Indian ISPs: We already give govt full access to web traffic
entrackr.com
entrackr.com
Yes. There is almost certainly access. But it’s partial and adversarial, not automatic as in India.
It even includes a helpful FAQ like agents wondering why they might receive copies of the same message multiple times. What happens there is when somebody they're spying on logs in via another device, their resync process involves everything being sent right on over directly, automatically, and in real time to the NSA again. They can even spy on video/audio in real time, with some promises to agents frustrated about audio falling out of sync with video - that they were working on a technical solution.
The companies at the time participating in PRISM were Apple, Google, Microsoft, Facebook, and others. That's undoubtedly been long since expanded.
[1] - https://en.wikipedia.org/wiki/PRISM
[2] - https://www.aclu.org/sites/default/files/field_document/Guid...
Numerous cases have been filed against the NSA in regards to PRISM, with nothing even remotely close to success. They are invariably thrown out because the NSA acting illegally or unconstitutionally can only be challenged by somebody with standing. You only have standing if you can prove you have been surveilled and affected because of such. Nobody can prove standing, so it's impossible to legally challenge a likely illegal program. Great system we have.
It's like if we were discussing a serial killer and you were like "don't you think other people have killed?"
The second reply to this post and someone is already redirecting the conversation to a country not mention in the story. Are you upset because you think India is being singled out? No where on the article or the comment does it imply that.
On HN there are a massive amount of discussion about US government spying already, it's not something that people aren't aware of.
Do you see any TLS connection resets based on SNI? If not, most(all?) indian ISPs already visibly do far more than average American ISP.
echo "example.com \n reverse_proxy localhost:8000" > Caddyfile; docker run caddy --net host -v $PWD:/config caddy run
It's slightly more complicated if you need redundancy, but not by much.
The plot for the movie was actually based on an account from an NSA employee who tipped one of the producers or director (I forget which) of the mass surveillance the agency was involved in.
To me this movie is iconic just because it predicted events so vividly almost a quarter of a century ago.
Now I think it's unrealistic because Will Smith and Gene Hackman survived the first 25 minutes of the film.
If you like "Enemy of the State," you absolutely must watch "The Conversation"[1] if you haven't already. You may decide, as many have before you, that it exists in the same universe as "Enemy of the State," and that Gene Hackman's character in "Enemy of the State" is an older, even more cynical Harry Caul from "The Conversation."
That it’s a misguided law is open for debate, but I don’t believe there is any state in the world that doesn’t monitor and control tele-communications (internet is regulated as tele-communications WW).
> ... access to this data is so accessible remotely that physically visiting an internet provider’s premises is no longer required for government agencies.
They were expecting government agents to have to physically visit the ISP's offices? Were they perhaps going to get their data on a floppy disk?
One of examples: https://en.wikipedia.org/wiki/Room_641A
Airgapped systems are also still a thing.
On-site access would also make it harder to abuse the data at scale.
I’m not surprised that the data is accessed remotely. But I can also understand scenarios where it makes sense to require physical access, and not because of long gone floppy disk drives or other ancient hardware.
[1] https://www.eff.org/deeplinks/2021/05/foriegn-intelligence-s...
"Rights of investigation" and "capillary monitoring" are poles.
Such rights were included even in the constitutions of many communist countries, despite the fact that there it was a routine activity for the secret police to open all suspect private correspondence and listen to many telephone calls. Nonetheless, they had to be careful to not get caught, because the official version was that their activities were illegal and even anti-constitutional.
Unfortunately, now almost everywhere such rights have been weakened or completely eliminated, without any good justification and without the opposition that such changes deserved.
What do you mean "without any good justification" ? It is for your own good to protect you from terrorists (the bad ones specifically), hate speech (anything which is against the official narative) and child porn. /s
Why would change deserve opposition when it is for your own good and the change is in better [1] ? /s
[1] See Monty Python's Life of Brian - Ex-lepper scene.
The FCC doesn't regulate content on cable TV. Technologically, there's no reason cable radio couldn't have existed.
https://en.wikipedia.org/wiki/Federal_Communications_Commiss...
Even if the FCC chose not to regulate broadcast programming, they or some other body, would still need to enforce rights to frequencies. That's their raison d'etre. Content policing is an added function, which the law has found valid in the past precisely because frequencies are limited. I can't see such public interest legal opinions being newly formed today.
Edit:
I would also like to add, one of the latest news was about malicious access of administrative data in Australia - which surely has in general more funds to invest in security than others. I would be concerned about personal data being copied in more repositories (multiplying chances of malicious access).
