Protection or threat? The pros and cons of the ’Dragnet’ Act
Protection or threat? The pros and cons of the ’Dragnet’ Act

Protection or threat? The pros and cons of the ’Dragnet’ Act

Which is more at risk: our national security or our privacy? That is the consideration the Dutch parliament must make when assessing a temporary law on our intelligence and security services. The intelligence and security services want more powers, without prior assessment. “We are being restricted in our fundamental rights without being aware of it.”

Suppose a General Intelligence and Security Service of the Netherlands (AIVD) officer could read all your emails and chat messages, that he or she could track exactly what websites you visit, what music you listen to, and what films you watch. Or imagine that an algorithm, searching for ‘suspicious’ word combinations, also searched your digital communications – not because you are a suspect, but because you happen to be using the same Internet cable as people who do pose a threat to the state. With the recent Child Benefits Scandal in mind, that is probably not a pleasant thought. Do we want to give the AIVD this power? On the other hand, what if a foreign hacker uses the same cable to extract secret company information, and the AIVD is unable to prevent it?

Such dilemmas play a role in the House of Representatives’ decision on whether to extend the powers of the Dutch intelligence and security services. With the amendment of the 2017 Intelligence and Security Services Act (Wiv 2017), which sets out the powers of the security services and the monitoring of their use of these powers, the services will be given more leeway. This is supposedly necessary due to the growing threat of cyber attacks from countries such as Russia and China, which the services recently warned about.

Opponents of the law, including the Bits of Freedom Foundation, point instead to the risks the new law poses for our privacy. The committee responsible for monitoring whether the services are justified in using their powers, the Toetsingscommissie Inzet Bevoegdheden (TIB), is also vehemently opposed to the new law. TIB member and technical expert Bert Hubert resigned in September in protest and sought publicity in an effort to turn public opinion. “People have no experience of the privacy disadvantages. No one has ever failed to get a job because of a text message overheard by the AIVD.” This unfortunately makes it an abstract concept, while the proposed change in legislation affects us all.

Eavesdropping

Proponents of the changes often refer to the Wiv 2017 as the Cyber Law, while opponents prefer to speak of the ‘Sleepwet’, a reference to the Dutch word ‘sleepnet’, meaning ‘dragnet’. The temporary law lists a long series of interventions (see ‘Main changes to the temporary law’ box) that should make it easier for security services to detect terrorists and foreign spies in time by hacking and intercepting all kinds of communication channels. Think of all the channels used by spies, as well as by Dutch citizens, to communicate: personal computers and phones, but also entire internet cables, servers, business software, apps, and so on.

The TIB was created in 2018 to ensure that the AIVD (General Intelligence and Security Service) and the MIVD (Military Intelligence and Security Service) would not exceed their constitutional limits in this context. The regulatory body assesses in advance whether interception is necessary, whether it is sufficiently targeted, and whether it does not unnecessarily affect random citizens. The TIB also assesses whether the action is proportionate, and whether the same result could also be achieved with less intrusive actions.

Over the past four years, the TIB has repeatedly had to pull back the Minister, under whose approval the services operate. For example, when the law first came into force in 2018, people’s biggest fear was that the services would randomly start tapping internet cables. In reality, for the past four years, the services were not able to tap any cable for content, because the TIB did not allow it. This is exactly what the intelligence services object to. What’s more, the whole process of seeking permission involves additional red tape, leaving less time for real detective work. As early as in the spring of 2021, the Court of Audit was forced to conclude that the power of the secret services left much to be desired. Approximately 10% of their staff would have to be deployed to deal with the additional demands of the legislation. “Countries like Russia and China can do whatever they want, but we have ethical principles,” the outgoing Defence Minister Henk Kamp complained last January in NRC. If the change in legislation was to go through, the TIB would have fewer opportunities to pull back the services in advance.

