H.R.1981, the end of online privacy as we know it.
spideroak.com
spideroak.com
The quotation marks imply that the quoted text, which the entire remainder of the post is built on, is part of the bill. It's not, as far as I can tell. In fact, there's no requirement that resembles those described in any conceivable way. Assuming the version on the Library of Congress website [0] is current, the only section regarding record-keeping by ISPs requires them to keep track of customer IP address assignments for 18 months:
> A provider of an electronic communication service or remote computing service shall retain for a period of at least 18 months the temporarily assigned network addresses the service assigns to each account, unless that address is transmitted by radio communication (as defined in section 3 of the Communications Act of 1934).
The only interpretation I can come up with is that the linked post is a deliberate lie.
---
(a) In General- Section 2703 of title 18, United States Code, is amended by adding at the end the following:
`(h) Retention of Certain Records- A provider of an electronic communication service or remote computing service shall retain for a period of at least 18 months the temporarily assigned network addresses the service assigns to each account, unless that address is transmitted by radio communication (as defined in section 3 of the Communications Act of 1934).'.
(b) Sense of Congress- It is the sense of Congress that records retained pursuant to section 2703(h) of title 18, United States Code, should be stored securely to protect customer privacy and prevent against breaches of the records.
---
In other words, it amends the existing language [0] which says (in part):
---
A provider of electronic communication service or remote computing service shall disclose to a governmental entity the—
(A) name;
(B) address;
(C) local and long distance telephone connection records, or records of session times and durations;
(D) length of service (including start date) and types of service utilized;
(E) telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and
(F) means and source of payment for such service (including any credit card or bank account number),
of a subscriber to or customer of such service when the governmental entity uses an administrative subpoena authorized by a Federal or State statute or a Federal or State grand jury or trial subpoena or any means available under paragraph (1).
[snip]
(f) Requirement To Preserve Evidence.—
(1) In general.— A provider of wire or electronic communication services or a remote computing service, upon the request of a governmental entity, shall take all necessary steps to preserve records and other evidence in its possession pending the issuance of a court order or other process.
(2) Period of retention.— Records referred to in paragraph (1) shall be retained for a period of 90 days, which shall be extended for an additional 90-day period upon a renewed request by the governmental entity.
---
So you're 100% right: the name, address, etc information is ALREADY being preserved. This legislation mandates that records of IP addresses linked to accounts be stored for at least 18 months, whereas before they would have been retained for 90-180 days.
---
[0]: http://www.law.cornell.edu/uscode/18/usc_sec_18_00002703----...
If I was unclear in the post I am very sorry and will amend the post.
That said the core of the post stand. The linking of currently stored data with IP-addresses creates a direct link from internet usage to personal data. Something that should scare most people.
Now I guess one could assume that our ISP's save our browser history, however there is no mandate in this bill for access to that data.
I will look over the blog post and make edits to clarify this.
Thank you very much for pointing this out!
I would like to thank you for pointing this out and I took the liberty of thanking you in my update of the post.
That sounds a lot like FUD tactics. The internet freedom camp seems to apply these more and more, seriously blurring the debate and screwing it over. Why are you doing these things? Why do you act as bad as the people crafting these laws? Why do you allow both camps in this debate to remove all truth altogether?
> (E) telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and
http://www.law.cornell.edu/uscode/18/usc_sec_18_00002703----...
The new law explicitly amends the previous law so that IP address records are stored for 18 months, as opposed to 90 days.
I'm speechless.
The reaction was pure hate for my posting because it was defending pedophiles (it wasn't). It felt like an angry mob that had nothing but revenge on its mind.
This is why the efforts to destroy all privacy will succeed. For the kids. Yeah, that's it.
The reaction was pure hate for my posting because it was
defending pedophiles (it wasn't).
What do you except? It's sad to see that even usually decent and intelligent people devolve into frothing mobsters when you oppose something that's 'for the children', however ridiculous it may be. It becomes especially despicable when you see the content industry essentially stating that child pornography is a fabulous excuse to justify domain seizures, censorship and other completely outrageous measures to protect their failing business model[1].It's pretty difficult (if not to say dangerous) to hold a position that's in opposition to such measures. Especially, as in my case, when one is of the opinion that it's not child pornography we should be fighting, but child abuse. The former is, for the most parts, a victimless crime (just look at what's consider child pornography today, it's absolutely ridiculous). I would even say that the holy crusade against child pornography obfuscates and hinders the fight against child abuse severely.
[1] http://torrentfreak.com/the-copyright-lobby-absolutely-loves...
See Amendment 36 at: http://judiciary.house.gov/hearings/mark_07272011.html
Got a piece of legislation on drilling for oil in Alaska? Call it the 'Freedom from Terrorism act' and just like that. It's approved. No one reads the entire Bill, so the name is a HUGE part of the process.
The fact that they actually went this far... I don't know whether to laugh or cry.
DRDL interconnects control and data sessions of protocols like FTP. During the identification process DRDL aggregates detailed traffic properties like MIME-type, filename, chat channel and SIP caller ID. This granularity enables you not only to see the Xbox Live traffic, but rather the Xbox Live users who are playing Halo 3.
It's not clear whether use of a VPN/SSH would prevent this kind of traffic analysis, but an obfuscation daemon of some kind could surely be written.
While it's kind of interesting, I've never researched how networks like Freenet, or WASTE, etc deal with those issues (or, if they even address them at all).
[1]http://www.proceranetworks.com/products/drdl-technology.html
The resolution is here: http://thomas.loc.gov/cgi-bin/query/z?c112:H.R.1981:
The resolution modifies the legal code (law) given here: http://www.law.cornell.edu/uscode/18/usc_sec_18_00002703----...
[Edit] There is a reasonable write-up of the action from an ACLU blog here: http://www.aclu.org/blog/tag/HR%201981
I live in Norway, and the DRD (Data Retention Directive) will be activated July next year (I think). At that time, I will push all my traffic through a VPN. My 5 cents.