4 ms·
That's actually the example [CALEA] I had in mind as well. I don't see a huge technical hurdle here, other than maybe a script to disable all peering interface
by bitskits 16y ago
That's actually the example [CALEA] I had in mind as well.
I don't see a huge technical hurdle here, other than maybe a script to disable all peering interfaces for every ISP in the US. This could be done by hand just as easily should Uncle Sam come knocking.
The real issue, to me, is the why behind this. The only real motivator is to prevent people from organizing to overtake a government they perceive as corrupt. Is it really worth exploring crippling our economy and stifling free speech at the same time? Forget the technical hurdle, what about the constitutional one?
Interesting that we also claim to have a way to "force" internet on a country who kills it, but at the same time are looking for a legal basis to kill it ourselves.
- roc 16y ago> "Forget the technical hurdle, what about the constitutional one?" We haven't had much luck with that one lately. I don't think the "Why" is quite so transparently dystopian. They don't want to turn off the entire internet. It's just another attempted end-run around the judicial process, to make it easier to further political and economic goals. e.g. filtering WikiLeaks or BitTorrent. The idea that they would need this to disconnect critical infrastructure to protect it from cyberattack is laughable. Any critical infrastructure that could still operate independent from the internet should not have a connection to the internet, and if it did should certainly have it's own disconnect capability. The only reason to put disconnect capability on the ISP or backbone carrier is to do it against the will of the target facility. If they wanted to protect things like the Hoover Dam [1] they'd just issue/enforce some government regs. [2] [1] The Dam Authority has already taken issue with being a talking point in this debate. Pointing out that, no, they are not foolish enough to have dam controls connected to the internet. [2] I'm pretty sure these already exist, as regards air-gaps for critical infrastructure and security requirements for networks that do have a connection to the public internet. There may not be a unified national service to flip connection-kill-switches, but that would be resolved with a government network project, not a new law. The government already has legal authority over infrastructure.
- security_ish 16y agoWhile I don't think it is technically impossible, I don't think it is as quick and easy to deploy and support as CALEA. For example... - ISPs would have to be able to characterize all their connections and subnets as being part of the critical infrastructure and of which parts of the critical infrastructure those users or networks were members. - This entails insane tracking and management - literally thousands of smaller CIP organizations might be served by one ISP - they have to know in real time what IPs/ranges/etc, and on what ports, those organizations are operating - Central management or the ability to engage the 'kill switch' implies that there is some means of remotely (read: outside the ISP control) engage the kill switch and remove those organizations from the network All of those points (and many more I can include later) make this vastly different from CALEA, where a warrant compels ISP personnel to engage collection on an IP or target of interest and to turn over that capture to the authorities. That puts the control in the hands of the ISP - the kill switch would put the controls of ISP assets in the hands of the government.