DOJ Already Monitoring Cable Internet Traffic
According to this Wired News article, the Justice Department is already using its new powers under the USA Patriot Act to obtain subscribers' identities and other information from cable operators without judicial oversight under Section 211 of the new legislation. Assistant Attorney General Michael Chertoff also says that the act has allowed police to obtain IP addresses of cable subscribers and has enabled DOJ to obtain court orders for ISP logs outside a court's traditional jurisdiction. The Senate Judiciary Committee has convened hearings to review the impact of the Bush administration's actions on civil liberties, but A.G. Ashcroft is not scheduled to appear until December 6. One wonders what effect the upcoming cable failure will have on government surveilance of the potentially criminal citizenry.
Actually, it's Echelon, not Eschalon. If you were trying to be funny, i guess I missed it.
Whats not mentioned in the register article (but recently had an article on slashdot) is TLS with SMTP - most people have no clue what this is, and how much of a potential headache it can be for carnivore operators to monitor smtp traffic.
:)
Carnivores purpose is twofold - to sniff your mail obviously, but dont forget it also builds tables of who emails who, and makes it easy for the carnivore operator to track who is associated with who. PGP doesnt help here since it just encrypts the message. However TLS combined with PGP does since it does its mailfrom and rcptto _after_ starttls is issued. Next time you set up a MTA make sure it has TLS support! Shameless plug: TLS for Dummies.
On a side note, dont forget you can tunnel your web proxy via stunnel, assuming you can talk the proxy operator into installing it for you
If you're worried that they are going to force you to give up logs outside of the normal court procedures that the constitution has set forth ... then just say, "Screw you!" when they come knocking on the door.
Section 211 doesn't give them the right to gun you down with machine guns and photon torpedos if you don't comply.
So, you might get arrested, but hey, at least you'll go to court!!!!!!!!!
The most disturbing suspension of civil liberties is the power the Bush administration has given itself to try suspected terrorists in secret military tribunals - all non-US citizens, even long time residents of the United States, can be tried and sentenced in secret military courts.
0 8_1.html
http://dailynews.yahoo.com/h/vvny/20011126/lo/301
If you're non-US citizen residing in the United States, you should be extremely worried.
Quite a few European countries have had problems with terrorosts for years. The UK with the IRA, the Spanish with the Basque (sp?) seperatists etc etc.
In these countries laws on human rights and free speach prevail. (Albeit precariously sometimes, I admit!)
The US, confronted with some of its first terrorist attacks imediatly goes into panic, ignoring the spirit of its consitution.
Not. Jingoistic bunk.
UK Antitterrorism legislation has been around for more than a decade, provoked precisely by the IRA issues. It, too, had sunsetted but repetitively renewed investigatory powers and it, too, treats hackers as terrorists.
It was one of the models from which PATRIOT/USA was cast.
No doubt, the US fell to the standards of its EU allies in adopting PATRIOT/USA, focusing more on getting trains to run on time to defend a nation than to maintain a nation worth defending. No doubt, it was not the American thing to do.
But far from being an icon of liberty, the EU legislation was the harbinger of what happened here.
Most cable modem DHCP pools issue IP addresses based on the MAC address of the requesting device.
How to Set the MAC Address For Dummies:
[root@box]# ifdown eth0
[root@box]# ifconfig eth0 hw ether 00:14:D9:AC:D3:12
[root@box]# ifup eth0
This should get you a new IP address on most cable modem services. Replace the MAC address (that string with 5 colons) with any similar string in the format
00:XX:XX:XX:XX:XX
..where each X is a value from 0-9 or A-F.
Write a script and set it as a cronjob. If your IP is changing every 15 minutes they're going to have a hell of a time keeping tabs on you. If thousands of cable users' IPs are changing every 15 minutes they're going to have a hell of a time keeping tabs on anyone.
Actually CNN has had several roundtable discussions on the secret military tribunals featuring several members (usually those from the ACLU).
Also remember that CNN is the MacDonalds of news: fast, cheap, and everywhere.
Most people who give a damn usually get their info from better sources (NYTimes, Salon, Frontline, the alternative press, etc) many of which bring up these issues all the time.
Don't badmouth the whole of American media when all you see of it is through the CNN keyhole.
What is music when you despise all sound?
A simple IP address is not big deal. What would they do with that?
21:14 192.168.0.1 -> http www.2600.org
21:14 192.168.0.1 -> nntp news.premium.com
21:35 192.168.0.1 -> http astalavista.box.sk
21:40 192.168.0.1 -> http www.princeton.edu
21:42 192.168.0.1 -> http www.slashdot.org
21:43 192.168.0.1 -> http www.islamicjihad.com
21:44 192.168.0.1 -> http goatse.cx
21:45 192.168.0.1 -> irc irc.dalnet.net
21:50 192.168.0.1 -> http gnutellahosts.com
21:53 192.168.0.1 -> http dormroom.school.edu
.
.
.
Looks like probable cause for a search warrant for software piracy, terrorist activity, and obscene pornography to me. And I can already picture the prosecution detailing what's on each selectively chosen site, outlining your criminal state of mind for a jury. (Unless you're not a U.S. citizen, in which case you may well be before a military tribunal).
Another proud carrier of the $rtbl flag
I don't understand the level of panic I'm seeing in most of the replies to this article. Have any of you folks actually read the legislation? Most of it consists of running "sed -e s/phone/phone, voice or internet" on existing laws. E.g., the ability to obtain IP address/name pairs from cable companies is analogous to the ability to map phone numbers to names. We're not exactly shredding the Bill of Rights, here.
