Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

101–110 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#101
post #71

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

But the question was not why the ISP would conform to CALEA instead of breaking it; it was why you as a programmer would take on the job of providing a snooping system, instead of some other job that does not need a lot of explanation about why it's actually not really so bad. There are reasonable answers to this, but I think it's a fair question.

(I don't agree that 'we' should pursue criminals (or suspects) using all legal means.)

Re: ITU Approves Deep Packet Inspection Recommendation

#102
post #90
post #30

Earlier quoted context omitted.

Other restrictions besides bandwidth exist. For example, DPI requires more CPU and memory, which are some of the major constraints of networking equipment, especially when the equipment resides at the edge (borders) of a Tier 1 ISP.

from ( http://en.wikipedia.org/wiki/Narus_(company) ) we have the following "A single NarusInsight machine can monitor traffic equal to the maximum capacity (10 Gbit/s) of around 39,000 DSL lines or 195,000 telephone modems. But, in practical terms, since individual internet connections are not continually filled to capacity, the 10 Gbit/s capacity of one NarusInsight installation enables it to monitor the combined t…

How much does it cost? (With operating expenses.)

Re: ITU Approves Deep Packet Inspection Recommendation

#103
There's a lot of misconceptions on DPI going on here. Without taking position, let me just share a few facts (I work with this...).

- DPI is used in most networks in the world, and is mainly used for throttling P2P or for traffic analysis. Legal interception e.g. classical wiretapping is a different thing, although it could use same hardware.

- DPI does cost some resources to the operator but the impact on end users is negligible (except for malfunctions or improperly dimensioned DPIs). It only adds a tiny amount to latency, which puts an upper limit on bandwidth. In many cases, the bandwidth is limited somewhere else on the link.

- DPI hardware works in several stages, typically: analyze IP flow (shallow inspection), if not enough to decide, to DPI (analyze HTTP headers etc), if not enough to decide, rely on heuristics based on traffic pattern etc.

- DPI is not very good at all at dealing with encrypted traffic, and most DPIs will not be able to do anything else than shallow inspection. (some claim to do traffic flow analysis, and some (normally transparent proxies) can break the HTTPS flow in two, but it would generate client errors).

- ITUs specifications won't have much impact on what ISPs do at the moment (as they already do it) but I guess could be a part of the wider regulatory discussion.

Re: ITU Approves Deep Packet Inspection Recommendation

#104
post #79

Keep in mind that this DPI system, besides making it easier to monitor people's communications and even censor them, would also make it very easy for them to identify the type of traffic that goes through the pipes, so they can know exactly how to charge it differently, which brings us to another one of ITU's proposals, which is to kill net neutrality and charge for "premium services" like watching Youtube, or using…

Note that a kind of sender-pays is already used in practice as all big content providers pay for CDN on a per GB basis, and the CDN company in turn pays for bandwidth.

Re: ITU Approves Deep Packet Inspection Recommendation

#105
post #97
post #94

Earlier quoted context omitted.

If you need DPI to determine what traffic to drop, you are running your pipes way too hot. It's the users traffic, why do you think you're in the best position to decide to drop one website's traffic over another?

It's their network.

User traffic is user traffic, if they're paying for it it should be all treated the same. I'm not saying you don't need to prioritize some traffic with QoS. I'm saying you don't need DPI to run a network. Sincerely, A network engineer

Re: ITU Approves Deep Packet Inspection Recommendation

#106

I recently approved my own proposal to encrypt all my packets via VPN. Inspect away.

a recent Chinese paper (its author is the creator of GFW) suggests that the GFW is capable of using SVM to filter SSH tunnel traffic, at the success rate of 95%, without affecting normal SA use.

http://www.solidot.org/story?sid=32532

Re: ITU Approves Deep Packet Inspection Recommendation

#107
post #72

Earlier quoted context omitted.

I can see that working in countries who might be reliant on others for parts of their tech infrastructure. But would that actually work in the UK? Here in the U.S., we like to be the ones creating recommendations for the rest of the world, not following them (at least not blindly). The excuse of "We're just doing what the ITU recommends" would never fly here.

> But would that actually work in the UK? Yes. This already happens with the EU; at least some of the unpopular things "forced" on the British government by the EU were actually requested by the UK in the first place.

That sounds plausible. I've heard the US do the same thing, making unpopular changes domestically by pursuing them through foreign policies, then bringing the US "world standard."

Re: ITU Approves Deep Packet Inspection Recommendation

#108
post #45

Earlier quoted context omitted.

It let's individual governments "pass the buck" of responsibility. When the objection in parliament is brought up of "This seems like a bad idea" the response is "We're just doing what the ITU recommends"

I can see that working in countries who might be reliant on others for parts of their tech infrastructure. But would that actually work in the UK? Here in the U.S., we like to be the ones creating recommendations for the rest of the world, not following them (at least not blindly). The excuse of "We're just doing what the ITU recommends" would never fly here.

I have no specific knowledge of these negotiations, but you have to look deeper to see who suggested what.

You might find that (e.g.) AT&T (pipes) or Comcast (pipes) or Cisco (hardware) lobbied with a lot of countries and US government bodies to make this happen. Depending on the outcome, they might have a lot to gain; and doing it this way, they appear a helpless victim, just "taking orders from the UN", when in fact it was their initiative.

E.g. ACTA (and its son, the TPP) are pushed hard by Hollywood - but are mostly presented to the congress and the public as "this is an international treaty we must follow"

Poltiics and diplomacy make sure that real reasons are almost never reflected in newspaper headlines.

Re: ITU Approves Deep Packet Inspection Recommendation

#109
post #19

I think it is a good time to start incorporating DJB's NaCl into ... everything. And also run HTTP Everywhere in the meantime. And set up opportunistic IPSEC. Sad day. On a related note, I suggest we stop calling the heads of state and bureaucratic organizations like the UN "Leaders" and starting referring to them by their real self appointed role, "Rulers". Language shapes perception, and we've been using the wrong…

Ruler sounds a little too majestic, how about dictators? with or without the prefix "tin pot" depending on desire for brevity vs accuracy.

Try it in conversation:

"US Rulers have recently made file sharing a crime carrying the death penalty" vs. "US Dictators have recently made file sharing a crime carrying the death penalty". I think Rulers sounds better (but I think "dictators" is still preferable to "leaders")

Re: ITU Approves Deep Packet Inspection Recommendation

#110
post #60

Earlier quoted context omitted.

Is it me or "National Security" really means National Insecurity? Where's freedom in the illusion of safety?

It seems to be a balancing act. Too little secrets, and your law enforcement has a very hard time detecting threats before they happen. When people use VOIP instead of telephone lines, it's very hard to wiretap Dangerous People (and non-dangerous people). It's easy to find ways that such things make it easier for people whose job, goals, sworn duties, etc are to Protect us, or our nation. Many people join the armed s…

Humans are so spectacularly bad at evaluating risk that it's impossible for the safety measures to be proportionate.
Post reply on HN