Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

61–70 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#61

This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Every feature I've implemented has been security/stability related. Inspection/filtering/shaping/limiting are absolutely critical on ISP networks. Taps/mirrors are critical to troubleshooting. If ISPs didn't deploy all kinds of filtering, the Internet would be mostly unusable.

Re: ITU Approves Deep Packet Inspection Recommendation

#62
post #33

Earlier quoted context omitted.

I think you're underestimating the limit to how fast DPI is or can get. The computations aren't complicated and like many kinds of algorithms you can trade space with time.

This statement might be correct (although I've never seen any evidence to support it), but it's still misleading because "forward the packet" is always going to require fewer resources than "read the packet, parse it using this set of algos, use the parse results to search your DB of shit you want to fuck with, optionally fuck with the packet, optionally forward the packet". An exception to this would be if you have…

They don't necessarily need to do anything with the packet then -- they could always pass a copy to cold storage, and then crunch the bits at their leisure in a massive data center.

Re: ITU Approves Deep Packet Inspection Recommendation

#63
Against big governments, nothing is stronger than the little men and women getting together.

If this is so bad (which I am not technically capable of understanding...), what shall we DO about it?

Signing the petition is probably not enough. Get people to have a minute of 'no internet' across the world? Similar to the Anti-SOPA movement? Suggestions welcome.

Re: ITU Approves Deep Packet Inspection Recommendation

#64
We need to start establishing a DPI/MITM resistant secret sharing protocol, and a related IP protocol.

E.g., a series of simple recaptcha-style tasks that need to be solved within 3 seconds each to be considered secure - in order to avoid active MITM with either machine or manual labor. Once a secret key is established, it can be used from that moment on.

Otherwise, opportunistic encryption can be MITMed and becomes useless.

Less secure: Require committing the equivalent of 10 seconds of a modern i5 processor to establish the shared secret within 20 seconds. That would be acceptable for two side of a connection, but not for a server or a MITM attacker.

Re: ITU Approves Deep Packet Inspection Recommendation

#65

This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

>>I'm not trying to flame you here, but I really must ask: How do you live with yourself?

It's not the tool itself that matters, but how it is used and by whom.

Re: ITU Approves Deep Packet Inspection Recommendation

#66
post #6
post #3

And of course you can't even read what they approved, because this extra-governmental body inexplicably restricts the text of their decisions to a nebulous list of "TIES users". Fucking awful.

The technical PDF is here (I shortened it because it was a long Google link): http://bit.ly/Yx0Sya

For some reason the download is not working here, but I was able to obtain it using Google's Quick View (and then Google Drive).. so here is a mirror: http://peramides.files.wordpress.com/2012/12/2012-1357y-2770...

Re: ITU Approves Deep Packet Inspection Recommendation

#67

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

>>I'm not trying to flame you here, but I really must ask: How do you live with yourself? It's not the tool itself that matters, but how it is used and by whom.

Why is it that technology is always a panacea when its benefits are positive but value-neutral when its benefits are negative?

Re: ITU Approves Deep Packet Inspection Recommendation

#68

This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

This comment was so emptily mean that I took the time to flag it.

Re: ITU Approves Deep Packet Inspection Recommendation

#69

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Every feature I've implemented has been security/stability related. Inspection/filtering/shaping/limiting are absolutely critical on ISP networks. Taps/mirrors are critical to troubleshooting. If ISPs didn't deploy all kinds of filtering, the Internet would be mostly unusable.

I work at an ISP, and this is absolutely true. Sometimes our mail servers get hammered, and we need to modify our blacklist to include servers, netblocks, and/or entire countries(!) at a time. In order to know what to block, we need to be able to know who is emailing whom. Sometimes, it's one of our customers, and we can call them up and tell them their box is owned. This kind of intrusive access is only used for maintenance, and without it we literally couldn't keep the mail servers online.

Re: ITU Approves Deep Packet Inspection Recommendation

#70
post #60

Earlier quoted context omitted.

Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?

It seems to be a balancing act. Too little secrets, and your law enforcement has a very hard time detecting threats before they happen. When people use VOIP instead of telephone lines, it's very hard to wiretap Dangerous People (and non-dangerous people). It's easy to find ways that such things make it easier for people whose job, goals, sworn duties, etc are to Protect us, or our nation. Many people join the armed s…

While that choice seems to make sense on a short term, I don't think giving up liberty can lead to safety in the long term. At some point your liberties will be so restricted that you're at the mercy of the rulers without much chance to influence how they rule.
Post reply on HN