Live data from Hacker News

ITU Approves Deep Packet Inspection Recommendation

itu.int

111–120 of 161 posts

Re: ITU Approves Deep Packet Inspection Recommendation

#111

I recently approved my own proposal to encrypt all my packets via VPN. Inspect away.

If this gets widespread enough, they'll just inspect traffic when it leaves your VPN gateway/server. VPN is fine for public wifi, or connections between predetermined networks but you can't stretch it much past that.

Or the VPN-s connect to each other if it gets widespread enough and you get Overnet, where only minority of your traffic needs to go outside. And when that gets regulated there will be OverOverNet etc.

Re: ITU Approves Deep Packet Inspection Recommendation

#112
post #105
post #97

Earlier quoted context omitted.

It's their network.

User traffic is user traffic, if they're paying for it it should be all treated the same. I'm not saying you don't need to prioritize some traffic with QoS. I'm saying you don't need DPI to run a network. Sincerely, A network engineer

If you treat your network's users them all the same, more power to you. Running the network and deciding what goes through it is still out of their control. I don't get why you're against those that do use DPI to run their network more easily, though.

Re: ITU Approves Deep Packet Inspection Recommendation

#113

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

No employee boycott is going to help, they'll just hire someone else. We won't see change until we start electing better leaders, or changing the system. Reduce the demand.

Or stop being employees in the industry which is why I no longer work for a defence contractor.

Re: ITU Approves Deep Packet Inspection Recommendation

#114
post #98
post #91

Earlier quoted context omitted.

narus-networks has solved this 'problem' long time ago...

Oh, it's obviously possible. Reading a little about Narus does not give me the impression that it's cost-effective, for any non-NSA sense of the word "cost". In any case, in my opinion our customers were not taking their problems very seriously, and their price sensitivity reflected that. If you have any trustworthy source of ballpark pricing for a 10Gb/s DPI solution, Narus or otherwise, I'm curious. I'm talking BAL…

well, i think you can look up the pricing for gateway nodes for cellular wireless equipment vendors (hspa/umts/lte/cdma etc.). my guess is that it should somewhere around 200-400k range. a sufficiently capable box can handle approx. 7 - 10m subscribers simultaneously doing data.

any cellular network that you send data on, already does this. standardization only levels the playing field.

Re: ITU Approves Deep Packet Inspection Recommendation

#115
post #68

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

This comment was so emptily mean that I took the time to flag it.

It is not empty. I've refused a job I was head-hunted for (IT at a morally questionable firm) on a moral basis, even though pay and conditions would have been better than what I have now. If my current job started requiring me to do something I didn't agree with morally, I would leave (or refuse to do it and be forced out if necessarily).

So I think it is a perfectly valid question (albeit an uncomfortable one) to ask. There may be valid reasons for the OP to do/stay in the job that we aren't seeing. Or there may not. We won't know if we don't ask, and the OP doesn't have to answer.

It is well within the guidelines of HN, it adds to the discourse, particularly on a topic that is basically about morals/ethics. Just because it is an uncomfortable question, doesn't make it fall within what should be flagged.

Re: ITU Approves Deep Packet Inspection Recommendation

#116
post #60

Earlier quoted context omitted.

It seems to be a balancing act. Too little secrets, and your law enforcement has a very hard time detecting threats before they happen. When people use VOIP instead of telephone lines, it's very hard to wiretap Dangerous People (and non-dangerous people). It's easy to find ways that such things make it easier for people whose job, goals, sworn duties, etc are to Protect us, or our nation. Many people join the armed s…

There are so very, very few Dangerous People, and so many, many non-dangerous people. The latter class also includes people with at least some money, so en masse, the non-dangerous people constitute a large amount of money. I reckon that an overwhelming majority of the wiretaps are to make money, rather than to catch Dangerous People, statistically speaking.

A lot of the reasoning behind extending surveillance stems from the need to find the people who enable the dangerous people to do dangerous things.

One example: when I got robbed a couple years back (an armed guy stole my laptop), I had the opportunity to discuss the strategies with the detective in charge of my case. A lot of resources were devoted to catch the guy with the gun, but very little to catching the person (or organization) buying the stolen goods (in this case, a laptop) and reselling them. If you catch the robber, it's easy to replace him. If you disrupt the chain at the receptor, you will do more damage. OTOH, if you catch the unsuspecting buyer of a stolen laptop, he (or she) will gladly point the authorities to the store where they'll find a convergence of many such value-chains. This is where most of the money is and where the most damage will be done to the system. That's why now I have the serial number of my laptops written down and all their labels photographed and stored. And all sensitive information encrypted, in case they don't want my laptop, but the data on it.

