6 ms·
The privacy concerns nonwithstanding, I'm puzzled how ISPs are supposed to actually implement that load of bollocks. We're talking DPI here, applied as a dragn
by datenwolf 10y ago
The privacy concerns nonwithstanding, I'm puzzled how ISPs are supposed to actually implement that load of bollocks.
We're talking DPI here, applied as a dragnet on each and every connection. The bill explicitly states that every connection is to be tracked, which means it disallows the stochastic methods that normally are used for traffic instrumentation.
And even storing "just" the metadata, over the course of a year, that's quite a significant amount of data. Where the hell are ISPs supposed to store that? And store it securely in a way, that only "lawfull" access is possible.
That bill is stupid and ludicrous and the people who came up with it should be institutionalized, IMHO. Not just because of the privacy concerns.
- loup-vaillant 10y ago> We're talking DPI here, applied as a dragnet on each and every connection. Didn't Tempora¹ achieve something very similar? This law sounds eerily similar. Still stupid and ludicrous, though. [1] https://en.wikipedia.org/wiki/Tempora https://en.wikipedia.org/wiki/Tempora
- Create 10y agoCreate 291 days ago | parent | on: UC Berkeley profs lambast new “black box” network ... Transparent monitoring for your protection In keeping with this spirit, here is a reminder of how we monitor (your) CERN activities. We monitor all network Traffic coming into and going out of CERN. Our new analysis infrastructure will be able to cope with the automatic live analysis of about one terabyte of data every day. All this data is stored for one year. http://cds.cern.ch/journal/CERNBulletin/2016/05/News%20Articles/2126902 http://cds.cern.ch/journal/CERNBulletin/2016/05/News%20Artic...
- datenwolf 10y agoThat's traffic analysis, not traffic metadata retention. The problem is not the computational load, but the storage capacity and bandwidth requirements. And what is stored at CERN is the analysis results of the data, not the data history itself. Also it's one TiB/day in total for the whole of CERN.
- mfukar 10y ago> The privacy concerns nonwithstanding, I'm puzzled how ISPs are supposed to actually implement that load of bollocks. DPI products have been doing that for years. No biggie. The law is still stupid, but not for technical reasons, imo.
- datenwolf 10y agoThe problem I see is not the computational power required for implementing the DPI, but the storage capacity and bandwidth required to implement retention for upo to a year. Lets assume that ISPs were applying a data cap of, let's say 200GiB/month. MTU for Ethernet is 1500 octets, with PPPoE it's 1480. IP Headers are at least 17 octets, so around 1% overhead for a optimally utilized connection. In that situation this gives about 2GiB/month of IP header data. Even if you strip that down to just the source/destination address that would still leave you with 800MiB/(customer·month) of data. That's the bottom baseline you have to provision for. Of course your typical TCP stream is highly redundant and even simple RLE compression will cut that. But ISPs have to provision for the worst case. Currently there are about 60M internet users in the UK. That would amount to about 536PiB/year of retention data to be provisioned for (worst case). And even if due to redundancies you can compress that down in practice that's still a lot of harddisks to keep around just to store the bare minimum (who with whom, but without context) of a whole country's internet traffic metadata (about 100k HDDs). That's a significant investment that's expected from ISPs to be implemented in a very short timespan.
- mfukar 10y agoDisclaimer: I won't claim to have read the law or even caring about what happens in the UK. From reading related articles, I get the idea its requirements can be implemented in terms of a browsing history, which could point to a date in the internet archive for all the legislator cares. Hint: that's how you compress browsing habits for > quadrillions of requests. I don't see why one would need complete packet traces of the whole thing.
- datenwolf 10y ago> From reading related articles, I get the idea its requirements can be implemented in terms of a browsing history, which could point to a date in the internet archive for all the legislator cares. Good luck doing that with a TLS secured connection. All you see is the TCP stream between the two peers. And thanks to PFS enforced on the server side you can't even go around and force people to escrow their keys. > I don't see why one would need complete packet traces of the whole thing. Because that's the only thing an ISP is able to see of a properly encrypted connection.
- m0nty 10y ago> implement that load of bollocks They are retrospectively making legal things which have been going on for years. https://www.theguardian.com/uk-news/2014/jan/28/gchq-mass-surveillance-spying-law-lawyer https://www.theguardian.com/uk-news/2014/jan/28/gchq-mass-su...
- Programmatic 10y agoBut it's more than that. If it's illegal to spy, that means you can't disseminate the fruits of that spying far and wide. You need to resort to parallel construction and carefully safeguarding your sources. This allows a massive expansion in the scope of capture and use of that information to more agencies in a "legitimate" manner. At least when it was illegal they had to contain the "conspiracy" lest it get out.
- Toenex 10y agoIndeed one way to devalue this information would be to swamp ISP servers with 'fake' data; hide our real activities in the noise. What we need is someone to release a modified versions of Chrome/IE/Firefox that spends all your browsing downtime accessing 'dodgy' sites. If everyone starting using it this information would soon become either impossible to store and pointless as everyone is a criminal according to the data.
- 3chelon 10y agoMaybe people will actively sign up to be part of botnets launching DDoS attacks continuously, just to generate enough noise.
- deleted 10y ago[deleted]