Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

11–20 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#11
post #6
post #3

And of course you can't even read what they approved, because this extra-governmental body inexplicably restricts the text of their decisions to a nebulous list of "TIES users". Fucking awful.

The technical PDF is here (I shortened it because it was a long Google link): http://bit.ly/Yx0Sya

I note that they're not applying DPI to encrypted traffic per the spec, but they do note that unencrypted portions of encrypted packets will still be inspected.

The example they give is that if a PDU is encrypted, but all of the other sections of the packet are not, then only the PDU won't be inspected.

Still, DPI is scary as all hell.

Re: ITU Approves Deep Packet Inspection Recommendation

#13

Earlier quoted context omitted.

If this gets widespread enough, they'll just inspect traffic when it leaves your VPN gateway/server. VPN is fine for public wifi, or connections between predetermined networks but you can't stretch it much past that.

Which is why you should use a VPN with shared ips.

Doesn't that hurt if you plan on any P2P stuff? Or do they support UPnP when NAT'ing you?

Re: ITU Approves Deep Packet Inspection Recommendation

#15
post #8

I recently approved my own proposal to encrypt all my packets via VPN. Inspect away.

Section 6.8 of the PDF deals with those pesky encrypted packets.

Only insofar as it talks about 1) partially encrypted traffic, 2) using local copies of the keys for decryption, or 3) flow identification of IPSEC. Properly done I don't see an IPSEC/L2TP VPN being vulnerable to DPI - although you will want a constant stream of "filler" packets going back and forward to thwart traffic analysis.

Otherwise, the whole thing is a disgrace and the engineers responsible for working on it need to take a long look at themselves. Dressing it up with examples of "Detection of Malware" is disingenuous, it's abundantly clear what the use case is here.

Re: ITU Approves Deep Packet Inspection Recommendation

#16
Can someone explain the problems with the ITU creating specifications? I thought I understood it, but all the recent excitement and anti-ITU sentiment tells me I must be missing something.

How is what the ITU does different from any standards body? They can propose standards for DPI, censoring, etc., but that won't magically make Level3 or Comcast or any particular ISP start playing with my packets.

What am I missing? Where does the stuff the ITU does somehow change the policies and actions of my ISP?

Re: ITU Approves Deep Packet Inspection Recommendation

#17
post #7

The hardest thing for me to understand is how every telco can complain of congestion, but they're perfectly willing to introduce unnecessary overhead for DPI. This is not a good day, not a good day at all.

How is DPI related to needing more bandwidth needed per base station or residential area?

Re: ITU Approves Deep Packet Inspection Recommendation

#18
post #6
post #3

And of course you can't even read what they approved, because this extra-governmental body inexplicably restricts the text of their decisions to a nebulous list of "TIES users". Fucking awful.

The technical PDF is here (I shortened it because it was a long Google link): http://bit.ly/Yx0Sya

http://www.google.co.il/url?sa=t&rct=j&q=&esrc=s...

Re: ITU Approves Deep Packet Inspection Recommendation

#19
I think it is a good time to start incorporating DJB's NaCl into ... everything. And also run HTTP Everywhere in the meantime. And set up opportunistic IPSEC.

Sad day.

On a related note, I suggest we stop calling the heads of state and bureaucratic organizations like the UN "Leaders" and starting referring to them by their real self appointed role, "Rulers".

Language shapes perception, and we've been using the wrong term for too long.

Re: ITU Approves Deep Packet Inspection Recommendation

#20

Earlier quoted context omitted.

Which is why you should use a VPN with shared ips.

Doesn't that hurt if you plan on any P2P stuff? Or do they support UPnP when NAT'ing you?

Many services offer port forwarding while on the VPN.
Post reply on HN