Live data from Hacker News

Disapproval of FCC regulations a significant blow against privacy protection

nytimes.com

141–150 of 242 posts

Re: Disapproval of FCC regulations a significant blow against privacy protection

#141

Earlier quoted context omitted.

A better analogy would be FedEx selling your incoming and outgoing addresses and package weights to third parties, not necessarily the contents of your packages.

Why not the contents? What happens when most content is not over a secure connection such e.g. Over HTTP? Could they not inspect the content? It sure seems like they could. For most people most of the internet is still insecure.

Why not HTTPS? There are ways to do MITM proxing that re-encrypt traffic. As a customer, you just need to install their CA certificate.

Or slightly worse, they could get browser vendors to include their CA (or pass legislation to force this).

What prevents this from happening?

In mobile, where the carrier controls everything (the network, the OS) it's not unlikely this is already happening.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#142

Earlier quoted context omitted.

Sure, but there's a cost to exercise that right. Right now, the cost of protecting myself from my ISP is quite high. I need to maintain DNS and VPN settings for every device in my home... many of which are personal devices of other family members with little patience for such techno-babble. I want a product that reduces the cost of exercising my right to privacy, and allows me to pay that cost with money instead of t…

There are commercially-available routers which support running all traffic through a VPN. That should handle all the devices in your house.

A VPN doesn't actually provide more privacy, it just changes who can snoop on your data.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#143
post #127
post #21

> In 2016, the F.C.C., which I led as chairman under President Barack Obama, extended those same protections to the internet. Oh how nice of Tom Wheeler to play the good-guy now. It took a lot of public outcry for him to change his tune about Net Neutrality.

> Oh how nice of Tom Wheeler to play the good-guy now. It took a lot of public outcry for him to change his tune about Net Neutrality. That's wrong. He was for net neutrality from day one at the FCC. You are probably thinking of the first net neutrality rule he proposed, which would have allowed for paid fast lanes, and interpreting that as somehow not being for net neutrality. When he proposed that rule that was abo…

> You are probably thinking of the first net neutrality rule he proposed, which would have allowed for paid fast lanes

That was the second; the first he got passed did not, but it was struck down by the courts for exceeding the power the FCC had without Title II reclassification. The draft of the replacement might have allowed paid prioritization (it was clearly not intended to, but it was limited because it attempted to stay within the boundaries of what would pass muster without Title II reclassification.) The final replacement order opted for Title reclassification, and was not only stronger than the draft, but stronger in many ways that the 2010 order it replaced.

Wheeler was always on the side of net neutrality, and in fact his actions in favor of it are one of the main reasons the issue became well known.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#144

Earlier quoted context omitted.

Yea that was my main question during this. What can we do. I thought https made this near impossible unless they MITM it, which would be difficult no? Or is it easy? This is all the more reason we need to start encrypting all communication. All my hand built services (home bots, etc) need to start using tls for everything.

Three problems here. First being that the ISP is a permanent MITM. Second is that TLS will not protect the hostnames, which are sent in the clear so that servers can identify the correct certificate for a given connection. Likewise, DNS is not encrypted (though companies like OpenDNS do provide alternatives here).

Regarding the MITM, more specifically i meant able to compromise HTTPS. If i sit between you and your https site, can i read all of your traffic?

I know very little about the nitty gritty of HTTPS, so forgive my ignorance, but i thought the most i could do was try to pass off a custom key (ie, spoof the key authority), but then the signing done from the https site (say, https://google.com) wouldn't be valid based on my bad key.

How common is it to read full https data if you're a MITM?

Re: Disapproval of FCC regulations a significant blow against privacy protection

#145
post #40

So the only thing I don't understand as far as the fuss about this is concerned -- everything I've read indicates that this is undoing a protection put in place late last year. So essentially we've gone back in time six months ago or so. If ISPs weren't selling our info then when they could have, why does it logically follow that we're now in some uncharted territory of ISPs selling personal info? Or is this simply b…

Here is a less editorialized summary of the bill: https://www.govtrack.us/congress/votes/115-2017/h202 It repealed 73 pages [1] of regulation on ISPs. Personally, I'd like to see more competition in the ISP space. This bill may help by reducing barrier to entry, but the central problem remains that national carriers have lobbied the state to prevent competition at the municipal level. Furthermore, this bill seems lik…

> Furthermore, this bill seems like a minor nuisance compared to the data collected by Facebook, Google, and the NSA.

This is the bullshit argument Republicans/ISPs are pushing that anyone technical should immediately realize as such. It's conflating two separate issues.

I can choose whether or not to use Google and Facebook, and indeed willingly "agree" to their TOS when I log on. But to even get to those providers, I need to go through an ISP. As someone in rural America, I don't have a choice in ISPs, and even in a lot of cities where you have "choice," they all share the same privacy-invading practices. That's the point of the rules passed by the FCC: protecting us, the consumers who are subject to the whims of anti-competitive corporations that have access to large swaths of our personal data.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#146
post #122

Earlier quoted context omitted.

