Slashdot Mirror


EU Still Looking at Mandatory Data Retention

An anonymous reader writes "Following up on a previous Slashdot article, European civil rights advocacy group Statewatch is detecting more rumbles of a possible weakening of privacy rights in the EU. The European council has been testing the waters for a new policy mandating retention of communications "traffic data" by all member states. The previous policy (adopted May 30) merely allowed an exception to EU privacy law for member states who wished to retain such data. Under the leaked draft proposal, law enforcement is to be allowed access to "traffic data" (identifying source, destination, time, etc.), which is similar to current US law. However, much worse is the requirement that telco providers retain such data for 12-24 months. Text of the draft framework decision is available. Also analysis by Statewatch. Backup link (in case of Slashdot effect)."

102 comments

  1. Sounds like... by cez · · Score: 3, Funny

    Someone has mad equity in the databackup / storage market out there

    --
    Walk with Music;
    1. Re:Sounds like... by Anonymous Coward · · Score: 0

      Or there's going to be a lot of backups using lzip

    2. Re:Sounds like... by Anonymous Coward · · Score: 0

      Would have been nice if they kept the data too. That way we can solve newsgroup retention on warez groups. ;)

      This would be a neat way to track SPAM back to the sender...

    3. Re:Sounds like... by srmalloy · · Score: 1

      If it wasn't for the requirement that the data be accessible to law enforcement, there wouldn't be a problem; WOM (Write-Only Memory) with capacities in the high exabyte range has been around for decades, and could be expanded to zettabyte and yottabyte ranges with very little research expenditure or manufacturing cost.

  2. How? by dattaway · · Score: 2

    This sounds like a great service from Big Brother, but how are they going to pull this one off? At taxpayer expense?

    I see the need to ping eachother with random terrabytes of data. Who's going to pay for this expensive archiving?

    1. Re:How? by cez · · Score: 1, Funny

      exactly, someone will pay, and someone will definately produce a nice proffit...whos that again?

      --
      Walk with Music;
    2. Re:How? by Anonymous Coward · · Score: 0

      That's ok, they'll just store the petabytes of data on transcapacitors.

    3. Re:How? by JCCyC · · Score: 3, Insightful

      "Gee, officer, our server just had a fatal crash last week."

      Or:

      "Gee, officer, the warehouse where we hold our pile of DVD-Rs with traffic logs just caught fire!"

      Or:

      "What the...? Someone seems to have demagnetized our entire pile of backup HDs! I'm shocked, just shocked!"

      What now? Mandatory data reliability? Or will you just have to hand your logs to the Gestapo every Tuesday?

    4. Re:How? by gl4ss · · Score: 1

      we're all taxpayers around here, and somebody has to pay for the data to be stored shit, so a taxpayer(s) pay it.

      on the other news, i thought they've had access to connection logs(connections from what to where,including time 'n stuff, but not what was in that connection) since ages, and i'd figure most/all isp's store those logs already, they sure had access for this kinda data couple of years ago(in finland. i know.).

      --
      world was created 5 seconds before this post as it is.
    5. Re:How? by dd301 · · Score: 1

      What now? Mandatory data reliability?

      I guess you are not familiar with the RIP bill in UK. Soon, it will be your responsibility to prove that you didn't destroy the logs on purpose.

  3. Encryption by Anonymous Coward · · Score: 0

    Well if all our data was encrypted, would all this "data retention" matter? I can just see Echelon spending gobs of cash to build supercomputers to crack all the mail and data being sent.

    Hey wait, they would just legislate to dumb our encryption down... :(

    CausticFit-

  4. Re:check it baby by J4tentacles · · Score: 1

    oh, heh, sorry bout that... Just thought it was cool.. can't seem to find forums here anyway.. does /. have forums?

  5. Bad for the echonomy by oliverthered · · Score: 3, Insightful

    There's no way this will get through (he says!)

    It will cost too much and with have an impact of inflation which no one in the EU wants to see at the moment. There will be bandwidth implications because of the storage and processing overheads and investment and development in new infrastructure and technologies will be hit.

    And who gains, well if the police can actually filter the data and find out what you up to then maybe a few people who have had criminals take away there liberties will feel better.

