first, please, please don't send passwords unencrypted. I'm not the only one who can look at your traffic. Spoofing a route in bgp is, to my understanding, not a difficult thing to do, which means that really, anyone on the net with a sufficiently well-connected BGP box can sniff your traffic.
but yeah... would just giving you access to all the information I had about your traffic be sufficient notification? That seems like the best way to handle it to me, I mean, if I've got a IDS all setup, it's no more work for me to let you see the results, and especially on incoming traffic, that has value to you.
>However I would expect you to get a notification before you started to murk around with my traffic, since it is liable to interfere with my use of the services that I have paid for.
Yeah. mucking about with people's traffic is tricky, and /certainly/ deserves a notification. Right now, the only time I do it is when you go over your transfer limits; in that case I use tc to bump you down to something that can't hurt me, and obviously, I tell you.
If I /wanted/ to provide a bulk transfer service, rather than limiting the overage accounts to 1mbps or less each, I'd take accounts that are in overage and let them have as much bandwidth as they want, just making that bandwidth a lower priority than the bandwidth of my paying customers.
Now, my experience with that kind of traffic shaping is that it's never perfect, you always interfere at least a little with the high priority traffic; or at least that's been the case every time I've tried doing that, so I don't. But, I've heard of others doing it with varying degrees of success; it's one of those things that can possibly make a cheaper service better if you allow the provider to muck with your packets.