What part of saying privacy/security comes at cost is trolling? It does. Whether you pay money directly or for lost access to features like persistent geolocation, using closed source internet-connect applications, etc, etc. Unless I'm missing something bad the OP said.

The Supreme Court recognized on multiple occasions that we have a right to privacy. In this specific instance, protecting privacy comes at no cost to an ISP, as they simply do not collect or sell your data. They literally have to do nothing, as setting up the systems to collect and opening the channels to sell takes work. This nothnig more than money grab.

> The Supreme Court recognized on multiple occasions that we have a right to privacy.

The right to privacy... from the government, not private businesses.

There are privacy regulations which affect private business such as HIPAA. But these are not 'rights'.

And just because they are regulated doesn't mean they are effective at the intended or worth the significant costs of implementation - which is the critique here. So unlike government where the risks are a certainty (because we give the state a monopoly on violence and other powers), the risks of private companies selling data are not nearly in the same league, regardless if you believe regulations are the way to go.

I personally would like to be able to invest money so we don't have to worry about ISPs selling data. TLS/VPNs are a solved problem. Same with the opportunity to use adblockers... ad companies collect as much data and that is entirely unregulated. No one seems to care. We just say 'use an ad-blocker'... a private solution. 'Do not track' regulations were a total failure.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#147
post #132

I want a privacy first router. Does such a product exist? Key features: - I pay a subscription for maintenance (so I'm not the product) say $10/mo - Automatically routes all traffic over a VPN. - Smart VPN bypass for performance-sensitive traffic like streaming video and gaming - Provides non-logging DNS service - Automatic advertisement blocking For VPN, DNS, and adblock I want the option to use servers & block list…

> VPN This is a political problem. Technology like a VPN or alternative DNS is little more than a placebo. With the ISP as a permanent MitM, modern deep-packet inspection, etc , you are probably still leaking a lot of information. Worse, you're only moving the problem to a different location. Even if you were able to hide your traffic from your local ISP, your VPN host or DNS service becomes your ISP de facto . Also,…

> Worse, you're only moving the problem to a different location

I agree that's true from a technical perspective. However, the VPN provider has an economic incentive to compete on privacy. I would much rather just trust my local ISP, but at least I have a choice in VPN providers.

> privacy shouldn't be limited to people with a technical background

Absolutely. That's why I want this as a product that Just Works instead of my own hacked-up implementation.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#148

Earlier quoted context omitted.

Start with not using their DNS servers (OpenDNS https://www.opendns.com ) Install HTTPS Everywhere ( https://www.eff.org/https-everywhere ) Install uBlock Origin (Chrome - https://chrome.google.com/.../ublock-origin / Firefox https://addons.mozilla.org/addon/ublock-origin/ )

Concur with your recommendations. Would throw some caution on the OpenDNS recommendation, though. They're U.S. based and owned by Cisco. Depending on your threat model, this may or may not be desirable.

I debated about the recommendation, but went with the simplest one to start.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#149

Earlier quoted context omitted.

Start with not using their DNS servers (OpenDNS https://www.opendns.com ) Install HTTPS Everywhere ( https://www.eff.org/https-everywhere ) Install uBlock Origin (Chrome - https://chrome.google.com/.../ublock-origin / Firefox https://addons.mozilla.org/addon/ublock-origin/ )

Just because you're not using their DNS servers doesn't mean they still don't see the DNS requests as its sent through their pipes and log them.

Correct, but it is a start.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#150

I am a strong advocate for privacy, please understand that before you continue reading this. I don't want ISPs to sell my browsing history, and I am continually disappointed in the Republican opposition to net neutrality and online privacy. I'm even working on an open source project involving cryptography and secret protection, so I have skin in the game. However, this headline is patently false, right? Congress didn…

Don't have a moment to read your sources at the moment. But weren't the protections only put into place last year because they weren't needed until then? In other words, they were under the jurisdiction of the FTC previously, so this particular legislation a moot point, because the FTC could just say "hey, you can't do that. case closed." Now because of the "common carrier exemption" I don't think that would hold up.…

If legal opinion is now that the FTC does not have the ability to regulate internet privacy, it is not the fault of congress, it is the fault of the 9th circuit's ruling ruling last year [1], which has effect over its area of jurisdiction.

Traditionally it is the FTC which regulates consumer privacy. The republican's position w.r.t. internet privacy is that regulating this is in the domain of the FTC, as has always been the case before [2][3][4].

Sources:

[1] https://iapp.org/news/a/the-att-v-ftc-common-carrier-ruling-...

[2] http://transition.fcc.gov/Daily_Releases/Daily_Business/2017...

[3] https://www.ftc.gov/news-events/media-resources/protecting-c...

[4] http://www.heritage.org/crime-and-justice/commentary/the-ftc...

Post reply on HN