Slashdot Mirror


Talk to One of the Chief Carnivore Reviewers

All right, this FBI Carnivore thing and the review it's undergoing at the Illinois Institute of Tech [IIT] has been getting lots of press and lots of flack. The person overseeing the legal end of the process is Dean Henry H. Perritt, Jr. of the IIT's Chicago-Kent College of Law. Ask Dean Perritt any question you want. Tomorrow afternoon we'll forward 10 of the highest-moderated ones to him, and we expect his answers back sometime next week. Note: Before you start questioning Dean Perritt, you may want to check this story in Slashdot's Your Rights Online section, which links to some interesting new Carnivore information. (Special thanks to pridkett for arranging this interview.)

19 of 79 comments (clear)

  1. Ethical question by Devolver42 · · Score: 5

    Is it fair for an individual or group with clear political ties to a system to give that system a review? In other words, how can you be unbiased while still being politically tied to the situation?

    --

    Devolver's Homepage... more fun than a box of crackerjacks.
  2. Is a whitewash inevitable? by Jay+Maynard · · Score: 4
    There's been a lot of comment on how the conditions the DoJ has put on the reviewers make a fair review impossible. Things like the right to edit before release, the right to veto participants, and the need to only use cleared personnel cast a cloud over the impartiality of the process. Many prestigious institutions were invited to submit proposals, and yet only two - yours and one other lesser-known - did. The backgrounds of the people at IIT and their past ties with the DoJ don't give any more reason to be comfortable.


    How do those of us concerned about Carnivore's immense power for invasion of privacy have any reason to believe what you and your institution produce will be other than a whitewash designed to make Carnivore appear in the most favorable light?
    --

    --
    Disinfect the GNU General Public Virus!
  3. Franklin by ucblockhead · · Score: 5

    Do you agree with Ben Franklin, that those who would trade liberty for security deserve neither?

    --
    The cake is a pie
  4. Why IIT? by update() · · Score: 5
    What factors do you think caused the FBI to select IIT over other applicants, like UC-Davis and the National Software Testing Laboratory? Political concerns or the technical merits of your proposal? What were they?

    ---------

  5. Oversight of this interview by Col.+Klink+(retired) · · Score: 5

    Are you free to answer questions posted here, or does the FBI review your answers first?

    --

    -- Don't Tase me, bro!

  6. Can you justify... by sconeu · · Score: 5


    Will you be able to justify the time and expense of a) reviewing Carnivore, and b) deploying Carnivore, when Network ICE has created Altivore, an open source program which claims to do everything for which the DOJ says that they need to use Carnivore?

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  7. Political or Technical Review? by Anonymous Coward · · Score: 5
    Is the substance of this review to be political or technical?

    To wit, is this review to determine if Carnivore performs actions that are within the scope of the law (political), or is it to define the complete potential of Carnvore (technical)?

    If the former has anything to do with it, how can you justify performing this review without bias with your clear political connections to the parties invovled?

  8. Your views on full-open vs (initial) closed review by psychosis · · Score: 4

    What are your feelings on the cries of the privacy rights community on allowing a fully open review of the source code?
    Would you have rather seen the code released on, something like www.fbi-carnivore.com (made up) for all to see/play with/use/abuse, or do you think that choosing a team of professionals to perform an independent review, with later possibilities to release more details (as is underway) is the right way to go?
    What is your repsonse to those who call you "lackeys" and "government pawns" because of your participation?
    All in all, best of luck. I personally feel that the semi-closed method is the better choice, because I know that holding a security clearance does not automatically cause you to lose your ability to think critically. I look forward to learning the results of your review (even if it is sometime "down the line".)

  9. Encrypted Traffic? by freq · · Score: 4

    Can you give us any clue as to if there is any functionality in Carnivore to specifically sniff, filter and analyze encrypted IP traffic?

    Is it conceivable after your team's analysis that future of current versions Carnivore would allow the FBI to flag certain encrypted traffic as "suspicous" ???

    --
    "Tension is the great integrity" -- R. Buckminster Fuller
  10. Why? by LaNMaN2000 · · Score: 5

    After all major research universities refused to apply to review Carnivore because the restrictions imposed on the reviewers are too stringent, why did IIT apply? What do you hope to acheive by reviewing Carnivore under the government's current terms?

    --

    ByteMyCode.com: A Web 2.0 code sharing community.
  11. Your impressions. by M-2 · · Score: 5

    Can you give us your first impressions of the concept of the Carnivore concept when you initially heard about it?

    Can you give us your initial feelings as to the legal standings under the Fourth Amendment that allows Carnivore to be used for the purposes stated, which it would appear technically violates the Electronic Communications Privacy Act?

    What is your impression of the amount of interest the Internet community at large is taking in the entire Carnivore concept? Do you feel there is too much paranoid fantasy going on, or do you feel there is some justification?
    ----

  12. Nevermind whether we trust you; do we trust FBI? by Russ+Nelson · · Score: 4

    How do we know that the FBI will only deploy that which you have reviewed? FOIA requests have shown that the FBI has used other technology, which has done more than capture email.

