Friday, 16 January 2026

Privacy, Secrecy and Creepy Snooping

Privacy and secrecy are different. Secrecy is me not telling you. Security is taking steps to prevent you finding out. Privacy is you not snooping on me to find out, and consideration is you not imposing your presence on me.

If I notice George Clooney at the table next to me, and carry on with my coffee and newspaper, not saying anything, I am being considerate. If you ask for his autograph, you are not. His identity and presence is not a secret, but the low voice in which he and his companion are talking is a simple security measure. If you try to listen, you are invading his privacy, and if I make no such attempt, I am respecting his privacy.

Privacy is defined in by contrast with "public". We have a concept of a public space - roughly as anywhere anyone can go without needing permission from the owner of the space - and the law says that we have no expectation of privacy in a public space. That street photographer can take a photograph of you. The most you can do is ask her not to publish the photograph. We have a concept of public knowledge - which is available from sources that anyone can look at without needing permission from the owner of the source. Newspaper articles, electoral rolls, the registers at Companies House, the Land Registry, documentaries, non-fiction books, plus anything that can be observed about you in the ordinary way. That Sally's hair is blonde is public knowledge, that it is actually mousy brunette, is known only to her hairdresser.

Any knowledge that is not public, is private, and trying to obtain that knowledge without the subject's permission is an "invasion of privacy". In almost every society in history, if I want to know something about even a friend, that is not available from observation in a public space or not available in public records and sources, good manners dictate that I ask them if I may ask them, and not take offence if they do not want to tell me.

I do that for the same reason that I pay my bills, do honest business, respect other people's property, and treat people with courtesy and dignity: it is good for business and makes for a liveable society. Societies in which people refrain from snooping on each other are more pleasant, as are families, marriages, friendships, workplaces, and even Sunday football teams.

We often mix up the ideas of secrecy, security, privacy and consideration. A conversation in a noisy cafe is difficult to overhear, and in ordinary language, we might say we had a private conversation there. But we didn't, we had a secret one. We didn't tell you we were meeting (secrecy) and we took steps to make it difficult to hear what we were talking about (security). A better-mannered colleague than you, passing by the cafe (public space) saw us talking and noting our body language (public knowledge) guessed we were having a meeting we did not want others to know about. However, they carried on (consideration) and made no attempt to find out what we were talking about (privacy).

When privacy activists talk about a "right to privacy", what they mean is "people should not snoop, especially the State". The principle that we are under no obligation to incriminate ourselves is close to a "right to secrecy".

The State rightly regards device and communication encryption as security to preserve secrecy, even if the initial intention was to stop those creeps at Meta from gathering every last thing they can get. When those security measures enable criminality, the State is right to ask on our behalf that something be done to disable the criminality.

One of the State's suggestions is client-side scanning of everyone's internet-connected devices all the time. This is snooping, an invasion of everyone's privacy, without proof of cause. Thus Lord Denning in Anton Piller KG v Manufacturing Processes Limited
Let me say at once that no court in this land has any power to issue a search warrant to enter a man's house so as to see if there are papers or documents there which are of an incriminating nature, whether libels or infringements of copyright or anything else of the kind. No constable or bailiff can knock at the door and demand entry so as to inspect papers or documents. The householder can shut the door in his face and say, "Get out."
Denning was re-stating the doctrine that "fishing expeditions" - the speculative gathering of information and looking for evidence of something criminal in it - are unacceptable. English Law prefers the Police to have a specific charge and a specific complaint, and can only gather evidence related to it. This has roots in practicality as well as respect for privacy.

Unfortunately, the Internet, cheap data storage and very fast processing, plus the (false) promise of accurate analysis by so-called "AI", removes the constraint of practicality. No-one would suggest gathering and analysing data from 500,000,000 people (online population of the EU) on a daily basis otherwise. What remains is a respect for privacy. The State claims that the detection of CSAM, and terrorist recruitment and propaganda, as more important than everyone's expectation that they will only be investigated if there is a specific charge. Certainly our "rights" sometimes conflict and need to be prioritised, and the way we prioritise those rights is itself a moral and political issue.

Even if we decide that client-side scanning is justified in certain cases under strict conditions, it will be snooping. It might be legal, and it may have good intentions, but it will still be snooping and it will still be creepy. Which will have repercussions on the way people feel about the State.