    Who looses, everyone else.

    --
    thank God the internet isn't a human right.
    1. Re:Bad for the echonomy by Anonymous Coward · · Score: 0

      Inflation? more like it will cripple an already weak IT and telecoms market.

    2. Re:Bad for the echonomy by oliverthered · · Score: 1

      That would force up prices to drive income from other sectors and create inflation.
      The cost of basic services would go up, causing inflation.

      --
      thank God the internet isn't a human right.
  6. Prices? by zmalone · · Score: 1

    How would this effect the European ISP community? Would the governments subsidize it, or would the costs be dumped on the consumer, increasing the cost of net access in Europe even higher then it already is?

    I suppose that in many regions where broadband has not been widely adopted (Britain?), this could work very well, but what about places where it has been?

    1. Re:Prices? by Tackhead · · Score: 3, Insightful
      > Would the governments subsidize it, or would the costs be dumped on the consumer, increasing the cost of net access in Europe even higher then it already is?

      Where, pray tell, do you think governments get the money they then distribute for "subsidies"?

    2. Re:Prices? by Anonymous Coward · · Score: 0

      i think its a stupid idea to require the ISPs in hte first place.

      but i would rather have the ISP's bear the costs, instead of taxes. Because the taxes collected will be wasted in committees and only eventually spent to make this a reality.

      the ISP's will raise the price a bit, set up what they need in an efficient manner.

    3. Re:Prices? by Anonymous Coward · · Score: 0

      No offence, but if the government subsidizes it, guess who's really paying... Yup, the good old consumer who's paying his taxes. If the government doesn't, telecommunications will rise in price yet again. Last weekend I downloaded 5GB from IRC (yeah, boo me), but go ahead and log it. Log all the episodes of Chobits and Farscape I got. Don't forget those times I checked slashdot and freshmeat and the postgresql manual. Imagine that on a scale of a million people doing that at the same time.

      As a citizen of the EU, I'm not really surprised. After numerous national attempts to put internet into a position where it either could be taxed, censored or monitored this is no surprise to me at all. In Belgium there are still a lot of people who remember the proposition of the Bit Tax (never came to be, it was basicly a tax you'd pay on the amount of datatraffic you had, before internet was even popular in Europe), the tax on computer monitors (another one that never saw the light of day), and these kind of propositions go on and on and on... Every day some looney here decides that we need to put internet where it belongs: heavily taxed, severely sensored, and of course monitored.

      OK, if this law passes, which I doubt it will due to the large costs in storage devices, let them store my e-mail (GnuPG), let them monitor my webtraffic (OpenSSL), my logins to other machines (OpenSSH) and whatever they see fit. The government doesn't really think us commoners would still choose unsecured protocols. Oh yea, I know that half of the non-tech population doesn't know about security yet, and I know that they could create a law making it illegal to use encryption, in theory.

      Let me get one of my favourite quotes: "If privacy is outlawed, only outlaws will have privacy".

    4. Re:Prices? by doctormetal · · Score: 1

      but i would rather have the ISP's bear the costs, instead of taxes. Because the taxes collected will be wasted in committees and only eventually spent to make this a reality.

      the ISP's will raise the price a bit, set up what they need in an efficient manner.


      Seems you aren't familiar with high bandwidth prices here in europe.

      The backbone providers must increase their prices to the ISPs and the ISPs themself face a double price increase to be charged to the users, which the users won't pay. All smaller ISPs will go out of business.

  7. The spooks have access already... by Chris+Croome · · Score: 5, Interesting

    I suspect that the US and UK and other governments spy agencies already have access to whatever electronic communications they want to tap.

    This is the case in the UK with regard to phones, however phone tap data is never used in court here because the state might then have to admit how they got it -- they would rather not convict people then admit their sources and the extent of the eve dropping that is going on.

    I suspect that draft proposals like this are based on the old trick -- suggest something totally over the top and impossible to implement then let well meaning people water it down, claim that government cares and listens and at the end of the day still get away with yet another outrageous new law and yet more erosion of privacy and civil liberties.

    But then again I'm probably not cynical enough, it's probably far worse than I can imagine already...

