Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

121–130 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#121
post #93
post #69

Earlier quoted context omitted.

I work at an ISP, and this is absolutely true. Sometimes our mail servers get hammered, and we need to modify our blacklist to include servers, netblocks, and/or entire countries(!) at a time. In order to know what to block, we need to be able to know who is emailing whom. Sometimes, it's one of our customers, and we can call them up and tell them their box is owned. This kind of intrusive access is only used for mai…

If the traffic is terminating on your own servers you in no way need deep packet inspection to determine the source of traffic and its nature. Even if the traffic wasn't terminating on your machines, you don't need DPI to determine src and dst ip:port tuples. Which is all you need to do what your suggesting.

My comment isn't about DPI specifically, but a whole range of intrusive monitoring policies at ISPs. In order to determine the originator of an email, you have to read (at least) the email headers. The IP address of the last hop is not that useful in routing email.

Re: ITU Approves Deep Packet Inspection Recommendation

#122
post #79

Keep in mind that this DPI system, besides making it easier to monitor people's communications and even censor them, would also make it very easy for them to identify the type of traffic that goes through the pipes, so they can know exactly how to charge it differently, which brings us to another one of ITU's proposals, which is to kill net neutrality and charge for "premium services" like watching Youtube, or using…

Note that a kind of sender-pays is already used in practice as all big content providers pay for CDN on a per GB basis, and the CDN company in turn pays for bandwidth.

Sure, but this was the case before CDNs as well. Unless you are a Tier 1 network you usually pay a fee to your upstream carrier.

However, the ITU would like to charge across many networks and discriminate based on the type of service provided.

So if data from your network A reaches the customer through networks B, C and finally D, then D would like to charge you to deliver it and not slow down things artificially.

Re: ITU Approves Deep Packet Inspection Recommendation

#123
post #24

Earlier quoted context omitted.

They're re-negotiating the ITRs, which are the provisions in the ITU's underlying treaty. Some general information (PDF): https://www.cdt.org/files/file/Global%20Internet%20Governanc... On the DPI issue: https://www.cdt.org/blogs/cdt/2811adoption-traffic-sniffing-...

I still haven't seen exactly how this would possibly be enforced. Just like products selectively choose features, even if the IETF or ITU says "mandatory", does not somehow create a law. The ITU can't just vote itself to tell an ISP how to handle traffic, even internationally. They could create a standard and then let individual countries tell vendors "hey, you must comply with B.123 in order to sell in our country"…

ITU is lobbied by governments wanting some level of snooping.

ITU votes to allow some kind of snooping in the standards.

Government asks ISPS etc to follow the internationally agreed standard. "We'll only use the snooping stuff for terrorists and images of child sexual abuse, really."

Government uses this new compliance to the standards to get your ISP to snoop on stuff.

The governments take this circuitous route so that they as individual governments don't get attacked by local libertarians. Defeating a measure like this in one country is hard; defeating it across international treaties is very hard.

Re: ITU Approves Deep Packet Inspection Recommendation

#124

Earlier quoted context omitted.

But the question was not why the ISP would conform to CALEA instead of breaking it; it was why you as a programmer would take on the job of providing a snooping system, instead of some other job that does not need a lot of explanation about why it's actually not really so bad. There are reasonable answers to this, but I think it's a fair question. (I don't agree that 'we' should pursue criminals (or suspects) using a…

http://en.wikipedia.org/wiki/Banality_of_evil

Exactly. What people wouldn't do in the name of bureaucracy.

Re: ITU Approves Deep Packet Inspection Recommendation

#125

Earlier quoted context omitted.

I once quit a job because one of my employer's servers became infected with some malware, spread it to client's computers and the employer refused to notify and apologise to said clients. I sincerely hope that you grow up and take responsibility for your own actions. They are the only things we truly own. I do not believe that you are evil for what you did but I most certainly believe that you are ignorant in a very…

I think maybe you missed the point that I actually agree with the mechanisms that are in place. I don't have any disagreements when the framework is used as it is designed to be used. Namely, within the context of due process and rule of law. More importantly: it's somewhat presumptuous of you to suggest I need to "grow up" or "take responsibility". I stood up in a ballroom full of law enforcement and telecom executi…

Those are all good ideas, as long as the state works as originally intended. I think you're putting too much faith in the system.

Re: ITU Approves Deep Packet Inspection Recommendation

#126

Earlier quoted context omitted.

I once quit a job because one of my employer's servers became infected with some malware, spread it to client's computers and the employer refused to notify and apologise to said clients. I sincerely hope that you grow up and take responsibility for your own actions. They are the only things we truly own. I do not believe that you are evil for what you did but I most certainly believe that you are ignorant in a very…

I think maybe you missed the point that I actually agree with the mechanisms that are in place. I don't have any disagreements when the framework is used as it is designed to be used. Namely, within the context of due process and rule of law. More importantly: it's somewhat presumptuous of you to suggest I need to "grow up" or "take responsibility". I stood up in a ballroom full of law enforcement and telecom executi…

I apologise for the tone of that comment.

The problem with due process and the rule of law is that those things are enforced by humans. People invariably suffer from corruption, in particular, those in power. The less they are capable of, the safer everyone is. Governments and corporations have done orders of magnitude more harm than smaller entities like gangs (though from an absolute perspective, the separation between a gang and a government is mostly ontological). The criminals are (for the most part) not the ones we should be worrying about.

The legal system we currently have is broken at best and dangerous at worst. Many people have no faith in it's ability to be just or balanced. There are concrete reasons for harboring a distrust of the judicial system, e.g. http://www.scientificamerican.com/article.cfm?id=lunchtime-l...