Friday, 9 January 2026

Client-Side Scanning Of Your Mobile Phone and Other Devices

For more than a decade, there has been as much internet security as anyone would want. HTTPS means anyone wanting to read your traffic has to de-crypt it, which is expensive, though they will know where it is going. VPNs removed that last bit of information. Client-side scanning is any way of looking at your device content before it is encrypted (on the send side) or after it is decrypted (on the receive side).

Let's assume that the privacy lobby's worst fears about mission creep come true, and that by, say 2030, all our devices have client-side scanning for all file types. See this paper for an example of the way the discussion is going.

Whatever we look at, type, write, read, say or hear will be sent to Government servers and scanned by AI, for evidence of an ever-increasing number of offences. (Yes there will be mediators, but they will not be English lawyers versed in the nuances of Western culture. They will be low-paid, off-shore workers in a non-European country.)

Client-side scanning will need Parliamentary approval. Everyone will be able to see it coming from a mile away and prepare for it.

The majority of users, who are well-mannered and law-abiding citizens, will not change their behaviour, as why should they? At the other extreme, Serious People doing Something Very Bad who want to go on doing it will have plenty of time to organise and convert to off-line ways of doing it. Their online behaviour will look utterly law-abiding. People who have been opportunistically doing Something Very Bad because modern devices made it easy and encryption made it reasonably un-identifiable, will either join the Serious People, or stop doing it. Lawyers and corporate executives will ask "do I want the Regulator / prosecution / HMRC / whoever else to see this?" and if the answer is NO, they will arrange an in-person meeting to communicate it.

The introduction of client-side scanning will, in other words, sanitise the Internet, remove some of the easy-come easy-go misbehaviour, but otherwise leave the real world unchanged. Cyber-bullying will stop, but old-fashioned bullying in-person will carry on. Conspiracies against the State will be discussed as before in quiet corners of noisy restaurants. Prices will be fixed by managers in queues for popular take-aways. People will need to work a little harder to conspire.

After a year or so, when the hot-heads have cooled down and the privacy activists have been imprisoned, scanning will be an expensive deterrent that does stop casual, opportunist law-breaking and activism, but does not stop the serious people. Universal cradle-to-grave client-side scanning will be the end of the Wild West of the Internet. That's probably a Good Thing.

Well, until we look at the practicalities.

First, scanning and subsequent identification by AI or other means will generate false positives: innocent images, voice calls, texts or e-mails that get classified as Bad. Liberal activists don't care about that - eggs and omelettes and all that - but the grown-ups at Apple do, which is why they abandoned their iCloud scanning development at the end of 2022.

Second, it will be easy for a malicious person to mess with your life. All they need to do is send you Bad Content, which the client-side scanner on your device will identify and report you as having. Before you even know it is there. We don't think about this now because we can delete the dodgy stuff if it ever reaches us. It does not even need to be malicious. All sorts of stuff gets returned by a Google search that we never see and didn't ask for. Apple et al will need to build in the facility to block images and files being sent to mail, messaging and other apps on their devices, while still allowing e.g. music streams and videos.

Third, remember the farce that was the Covid app? Billions of the taxpayers' money spent on a program with more flaws than a cheap diamond? What makes you think Government-specified client-side scanning will be any better? Scanning software needs to operate at a very deep level (the "kernel") of the device's operating system. Nobody outside Apple (for iOS), Google (for Android) and Microsoft (for Windows) has the detailed kernel-level knowledge required to write it well. If previous projects are a guide, the scanning software will be developed by low-bid sub-contractors who will scatter to the four winds a month after they are paid. That's how Government IT contracts work. So our phones, tablets and even maybe laptops will freeze until re-boot, brick themselves beyond re-boot, stutter, lock us out, fail to run apps at random and otherwise misbehave. Not a few devices once a year, but every device every month.

Client-side scanning is a terrific deterrent. Shame it will create way more problems than it will solve. But then, you know, it is better that ten innocent people are wrongly found guilty than one guilty person is wrongly found innocent. 
At least, I think that was the quote.

Friday, 2 January 2026

A Prosperous 2026 To You

This year I am making no resolutions. 

There may be things I need to change, but either I can't figure out what or I know I won't be arsed to do them. Or it could be that while I have physically recovered from The Flu, my brain is not really up for constructive, pro-active thought.

Plus it's sodding cold (anything below 40F is "sodding cold"). 

I have been meditating on these lyrics from Taylor Swift's Florida

Little did you know
your home's really only
a town you're just a guest in

There you are, thinking you're living somewhere that's home, and then you do something, or you stop following the herd, and suddenly it's just a town, any old town, and they think of you as just some tourist in a hotel room. Tolerated, not accepted; with no rights of residence, so move along now they're tired of you. 

