Live data from Hacker News

Deep packet inspection is dead, and here's why (2017)

security.ias.edu

121–126 of 126 posts

Re: Deep packet inspection is dead, and here's why (2017)

#121
I think (and hope), that the next big thing (after https) -- will be VPNs by default. (and independent from the internet provider service).

By default, nobody, and I mean, nobody needs to know ones home IP address, period. And nobody needs know what sites a person visit or when.

So not only DPI should go away, but also IP address-based blacklisting/whitelisting, tracking/ advertising and so on.

Re: Deep packet inspection is dead, and here's why (2017)

#122
post #59

Earlier quoted context omitted.

> On the other hand, the owner of a network has some right to look into the packets on that network. I don't agree. If you let a guest use your WiFi network for instance, there's no inherent moral right for you to intercept their emails. However I generally agree with the principle that if you own a device, you have the right to learn what it's doing, and the trend towards black boxes is concerning.

You have no more right to learn what a particular device is doing than you have in intercepting emails of guests on Wi-Fi. You might have purchased a particular device, but you generally don't have the rights to the software or firmware that runs it. If you're truly concerned, you should support manufacturers that leave their system open by design, or support open source devices, and contact manufacturers describing…

> but you generally don't have the rights to the software or firmware that runs it

Legally this is correct in certain jurisdictions. But I'd say this is similar to arguing that you have no right to know the ingredients in food you buy.

Re: Deep packet inspection is dead, and here's why (2017)

#123

Earlier quoted context omitted.

Yes, with fewer features. Don't make the mistake of thinking you are a representative of all customers. YOU may not care about connectivity, but others, many others, do.

Yes, but the right way to do this is to get a separate device for the connectivity part, in order to protect yourself against services having much shorter lifetime than hardware. Techies knows this, and customers who got burned on smart TVs know this too. Regular people don't always realize this, but companies pushing smart TVs know this perfectly well . This is pretty obvious planned obsolescence. In my eyes, it's s…

I recently got a smart TV, and I use the netflix app built into it, as well as the general video player for playing files I have on my computer's media server... But I used to just use my Playstation for that before I got a tv with the apps.

As long as the tv has import ports I can use other devices than the TV itself to get content so I'm not really concerned about that.

I bought the TV because it was good at being a TV - that is, it is OLED, high res, good upscaling, etc. The "smart" stuff I could take or leave, but I'm enjoying the convenience of it while it works.

Re: Deep packet inspection is dead, and here's why (2017)

#124
post #89

Earlier quoted context omitted.

I would also smash any 2.4gz antennas inside the TV for a good measure. They might not have access to your WiFi network, but the XFinitiWiFi is available to any TV maker for a modest sum of money. That, or you can buy a commercial display instead of a TV.

4G radios are also pretty cheap now and antennas can be embedded on-circuit.. Might need to invest in a large Faraday cage

Don’t forget that tin foil hat!

Re: Deep packet inspection is dead, and here's why (2017)

#125
post #25

I'm worried about this development. One the one hand, ubiquitous encryption is simply required for security on the internet. Things like lets encrypt and warning on http are great improvements. On the other hand, the owner of a network has some right to look into the packets on that network. Especially if the owner of the network also owns the end-points of that traffic. My main use-case here isn't corporate networks…

You have a choice. Boycott especially egregious offenders and packet filter and deny service to any suspicious device on _your_ home network.

Years ago sticking these types of devices on a trusted home LAN would have been unthinkable.

Re: Deep packet inspection is dead, and here's why (2017)

#126
post #59

Earlier quoted context omitted.

> On the other hand, the owner of a network has some right to look into the packets on that network. I don't agree. If you let a guest use your WiFi network for instance, there's no inherent moral right for you to intercept their emails. However I generally agree with the principle that if you own a device, you have the right to learn what it's doing, and the trend towards black boxes is concerning.

You have no more right to learn what a particular device is doing than you have in intercepting emails of guests on Wi-Fi. You might have purchased a particular device, but you generally don't have the rights to the software or firmware that runs it. If you're truly concerned, you should support manufacturers that leave their system open by design, or support open source devices, and contact manufacturers describing…

> You might have purchased a particular device, but you generally don't have the rights to the software or firmware that runs it.

True, I don't have a right to see their source code. But decent laws shouldn't prevent me from reverse-engineering the code (DMCA is not a decent law).

Moreover, access to code is orthogonal to control over devices one owns. If I own a device, I should be the one who has ultimate control over it.

Post reply on HN