4 ms·
I'm against anything involving more information gathering, but I'm curious - can anyone explain how this differs from existing CALEA requirements?
by willidiots 15y ago
I'm against anything involving more information gathering, but I'm curious - can anyone explain how this differs from existing CALEA requirements?
- JoshTriplett 15y agoAlmost nothing to do with each other. CALEA requires telephone services to support wiretaps. This would require ISPs, businesses, wifi access points, and anything else sitting between you and the internet to keep a log of dynamic IP addresses and other such connection information.
- palish 15y agoI thought they had to keep logs of dynamic IP addresses already. I know for a fact that coffee shops are required to keep such logs (due to Sept 11th --- discovered this during a phone conversation with a local coffee shop's "router provider").
- runningdogx 15y agoDid you ask the router provider to cite the law requiring them to keep logs?
- palish 15y agoNo... I may as well explain what happened, to put it into context. I was about 19 at the time, and sort of naive. I was trying to figure out why the local coffee shop needed to pay so much money for their internet service. One of the recurring costs was support for their router, which seemed kind of crazy to me at the time (being a tech geek). This was after I had just discovered and fixed a security vulnerability in that router --- I had brought my girlfriend's MacBook to the shop, and noticed I could connect to their payment processing computer (due to the router being misconfigured). That computer had a text file filled with hundreds of full plaintext credit card numbers. So anyway, I went to the owner and put in some time to help him fix this, and that's how I wound up in a position to question "why the heck does this router cost so much per month?" I was toying with the idea of just replacing the whole thing with an inexpensive Linksys or something. (I realize how bad of an idea it is now --- but hey, I was 19.) So I wound up on the phone with one of the sales guys from the router company. He started rattling off (good) justifications for their router: per-customer bandwidth limiting, etc. Among those reasons was "and after Sept 11th, coffee shops are required to comply with <some impressive-sounding regulation name>, which requires them to keep logs of which computers are using their internet, and when". I don't remember anything beyond that, sorry.
- willidiots 15y agoI know there's more to it than this. I realize this was CALEA's original intent, but I clearly recall around 2004-2005, the various TLA's expanded it to include ISPs. Did a little research of my own and found EFF has a nice primer: https://www.eff.org/pages/calea-faq https://www.eff.org/pages/calea-faq . It seems that CALEA started out in '94 for voice calls over the PSTN, but was expanded in 2004 to include "VoIP providers" and "broadband internet providers". Whether the latter are responsible only for monitoring voice-over-broadband, or all data exchanges, is very unclear. Looking at the case files it certainly SEEMS like they're already capturing data exchanges. There are two major differentiators, however, that make H.R. 1981 much more scary. Firstly, the service providers are responsible for capturing this data proactively - effectively a constant blanket wiretap, at the provider's expense. Compare this to CALEA, where the capture begins only after a court order, and the cost is billed to the government. Secondly, and more disturbingly, this bill represents the shift in mindsets of our elected officials. When drafting CALEA in '94, Congress went out of their way to ensure it only applied to PSTN calls (specifically stating it would NOT apply to data networks such as the Internet) and minimized the amount of content logged by the telcos. The baseline assumption was that people are innocent until proven guilty. H.R. 1981 seems to think it's the other way around.