There is a real tension between civil liberties and physical safety, no matter what Ben Franklin said; we have enemies who want to slaughter us wholesale, and the freedoms available to them in this country are enabling them to do so. In this context, the USA Patriot Act is a reasonable compromise, despite the newspeak name. The freedoms it sacrifices are non-essential (yes, there is such a thing), and yet it has a fighting chance of being effective. It represents a sweet-spot in the freedom/safety trade-off.
Even if it were the piece of totalitarian toilet paper some would have us believe, it at least has a sunset clause. I.e., on Dec. 31, 2005, the USA Patriot Act ceases to be the law of the land. Not quite what you'd expect from a fascist power-grab.
I suspect the most hyperbolic complaints about this piece of legislation come from people who are upset about the general erosion of civil liberties underway. If you fall into this category, your energy is wasted on the USA Patriot Act. Executive orders allowing military tribunals and spying on lawyers are massively more troubling than the FBI being able to find out whose machine is at 65.12.14.153; if you don't understand why, I'm afraid you've been spending too much time on slashdot.
Here is an email I received from my local provider (Cox) I received it today 11292001:
Dear Cox @ Home Customer:
As you know from our previous emails, Excite @ Home, our vendor in delivering
your Cox @ Home service, filed for Chapter 11 Bankruptcy protection at the end
of September. We have endeavored to keep you informed of the potential impact
this Bankruptcy could have on your Cox @ Home service and are writing to you
today to provide the latest information we have available.
First, we want you to know that we are committed to providing you uninterrupted
high speed Internet service. Cox Communications has been working diligently in
negotiations with Excite @ Home and using all legal avenues available to protect
you, our valued customer. Meanwhile, we have been forging ahead with our
plans to deliver reliable high speed Internet service to you on our Cox-managed
network. You will soon be receiving additional information about our new Cox
High Speed Internet(sm) service, along with information to help you convert to this
new service.
The latest developments with Excite @ Home:
This month, Excite @ Home's creditors petitioned the Bankruptcy court with a
motion to allow Excite @ Home to terminate service agreements with its cable
affiliates on November 30th. This includes agreements with Cox, Comcast and
AT&T. If the Court grants the creditors' request, there conceivably could be a
temporary disruption in the services that Excite @ Home provides to
approximately 3.7 million customers served by its North American cable affiliates.
We are doing everything possible to see that there will not be a disruption in your
service, but also want you to understand the possibilities and to be prepared:
*If the Judge's ruling states that Excite @ Home may terminate its service
agreements with Cox and the other cable affiliates, this does not mean that
Excite @ Home will automatically turn off the service on November 30th.
*With the Judge's approval, Excite @ Home would then have the ability to make
a decision on termination; however, we are negotiating with them to prevent any
service disruption.
*If Excite @ Home decides to terminate service despite our efforts to negotiate a
temporary arrangement, the question remains as to when the service would be
terminated. We are doing everything we can to ensure that your Cox @ Home
service continues until we can transition you to our new Cox-managed Internet
service. In short, we are doing our best to make sure that you will never be
without high speed Internet service.
Additional help Cox is providing:
In addition to exercising legal avenues, negotiating with Excite @ Home, and
building our own high speed Internet service, Cox is also offering the following to
help you and to keep you informed during this transitional period:
* Toll Free Customer Information Line (1-877-832-4751). You can call in for
the latest updates as we work to quickly resolve any service issues.
* Website Message Center at www.cox.com/info We will provide online
updates and a "Frequently Asked Questions" (FAQ) section to address your
concerns.
* Automatic Account Credits. We will credit your account automatically for
service and leased equipment so that you are reimbursed for any time you
are without service.
* Free, temporary dial-up Internet access. In the unlikely event that you
should experience a service disruption, we have arranged for temporary
dial-up access to the Internet via NetZero(r). In order to take advantage of
this precautionary option, please see the "What Should I be Doing Right
Now" section that follows.
Cox has a long history of outstanding service in your community. We pride
ourselves on providing high quality products and the best customer service.
Please know that we are committed to our customers and understand the
extent to which you enjoy the services we provide. We recognize that you
have a choice in service providers and we will continue to do our best to
remain your choice now and in the future. In advance, we apologize for any
inconvenience that the Bankruptcy of our vendor Excite @ Home may cause
you.
Stay tuned for more details, and thank you for choosing Cox.
Sincerely,
The Cox High-Speed Internet Team
Cox Communications, Inc.
_______________________________
What Should I be Doing Right Now?
1. Check your Cox @ Home email daily. Opened messages will be saved
automatically to your hard drive.
2. Download free dial-up Internet software. In the unlikely event that Excite
@ Home terminates your service, you would lose connectivity to the Internet and
access to your Cox @ Home services such as email and webspace. We do not
recommend that you install the software at this time, just download the software
and save it so that it may be installed should you have an interruption in service.
In order to restore access to the Internet and to set up a temporary email
address, we recommend that you register for dial-up service via NetZero and
download the necessary software. You will not be able to download the software
from your home after your Internet service has already been disrupted. While a
free dial-up connection is not ideal, it will give you temporary access to the
Internet for surfing, making transactions, etc. However, you will not be able to
access your Cox @ Home email accounts while the service is shut down. For
information on how to download this software, please visit www.cox.com/info
3. Back up your personal web page to your hard drive or to a CD. (This is a
good precautionary measure to follow at any time.)
4. In the unlikely event that there is a disruption in service, keep your cable
modem connected to your PC until service is restored.
5. Watch for more information from Cox on the transition of your service to
Cox High Speed Internet. At such time that you can make the transition to our
new service, Cox will be providing you with all of the information you need to make
your transition as smooth as possible.
It seems like they are trying their asses off not to lose any customers, which seems to be a very good sign.
I hate sigs.