Main changes to the temporary law

  • If the services want to eavesdrop on or copy computers or phones that are also used by innocent third parties, they would be able to do so without prior consent. This ‘side-hacking’ currently requires prior permission from the TIB.
  • Under the new legislation, the services would be allowed, without further ado, to wiretap any cable for a year ‘for reconnaissance purposes’. They would not have to provide a single reason for this. They would, however, have to ask for permission to then use the data for a deeper intelligence process.
  • The services would be allowed, without prior consent from TIB, to have their computers and algorithms search communication traffic intercepted in bulk for targets.
  • It would be possible to indefinitely keep bulk files that had not been tested for relevance, if the CTIVD gave permission for it.
  • The services could appeal against the decisions of the TIB and the CTIVD to the Council of State. In these cases, the ultimate decision would rest with the judge.
  • The proposed legislation facilitates strategic hacks on companies. For example, the services no longer have to explicitly disclose to the TIB the technical risks of their actions.
  • Much of the monitoring of the security services that is currently done upfront would shift to retroactive assessment. This covers actions investigating cyber threats from blacklisted countries such as Russia, China, and Iran.

Most applications approved

A growing threat of cyber attacks, combined with secret services that can no longer vouch for our national security due to all the red tape and cumbersome protocols: that sounds serious. Yet the TIB’s annual reports do not give the impression that the services’ wings are clipped. In recent years, the TIB has approved the vast majority of the services’ applications. In 2021, for example, the AIVD and MIVD jointly submitted 3,071 requests. Of these, the AIVD had to cancel 3.3%, and the MIVD 7%. By the way, these numbers say nothing about the content of the applications – so it may be that the few cases that were rejected happened to be crucial.

The services find the slowness of the approval process to be too prohibitive. But if matters are really urgent, the services can always use an emergency procedure; investigators can then start straight away, without waiting for a response from the TIB. In 2021, this happened 101 times. “The services prefer to ask for permission less often, because the entire procedure takes three weeks,” Hubert says. “However, of these three weeks, the TIB only needs three days to assess the application. This means that part of the bureaucracy lies with the services themselves, and a lot can be done without necessarily having to change the law. This is an aspect I'm missing in the debate around the Wiv 2017.”

Snooping around on internet cables

One of the controversial amendments to the law concerns so-called untargeted cable interception: the services would be allowed to intercept any cable for a year ‘for reconnaissance purposes’, without permission from the TIB. So far, such permission has always been required. In 2021, for example, the regulatory body refused to give permission for this twice. In the first case, a fair amount of the internet traffic of Dutch citizens and other parties would have been stored and ended up unseen in the hands of a foreign security service. It was unclear to the TIB how this would contribute to the security of the Netherlands. In the second request, the regulator felt that there was a danger that intelligence and security service employees would also be able to track for random Dutch citizens who visited which websites at what time. Once again, the TIB did not find the procedure to be justifiable under the security objective described by the AIVD.

Instead of targeted searches for important information on internet cables, the proposed legislative amendments would allow the services to take untargeted ‘snapshots’ of our internet traffic as part of future investigations into countries with aggressive cyber programmes against the Netherlands. If those snapshots, i.e. samples, point to suspicious dealings, they could lead to a new investigation request. Only then would the AIVD have to seek permission from the TIB to investigate matters further.

Hubert finds this to be a worrying development. “Right now, the intelligence services have to provide a serious reason for snooping around on cable. Soon they will be able to do so on any cable, even if it runs to the Media Park, or to a student complex with lots of international students.”

Foto door Etienne Girardet via Unsplash.

Radboud University Professor of Digital Security and member of the evaluation committee responsible for assessing the monitoring of the services Bart Jacobs does not share these concerns. “Hubert is reducing the action to intercepting the communications of a known individual. The point is precisely that you don’t know in advance whose communications you should intercept. If the services were allowed to properly explore what is happening on a cable beforehand, they could bring in more targeted data. So you could say that this is actually better for our privacy.”

An AIVD spokesman informed us that the services were not at all interested in eavesdropping on innocent citizens. “This law was submitted to protect the Netherlands and Dutch interests from countries with offensive cyber programmes – a real threat – and not to invade citizens’ privacy.”

Lotte Houwing, policy advisor at Bits of Freedom, does not find this reassuring at all. “You’re basically saying: in order to see who we want to tap, we first tap everyone. And this is supposed to allay our concerns about breaches of privacy.”

Strategic hacks

Another planned change is to make it easier for the services to ‘strategically hack’ companies. For example, the security services could break into a company like Strava, the app that tracks location data for runners. Incredibly useful if you want to find out the exact location of an individual dangerous to the state. Under the new law, the services would no longer have to detail the technical risks involved in the hack, for example when using zero days, software leaks.