Having said that, catching the people who support the really dangerous extremists, the drug-dealers, the pedophiles and the slave-traders involves catching who, at the surface, seems rather harmless, making donations to religious organizations, smoking a joint at a party, buying porn online and groceries from Walmart.

On one hand, we may want to make our technology difficult to abuse, but, on the other, we may also want to find people who are very good at protecting their tracks, and do so through people who really don't know how to do it.

Re: ITU Approves Deep Packet Inspection Recommendation

#117
post #71

Earlier quoted context omitted.

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

But the question was not why the ISP would conform to CALEA instead of breaking it; it was why you as a programmer would take on the job of providing a snooping system, instead of some other job that does not need a lot of explanation about why it's actually not really so bad. There are reasonable answers to this, but I think it's a fair question. (I don't agree that 'we' should pursue criminals (or suspects) using a…

http://en.wikipedia.org/wiki/Banality_of_evil

Re: ITU Approves Deep Packet Inspection Recommendation

#118
post #71

Earlier quoted context omitted.

Speaking as someone who has implemented [shallow] inspection/filtering and CALEA-type features on comms equipment for markets both in and outside of the US.) I'm not trying to flame you here, but I really must ask: How do you live with yourself? I know how trollish that sounds, but I seriously don't understand engineers who voluntarily work against our own ethos. It's not like this is an industry in which implementin…

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

I once quit a job because one of my employer's servers became infected with some malware, spread it to client's computers and the employer refused to notify and apologise to said clients.

I sincerely hope that you grow up and take responsibility for your own actions. They are the only things we truly own. I do not believe that you are evil for what you did but I most certainly believe that you are ignorant in a very dangerous way.

Re: ITU Approves Deep Packet Inspection Recommendation

#119
post #71

Earlier quoted context omitted.

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

I once quit a job because one of my employer's servers became infected with some malware, spread it to client's computers and the employer refused to notify and apologise to said clients. I sincerely hope that you grow up and take responsibility for your own actions. They are the only things we truly own. I do not believe that you are evil for what you did but I most certainly believe that you are ignorant in a very…

I think maybe you missed the point that I actually agree with the mechanisms that are in place. I don't have any disagreements when the framework is used as it is designed to be used. Namely, within the context of due process and rule of law.

More importantly: it's somewhat presumptuous of you to suggest I need to "grow up" or "take responsibility". I stood up in a ballroom full of law enforcement and telecom executives and advocated for the legal, lawful reasons why someone might want to use a prepaid phone without requiring identification. I argued that once you got past accounting, there was no reason to associate the usage details of a phone with a particular party. I even used examples of law enforcement abuse of these facilities to make my point.

There is a lot of misinformation in this thread about what "interception" really means and how it's done. And I suspect in no small way that this is because LEAs dont want to tip their hands as to sources and methods. I won't either.

What I can say is this: if someone is capturing your traffic and has a court order to do it, it's because there is strong evidence that you're using that traffic to conduct illegal activity. A judge is the final arbiter and looks at the evidence (not collected traffic) to support that conclusion.

So...

Don't try and sell Adderall on Craigslist. Don't steal credit cards or trade secrets via bots that "phone home". Don't kidnap children and then send pictures of them to your friends.

The Fourth Amendment protects you against UNREASONABLE search. The reasonableness test is left up to the courts to decide on.

Re: ITU Approves Deep Packet Inspection Recommendation

#120
post #71

Earlier quoted context omitted.

Allow me to add my $0.02 to this discussion. I've implemented CALEA type features for a major ISP. I did it because it was the law that we implement it. I'm generally in favor of following the law. Mind you, CALEA doesn't do anything that couldn't already be done with the law. And you get more protections via CALEA than you'd get otherwise. For one thing, there are warrants that are delivered to a judge for review wh…

But the question was not why the ISP would conform to CALEA instead of breaking it; it was why you as a programmer would take on the job of providing a snooping system, instead of some other job that does not need a lot of explanation about why it's actually not really so bad. There are reasonable answers to this, but I think it's a fair question. (I don't agree that 'we' should pursue criminals (or suspects) using a…

I'd rather have good people involved in "evil" systems, to at least try to balance them, than have evil people involved in "evil" systems where there's nothing but external agencies to provide balance.

And whatever the system is I'd much rather have competent people working on it.

Post reply on HN