# Better Privacy Means Less Privacy? WTF?

**URL:** <https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860>\
**Category:** The BBQ Pit\
**Created:** [January 25, 2015, 3:54pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860 "2015-01-25T15:54:52Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [January 25, 2015, 3:54pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/1 "2015-01-25T15:54:52Z")

</div>

In this dispatch from Bizarro World, a former spy chief claims that improved privacy will lead to loss of privacy:

> [@](#):
>
> The increasing use of encryption technologies in everyday emails and messaging services will lead to “ethically worse” behaviour by the intelligence agencies, a former head of GCHQ has predicted.
> 
> Sir David Omand warned there would be greater intrusion on individuals’ privacy, not less, if agencies are unable to intercept communications – because they will be forced into more direct spying methods…
> 
> “Close access” means surveillance techniques that require physical proximity to the target. It could mean physical observation, bugging their room, or directly hacking into their mobile phones or computers.
> 
> Sir David said: “You can say that will be more targeted but in terms of intrusion into personal privacy – collateral intrusion into privacy – we are likely to end up in an ethically worse position than we were before.”…

My conclusion: Sir David needs to inquire as to whether National Health Service coverage and/or any extra civil service benefits from his career provides coverage for his severe case of impacted rectocranial inversion. To those of us who can see the world outside our own colons, it is obvious that taking away techniques that facilitate broad fishing-expedition surveillance (e.g. mass scanning of phone and Internet communications) and forcing a shift to techniques that must be targeted at specific suspects (e.g. the listed “close access” options) will induce ethical _reform_ and _cleanup_ in the intelligence agencies.

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [January 25, 2015, 5:05pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/2 "2015-01-25T17:05:02Z")

</div>

> [@Steve\_MB](#):
>
> … it is obvious that taking away techniques that facilitate broad fishing-expedition surveillance (e.g. mass scanning of phone and Internet communications) and forcing a shift to techniques that must be targeted at specific suspects (e.g. the listed “close access” options) will induce ethical _reform_ and _cleanup_ in the intelligence agencies.

Or it will turn intelligence agencies into modern day Stassis that hire half the population to spy on the other half. Or if not hire them, frighten or intimidate them into spying on their neighbors. I’m not suggesting this is what the guy meant, but it is one possibility.

---

<div class="post-metadata">

**Author:** ![OldOlds](https://avatars.discourse-cdn.com/v4/letter/o/a3d4f5/32.png) [@OldOlds](https://boards.straightdope.com/u/OldOlds)\
**Post date:** [January 25, 2015, 5:11pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/3 "2015-01-25T17:11:21Z")

</div>

You need to think of the various security agencies like any other addict. Just as the drug addict will do contortions to justify and rationalize any behavior to get his fix, these fellows will do likewise to justify collecting any and all information.

Just as I roll my eyes as the junkie tells me how none of this is his fault, so I do when an NSA/CIA/GHQ spokesman tells me this is for my own good.

Go Fuck Yourselves.

---

<div class="post-metadata">

**Author:** ![Octarine](https://avatars.discourse-cdn.com/v4/letter/o/22d042/32.png) [@Octarine](https://boards.straightdope.com/u/Octarine)\
**Post date:** [January 25, 2015, 6:57pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/4 "2015-01-25T18:57:45Z")

</div>

His point’s not _that_ outlandish. He’s saying that by not allowing organizations like the NSA to spy on us one way, they’re not going to just go “Oh well, time to stop spying, guys” - they’ll go to even more extreme and invasive measures to get information. However, it seems like hos solution is to not increase security, rather than addressing the rather serious underlying problem that this NSA is completely nuts.

---

<div class="post-metadata">

**Author:** ![Little\_Nemo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/little_nemo/32/3120_2.png) [@Little\_Nemo](https://boards.straightdope.com/u/Little_Nemo)\
**Post date:** [January 25, 2015, 7:51pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/5 "2015-01-25T19:51:23Z")

</div>

If you’re going to spied upon, intrusive spying is better than non-intrusive spying. At least then you know it’s happening.

