EU plans to block terror sites, but doesn't know how

Commission at 'early stage' of bafflement


A meeting of EU interior ministers held in August in the wake of the 'liquid bomb plot' arrests called for the acceleration of European plans to tackle terrorism, and as part of these, for measures to "tackle the use of the Internet by terrorists to radicalise young people, spread messages of hate and plan mass murder" (see Home Office announcement). Ah yes, but how?

Speaking after the meeting Franco Frattini, Justice & Home Affairs Commissioner, said that the Internet should be made a "hostile environment" for terrorists. "I think it's very important to explore further possibilities of blocking websites that incite to commit terrorist actions," The Times reported. Yes Franco, but how do you propose to do that, exactly? Or even approximately?

After the August meeting Spy Blog wrote to Frattini asking for details of what he was proposing, and putting forward a detailed list of 17 questions covering consultation, mechanisms, definitions, distinctions and safeguards. Spy Blog now has a response from Jonathan Faull, EU Commission Director General for Justice, Freedom and Security, but although lengthy, the document sheds little or no light on the matter.

Essentially, the Commission seems to know approximately what it wants to do, to have barely the vaguest of notions how to go about doing it, but to be exceedingly keen to assure people that it won't do anything that is in conflict with the principles of the European Union. Take question one, for example, "Are you proposing a European Union version of the national level firewall content filtering and censorware software such as is used in the 'Great firewall of China' or in Saudi Arabia and other repressive regimes?"

Faull responds with a refrain that will become tedious well before question 17. "At such an early stage of our consultations it would be premature to speak about a specific solution... [so ominously, perhaps we're not altogether ruling that one out]... the European Union is founded on the principles of liberty, democracy, respect for human rights and fundamental freedoms, and the rule of law. In consequence, policy options undermining such principles will be necessarily ruled out."

Relieved? We know we were. So even if Europe does build a Great Firewall it won't be one that undermines our basic principles, right...

Question two then, "Are you proposing to ban websites in the United States of America, such as Yahoo Groups of the Google search engine cache? This is where the vast majority of home made bomb making instructions are written and published on the Internet?" A good question, says Faull, confirming that much of the material in question is hosted outside of European jurisdiction, and adding that "a particular web site may contain both legitimate content and content aiding or abetting terrorism. Such factors will be considered as part of our consultation process."

So we can put that one down as a 'don't know', then. How will they differentiate between research for scientific and terrorist purposes? What will they do to stop blocked sites immediately popping up elsewhere, how will they make sure they get the right sites, and only the right sites, who will pay for mistakes, and how much will it all cost?

Faull, ever so politely, has coherent answers to none of these questions, and more, but then "we are still at the early stage of a the beginning of consultations and it would be premature to speak about a specific solution," and of course as "we are still considering legislative and non legislative options, we cannot speak about a specific option." Much more, or should we say less, at Spy Blog. We particularly commend the answer covering the precise definition of terrorism, set down confusingly here (some might suggest certain Governments could fall victim to (d)-(i) of Article 1), but subject to the "current reflection and consultation exercise [which] will consider whether a modification of such articles is actually required". So it's precise and set down, but fluid. Perhaps.

Note however that the decidedly vague nature of the Commission's planning does not necessarily mean it is not starting to happen anyway. The Internet has figured increasingly prominently in recent UK anti-terror legislation and investigations, and the Justice & Home Affairs Ministers are likely to continue to move the agenda on, with or without the Commission's consultations. ®


Other stories you might like

  • Returning to the Moon on the European Service Module
    Moving to series production and dealing with the US, where things are done slightly differently

    Interview NASA has set late August as the launch window for its much-delayed Artemis I rocket. Already perched atop the booster is the first flight-ready European Service Module (ESM). Five more are in the pipeline.

    Airbus industrial manager Siân Cleaver, whom The Register met at the Goodwood Festival of Speed's Future Lab, has the task of managing the assembly of the spacecraft, which will provide propulsion, power, water, oxygen and nitrogen for the Orion capsule.

    Looking for all the world like an evolution of the European Space Agency's (ESA) International Space Station (ISS) ATV freighter, the ESM is not pressurized and measures approximately 4 meters in length, including the Orbital Maneuvering System Engine (OMSE), which protrudes from the base.

    Continue reading
  • Running DOS on 64-bit Windows and Linux: Just because you can
    DOS isn't dead. You can still run it and its apps, even now

    FOSS Fest There are still ways to run DOS apps under 64-bit Windows and Linux, and a lot of free apps to choose from.

    One of the differences between the Microsoft and Apple approaches to maintaining widely used OSes is that Apple is quite aggressive about removing backwards compatibility, while Microsoft tries hard to keep it.

