So I was specifically told by a detective.
*Australia has laws that requires ISPs to keep metadata for at least two years.
So I was specifically told by a detective.
*Australia has laws that requires ISPs to keep metadata for at least two years.
Yes, my intention was to say that it'll get their attention, but as a single data point won't justify a raid.
The detective said it to me as part of the conversation in which I was told I could collect my seized equipment, and it was said in a way that implied they thought I was still "guilty" despite the fact they found nothing incriminating in the multiple terabytes of data they seized.
The other (laughable) 'red flag data points' the detective mentioned were:
- The usage of virtual machines
- Having downloaded items from MEGA
Incredibly low bars for suspicion if you ask me, but then I know a bare minimum about technology...
I believe URLs are captured where it's possible for them to be captured.
I assume they'd usually be following backwards from an IP address, e.g., in some investigation they've raided some server logs and found a connection from an IP address, and they'd then go to the ISP to get the name/address of the subscriber. They seem to do this quite frequently.
Interesting (cherry-picked for maximum outrage) excerpts:
In a report tabled in parliament by the Ombudsman in February 2021 (covering the period from 1 July 2018 to 30 June 2019) all agencies investigated were found to have accessed Australians’ metadata without the proper authorisation. “We identified instances at all inspections in 2018-19 where agencies had accessed telecommunications data without proper authority. As such, the disclosure of the data was unauthorised,”.
The committee heard that while mandatory data-retention laws permit just 21 agencies to access the metadata, more than 87 other entities — including councils, the Victorian Institute of Education, the RSPCA and the South Australian fisheries department — have used section 280 to gain access.
(Unrelated side note: this is the same country wanting to be given backdoor keys to encrypted communications).
I think a court warrant is needed before the ISP records can be accessed.
What ASIO can do, however, may be a different story.