That can be risky, Hubert says. “Suppose you’re following a spy through a software leak in his Android phone. If this spy is simultaneously also being followed by the Iranian government, you risk them discovering the leak and being able to hack all Android phones.”

According to Houwing, this has consequences at several levels. It prevents the TIB from factoring technical risks into their assessment of an application, but it also makes the services less motivated, a priori, to seriously consider such risks. “If you know that the regulatory body will be looking into these technical risks, you already start thinking about it from a different perspective. Of course, the services have an interest in deploying their hacking power without anyone finding out, but that is a consideration based on their own interests, not those of citizens.”

Rowin Jansen, researcher at Radboud University and expert in the field of intelligence services, says that as it stands, strategic operations almost automatically lead to a disagreement with the regulator. This is due to the vagueness of the current law. “In a strategic operation, you have to deploy certain powers with the aim of building up an information position, which you will only benefit from at a later stage,” he explains. “Setting up an informant network abroad is also a strategic operation. In the digital context, the legislation allows for this, but without providing any clear frameworks. That makes it very difficult to regulate this.”

The TIB tests every power of the security services, including strategic hacks therefore, in terms of its necessity, proportionality, targeting and subsidiarity. “The problem is that these kinds of operations are often not that targeted,” says Jansen. “They may be necessary, but any benefit they may bring is in the future, so you cannot know in advance whether the hack is proportional, or not. This requires further interpretation by the legislator, but that is quite complex.”

Difficult task

While the TIB will have less opportunity to carry out advance assessments of the AIVD and MIVD, a second review committee, the Intelligence and Security Services Regulatory Commission (CTIVD), will actually gain more powers. The CTIVD currently tests the security services’ compliance with rules during and after the fact. The committee is allowed, even now, to interview any AIVD and MIVD employees, look into files, and sift through dossiers. Under the proposed law, if the CTIVD concludes that the services have broken the rules, they have the power to pull the emergency brake as yet in some cases. The security services must then discontinue the contested action. The Minister responsible for the services can, in such cases, appeal against the decision of the CTIVD to the Council of State. In such cases, it is ultimately the judge who decides whether the services can go ahead, or not.

Jansen is not convinced by this proposed power structure. “A certain amount of decision-making power is shifting to the courts, which are thereby assigned a very difficult task, precisely because these are operations that involve many individual rights. It is not always clear in advance exactly how to conduct the assessment; there is a certain value-based element in that. This can lead to the judge forbidding certain investigations, while politicians in The Hague might believe, for all sorts of other reasons, that these investigations should be allowed. This creates a very difficult field of tension. We really need to think about it in fundamental terms.”

Safeguarding the rule of law

Paul Bovend'Eert, Professor of constitutional law at Radboud University, is very surprised to hear that the new law will weaken the TIB's position. He was a member of the legal committee that on the contrary advised the Dutch government this spring to strengthen ex-ante supervision. In fact, the European Court of Human Rights has been increasingly vocal about the importance of independently monitoring intelligence and security services. “Of course, you can also opt for a minimal variant, but why not ensure that the rule of law is adequately safeguarded?” he says. “This proposal actually weakens our legal protection.”

The fact that the CTIVD will have more power to intervene does not reassure him. “The harm is already done by then. Privacy has already been invaded, the information has already been collected, and the intelligence services have already gone too far.”

The proposed law is a temporary amendment: in approximately five years' time, the supervision law should take definite shape. However, Bovend'Eert fears that the current changes are a prelude to abolishing all ex-ante supervision. “After some years, the AIVD and MIVD can say: we’ve applied this model to offensive cyber countries and it’s going so well, let’s extend it to the entire law. It’s in their interest to have the widest possible powers for their investigations. On the other hand, there is the importance of the rule of law. We are being restricted in our fundamental rights without being aware of it. To still be able to monitor this government, you need a body that can exercise this regulatory power in confidence. Otherwise, you are squandering the rule of law.”

This article is a translation of an article written in Dutch by Enith Vlooswijk that appeared earlier on NEMO Kennislink. Foto door Jefferson Santos via Unsplash.

Contact information

Theme
Media & Communication, Law, Current affairs