    One of the few times Microsoft removed a whole compatibility layer from Windows was with the launch of 64-bit Windows, which went mainstream with Vista in 2007. 64-bit editions of Windows can't run 16-bit apps, whether they're for DOS or Windows.

    Continue reading
  • China's blockchain boosters slam crypto as Ponzi scheme
    Communists reckon Bill Gates and Warren Buffet got it right

    Executives at China's Blockchain-based Service Network (BSN) – a state-backed initiative aimed at driving the commercial adoption of blockchain technology – labelled cryptocurrency "the biggest Ponzi scheme in human history" in state-sponsored media on Sunday.

    "The author of this article believes that virtual currency is becoming the largest Ponzi scheme in human history, and in order to maintain this scam, the currency circle has tried to put on various cloaks for it," wrote Shan Zhiguang and He Yifan in the People's Daily.

    He Yifan is the CEO of startup Red Date Technology – a founding member and architect behind BSN – where he serves as executive director. Co-author Zhiguang Shan is chair of the BSN Development Alliance.

    Continue reading
  • Carnival Cruises torpedoed by US states, agrees to pay $6m after waves of cyberattacks
    Now those are some phishing boats

    Carnival Cruise Lines will cough up more than $6 million to end two separate lawsuits filed by 46 states in the US after sensitive, personal information on customers and employees was accessed in a string of cyberattacks.

    A couple of years ago, as the coronavirus pandemic was taking hold, the Miami-based biz revealed intruders had not only encrypted some of its data but also downloaded a collection of names and addresses; Social Security info, driver's license, and passport numbers; and health and payment information of thousands of people in almost every American state.

    It all started to go wrong more than a year prior, as the cruise line became aware of suspicious activity in May 2019. This apparently wasn't disclosed until 10 months later, in March 2020.

    Continue reading
  • India extends deadline for compliance with infosec logging rules by 90 days
    Helpfully announced extension on deadline day

    India's Ministry of Electronics and Information Technology (MeitY) and the local Computer Emergency Response Team (CERT-In) have extended the deadline for compliance with the Cyber Security Directions introduced on April 28, which were due to take effect yesterday.

    The Directions require verbose logging of users' activities on VPNs and clouds, reporting of infosec incidents within six hours of detection - even for trivial things like unusual port scanning - exclusive use of Indian network time protocol servers, and many other burdensome requirements. The Directions were purported to improve the security of local organisations, and to give CERT-In information it could use to assess threats to India. Yet the Directions allowed incident reports to be sent by fax – good ol' fax – to CERT-In, which offered no evidence it operates or would build infrastructure capable of ingesting or analyzing the millions of incident reports it would be sent by compliant organizations.

    The Directions were roundly criticized by tech lobby groups that pointed out requirements such as compelling clouds to store logs of customers' activities was futile, since clouds don't log what goes on inside resources rented by their customers. VPN providers quit India and moved their servers offshore, citing the impossibility of storing user logs when their entire business model rests on not logging user activities. VPN operators going offshore means India's government is therefore less able to influence such outfits.

    Continue reading
  • Hangouts hangs up: Google chat app shuts this year
    How many messaging services does this web giant need? It's gotta be over 9,000

    Google is winding down its messaging app Hangouts before it officially shuts in November, the web giant announced on Monday.

    Users of the mobile app will see a pop-up asking them to move their conversations onto Google Chat, which is yet another one of its online services. It can be accessed via Gmail as well as its own standalone application. Next month, conversations in the web version of Hangouts will be ported over to Chat in Gmail. 

    Continue reading
  • OpenSSL 3.0.5 awaits release to fix potential worse-than-Heartbleed flaw
    Though severity up for debate, and limited chips affected, broken tests hold back previous patch from distribution

    The latest version of OpenSSL v3, a widely used open-source library for secure networking using the Transport Layer Security (TLS) protocol, contains a memory corruption vulnerability that imperils x64 systems with Intel's Advanced Vector Extensions 512 (AVX512).

    OpenSSL 3.0.4 was released on June 21 to address a command-injection vulnerability (CVE-2022-2068) that was not fully addressed with a previous patch (CVE-2022-1292).

    But this release itself needs further fixing. OpenSSL 3.0.4 "is susceptible to remote memory corruption which can be triggered trivially by an attacker," according to security researcher Guido Vranken. We're imagining two devices establishing a secure connection between themselves using OpenSSL and this flaw being exploited to run arbitrary malicious code on one of them.

    Continue reading

Biting the hand that feeds IT © 1998–2022