certain notoriety. Why did you want to do it? Why did you do it in the first place?
Speaker H: We did it purely for a bit of fun. There were very few, in fact there were no malicious hackers around in those days. There was nobody sort of trying to release people’s data and hijack their information and blackmail them, mainly because there were no big databases you could hack into to do that. Databases in those days were filing cabinets in the basement, so You wouldn’t hack into someone’s computer to steal their information. What you would do is hack into someone’s computer because you wanted to see if you could beat the machine. At the end of the day, we had BBC Micros, Commodore PETs, Sinclair Spectrums, which cost £200 or £300 in those days, linked up in the case of Prestel, if you were using Prestel or Micronet 800 or one of these systems you could subscribe to like those or Telecom Gold, linked up to a mainframe costing £4 or £5 million.. And we all knew that what we were allowed to see on those systems from our Spectrums and BBCs was purely based on what password we typed in. And it was all a bit of a game trying to find other accounts, other passwords in order to see if we could beat the machine. And ultimately myself and Steve managed to become system manager, system administrator on one of the Prestel test mainframes. Found some information there including live copies of user data which included Prince Philip’s. We typed it in. It said good afternoon or good morning because it was very late at night if I remember. ‘HR agency, Duke of Edinburgh, welcome to Prestel.’ And we thought that was a bit of fun. We took our findings, or I took our findings, to Micronet, which was part of Prestel, thinking they’d be kind enough to want to talk to me and find out how I’d managed to break into their system. But instead they contacted the Metropolitan Police Computer Crime Unit and we were arrested.
Speaker A: Well, the tributes have all pointed out that Steve will be much missed, and so thank you very much, Rob. We’ve got to move on. We would like to talk about him a lot because It was a lot of tributes to him on the web. Thank you. Thank you. Robert Shiffrin on the passing of computer security journalist and hacker Steve Gold, who died of complications during a heart operation and leaves a wife and young son. Now, if you’ve been listening to Password for the past 2 weeks, you’ll know there’s a debate going on about the dangers of artificial intelligence. Professor Stephen Hawking has warned that superintelligent machines could make human life extinct, and he’s just one of hundreds of experts, including myself, who’ve signed an open letter calling for a more careful approach to the development of, for example, driverless cars, avatars, and human-level intelligent computers. On the line from London’s Imperial College, the professor of cognitive robotics Murray Shanahan has been telling me why he signed up after a closed conference earlier this month in Puerto Rico of all the world’s top AA minds. The proceedings are now online on the events page of the Future of Life Institute. Murray’s keen to get everyone to understand the risks and to keep them in proportion. The new film Ex Machina about a robot The film Robotic Romance is based on his book, and he says science fact must be kept strictly separate from fiction and fantasy.
Speaker G: The sort of background to that is that, and what doesn’t come across in the media, is that this is not an immediate concern. There’s no need for panic about these kinds of things at the moment. But the kind of message that Nick Bostrom would put across is to say, but nevertheless, there is a significant risk of that kind of AI, human-level AI, being developed, you know, say within this century, and that that might seem a long way off, but we should probably think about, you know, the ramifications of that right now, especially if there are some risk involved. So there’s two completely different things. One is short-term, pretty certain it’s going to play an important role, so we should be thinking about ethics there. Long-term, you know, who knows when, who knows whether, who knows what it’ll be like, small chance of a big problem that we should be thinking maybe a bit about now as well.
Speaker E: So why is it, do you think, then, that Elon Musk and Stephen Hawking have suddenly, as you say, made these— what you say is alarmist pronouncements?
Speaker G: Well, I think it’s because— it’s because they’ve been reading Nick Bostrom’s work and the work of Nick Bostrom and Eliezer Yukowsky and people like that and listening to Jan Tallinn and all of those people have messages that are worth listening to. But the trouble is that when then you get very famous people compressing those messages into little sound bites that have none of the details, none of the caveats, none of the uncertainty, none of the timescale, none of that gets mentioned and then it becomes this alarmist message which gets the media all overexcited. And the media make it even worse, by the way. So they make no effort, quite often, to get to the bottom of what might be behind those pronouncements. So you start off with something which is a rather cautious, albeit dramatic message from somebody like Nick Bostrom, but cautious, carefully developed in a 400-page book, and then you get a a 30-word soundbite in the mouth of Stephen Hawking or Elon Musk, and it’s just the 30-word soundbite is just what gets all the attention. So you lose all of the nuance, all of the intellectual background, all of the details. It’s kind of infuriating. I mean, when I’m having a go at the media, I’m not having a go at you, Peter. I’m having a go at the kind of, you know, different kind of media that’s sort of— and by all means, you know, it’s By no means is it everybody, of course. There are some well-written, balanced articles, but there’s just— I mean, it’s red rag to a bull, really, when somebody like Stephen Hawking says something like that. You’re absolutely bound to get Daily Mail, picture of Terminator, you know, we’re all going to die.
Speaker A: No, you’re absolutely right.
Speaker E: So in that case, how long have we got?
Speaker G: Well, what do you seriously say to that? You’ve heard my answer with all the caveats, all of the, you know, no quick soundbite there.
Speaker A: No, I know, I know.
Speaker E: I mean, obviously, you know, I mean, it’s an area that I suppose has probably been, it’s exercised quite a lot at the moment.
Speaker A: And I mean, there seems to be a raft of films that are doing the rounds as well, and that always does make it a bit difficult.
Speaker G: Ex Machina is the one that I’ve been involved in, and that’s related to this kind of issue as well, of course.
Speaker A: Well, as you will know if you’re a regular listener, we’ve been holding a competition to find the best sound effect that signifies traveling through time, and now we have a winner. Matt Shopland from Harrow has emerged from the mists. Here’s the winning sound effect. Well done, Matt! You’ve won a House of Marley Bluetooth speaker worth £100, and you can collect it from us here at at 144 Borough High Street, or we’ll send it to you in the post. The sound effect will be used in the Time Traveller series of audiobooks for children. You’re listening to Password on Resonance FM, and if you’ve just joined us, you’ve missed it. But we’ll be back next week, and you can find out more about technology and society at our website, Future Intelligence, and sign up for our regular newsletter. Password is made by Angel Media Productions CIC. Thanks for listening.
Speaker G: Goodbye.
