Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

51–60 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#51
post #19

I think it is a good time to start incorporating DJB's NaCl into ... everything. And also run HTTP Everywhere in the meantime. And set up opportunistic IPSEC. Sad day. On a related note, I suggest we stop calling the heads of state and bureaucratic organizations like the UN "Leaders" and starting referring to them by their real self appointed role, "Rulers". Language shapes perception, and we've been using the wrong…

> Language shapes perception Isn't this an argument to to continue using the term "leaders"? Surely calling them "rulers" would, under your logic, push them further towards "rulership"?

They already know they are rulers. It's for the rest of the people.

I have heard people seriously say "Of course I prefer it with copy protection! It protects my copy!" back in the day when DRM was called copy protection. I'm sure they would have been wiser if the thing was called "Copy Restriction", because that's what it does. Similarly, I'm sure more people would realize what DRM means if it was called Digital Restriction Management (which is what it really is).

These things run deep. Who would dare oppose the PATRIOT act? Real patriots should, but none would. These terms run very, very deep.

Re: ITU Approves Deep Packet Inspection Recommendation

#52
post #7

The hardest thing for me to understand is how every telco can complain of congestion, but they're perfectly willing to introduce unnecessary overhead for DPI. This is not a good day, not a good day at all.

How is DPI related to needing more bandwidth needed per base station or residential area?

The main limit to bandwith is speed of routing the packets. This is why QoS typically fails for IP; it is usually cheaper to just use a faster dumb router than to use a slower smart router.

Re: ITU Approves Deep Packet Inspection Recommendation

#53
post #42

Earlier quoted context omitted.

Latency != bandwidth. Also, one goal of DPI is to enable granular QoS policy. So the total bandwidth available would stay the same, but the bandwidth available to each app would vary depending on network conditions and the will of the network operator.

"In TCP connections, the large bandwidth-delay product of high latency connections, combined with relatively small TCP window sizes on many devices, effectively causes the throughput of a high latency connection to drop sharply with latency" --Wikipedia It does equal bandwidth until everything is jumbo frames UDP

If you would have pasted a larger part of the quote, you would have included the part of increasing the window size (e.g. window scaling, selective ACKs, like almost everything out there supports) and the mention of satellite links to refer to high latency conditions. And that notwithstanding that, we are talking about additional latency of microseconds against a typical delay of at least 30 milliseconds. "drop sharply" just doesn't apply here.

If you want to argue against DPI that's fine but "it'll make the Internet slower" comes off as whining plus you're fighting against the exponential effects of Moore's law. A quick Google search tells me there are several products that'll do line rate DPI at 10Gbps.

There are much better arguments to be made against DPI such as privacy, a slippery slope to a walled garden, or just plain unfairness.

Re: ITU Approves Deep Packet Inspection Recommendation

#54

Earlier quoted context omitted.

Seriously, though, who are these people? I mean, how can I get a cushy gig like that? You have to wonder about them as individuals, right? What path has their lives taken that they step into a room make a horrible decision like this and not retch. Is it a perverse sense of superiority over the people who are left out from the decision-making? Is it a complete lack of personality and individual thought? Or is it just…

From what I've experienced (as someone who occasionally rubbed elbows with such UN technocrats when I worked in international health), it's your last path that rules their lives. They are almost without exception climbers, both social and professional, much more anxious to climb the next step on the ladder than actually to build or change something for the better. Often, they start out idealistic and slowly change in…

It's like we have a bunch of Sisyphus clones running around.

Re: ITU Approves Deep Packet Inspection Recommendation

#55
This is not worthy of "the sky is falling" levels of panic.

My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems.

On the other hand, CALEA has been on the books for over 15 years, and that is the kind of thing to watch out for -- it does mandate features that provide snooping to the government on demand.

(Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.)

Re: ITU Approves Deep Packet Inspection Recommendation

#56
post #33

Earlier quoted context omitted.

I think he is referring to the fact that significant CPU resources are required for DPI and if the DPI can't keep up, things will slow down.

I think you're underestimating the limit to how fast DPI is or can get. The computations aren't complicated and like many kinds of algorithms you can trade space with time.

This statement might be correct (although I've never seen any evidence to support it), but it's still misleading because "forward the packet" is always going to require fewer resources than "read the packet, parse it using this set of algos, use the parse results to search your DB of shit you want to fuck with, optionally fuck with the packet, optionally forward the packet". An exception to this would be if you have big iron on the edge that protects resource-poor interior nodes. This situation is unavoidable sometimes (DDOS), but it's not what anyone should aim for.

Re: ITU Approves Deep Packet Inspection Recommendation

#57

IPSec to the rescue?

IPSec by itself isn't going to really help. If they are doing DPI, they can MITM your IPSec connections. You still need a key management system, and I am not aware of any large-scale systems that are in-place to just "switch on" IPSec, that is, suddenly provide you with the certificates for every IP you want to connect to.

If they are doing DPI, they can MITM your IPSec connections.

what, how? dpi just means looking at packets inside ip. it doesn't somehow grant you the ability to do man-in-the-middle attacks.

deep packet inspection is already possible. that doesn't mean that tls or ipsec or any other protocol is broken.

(i agree with the need for key management etc; it's just the quoted statement above that seems wrong).

Re: ITU Approves Deep Packet Inspection Recommendation

#58

This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.)

I'm not trying to flame you here, but I really must ask: How do you live with yourself?

I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementing CALEA is the only possible way to feed a family. Job opportunities are practically endless.

Re: ITU Approves Deep Packet Inspection Recommendation

#59
post #45

Can someone explain the problems with the ITU creating specifications? I thought I understood it, but all the recent excitement and anti-ITU sentiment tells me I must be missing something. How is what the ITU does different from any standards body? They can propose standards for DPI, censoring, etc., but that won't magically make Level3 or Comcast or any particular ISP start playing with my packets. What am I missing…

It let's individual governments "pass the buck" of responsibility. When the objection in parliament is brought up of "This seems like a bad idea" the response is "We're just doing what the ITU recommends"

I can see that working in countries who might be reliant on others for parts of their tech infrastructure. But would that actually work in the UK?

Here in the U.S., we like to be the ones creating recommendations for the rest of the world, not following them (at least not blindly). The excuse of "We're just doing what the ITU recommends" would never fly here.

Re: ITU Approves Deep Packet Inspection Recommendation

#60
post #22

Earlier quoted context omitted.

They won't need luck, they have the rubber stamps of "National Security" and "We Promise We'll Only Use It For Bad Guys". I imagine that someone somewhere could find a way to apply the interstate commerce clause to let the US gov do what it wants there, too. They've already been effectively wiretapping and storing a lot, if you believe some of the recent whistleblowers, and so far there's been no effective pushback.

Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?

It seems to be a balancing act. Too little secrets, and your law enforcement has a very hard time detecting threats before they happen. When people use VOIP instead of telephone lines, it's very hard to wiretap Dangerous People (and non-dangerous people).

It's easy to find ways that such things make it easier for people whose job, goals, sworn duties, etc are to Protect us, or our nation. Many people join the armed services and civil service (of any country) for that reason. I rather like the idea of our intelligence agencies finding out ahead of time about genuine threats (whether from foreign states or from terrorists and the like), even while at the same time I am frightened by the potential slippery slope of where this could lead if unchecked.

At some point, you really do have to decide whether you prefer safety or liberty. Part of me wants to shout "liberty!", as it's a founding principle of our country, but as a parent and citizen it's very easy to also want safety.

Post reply on HN