    --
    Check out MKDoc a mod_perl CMS
    1. Re:The spooks have access already... by teslatug · · Score: 1
      hehe...
      But then again I'm probably not cynical enough, it's probably far worse than I can imagine already...
      How much more cynical can you get? I hope that was intentional...
    2. Re:The spooks have access already... by Anonymous Coward · · Score: 0

      i think it was intentional. in fact, im pretty sure.

  8. One good thing... by Teknogeek · · Score: 2, Informative

    Given how much storage space two years of ISP logs could take up, the amount of storage hard drives can hold is quite likely to go up VERY fast.

    Of course, whether or not that's so good a thing when you take into consideration the privacy concerns can be a rather complex debate.

    At least we'll have more room for pr0n! :)

    --
    I mod down anyone who uses M$ in their posts. I like to live on the edge.
  9. "if all our data was encrypted" by oliverthered · · Score: 1, Troll

    You would have to re-write all the network protocols (IP/TCPIP etc...) with encryption.

    If you went to a kiddie porn site they could find out from your network traffic and get a search warrant.

    If you were frequently on a chat room the same time as xx who was later found dead they'd be round the next morning.

    If you were connecting to predominantly Jewish sites then the secret police would be round and take you away.

    --
    thank God the internet isn't a human right.
    1. Re:"if all our data was encrypted" by Anonymous Coward · · Score: 0

      If you were a paranoid freak people in white coats would show up, and we wouldn't have to listen to you anymore.

    2. Re:"if all our data was encrypted" by Anonymous Coward · · Score: 0

      Nope, he made the insightful point, you didn't.

    3. Re:"if all our data was encrypted" by Anonymous Coward · · Score: 0

      You can easly stop listening either un-install the text to voice software or turn off the amp.

    4. Re:"if all our data was encrypted" by Anonymous Coward · · Score: 1, Informative

      IPSec is part of IPv6. It is in FreeBSD and will be in Linux soon. Encryption at IP level of the stack is a pretty old idea. If you are paranoid now, you can get FreeSwan (sp?) for Linux.

    5. Re:"if all our data was encrypted" by Anonymous Coward · · Score: 0

      If I'm paranoid, or didn't want to be caught....

      I'd IP tunnel to IPv6, bounce through a couple of hacked boxen, setup some freeking weird IP networks, so the logs look like shit and are too hard to track down.

      Install a cron job that downloads/submits etc whatever I want while I down the doctors and does all the cleaning up.

      and collect it all later.

  10. Question: How Long Do US Telecos Retain "data" by Anonymous Coward · · Score: 0

    I've always wondered how long my "traffic data" is privy to others who may want to snoop. Anybody know?

  11. I'm sure glad I don't live in Europe... by bsDaemon · · Score: 5, Funny

    I know our benevolant, wise, and responsible US Federal Government would never enact such blantant acts of controll over its freedom-loving, tuned in, and watchful citizens. Oh, wait... /me packs his things and heads for Antarctica

    1. Re:I'm sure glad I don't live in Europe... by Anonymous Coward · · Score: 0

      Nah, the laws in Antartica are even harsher. There just aren't enough people there to complain so we never hear about it.

    2. Re:I'm sure glad I don't live in Europe... by Quintin+Stone · · Score: 1

      But the good news is that there's no one there to enforce them!

      --

      "Prejudice is wrong; you should hate everyone the same."

  12. What about global communcations? by Auridel · · Score: 3, Interesting

    From the draft:

    a) Data necessary to follow and identify the source of a communication;

    b) Data necessary to identify the destination of a communication;

    c) Data necessary to identify the time of a communication;

    d) Data necessary to identify the subscriber;

    e) Data necessary to identify the communication device.


    And:

    These types of data shall not concern the content of the exchanged correspondence or the consulted information, in any form...

    So, they couldn't read my e-mail, but they could get a complete list of everyone I've exchanged e-mail with in the last 12-24 months?

    What I really wanna know is how this will affect communications between parties outside the EU that just happen to pass through EU routers. I couldn't find any specific mention of this (granted, I didn't comb through the draft too carefully.)

    1. Re:What about global communcations? by dattaway · · Score: 2

      How is this going to affect the vast community of ad-hoc wireless links that sprout up overnight? Are they going to police them too? Are they going to try and track the people who bounce microwaves off buildings, the sky, and such?

