This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…
Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…
ITU Approves Deep Packet Inspection Recommendation
61–70 of 161 posts
Re: ITU Approves Deep Packet Inspection Recommendation
#62Earlier quoted context omitted.
I think you're underestimating the limit to how fast DPI is or can get. The computations aren't complicated and like many kinds of algorithms you can trade space with time.
This statement might be correct (although I've never seen any evidence to support it), but it's still misleading because "forward the packet" is always going to require fewer resources than "read the packet, parse it using this set of algos, use the parse results to search your DB of shit you want to fuck with, optionally fuck with the packet, optionally forward the packet". An exception to this would be if you have…
Re: ITU Approves Deep Packet Inspection Recommendation
#63If this is so bad (which I am not technically capable of understanding...), what shall we DO about it?
Signing the petition is probably not enough. Get people to have a minute of 'no internet' across the world? Similar to the Anti-SOPA movement? Suggestions welcome.
Re: ITU Approves Deep Packet Inspection Recommendation
#64E.g., a series of simple recaptcha-style tasks that need to be solved within 3 seconds each to be considered secure - in order to avoid active MITM with either machine or manual labor. Once a secret key is established, it can be used from that moment on.
Otherwise, opportunistic encryption can be MITMed and becomes useless.
Less secure: Require committing the equivalent of 10 seconds of a modern i5 processor to establish the shared secret within 20 seconds. That would be acceptable for two side of a connection, but not for a server or a MITM attacker.
Re: ITU Approves Deep Packet Inspection Recommendation
#65This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…
Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…
It's not the tool itself that matters, but how it is used and by whom.
Re: ITU Approves Deep Packet Inspection Recommendation
#66And of course you can't even read what they approved, because this extra-governmental body inexplicably restricts the text of their decisions to a nebulous list of "TIES users". Fucking awful.
The technical PDF is here (I shortened it because it was a long Google link): http://bit.ly/Yx0Sya
Re: ITU Approves Deep Packet Inspection Recommendation
#67Earlier quoted context omitted.
Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…
>>I'm not trying to flame you here, but I really must ask: How do you live with yourself? It's not the tool itself that matters, but how it is used and by whom.
Re: ITU Approves Deep Packet Inspection Recommendation
#68This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…
Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…
Re: ITU Approves Deep Packet Inspection Recommendation
#69Earlier quoted context omitted.
Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…
Every feature I've implemented has been security/stability related. Inspection/filtering/shaping/limiting are absolutely critical on ISP networks. Taps/mirrors are critical to troubleshooting. If ISPs didn't deploy all kinds of filtering, the Internet would be mostly unusable.
Re: ITU Approves Deep Packet Inspection Recommendation
#70Earlier quoted context omitted.
Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?
It seems to be a balancing act. Too little secrets, and your law enforcement has a very hard time detecting threats before they happen. When people use VOIP instead of telephone lines, it's very hard to wiretap Dangerous People (and non-dangerous people). It's easy to find ways that such things make it easier for people whose job, goals, sworn duties, etc are to Protect us, or our nation. Many people join the armed s…