Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

71–80 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#71

This is not worthy of "the sky is falling" levels of panic. My experience with standardization efforts is that they generally run well behind the technology innovators. DPI has been around for a while. A DPI standard (or series of standards) out of the ITU will simply make public the baseline expectations of vendors and users of DPI systems. On the other hand, CALEA has been on the books for over 15 years, and that i…

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Allow me to add my $0.02 to this discussion.

I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law.

Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise.

For one thing, there are warrants that are delivered to a judge for review which then find their way to a company attorney. Only then does any interception take place. I can live with the checks and balances that are in place under this system.

I sometimes find it incredible that people are so quick to embrace lawlessness and then expect their duly-elected governments to follow those laws to the letter. Believe me, if enough people actually cared and went to their legislature, things would change. Of course, most people agree that we should pursue criminals using all legal means.

BTW, I'm in agreement that this system could be abused. Of course, that's always been the case. Laws are just words on paper unless there are people who will enforce them. If those folks look the other way, well, you're right back where you started.

And before you go into privacy rights, let me suggest to you that the millions of people posting their personal information on FB and getting their email via Google provide a pretty substantial counterweight to your position.

Re: ITU Approves Deep Packet Inspection Recommendation

#72
post #45

Earlier quoted context omitted.

It let's individual governments "pass the buck" of responsibility. When the objection in parliament is brought up of "This seems like a bad idea" the response is "We're just doing what the ITU recommends"

I can see that working in countries who might be reliant on others for parts of their tech infrastructure. But would that actually work in the UK? Here in the U.S., we like to be the ones creating recommendations for the rest of the world, not following them (at least not blindly). The excuse of "We're just doing what the ITU recommends" would never fly here.

> But would that actually work in the UK?

Yes. This already happens with the EU; at least some of the unpopular things "forced" on the British government by the EU were actually requested by the UK in the first place.

Re: ITU Approves Deep Packet Inspection Recommendation

#73
Historically the ITU was a forum through which Ma Bell marketed her switching equipment to national phone companies outside North America. Presumably this is more of the same, except Ma Bell was divested of most equipment manufacturing and it's all IP now so other companies (USA, Japan, Germany, with a few others) are driving. The capacity for spying on and shaping the internet use of customers/subjects is appealing for many decision-makers. Among "first world" nations, we probably shouldn't discount the persuasiveness of the various American TLAs with their various evil projects. Don't you want your national constabulary to buy the same crap the DHS buys?

I suspect that if all of this was for reasonable network maintenance then the ITU wouldn't need to be involved. The equipment manufacturers have the researchers; they don't need the ITU to tell them how to shut down open mail relays.

What makes me less concerned about these proceedings is that all this is happening anyway, whether we're told or not. Yes Virginia, there are bad people in the world, and some of them run phone companies, while others spy on the citizens who pay their salaries. Eventually they'll all be routed around, and we have encryption anyway. Sure key management is hard, but if your opponent controls national network operators then you'll use something better than TLS.

Re: ITU Approves Deep Packet Inspection Recommendation

#74

Against big governments, nothing is stronger than the little men and women getting together. If this is so bad (which I am not technically capable of understanding...), what shall we DO about it? Signing the petition is probably not enough. Get people to have a minute of 'no internet' across the world? Similar to the Anti-SOPA movement? Suggestions welcome.

Replace the Internet with a wireless meshnet. Problem solved.

Re: ITU Approves Deep Packet Inspection Recommendation

#75
post #62

Earlier quoted context omitted.

This statement might be correct (although I've never seen any evidence to support it), but it's still misleading because "forward the packet" is always going to require fewer resources than "read the packet, parse it using this set of algos, use the parse results to search your DB of shit you want to fuck with, optionally fuck with the packet, optionally forward the packet". An exception to this would be if you have…

They don't necessarily need to do anything with the packet then -- they could always pass a copy to cold storage, and then crunch the bits at their leisure in a massive data center.

