Live data from Hacker News

RouterOS – Communications Assistance for Law Enforcement Act (2012)

wiki.mikrotik.com

11–20 of 57 posts

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#11
Welp. That's news to me. Thought it was just Telco's and not bleedy every bloody Networking equipment vendor out there. And especially not on every MitM VoiP providers. This clinches the death of Skype though. This is why we can't have nice things.

I need to stop reading these things. I just become more and more misanthropic as days go by.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#12

Earlier quoted context omitted.

> Not sure this is front-page worthy why not ? i believe it is especially as i imagine most people are not aware that such things exist in freedom lands

To be fair, this makes perfect sense. It allows compliance with wiretap warrants. Which are perfectly reasonable.

They are not. This is broadband. This goes far beyond pen-registers.

This is bloody everything from a particular endpoint, and not in an application specific manner. There is very little but storage reqs and someone getting uppity keeping this from becoming a dragnet type of surveillance mechanism.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#13

Every router is technically capable of doing this. It's just firewall rules and pcap. Not sure this is front-page worthy.

It depends, I've got some junipers that only pass the application processor the first N bytes of a packet, and even captures are limited to the first N bytes. Vendor docs say that if you need captures, you should do them on the switch, or use DPI and route everything through the application processor.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#14
post #11

Welp. That's news to me. Thought it was just Telco's and not bleedy every bloody Networking equipment vendor out there. And especially not on every MitM VoiP providers. This clinches the death of Skype though. This is why we can't have nice things. I need to stop reading these things. I just become more and more misanthropic as days go by.

I feel you. But don't give up hope. The guy behind the I2P protocol has some thoughts about the free internet on his blog https://medium.com/@zlatinbalevsky/im-not-a-prophet-but-i-pl...

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#15
post #11

Welp. That's news to me. Thought it was just Telco's and not bleedy every bloody Networking equipment vendor out there. And especially not on every MitM VoiP providers. This clinches the death of Skype though. This is why we can't have nice things. I need to stop reading these things. I just become more and more misanthropic as days go by.

Good! It's important for you to understand how privacy is never guaranteed. Sniffing and tracking who you are talking to is the oldest page in the FBI, CIA, and NSA playbook.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#16

Every router is technically capable of doing this. It's just firewall rules and pcap. Not sure this is front-page worthy.

> Not sure this is front-page worthy why not ? i believe it is especially as i imagine most people are not aware that such things exist in freedom lands

if you're on HN there is a level of confidence that you understand basic networking, and that you are aware your traffic goes through a multitude of devices before you get the data you requested.

it should come as no surprise that those devices can log the data passing through it.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#18
post #12

Earlier quoted context omitted.

To be fair, this makes perfect sense. It allows compliance with wiretap warrants. Which are perfectly reasonable.

They are not. This is broadband. This goes far beyond pen-registers. This is bloody everything from a particular endpoint, and not in an application specific manner. There is very little but storage reqs and someone getting uppity keeping this from becoming a dragnet type of surveillance mechanism.

The warrant is part that makes it not a dragnet.

Re: RouterOS – Communications Assistance for Law Enforcement Act (2012)

#20
post #13

Every router is technically capable of doing this. It's just firewall rules and pcap. Not sure this is front-page worthy.

It depends, I've got some junipers that only pass the application processor the first N bytes of a packet, and even captures are limited to the first N bytes. Vendor docs say that if you need captures, you should do them on the switch, or use DPI and route everything through the application processor.

You could probably develop a "NSA sniffer" to determine when captures are happening by noting network degradation, especially if it forces everything onto the application processor and off of fast-path.
Post reply on HN