    The basic problem here is that one connection to one wire gives them access to everyone's traffic passing on that wire. So the only limitation on the FBI's activities is your review and our trust that they are actually running what you have reviewed. What is to prevent them from running a new version of Carnivore, which has new capabilities. Given people's intolerance of "child porn" (including non-purient pictures of young nudists, pictures legal in one country but not another, and pictures of adults who look and dress younger than their age), what is to prevent the FBI from looking for people reading alt.binaries.pictures.kiddie-porn?

    --
    Don't piss off The Angry Economist
  13. Postal Mail vs. Electronic Mail by drenehtsral · · Score: 5

    In the end a system like carnivore will only work for a while, and only against fairly unintelligent users because end-to-end strong encryption is no longer compuationally infeasable. Joe Schmoe with the middle of the road prebuilt gateway could easily handle the processor load of encrypting all his e-mail with 2048 bit RSA (which is now freely available, and even exportable). Not only that, but even with existing (and reasonably near-term) quantum computers, we are not even near enough qbits to start tackling these cyphers, since they can't be broken down when being fed to a quantum computer.

    So in short, is this whole thing just a moot point? Who would Carnivore really catch?

    --

    ---
    Play Six Pack Man. I
  14. Comparing to wire-tapping laws by VP · · Score: 5

    During the congressional hearing on Carnivore, the FBI stated that current wire-tapping laws are adequate for the use of Carnivore. Further more, they revealed that the uses so far of Carnivore had been according to the regulations of optaining a "pen-register" wire tap. Are you aware that (from what we know) technically Carnivore is much closer to the concept of trunk-tapping, as most, if not all the traffic at the ISP has to go through Carnivore? AFAIK, trunk-tapping is illegal - would you be of the opinion that Carnivore automatically falls under the same illegal category of wire-tapping?

  15. Are you willing to lose everything for your rights by anticypher · · Score: 5

    If you found that carnivore did more than the FBI is claiming, would you stand up to their threats if you published your results to counter their "edited" report? Would you be willing to lose everything you have to stand up for the rights of Americans, your property, your retirement, your liberty, and your professional reputation? You would be vilified and persecuted by the FBI for your actions, even though you would win the admiration of liberty loving individuals all over America.

    Or...

    Would you shrug your shoulders, and knowing that some day the truth will out, say nothing if the FBI completely changed your report, and hope that when exposed your reputation is not too badly tarnished?

    the AC

    --
    Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
  16. Exactly what will you be looking for? by Masem · · Score: 5

    Right now, most people think of Carnivore as a black box that basically looks at email headers, grabs the emails of headers of marked addresses, and copies that off to somewhere else. Certainly enough speculation on the technical aspects of this, and many on the ethical side. What will you be looking for when you actually start this study? Are you trying to understand the technology behind it? Are you looking at it's effectiveness? The invasion of privacy issues that come from it? Will you be allowed to make suggestions and recommendations to the FBI, or are you mainly there to try to tell us, the American public, what and what not the Carnivore system can do?

    --
    "Pinky, you've left the lens cap of your mind on again." - P&TB
    "I can see my house from here!" - ST:
  17. Is this a real review? by Apuleius · · Score: 5

    Jeff Schiller of MIT
    has declined to review Carnivore,
    saying that "what they want is a rubber stamp."

    Obviously, you will say you intend to do a genuine
    review.

    Why should anyone take your word over Schiller's?

  18. Why do you get privacy but deny the rest of us? by westfirst · · Score: 4

    The names of the IIT reviewers were initially redacted and only revealed when it turned out that the electronic version was poorly constructed. Why were the names hidden? Do you feel that it's hypocritical to demand privacy for your reviewers while stripping away the privacy of everyone else? If it's so important that our actions be open, why can't yours be open?

  19. Carnivore vs. Sniffer vs. Altivore by RobertGraham · · Score: 5
    I'm the author of Altivore and a long time sniffer user. The RFP was for a "technical" review to validate that Carnivore captures only the data allowed by the court order. Yet reading the resumes of the members of your team, I don't see anybody with sufficient techical experience in sniffing technologies.

    Packet reassembly and state-based protocol analysis are critical to the minimization function. My believe is that Carnivore is essentially stateless, just like my own Altivore. I can create real-world scenarios where Altivore fails the minimization test. Sure, they occur less than 1% of the time; I don't know how that fits within the law. However, software can be written to meet minimization requirements 100% of the time (e.g. BlackICE does this for detecting cr/hacking).

    My question is: will a sniffing expert be analyzing the packet reassembly and protocol analysis part of the source code in order to validate that Carnivore captures all the data authorized by the court order, but no additional data? Moreover, is there really somebody on your team that understands even what I'm talking about?