How to dodge RIP

Report shows how


Updated A report due to be published tonight will explain how to dodge the government's email snooping bill via a few simple steps.

The paper, courtesy of Web security experts Ian Brown and Brian Gladman, shows you don't have to be an Internet genius to bypass the proposed controls in the Regulation of Investigatory Powers (RIP) Bill. It says criminals will easily be able to circumvent the email monitoring controls in RIP, therefore making the proposed legislation unworkable.

The report has already been distributed to MPs ahead of this evening's House of Commons debate on the RIP bill.

Brown, an Internet security expert at University College London, and Gladman, an ex-Ministry of Defence information security expert, claim the interception technology needed for the government's email monitoring plans is already obsolete.

Speaking to The Register, Gladman said: "The underlying concern in RIP is that it is going to spend a lot of taxpayers' money for no effect. It is easy for criminals to get around it."

The report labels the powers in RIP "technically inept", and goes on to list several ways that even cyber virgins would be able to evade the interception devices, or "black boxes", which some ISPs in the UK will have to install.

It outlines four main ways of dodging the bill. The first is pretty simple - use a smaller ISP. The government has said it will only fit black boxes in some larger ISPs.

Second is to use a server overseas and use the diffie-hellman technique. By signing on to this, through sites such as http://www.mail2web.com, email can only be intercepted at either the server or the end-user's computer, but not in between.

Another option involves the growing use of ADSL and cable modems - with these, people can stay online and not need servers. The final method uses the emerging Internet protocol IPv6, which renders black boxes redundant - all data is machine encrypted by default.

"It's so easy for criminals to get around this it's just not true," said Gladman. "This is not going to work - it will impact on honest people, drive away business and harm e-commerce, but will not catch criminals and will waste a lot of money in the process."

Gladman also pointed out that, despite the enormous amount of time and energy spent on RIP, the Government was still unable to protect Internet users from the security debacles at Powergen last week - when customer names and credit card numbers were exposed on the Web.

"We both feel this bill is ridiculour, it will undermine trust and is already impacting on business. And the worrying thing is that the government is carrying on regardless," said Gladman. The report will be published on FIPR's Website at 19.00 BST.®

Related Stories

RIP branded 'zombie legislation' as it passes Lords
RIP Bill: Full Coverage
ISP RIPs up UK domicile


Other stories you might like

  • Tesla driver charged with vehicular manslaughter after deadly Autopilot crash

    Prosecution seems to be first of its kind in America

    A Tesla driver has seemingly become the first person in the US to be charged with vehicular manslaughter for a deadly crash in which the vehicle's Autopilot mode was engaged.

    According to the cops, the driver exited a highway in his Tesla Model S, ran a red light, and smashed into a Honda Civic at an intersection in Gardena, Los Angeles County, in late 2019. A man and woman in the second car were killed. The Tesla driver and a passenger survived and were taken to hospital.

    Prosecutors in California charged Kevin George Aziz Riad, 27, in October last year though details of the case are only just emerging, according to AP on Tuesday. Riad, a limousine service driver, is facing two counts of vehicular manslaughter, and is free on bail after pleading not guilty.

    Continue reading
  • AMD returns to smartphone graphics with new Samsung chip for your pocket computer

    We're back in black

    AMD's GPU technology is returning to mobile handsets with Samsung's Exynos 2200 system-on-chip, which was announced on Tuesday.

    The Exynos 2200 processor, fabricated using a 4nm process, has Armv9 CPU cores and the oddly named Xclipse GPU, which is an adaptation of AMD's RDNA 2 mainstream GPU architecture.

    AMD was in the handheld GPU market until 2009, when it sold the Imageon GPU and handheld business for $65m to Qualcomm, which turned the tech into the Adreno GPU for its Snapdragon family. AMD's Imageon processors were used in devices from Motorola, Panasonic, Palm and others making Windows Mobile handsets.

    Continue reading
  • Big shock: Guy who fled political violence and became rich in tech now struggles to care about political violence

    'I recognize that I come across as lacking empathy,' billionaire VC admits

    Billionaire tech investor and ex-Facebook senior executive Chamath Palihapitiya was publicly blasted after he said nobody really cares about the reported human rights abuse of Uyghur Muslims in China.

    The blunt comments were made during the latest episode of All-In, a podcast in which Palihapitiya chats to investors and entrepreneurs Jason Calacanis, David Sacks, and David Friedberg about technology.

    The group were debating the Biden administration’s response to what's said to be China's crackdown of Uyghur Muslims when Palihapitiya interrupted and said: “Nobody cares about what’s happening to the Uyghurs, okay? ... I’m telling you a very hard ugly truth, okay? Of all the things that I care about … yes, it is below my line.”

    Continue reading

Biting the hand that feeds IT © 1998–2022