Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

41–50 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#41
post #22

Good luck with that. What they have just "approved" is the IP-equivalent of opening every single piece of mail. That is, wiretapping.

They won't need luck, they have the rubber stamps of "National Security" and "We Promise We'll Only Use It For Bad Guys". I imagine that someone somewhere could find a way to apply the interstate commerce clause to let the US gov do what it wants there, too. They've already been effectively wiretapping and storing a lot, if you believe some of the recent whistleblowers, and so far there's been no effective pushback.

Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?

Re: ITU Approves Deep Packet Inspection Recommendation

#42

Earlier quoted context omitted.

Bandwidth is the measure of data over time. DPI is a process which inspects each piece of data and that takes time. Therefore, the bandwidth will decrease.

Latency != bandwidth. Also, one goal of DPI is to enable granular QoS policy. So the total bandwidth available would stay the same, but the bandwidth available to each app would vary depending on network conditions and the will of the network operator.

"In TCP connections, the large bandwidth-delay product of high latency connections, combined with relatively small TCP window sizes on many devices, effectively causes the throughput of a high latency connection to drop sharply with latency" --Wikipedia

It does equal bandwidth until everything is jumbo frames UDP

Re: ITU Approves Deep Packet Inspection Recommendation

#43
post #24

Can someone explain the problems with the ITU creating specifications? I thought I understood it, but all the recent excitement and anti-ITU sentiment tells me I must be missing something. How is what the ITU does different from any standards body? They can propose standards for DPI, censoring, etc., but that won't magically make Level3 or Comcast or any particular ISP start playing with my packets. What am I missing…

They're re-negotiating the ITRs, which are the provisions in the ITU's underlying treaty. Some general information (PDF): https://www.cdt.org/files/file/Global%20Internet%20Governanc... On the DPI issue: https://www.cdt.org/blogs/cdt/2811adoption-traffic-sniffing-...

They are negotiating the underlying treaty, but I don't think this is a treaty provision. It's a standards document, adopted by World Telecommunication Standardization Assembly (WTSA), not WCIT, which is renegotiating the treaty. Basically, this is not a law, it's a spec.

Re: ITU Approves Deep Packet Inspection Recommendation

#44
post #24

Can someone explain the problems with the ITU creating specifications? I thought I understood it, but all the recent excitement and anti-ITU sentiment tells me I must be missing something. How is what the ITU does different from any standards body? They can propose standards for DPI, censoring, etc., but that won't magically make Level3 or Comcast or any particular ISP start playing with my packets. What am I missing…

They're re-negotiating the ITRs, which are the provisions in the ITU's underlying treaty. Some general information (PDF): https://www.cdt.org/files/file/Global%20Internet%20Governanc... On the DPI issue: https://www.cdt.org/blogs/cdt/2811adoption-traffic-sniffing-...

I still haven't seen exactly how this would possibly be enforced. Just like products selectively choose features, even if the IETF or ITU says "mandatory", does not somehow create a law. The ITU can't just vote itself to tell an ISP how to handle traffic, even internationally.

They could create a standard and then let individual countries tell vendors "hey, you must comply with B.123 in order to sell in our country" -- but they can do that anyways. If a government wants snooping capabilities, you can bet every vendor will add it to get their business. It's still the government that decides if it's mandatory to turn on or not.

Again, I'd like to hear the full path from the ITU taking a vote, to my ISP suddenly snooping in on stuff. I can't figure it out.

Re: ITU Approves Deep Packet Inspection Recommendation

#45

Can someone explain the problems with the ITU creating specifications? I thought I understood it, but all the recent excitement and anti-ITU sentiment tells me I must be missing something. How is what the ITU does different from any standards body? They can propose standards for DPI, censoring, etc., but that won't magically make Level3 or Comcast or any particular ISP start playing with my packets. What am I missing…

It let's individual governments "pass the buck" of responsibility. When the objection in parliament is brought up of "This seems like a bad idea" the response is "We're just doing what the ITU recommends"

Re: ITU Approves Deep Packet Inspection Recommendation

#46

IPSec to the rescue?

IPSec by itself isn't going to really help. If they are doing DPI, they can MITM your IPSec connections. You still need a key management system, and I am not aware of any large-scale systems that are in-place to just "switch on" IPSec, that is, suddenly provide you with the certificates for every IP you want to connect to.

Re: ITU Approves Deep Packet Inspection Recommendation

#47
Appendix I & II are frighting in their casual use of major headings. Looks an awful lot like the fabled "tier-ed internet".

Heck, one of the diagrams even categorizes IP traffic in 4 levels: Gold, Silver, Bronze, P2P. I'm not an owner of tinfoil hats, but this has a lot of implications to a distributed web.

Appendix Examples: I.2.1 Differentiated services based on service identification

I.2.2 Traffic monitoring

I.2.4 Traffic statistics and services-based billing

I.3.1 DPI used as a bidirectional tool for service control

I.5 DPI use case: Traffic control

I.5.3 DPI-based policing of peer-to-peer traffic

I.9.2 DPI engine use case: Simple fixed string matching for BitTorrent

II.4.11 Example “Identify uploading BitTorrent users”

II.4.13 Example “Blocking Peer-to-Peer VoIP telephony with proprietary end-to-end application control protocols”

Re: ITU Approves Deep Packet Inspection Recommendation

#49
post #24

Earlier quoted context omitted.

They're re-negotiating the ITRs, which are the provisions in the ITU's underlying treaty. Some general information (PDF): https://www.cdt.org/files/file/Global%20Internet%20Governanc... On the DPI issue: https://www.cdt.org/blogs/cdt/2811adoption-traffic-sniffing-...

I still haven't seen exactly how this would possibly be enforced. Just like products selectively choose features, even if the IETF or ITU says "mandatory", does not somehow create a law. The ITU can't just vote itself to tell an ISP how to handle traffic, even internationally. They could create a standard and then let individual countries tell vendors "hey, you must comply with B.123 in order to sell in our country"…

It's not about enforcement. It's about deniability and ass-covering.

My sport (paragliding) has been destroyed by similar actions from the governing body in the last 18 months. They don't need to say "you should do X". All they need to say is "we think that maybe you should do X" and suddenly everybody falls into line and does X. It's not about enforcement, it's about not being seen to contradict a perceived authority.

Re: ITU Approves Deep Packet Inspection Recommendation

#50
One way to think of this is as a cat and mouse game.

Another way is that some people are developing high-bandwidth, distributed, and anonymous internet software and some other people are writing tests that this software is expected to fail presently but that the developers must pass in order to make it to the next level of hardened security and reliability.

Post reply on HN