Not to mention that the judicial system is 'dumb' in the sense that it's primary goal is to enforce laws, not to improve society. Having a machine which processes instructions in this way and which simultaneously has the power to ruin someone's life is a bad idea by all metrics. Those two goals (enforcing the law and improving people's wellbeing) are commonly at odds due to the nature of how human societies function and how politics influence things which they ought not to.

The prison system also fares badly when it comes to solving problems - the reoffending rates are extremely high in many places - http://en.wikipedia.org/wiki/Recidivism#Recidivism_rates

So how can anyone take this joke of a system seriously and expect it to be capable of policing itself when emotion is so deeply embedded in the judgements and actions it yields? The judge's decisions are emotional. The system as a whole is crafted out of an inability to deal with emotion (i.e. prisons being primarily revenge mechanisms as opposed to institutions which help people to stop being violent against others).

This is the bigger picture of the situation we find ourselves in. IMO, adding to the arsonal of weapons which this system has access to will serve to cripple, not improve society. In other words, this is all counter-productive and does not take the reality of human nature into account. It is an idealistic perspective.

Re: ITU Approves Deep Packet Inspection Recommendation

#127
post #71

Earlier quoted context omitted.

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

But the question was not why the ISP would conform to CALEA instead of breaking it; it was why you as a programmer would take on the job of providing a snooping system, instead of some other job that does not need a lot of explanation about why it's actually not really so bad. There are reasonable answers to this, but I think it's a fair question. (I don't agree that 'we' should pursue criminals (or suspects) using a…

So your argument is that I should not be a part of this system? Because you don't agree with it?

As a person interested in PRIVACY and LAW and INTENRET TECHNOLOGY, who would you think I'd rather have working on this type of system? Someone else? Or myself: a person who knows what his motivations are, who knows what the laws are, who knows what the implications for others are, and who wants to see things done properly.

If it's all the same to you, I'd rather it was ME. Believe me, you're lucky to have a guy like me pushing back against law enforcement when their requests get over-broad.

Remember that good people are part of this system and use their judgement to make sure abuses dont occur. I trust my judgement.

Given how much worship Richard Feynman gets around these parts, I'm wondering how people reconcile that sentiment with the fact that he worked on the development of the atomic bomb. FWIW, he seemed to be pretty OK with his role.

Re: ITU Approves Deep Packet Inspection Recommendation

#128
post #94

Earlier quoted context omitted.

Every feature I've implemented has been security/stability related. Inspection/filtering/shaping/limiting are absolutely critical on ISP networks. Taps/mirrors are critical to troubleshooting. If ISPs didn't deploy all kinds of filtering, the Internet would be mostly unusable.

If you need DPI to determine what traffic to drop, you are running your pipes way too hot. It's the users traffic, why do you think you're in the best position to decide to drop one website's traffic over another?

Note that I said in my original comment that my experience has primarily been implementation of shallow inspection.

Subscriber-connected edge gear is often oversubscribed. Lots of little pipes coming in from households; one or two medium-sized pipes headed to the core.

> It's the users traffic, why do you think you're in the best position to decide to drop one website's traffic over another?

All too often it's not actually the subscribers' traffic that causes problems; it may be malware.

Re: ITU Approves Deep Packet Inspection Recommendation

#129

Earlier quoted context omitted.

I think maybe you missed the point that I actually agree with the mechanisms that are in place. I don't have any disagreements when the framework is used as it is designed to be used. Namely, within the context of due process and rule of law. More importantly: it's somewhat presumptuous of you to suggest I need to "grow up" or "take responsibility". I stood up in a ballroom full of law enforcement and telecom executi…

I apologise for the tone of that comment. The problem with due process and the rule of law is that those things are enforced by humans. People invariably suffer from corruption, in particular, those in power. The less they are capable of, the safer everyone is. Governments and corporations have done orders of magnitude more harm than smaller entities like gangs (though from an absolute perspective, the separation bet…

So our legal system is a joke? That's news to me. I'd actually argue that it's been pretty damn effective in keeping our society from devolving into complete bedlam.

Your comments reflect all the certitude of someone who has never seen real evil up close. To suggest that a system that functions properly 90% of the time is a worthless endeavor isn't a realistic position I'm willing to argue with.

And I don't agree with your assertions. Statements like "Many people have no faith in it's ability to be just or balanced" doesn't jibe with the reality of our political economy. Every single day, hundred of millions of Americans go to work and get on with their lives. If the system was as broken as you claim, I seriously doubt we'd have the strength and standing among nations that you seem to ready to dismiss.

If you're getting all your information from magazines and wikipedia, you're bound to be misinformed about the reality of the task at hand.

And finally, statements like "The criminals are (for the most part) not the ones we should be worrying about" is simply indefensible. The justice system exists because people demand that it exist to protect them. They have agreed either explicitly or implicitly to the arrangement that we have today.

I know many members of law enforcement. They are by and large good people trying to do a hard job. A very hard job. Ask yourself if you have the courage to confront dangerous situations every single day, deal with persistent mendacity from nearly everyone you meet, and still maintain a level of professionalism and respect for individual liberty. That's an awfully high bar to set for a person and part of the miracle of our system is that it happens with such a level of regularity that we take it for granted. That's NOT the case in other countries.

Re: ITU Approves Deep Packet Inspection Recommendation

#130
post #71

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

>I'm generally in favor of following the law.

IMO it is the responsibility of every citizen to ignore laws that are stupid. Civil disobedience.

I realize this would mean some people might say "going 30 by a school zone is stupid!". So be it. If you disobey laws that most people believe are right, then you lose and face the consequences. If you disobey laws that most people will realize are stupid nothing is likely to happen to you.

Post reply on HN