---

<div class="post-metadata">

**Author:** ![kaylasdad99](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kaylasdad99/32/3398_2.png) [@kaylasdad99](https://boards.straightdope.com/u/kaylasdad99)\
**Post date:** [January 26, 2015, 10:22am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/6 "2015-01-26T10:22:46Z")

</div>

> [@Octarine](#):
>
> His point’s not _that_ outlandish. He’s saying that by not allowing organizations like the NSA to spy on us one way, they’re not going to just go “Oh well, time to stop spying, guys”

Wait a minute, why NOT?

---

<div class="post-metadata">

**Author:** ![Claverhouse](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@Claverhouse](https://boards.straightdope.com/u/Claverhouse)\
**Post date:** [January 26, 2015, 11:30am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/7 "2015-01-26T11:30:37Z")

</div>

If you don’t give us a hundred virgins every year, we will have to kidnap a thousand forcefully. It will be _your_ fault for not reasonably giving in to our overwhelming strength.

---

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [January 26, 2015, 11:35am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/8 "2015-01-26T11:35:23Z")

</div>

> [@Little\_Nemo](#):
>
> If you’re going to spied upon, intrusive spying is better than non-intrusive spying. At least then you know it’s happening.

Also, and perhaps more importantly, intrusive spying is better because it does not scale as electronic fishing expeditions do. Once the infrastructure is in place, electronic snooping on the 1,000,000th person is trivially cheap, so the tendency is to snoop on everyone. The “close access” techniques don’t work that way – the 1,000,000th physical observation, direct hack, etc don’t cost any less than the 1,000th (and given that every one in between also costs the same, the numbers can’t really get as high as the former to begin with). This forces a careful selection of targets, which is what these guys were supposed to be doing anyway.

---

<div class="post-metadata">

**Author:** ![YogSothoth](https://avatars.discourse-cdn.com/v4/letter/y/8edcca/32.png) [@YogSothoth](https://boards.straightdope.com/u/YogSothoth)\
**Post date:** [January 26, 2015, 4:55pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/9 "2015-01-26T16:55:39Z")

</div>

Spy agencies aren’t going to stop or cut back their spying if something gets in their way, they are only going to try harder. To induce reform, there would have to be massive prosecutions and cultural shifts and I just don’t see that happening. These are people who have bought into the line that if the government knows everything, it makes people the most safe.

They have to hire people like me, who don’t care about what you’re doing, and wouldn’t take a missed opportunity as a sign that massive change is needed. 😃

---

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [January 26, 2015, 5:29pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/10 "2015-01-26T17:29:39Z")

</div>

> [@YogSosoth](#):
>
> Spy agencies aren’t going to stop or cut back their spying if something gets in their way, they are only going to try harder. To induce reform, there would have to be massive prosecutions and cultural shifts and I just don’t see that happening.

That’s the advantage or relying on the laws of economics (i.e. the above noted linear-scaling cost of “direct access” methods) rather than statutory laws – the former are far less susceptible to evasion.

---

<div class="post-metadata">

**Author:** ![Spectre\_of\_Pithecanthropus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spectre_of_pithecanthropus/32/12343_2.png) [@Spectre\_of\_Pithecanthropus](https://boards.straightdope.com/u/Spectre_of_Pithecanthropus)\
**Post date:** [February 2, 2015, 5:26am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/11 "2015-02-02T05:26:24Z")

</div>

> [@Steve\_MB](#):
>
> In this dispatch from Bizarro World, a former spy chief claims that improved privacy will lead to loss of privacy:
> 
> […] shift to techniques that must be targeted at specific suspects

But then even if NSA and MI5 do have massive amounts of metadata, all indexed and cross referenced, someone still has to make the decision to investigate a particular person or transaction, IOW that the person concerned _is_ a suspect. Undeniably, this arrangement presents the possibility of abuse, but I’m not opposed to the collection of metadata in principle. I consider that far less an affront to my rights than it would be if I somehow got on the limited suspect list erroneously, given that such an error would imply that I am a suspect.

