Live data from Hacker News

RouterOS – Communications Assistance for Law Enforcement Act (2012)

wiki.mikrotik.com

21–30 of 57 posts

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#21
post #17

Might be dumb question, but won't this configuration need admin ssh access to add required rules and local server to log that traffic?

Not admin access:

> Calea provided options are available only for specific RouterOS user, as Calea server configuration as "tap" configuration. Specific user should have 'sniff' policy enabled at RouterOS user configuration

So the admin has to set up a user account on the device.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#22

Every router is technically capable of doing this. It's just firewall rules and pcap. Not sure this is front-page worthy.

> Not sure this is front-page worthy why not ? i believe it is especially as i imagine most people are not aware that such things exist in freedom lands

> why not ? i believe it is especially as i imagine most people are not aware that such things exist in freedom lands

Do you mean firewall rules? Because firewall rules definitely exist in "freedom lands."

A lot of the comments here seem to show an eagerness to misunderstand this. Even in a "freedom land" law enforcement still needs the power to intrusively investigate criminal suspects, because ineffective law enforcement is a bad thing and a threat to liberty.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#23
post #20
post #13

Earlier quoted context omitted.

It depends, I've got some junipers that only pass the application processor the first N bytes of a packet, and even captures are limited to the first N bytes. Vendor docs say that if you need captures, you should do them on the switch, or use DPI and route everything through the application processor.

You could probably develop a "NSA sniffer" to determine when captures are happening by noting network degradation, especially if it forces everything onto the application processor and off of fast-path.

like putting a script on the switch that says the cpu utilization is x% higher? Do higher end switches report out utilization of the packet processing asic? I have a few high end switches in my homelab, I can of course tell the utilization of the management processor but I have never tried to delve into what the actual switch chip is doing.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#24
post #20

Earlier quoted context omitted.

You could probably develop a "NSA sniffer" to determine when captures are happening by noting network degradation, especially if it forces everything onto the application processor and off of fast-path.

like putting a script on the switch that says the cpu utilization is x% higher? Do higher end switches report out utilization of the packet processing asic? I have a few high end switches in my homelab, I can of course tell the utilization of the management processor but I have never tried to delve into what the actual switch chip is doing.

I was thinking more remotely noticing that throughput dropped - my switches can route at line speed if they avoid the CPU, but if the CPU is involved it drops to about half line speed.

If you're the one controlling the network router, you know when the sniffing is going on - this would be trying to detect that your ISP has turned the "NSA button" on.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#25

Not sure why this is on the front page, but to clarify it's required by the FCC [0] for carriers. Microtik, just like every other network vendor, has this in their product (port mirroring for law enforcement) so that they can check the box. CALEA has been around since the 90s [1]. [0] https://www.fcc.gov/public-safety-and-homeland-security/poli... [1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...

I found this interesting insofar as it is somewhat rare for endpoint CPEs to have these features baked in, in particular with any sort of CALEA semantics. This is almost always a burden pushed on the transitory service providers upstream from the device. Network device OEMs, in my experience running an ISP (in addition to both making routers and white-labeling them for our service), have never been held to the CALEA requirements historically.

The wikipedia article you shared actually states this pretty clearly as well:

>" The IP-based "soft switches" typically do not contain a built-in CALEA intercept feature; and other IP-transport elements (routers, switches, access multiplexers) almost always delegate the CALEA function to elements dedicated to inspecting and intercepting traffic. In such cases, hardware taps or switch/router mirror-ports are employed to deliver copies of all of a network's data to dedicated IP probes."

(I realize that Microtik's RouterOS may end up on headend router devices and that is likely why this exists, but the implementation details here are just a little odd when you can just port mirror on a switch instead)

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#26
post #9

Not sure why this is on the front page, but to clarify it's required by the FCC [0] for carriers. Microtik, just like every other network vendor, has this in their product (port mirroring for law enforcement) so that they can check the box. CALEA has been around since the 90s [1]. [0] https://www.fcc.gov/public-safety-and-homeland-security/poli... [1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Specifically, _1994_, another banner year for undermining civil liberties and privacy, what with the passage of the new sentencing provisions of the federal crime bill and continuing effort to prevent wider use of encryption by individuals through action against PGP: all by a "liberal" US administration that would also accelerate consolidation of mass media in the hands of a few big corporations.

Yes, 1994 and 1996 [0] were both horrible years for bad "telecomm" policy. I remember debating this in my "Regulations" class in the early 2000s and how, even by then, we could see the potential longer term damages emerging. I think it also played a role in influencing the markets (with respect to tech companies) to think how they do (continuous growth / continuous significant increase in QoQ profits). The late 80s and early 90s were a wild ride of ignorance in policy making. The Clipper Chip, interesting takes on crypto export control all the way through the advent of the DMCA.

Interesting times with many unfortunate decisions.

[0] https://en.wikipedia.org/wiki/Telecommunications_Act_of_1996

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#28

Quoted post unavailable.

>don't blame the cops (because: if you get ripped off on eBay or your child goes missing, you do want some kind of resolution, right?)

I'm not sure where you live, but in my neck of the woods, going to the cops in these scenarios might even be slightly worse than not going to them, let alone better.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#29

Go address some of the posters "why is the front page worthy" - I'm not surprised that 3 letter agencies get all the data they want, but very often it's very covert and not so "official".

"why is this on the front page?"

because someone found and read this wiki and decided to share it with others who also found it interesting so they upvoted it. now here we are

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#30

Quoted post unavailable.

>don't blame the cops (because: if you get ripped off on eBay or your child goes missing, you do want some kind of resolution, right?) I'm not sure where you live, but in my neck of the woods, going to the cops in these scenarios might even be slightly worse than not going to them, let alone better.

[deleted]
Post reply on HN