At least in Bob Dylan's Just Like Tom Thumb's Blues 

If you're lookin' to get silly
You better go back to from where you came
Because the cops don't need you
And, man, they expect the same

we already know we're a tourist there, and can "go back to New York City". In Taylor Swift's song, we lose our home and have to sit out the "shit storm back in Texas" in that mythical land of escape, Florida.


Warning: this is a track that can easily wind up on repeat.

Friday, 26 December 2025

Niina - Girls Just Wanna Have Fun (Happy Boxing Day)

 

 Qobuz suggested this earlier in the year. It took a couple of listens before I heard the lines "Cherries for breakfast / and pancakes for lunch / and I'm not being silly / and I'm not being drunk" which may be the best lyrics of 2025.

Have a good Boxing Day.

Friday, 19 December 2025

Flu Recovery (Week Three)

This recovery is slow. I have had a three-day fever followed by a week's weakness before, but I was a sprightly lad in my late fifties when that happened, so it wasn't quite as lingering as this. I've gone out and about three days this week - Thursday was too wet - but I've avoided the mile walk to and from the local station and have been driving into Richmond instead. When I've come back, I have dived under the blankets to rest for an hour or so. I've watched so much You Tube over the last three weeks, the algorithm has run out of suggestions.

I have, however, understood my brief obsession with wild camping videos, and not just because the ones the algorithm served me were from Katie Roams and WIldBeare. Nope, it's all about building a cozy wrapped-up, place to sleep. Just like I do on the couch during the day and the bed at night. Except they have rain hammering on a thin plastic tent and the outside temperature is way lower than I could sleep in. And the ground is damp.

Katie Roams

WildBeare

In the UK, wild campers need the permission of the land-holders to camp on their land. However, camping without permission is a civil offence, not a criminal one, so the Police are not involved, leaving the landowner would need to prove that Katie Camps had camped on their land and then bring an action in civil court. Which means they would need to actually catch her doing so, and that would mean sending people to search for near-camouflaged tents in the hours between dusk and dawn. Which is not going to happen. Because the two rules of wild camping are: a) arrive late, leave early; b) leave no trace. Follow those and the odds of being caught are de minimus. This may explain why the sites these You Tubers choose are, at least in the UK, so generic. One recognisable landmark, and the video is proof enough.

I want my brain back.

Friday, 12 December 2025

A Brief History of My Fever and Flu

As far as I can work out - given three days' incubation - it was someone on SouthWest Trains on the 27th of November. According to one article about what pupils in various schools were being sent home for, I had three options: Covid, the H3N2 flu virus, and something called RSV (Respiratory syncytial virus). It can't be Covid, because the Government told me I would be immune if I had my jabs back in 2021, which I did. RSV is apparently always with us in winter, but the symptoms didn't match. That leaves the H3N2 virus, which gave me a three-day fever and left me weak as kitten for days afterwards: I lost four kilos in four days, and as of writing, have only got one of them back. I came down on Sunday 30th November and didn't leave the house until Sat 6th December when I went out to do some food shopping. For the next week, I managed to go out for a half-hour walk each day. Walking on level ground was okay, but steps and stairs required a rest half-way up. This last week I have made some trips by train (the persistent winter cough is calm at the moment, unless I get a severe change of air). Stairs and steps still need half-speed.

In the meantime, my brain is functioning at about 80% for 5-6 hours a day and then sends me to sleep on the sofa under blankets or to bed at night. (Eating too heavily at lunchtime also sends me into nap mode.) Routine stuff got done, but anything requiring thought and actual decision-making is still on hold. Yes, I have fallen asleep with far too many You Tube videos droning away in the background.

The bureaucrats (some of whom are doctors and "health experts") are saying that it's all our fault for not getting the "flu jab" earlier in the autumn, despite the fact that this year's flu jab is useless against H3N2. Flu jabs are developed to counteract whatever goes around Australia and the Far East in our summer (their winter) and that works about seven years out of ten. The other three, we have a "bad winter flu". I have had the flu jab once: I felt like c**p for two days afterwards and caught a really bad cold afterwards. So that works.

2025 seems a long way away already. A fever will do that to you.

Friday, 5 December 2025

Millennium Bridge


I'm not sure why I like this. Maybe because the perspective feels wonky? What with Blackfriars Bridge seeming underneath the Millennium Bridge. And all those people standing on something that looks unsupported?