---

<div class="post-metadata">

**Author:** ![Nava](https://avatars.discourse-cdn.com/v4/letter/n/da6949/32.png) [@Nava](https://boards.straightdope.com/u/Nava)\
**Post date:** [February 2, 2015, 6:03am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/12 "2015-02-02T06:03:29Z")

</div>

> [@Spectre\_of\_Pithecanthropus](#):
>
> But then even if NSA and MI5 do have massive amounts of metadata, all indexed and cross referenced, someone still has to make the decision to investigate a particular person or transaction, IOW that the person concerned _is_ a suspect. Undeniably, this arrangement presents the possibility of abuse, but I’m not opposed to the collection of metadata in principle. I consider that far less an affront to my rights than it would be if I somehow got on the limited suspect list erroneously, given that such an error would imply that I am a suspect.

Not necessarily, they can define the targets along the lines of “if [set of checks], those people are guilty.”

Actual case, not from spying but involving a bad set of checks definition:  
Spain’s Treasury “prefiles” taxes for people. They prep your taxes, so you can either accept them or send them back with corrections - since most of the data will be there, this is generally viewed as a good thing. This is for the yearly income tax: actual data is used. It may be incomplete but it’s actual, it’s both current and real.  
At one point my local Treasury decided to prefile for the self-employed’s quarterlies, based on data from two years before. Cue every local self-employed: :eek:. The rejection was so wide that they haven’t done it again. But!  
Each of those prefiled withdrawals got tagged as “canceled”. Not “paid”.

Two years later, some genius ran a “select any tax withdrawals which are not labeled ‘paid’ and send to forced collections.”

---

<div class="post-metadata">

**Author:** ![Novelty\_Bobble](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@Novelty\_Bobble](https://boards.straightdope.com/u/Novelty_Bobble)\
**Post date:** [February 2, 2015, 10:11am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/13 "2015-02-02T10:11:57Z")

</div>

Is there a link for the full article? The excerpts as they stand don’t seem to be anything outrageous. It seems a perfectly reasonable assumption that surveillance will be driven in the direction stated.  
The author _may_ be saying that is a good thing or a bad thing or he may be simply stating a neutral opinion but without then full context we can’t say.

---

<div class="post-metadata">

**Author:** ![Bryan\_Ekers](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bryan_ekers/32/183_2.png) [@Bryan\_Ekers](https://boards.straightdope.com/u/Bryan_Ekers)\
**Post date:** [February 2, 2015, 2:52pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/14 "2015-02-02T14:52:58Z")

</div>

Interesting dichotomy, though. Can you detect more potential terrorist activity by looking at ten million people superficially or ten thousand people intensely?

---

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [February 2, 2015, 3:14pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/15 "2015-02-02T15:14:25Z")

</div>

> [@Novelty\_Bobble](#):
>
> Is there a link for the full article?

I’m not sure which of several Google hits it was; my best guess is [here](http://www.thebureauinvestigates.com/2015/01/23/encryption-will-lead-to-ethically-worse-behaviour-by-spies-says-former-gchq-chief/).

> [@](#):
>
> The excerpts as they stand don’t seem to be anything outrageous. It seems a perfectly reasonable assumption that surveillance will be driven in the direction stated.  
> _The author may be saying that is a good thing or a bad thing or he may be simply stating a neutral opinion_ but without then full context we can’t say.

Apparently the phrase “ethically worse” has some other meaning with which I have not been familiar. Could you expound upon that?

---

<div class="post-metadata">

**Author:** ![Kobal2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kobal2/32/20_2.png) [@Kobal2](https://boards.straightdope.com/u/Kobal2)\
**Post date:** [February 2, 2015, 4:15pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/16 "2015-02-02T16:15:09Z")

</div>

> [@Little\_Nemo](#):
>
> If you’re going to spied upon, intrusive spying is better than non-intrusive spying. At least then you know it’s happening.

And you can be more social, buy the guy tailing you 24/7 a cup of coffee once in a while, go over your weekly schedule together to see if there are ways you could be more accomodating of his own priorities, convene on the times when it might not be too disruptive for his team to ransack your entire house, maybe CC him your bank statements to spare him the hassle of breaking through your emails… it’s just a more humane way of doing things all around.