    2. Re:What about global communcations? by mr_teem · · Score: 1

      What I really wanna know is how this will affect communications between parties outside the EU that just happen to pass through EU routers.

      My read is that unless the communication involves at least one EU telecom subscriber, nothing will be recorded. [Insert big handwave icon] The bits are just passing through the backbone from Quito to Tashkent.

      From the draft...

      The data that the draft framework seems to want to have retained looks, in principle at least, no more than the equivalent of telephone logs. In many police procedurals, the detectives "check the phone logs". ("Hey, Gordo called Magdeburg six times last week. Wasn't Icepick Johann rumoured to be hanging out there?") Investigators of all kinds track leads and pull threads. With this kind of data, they might be able to find different kinds of patterns. ("Wow! Gordo started hitting flycheap.com two minutes after he got that last call from Barcelona. Wonder what scared him?")

      --
      --- "It annoyed me, so I fixed it." -- Tom's First Principle of Engineering
    3. Re:What about global communcations? by Lysander+Luddite · · Score: 2

      Cool. I can imagine 90% of all stored data being spam. The government will become the chief authority on spam, knowing who sends it, to him and on what machine they did it. :)

  13. US law??? by McFly777 · · Score: 1

    The story mentions the existance of a US law requiring data rentention. I have not heard of this. What are the US requirements??

    --

    McFly777
    - - -
    "What do people mean when they say the computer went down on them?" -Marilyn Pittman
    1. Re:US law??? by Amazing+Quantum+Man · · Score: 3, Informative

      They weren't talking about US law re data retention. They were talking about US law re what's accessible to law enforcement such as "traffic data".

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
  14. Information used by Drug Cartels.. by sadr · · Score: 4, Informative

    This is exactly the information used by drug cartels to assassinate informants, as described in a previous Slashdot article.

    If the information is being kept, unauthorized access will occur.

    SKG

  15. I'll tell you how.... by Anonymous Coward · · Score: 0

    IF you were to not be taxed by the bit, then simply have everyone move data back and forth to some out-of-country server while you sleep at night.... and make them .EXE files so they don't compress nicely! And, of course, do this while you sleep.... or just poll away on the Slashdot.org home page! Haha!

  16. Re:Question: How Long Do US Telecos Retain "data" by bluGill · · Score: 4, Funny

    Just a minute
    Flips on atari 800xl
    pick up microphone and speak into it
    "Computer, find me information on Anonymous Coward"
    1030 (300 baud) modem dials out
    short wait
    Faster than you can read, the following appears, often in higher resolution than the computer can drive)
    you got a C in gym class in 4th grade
    Video of your at the office christmas party
    Your rejection letter from MIT
    (censered) communication from your bed last night, taken from microphone in your light
    copy of your bare butt on the office copier
    complete shower videos from 9th grade gym
    Complete history of your postings to /.

    At least that is how it would be in the movies.

  17. Re:Question: How Long Do US Telecos Retain "data" by mwjlewis · · Score: 2, Informative
    I don't have an awnser for you about telco's, but from a small ISP's (4000 suscribers) perspective, No data is loged. I used to work at a since dead ISP CapuNet and we never paid any attention to the traffic that passed through our network other then, the traffic patterns and link utilization of the main trunks we had. As far as I know, NO logging of headers or raw data was done by us. The only time that would pay attention is in the event that someone is sending an obscene amount of email (notified by outside complaints) or if there was a DDOS attack from or against our clients.

    --
    www.oobersworld.com - For those that ride.
  18. Hacktivism by return+42 · · Score: 2, Interesting
    This strikes me as an area where Declan McCullough's position makes sense. We already have PGP and friends to protect email. Projects like Infranet, Anonymizer and Freenet can protect surfing and file-sharing. Laws to criminalize such tools, or mandate key escrow, will lag behind and won't be very effective, particularly if the tools are widely used.

    Not that political action won't help too, but it's easier to get a law defeated or repealed if it doesn't work anyway.

    1. Re:Hacktivism by Anonymous Coward · · Score: 0

      PGP et al are no help here as the proposed legislation doesn't cover email bodies only the headers (who communicates with who, when and between which IP addresses).

