Live data from Hacker News

Indian ISPs: We already give govt full access to web traffic

entrackr.com

21–30 of 113 posts

Re: Indian ISPs: We already give govt full access to web traffic

#21

5 days ago i wrote about UK govt doing scans of all websites hosted in UK for "security" reasons and i was downvoted for " Stop lying and not relevant, you clearly came here with an agenda"... i guess we really do have an agenda when the government has access to full internet web traffic and they can pick and choose their targets with impunity https://news.ycombinator.com/item?id=33470079#33470409

And in some countries we are starting to see "Adopt electronic payment: simple and safe" - which implies, "create tracks" -, as generic anonymous advertisement... Even on the electronic billboards of motorways!!!

Re: Indian ISPs: We already give govt full access to web traffic

#22
post #10

Yes they do, mainly because it’s the law. That it’s a misguided law is open for debate, but I don’t believe there is any state in the world that doesn’t monitor and control tele-communications (internet is regulated as tele-communications WW).

The level of surprise does seem overblown. This bit stuck out to me: > ... access to this data is so accessible remotely that physically visiting an internet provider’s premises is no longer required for government agencies. They were expecting government agents to have to physically visit the ISP's offices? Were they perhaps going to get their data on a floppy disk?

The model where law enforcement officers have to visit ISP facilities reduces the duration and scope of surveillance. Throw in a process where you need to get court approval into the mix, and this provides some level of oversight into the surveillance machinery. (Though abuses are certainly possible with this model, see [1]).

[1] https://www.eff.org/deeplinks/2021/05/foriegn-intelligence-s...

Re: Indian ISPs: We already give govt full access to web traffic

#24
post #6

But how... I mean presumably they don't install a root cert on every client device?

They can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already provides a lot of information to profile individual citizens. QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away…

How would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense

Re: Indian ISPs: We already give govt full access to web traffic

#25
I think we must all agree that national governments have a duty of care towards their citizens.

From the Indian govt perspective, the dominance of the Internet by foreign owned businesses means that the country is vulnerable to malfeasance should those foreign governments mean India harm or come to decide - over the head of the government - what the Indian people want or need.

This is about national sovereignty and national security. We have seen how those values trump privacy concerns for individuals in any country, including the US, so must accord the same understanding for other nations also.

Re: Indian ISPs: We already give govt full access to web traffic

#26
post #24

Earlier quoted context omitted.

They can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already provides a lot of information to profile individual citizens. QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away…

How would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense

NATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too.

IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space. Each citizen can then be assigned an unique IP address which makes it easier to distinguish traffic without the cooperation of each NATing layer.

[1] https://support.huawei.com/enterprise/en/doc/EDOC1100055044/...

Re: Indian ISPs: We already give govt full access to web traffic

#27

5 days ago i wrote about UK govt doing scans of all websites hosted in UK for "security" reasons and i was downvoted for " Stop lying and not relevant, you clearly came here with an agenda"... i guess we really do have an agenda when the government has access to full internet web traffic and they can pick and choose their targets with impunity https://news.ycombinator.com/item?id=33470079#33470409

Looking at that, I'd suggest the downvotes are from being technically wrong (the “Scanning for vulnerabilities won't help you find critics. If you wanted to look for critics, you would scan for critics.” argument – there are better/easier ways to achieve what you are talking about a government trying to achieve so why would they go to that effort?). Maybe some considered the comment concerning India on a thread about the UK was pulling things off-topic, though as not all voters replied with clarifying comments we'll never know.

The lying/agenda thing seems to just be one comment. Try not to assume that one angry reply represents a larger chunk of HN's readership. The Internet is full of bus-stop boxers, it is best to not let them wind you up overly.

Re: Indian ISPs: We already give govt full access to web traffic

#28
post #6

But how... I mean presumably they don't install a root cert on every client device?

like the other commenter said, they have IP address information which they "can" corelate from say logs from reddit and pin point which anonymous user posted something. or where a particular email was sent from, they find the email, they can trace it back to the sender and looking at logs, can find where and which device that was from.... ipv6 is very prevalent in india and you don't need a wifi AP level monitoring as you can do on a per-device basis

Re: Indian ISPs: We already give govt full access to web traffic

#29
post #3

An important point is whether legislation exists which allows such "monitoring". Edit: I would also like to add, one of the latest news was about malicious access of administrative data in Australia - which surely has in general more funds to invest in security than others. I would be concerned about personal data being copied in more repositories (multiplying chances of malicious access).

>An important point is whether legislation exists which allows such "monitoring".

One thing that people from the "global north" need to remember is that in most of the world, laws are just loose guidelines.

Re: Indian ISPs: We already give govt full access to web traffic

#30

5 days ago i wrote about UK govt doing scans of all websites hosted in UK for "security" reasons and i was downvoted for " Stop lying and not relevant, you clearly came here with an agenda"... i guess we really do have an agenda when the government has access to full internet web traffic and they can pick and choose their targets with impunity https://news.ycombinator.com/item?id=33470079#33470409

Looking at that, I'd suggest the downvotes are from being technically wrong (the “Scanning for vulnerabilities won't help you find critics. If you wanted to look for critics, you would scan for critics.” argument – there are better/easier ways to achieve what you are talking about a government trying to achieve so why would they go to that effort?). Maybe some considered the comment concerning India on a thread about…

oh no, not that. >Try not to assume that one angry reply represents a larger chunk of HN's readership.

you get to have a thick skin when you are on an anonymous public platform. i accept that....

i live in a place where i have to actually assume malice on part of the government because the government "is" hostile against me. Again, this isn't some tin-foil conspiracy but as you might've guessed from my handle, its yeah...

So that comment earlier and the current article about ISPs tracking users, this is primarily to catch critics and dissenters.

Post reply on HN