---

<div class="post-metadata">

**Author:** ![Bryan\_Ekers](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bryan_ekers/32/183_2.png) [@Bryan\_Ekers](https://boards.straightdope.com/u/Bryan_Ekers)\
**Post date:** [February 3, 2015, 2:42am UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/17 "2015-02-03T02:42:44Z")

</div>

> [@Kobal2](#):
>
> And you can be more social, buy the guy tailing you 24/7 a cup of coffee once in a while, go over your weekly schedule together to see if there are ways you could be more accomodating of his own priorities, convene on the times when it might not be too disruptive for his team to ransack your entire house, maybe CC him your bank statements to spare him the hassle of breaking through your emails… it’s just a more humane way of doing things all around.

[“Gary, here, never sees his daughter because of people like you!”](https://www.youtube.com/watch?v=Cizlx6ODhuE)

---

<div class="post-metadata">

**Author:** ![Novelty\_Bobble](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@Novelty\_Bobble](https://boards.straightdope.com/u/Novelty_Bobble)\
**Post date:** [February 3, 2015, 2:20pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/18 "2015-02-03T14:20:00Z")

</div>

> [@Steve\_MB](#):
>
> Apparently the phrase “ethically worse” has some other meaning with which I have not been familiar. Could you expound upon that?

It was clear to me when I wrote it, not so much now.🙂  
I think my point was that (from the excerpt alone) he isn’t necessarily suggesting that the intelligence services _should_ behave in an ethically worse way, but that…leopards and spots and whatnot…they probably will, and that the increase in encryption technology will push them down that track, but again he doesn’t seem to be making a value judgement on that. Of course once a spook always a spook.

Thanks for the article BTW, interestingly, reading to the bottom I can see this addition.

> [@](#):
>
> - This article was updated on January 28 after Sir David Omand contacted us to clarify and explain his remarks. The headline has been amended to say “Encryption risks leading to ‘ethically worse’ behaviour” instead of “Encryption will lead to ‘ethically worse’ behaviour”. We have also added a paragraph to explain Sir David’s belief that the security services would be put in an “ethically worse” position as a result of more encryption, not that they would set out to be “ethically worse” in their motives.

Which suggests that I’m not alone in my ambiguous reading of his comments.

---

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [February 3, 2015, 3:03pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/19 "2015-02-03T15:03:15Z")

</div>

> [@Novelty\_Bobble](#):
>
> It was clear to me when I wrote it, not so much now.🙂  
> I think my point was that (from the excerpt alone) he isn’t necessarily suggesting that the intelligence services _should_ behave in an ethically worse way, but that…leopards and spots and whatnot…they probably will, and that the increase in encryption technology will push them down that track, but again he doesn’t seem to be making a value judgement on that. Of course once a spook always a spook.
> 
> Thanks for the article BTW, interestingly, reading to the bottom I can see this addition.  
> Which suggests that I’m not alone in my ambiguous reading of his comments.

My point is that “direct access” methods are _not_ ethically worse, and in fact are ethically _better_, because their non-scaling labor-intensive resource requirements make it necessary for the police and intelligence agencies to pick and choose individual suspects rather than snoop on the entire population.

Of course, if Sir David’s “ethics” do not include a _work_ ethic, then I suppose he would see a protocol that forces agents to get off their butts and do legwork to be “worse” than one that allows them to sit at keyboards all day.

---

<div class="post-metadata">

**Author:** ![Novelty\_Bobble](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@Novelty\_Bobble](https://boards.straightdope.com/u/Novelty_Bobble)\
**Post date:** [February 3, 2015, 4:52pm UTC](https://boards.straightdope.com/t/better-privacy-means-less-privacy-wtf/710860/20 "2015-02-03T16:52:55Z")

</div>

> [@Steve\_MB](#):
>
> My point is that “direct access” methods are _not_ ethically worse, and in fact are ethically _better_, because their non-scaling labor-intensive resource requirements make it necessary for the police and intelligence agencies to pick and choose individual suspects rather than snoop on the entire population.

FWIW I’d agree. Greater _specific_ intrusion into carefully selected targets seems like a preferable position to the general trawling operation we currently have.