I have several responses:

A) this is probably true to an extent. B) slurping everything to disk is impractical, and no one has that much storage, so you're back to parsing and deciding at the boundary. This "leisure" time doesn't ever happen when you save everything all the time. C) this point seems to contradict the various claims of reasonable network maintenance I've seen; if it's trash you want to drop, you want to drop it on the floor not on your disk. If you're keeping actual traffic rather than just summaries of traffic, you're not doing reasonable network maintenance.

Re: ITU Approves Deep Packet Inspection Recommendation

#76
post #22

Earlier quoted context omitted.

They won't need luck, they have the rubber stamps of "National Security" and "We Promise We'll Only Use It For Bad Guys". I imagine that someone somewhere could find a way to apply the interstate commerce clause to let the US gov do what it wants there, too. They've already been effectively wiretapping and storing a lot, if you believe some of the recent whistleblowers, and so far there's been no effective pushback.

Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?

I have heard that there is an age-old debate in the NSA and CIA about whether it is better to encourage consumer security so that we're less vulnerable, or to encourage the existence of known-to-the-government problems to facilitate signals intelligence.

Ever since 9/11 the signals intelligence side has completely won. And I suspect will continue to until the first major confirmed case of a major cyber attack on the USA that significantly inconveniences the general public. (Ideally an attack from a tiny power - something the size of Al Qaeda circa 9/11 would be perfect.) Then there will be much handwringing over how we could have let ourselves be so vulnerable.

Re: ITU Approves Deep Packet Inspection Recommendation

#77

Earlier quoted context omitted.

Bandwidth is the measure of data over time. DPI is a process which inspects each piece of data and that takes time. Therefore, the bandwidth will decrease.

Latency != bandwidth. Also, one goal of DPI is to enable granular QoS policy. So the total bandwidth available would stay the same, but the bandwidth available to each app would vary depending on network conditions and the will of the network operator.

Wikipedia says, "In computer networking and computer science, the words bandwidth, network bandwidth, data bandwidth, or digital bandwidth are terms used to refer to various bit-rate measures, representing the available or consumed data communication resources expressed in bits per second or multiples of it (bit/s, kbit/s, Mbit/s, Gbit/s, etc.)."

All else being equal, increasing the denominator reduces the rate. It's just math.

Re: ITU Approves Deep Packet Inspection Recommendation

#78
post #72

Earlier quoted context omitted.

I can see that working in countries who might be reliant on others for parts of their tech infrastructure. But would that actually work in the UK? Here in the U.S., we like to be the ones creating recommendations for the rest of the world, not following them (at least not blindly). The excuse of "We're just doing what the ITU recommends" would never fly here.

> But would that actually work in the UK? Yes. This already happens with the EU; at least some of the unpopular things "forced" on the British government by the EU were actually requested by the UK in the first place.

Out of interest, like what?

Re: ITU Approves Deep Packet Inspection Recommendation

#79
Keep in mind that this DPI system, besides making it easier to monitor people's communications and even censor them, would also make it very easy for them to identify the type of traffic that goes through the pipes, so they can know exactly how to charge it differently, which brings us to another one of ITU's proposals, which is to kill net neutrality and charge for "premium services" like watching Youtube, or using other type of P2P traffic (Skype, WebRTC, torrents, etc):

http://itu4u.wordpress.com/2012/10/25/proposal-for-ict-and-i...

They want to do this, they say, to help "grow the Internet" (hasn't the Internet grown fast enough without their help in the past 20 years?), despite the fact that evidence suggests that the sender-pays system would slow down the growth of the Internet, not make it any faster (research paper):

http://mercatus.org/publication/do-high-international-teleco...

Re: ITU Approves Deep Packet Inspection Recommendation

#80
post #71

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

I honestly don't see how voluntary self-disclosure on FB or anywhere else has anything to do with privacy rights.
Post reply on HN