RouterOS – Communications Assistance for Law Enforcement Act (2012)
wiki.mikrotik.com
wiki.mikrotik.com
[0] https://www.fcc.gov/public-safety-and-homeland-security/poli... [1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...
Interesting times with many unfortunate decisions.
[0] https://en.wikipedia.org/wiki/Telecommunications_Act_of_1996
Regan rolled back enforcement of many rules, and the rules were changed to exand Clear Channel's (and other) monopolies under W.
The wikipedia article you shared actually states this pretty clearly as well:
>" The IP-based "soft switches" typically do not contain a built-in CALEA intercept feature; and other IP-transport elements (routers, switches, access multiplexers) almost always delegate the CALEA function to elements dedicated to inspecting and intercepting traffic. In such cases, hardware taps or switch/router mirror-ports are employed to deliver copies of all of a network's data to dedicated IP probes."
(I realize that Microtik's RouterOS may end up on headend router devices and that is likely why this exists, but the implementation details here are just a little odd when you can just port mirror on a switch instead)
This isn't targeting CPE equipment - MicroTik is baking into their unified OS. If you're a service provider you don't configure CALEA in the CPE, you configure it upstream in the headend where all traffic from your customers egress your network. It's much easier to grab it all at the bottleneck than to have data streaming over your expensive last mile twice for each customer, that doesn't make any network architecture or OpEx sense. It's just easier to make CALEA a function of RouterOS vs target specific models. There's nothing specific about the hardware that's required to implement the functionality.
I just learned bout it for the first time.
I need to stop reading these things. I just become more and more misanthropic as days go by.
Some SOHO networking devices made by Microtik, QNAP and Ubiquiti contain Arm SoCs made by AWS (Annapurna Labs), https://en.wikipedia.org/wiki/Annapurna_Labs
The venerable PC Engines APU2 is a fanless x86 AMD 10W TDP router with 4GB ECC RAM, TPM 2.0 and GPIO pins, open schematics and coreboot, which can run pfSense, OPNsense, OpenBSD, Linux, FreeBSD and OpenWRT, with virtualization support. Constrained by supply chain at present. mPCIe slots for WiFi, LTE & mSATA.
Ubiquiti ERLite-3 can run Linux and OpenBSD (octeon/MIPS).
There are some generic Intel-based small routers, https://www.servethehome.com/topton-intel-j4125-4x-i225-fanl...
because someone found and read this wiki and decided to share it with others who also found it interesting so they upvoted it. now here we are
Maybe better to add this date to the title.
> Calea provided options are available only for specific RouterOS user, as Calea server configuration as "tap" configuration. Specific user should have 'sniff' policy enabled at RouterOS user configuration
So the admin has to set up a user account on the device.
So it can be both - dedicated user with the appropriate permission, or admin himself.
Though if there are other remote access vulnerabilities, someone may be able to use the feature maliciously once they're in.
Is there any way to not have a backdoor built into my router?
This is a way for the router administrator (you) to manually give the police access to a copy of traffic in response to a warrant. The assumption here is that this router is being run at an ISP, and you're a netadmin responsible for handling legal compliance requests.
It's just firewall rules and pcap.
Not sure this is front-page worthy.
I didn't know about CALEA since before but I've dealt with lots of network infrastructure (never in the US though), so I found this interesting, and upvoted it.
why not ? i believe it is especially as i imagine most people are not aware that such things exist in freedom lands
This is bloody everything from a particular endpoint, and not in an application specific manner. There is very little but storage reqs and someone getting uppity keeping this from becoming a dragnet type of surveillance mechanism.
it should come as no surprise that those devices can log the data passing through it.
Do you mean firewall rules? Because firewall rules definitely exist in "freedom lands."
A lot of the comments here seem to show an eagerness to misunderstand this. Even in a "freedom land" law enforcement still needs the power to intrusively investigate criminal suspects, because ineffective law enforcement is a bad thing and a threat to liberty.
the point is that in the US this [the device you own snitching on you] is required by law
https://en.m.wikipedia.org/wiki/Communications_Assistance_fo...
absolutely nothing ? are you sure about that
“Why are you so concerned with the old Constitution” you proclaim, “we have the patriot act instead. It even has the word patriot in its title and the iPatriot act is on the way to replace the old patriot act. I support next-thing.”
If you're the one controlling the network router, you know when the sniffing is going on - this would be trying to detect that your ISP has turned the "NSA button" on.
That process says more about the people in power than the people using the internet especially when you see how leading search engines can be with their results, its like they want you to fail in order to consolidate their top tier position in society, intellectual feudalism.