One thing that people from the "global north" need to remember is that in most of the world, laws are just loose guidelines.
But there is always the next target(s) to go after, to keep in check, in a pop culture sense. So one way is to see this (article and this HN post) as a hit piece.
But also configuring or avoiding certain other software: https://spyware.neocities.org/articles/index.html
I suppose the news here is that the response was so relaxed that governments started doing it publicly and explaining the tech.
This started in the 60s! I remember hearing about it in the mid 90s on random internet forums.
But seriously, to me this is a sign that a state is never the friend of its people. There are no sensible security arguments without also looking at the dangers of dragnet surveillance. The US isn't different, the EU isn't different.
QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away the need to track 5-tuples to identify individual customers, easing the scaling of monitoring.
[1] https://datatracker.ietf.org/doc/html/rfc8999
IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space. Each citizen can then be assigned an unique IP address which makes it easier to distinguish traffic without the cooperation of each NATing layer.
[1] https://support.huawei.com/enterprise/en/doc/EDOC1100055044/...
You don't understand how IPv6 works.
Couldn’t reply to other comment
All I'm saying is that there's better segregation of the traffic from each IP resulting in easier analysis without the cooperation of NATing layers.
This page [1] shows I am using HTTP/3 which unless I am mistaken requires QUIC to work.
Otherwise there wouldn't be illegal dragnets (Room 641A, DITU, PRISM).
The lying/agenda thing seems to just be one comment. Try not to assume that one angry reply represents a larger chunk of HN's readership. The Internet is full of bus-stop boxers, it is best to not let them wind you up overly.
you get to have a thick skin when you are on an anonymous public platform. i accept that....
i live in a place where i have to actually assume malice on part of the government because the government "is" hostile against me. Again, this isn't some tin-foil conspiracy but as you might've guessed from my handle, its yeah...
So that comment earlier and the current article about ISPs tracking users, this is primarily to catch critics and dissenters.
I was suggesting that the downvotes there, complained about above, where people disagreeing with this possibility, on the basis that it would not offer a practical amount of extra information (considering the effort involved) than already being gleaned with other methods they are already using. Not generally how downvotes should be used IMO, but it happens.
it could something like adblocker list, No more central CA.
"The Internet is broken."
"The conventional Internet is currently like a system of roads with deep potholes and highwaymen all over the place. Even if you still can use the roads (e.g. send emails, or browse websites) your vehicle might get hijacked, damaged, or long arms might reach into its back and steal your items (data) to use it against you and sell it to others - while you can't even notice the thievery nor accuse and hold the scroungers accountable. The Internet was not designed with security in mind: protecting against address forgery, routers learning metadata, or choosing trustworthy third parties is nontrivial and sometimes impossible."
they are not thieving your precious bits, they are copying them as they are transmitting them. this s also why you cannot even notice the “thievery”.
furthermore, this analogy is mangling together data legitimacy, security, and property rights all into one big ball of “be worried, the internet is stealing you because it wasn’t designed with safety in mind”
Comparing the internet to a highway system is a common and useful thing to do. Your objections are strange.
> they are not thieving your precious bits,
If I look over your shoulder at the ATM and learn your PIN, is it not clear what I mean when I say that "I've stolen your PIN?"
> mangling together data legitimacy, security, and property rights all into one big ball
Is entirely intentional, because these are things to be worried about on the internet.
GNU Project is community-driven, after all.
From the Indian govt perspective, the dominance of the Internet by foreign owned businesses means that the country is vulnerable to malfeasance should those foreign governments mean India harm or come to decide - over the head of the government - what the Indian people want or need.
This is about national sovereignty and national security. We have seen how those values trump privacy concerns for individuals in any country, including the US, so must accord the same understanding for other nations also.
Loose terms like "national security" are like good times that breed weak leaders. I think we must all agree that citizens have a right against persecution.
What track record does this government have that suggests they will do no wrong with their internet history logs?
Yes this is true!
Hence government needs to invest in indoctrination in order to better convince the people of the justness of their actions. Singing the national anthem, waving the flag, inventing enemies without and within - it's pretty easy to build the 'cognitive infrastructure' required to carry the day
What if the citizens were agents of the enemy?
for example, the government might suspect a citizen to be an agent of the CCP. Would you defend that individuals right to privacy, vs the nations right to security?
Unless the assumption is that all citizens of a country are potentially enemies of the state and we are all highly trained spies operating under deep cover for years...