  19. All your data ... by burgburgburg · · Score: 1, Funny

    are belong to EU.

  20. Does it trump the Data Protection Act? by Hairy+Dude · · Score: 1
    In the UK, under the Data Protection Act 1998, it is illegal to retain data for longer than necessary. 12-24 months may well be considered to be longer than necessary for many types of data.

    So, my question is: Would this European Directive (or whatever) override the Data Protection Act?

    1. Re:Does it trump the Data Protection Act? by LichP · · Score: 3, Interesting

      More fundamentally, it is my understanding that (and I may well be wrong) that the 1998 Data Protection Act was revised from the original act to generally be updated where appropriate and become compliant with the relevant EU directive on Data Protection. So any new EU directive concerning data retention would not only be fudged at the UK level (kinda surpassable) but would also conflict with an earlier EU directive, which would be a bit messy.

      Not that it really matters - this whole process is massively unfeasible. To put it in context, my flatmates and I have easily downloaded over a quarter of a terabyte of data over the last year over our ADSL line - the figure probably reaches much higher. Scale this up across the continent and the figures are going to get unrealistically enormous. Even just logging e-mail and dns activity is going to burn a heck of a lot of storage capacity.

      What are the EU going to do? Spend many billions of euros on implementing the required software and (more fundamentally) hardward changes across the continent, money they could be spending on, for example flood relief? Or will they just tell the ISPs to get on with it, leaving them fundamentally crippled with the cost of internet access skyrocketing as ISPs drop like flies?

    2. Re:Does it trump the Data Protection Act? by Anonymous Coward · · Score: 1, Informative

      and the answer is, YES, as that's what EU directives do : they override national legislation.

      I think the general problem is that there is no public debate over any issue of IP and data privacy. I personnaly believe that these are the two mot important topics that may affect citizens in this century, and that these discussion should become central at any level of democracy, which inludes the EU. Citizens should stop whining with their national governments since these are helpless anyway, and should concentrate on pressuring the EU, through European Parliement elections and by closely monitoring the stance of their national governments in the Council. That's what corporate lobbies, which know better, do.

    3. Re:Does it trump the Data Protection Act? by gl4ss · · Score: 1

      the point is not to log all _data_, but connections. so they can see if you did connect for example, on everyday of your life to this a little too teenysexx site.

      --
      world was created 5 seconds before this post as it is.
    4. Re:Does it trump the Data Protection Act? by LichP · · Score: 1

      But like I said, even logging 'transactional' traffic, like what e-mails you've sent, what sites you've been to, what irc channels you lurk in, etc is *still* going to burn far too much storage space. Plus the overhead of archiving this information in any kind of usable fashion is going to require extra procesing burden and suchlike.

      Anyway, if you didn't log all data, then the whole system could blow back in the faces of investigators. Imagine someone being in e-mail contact with a terrorist suspect, say, who just happens to be a friend from school. The police might accuse them of conspiracy, citing the e-mail transactions. But if the content of that e-mail isn't logged then the police can't prove squat - said person could claim that they were merely catching up on old times. If both parties were sensible enough to delete and shred their copies of the e-mails at the time, then two years later after constant abuse of the disk sectors those e-mails occupied will have (very likely) irretrievably destroyed that data, and the police are left asking the politicians why they didn't enforce a stricter achiving scheme :-)

  21. and who's is going to pay my extra NAS? by frankske · · Score: 1

    Is the EU council going to give me funds to buy an extra NAS to store 24 months of communications on?

  22. Along with the UK "Give us your passwords .. by burgburgburg · · Score: 2, Funny

    and if you tell anyone you've given us your passwords, you'll be jailed" laws and London "Every square inch is under 24/7 video surveillance", it really seems like our friends across the pond are giving us a run for the money in the "Who'll completely destroy the notion of privacy and/or civil liberty first" contest. Good thing we've still got TIPS.

  23. Re:Question: How Long Do US Telecos Retain "data" by the+way,+what're+you · · Score: 1
    I've always wondered how long my "traffic data" is privy to others who may want to snoop. Anybody know?

    Please hold for a moment while I pull up your record. (...) Sir, your retention period is set at 36 months. Is there anything else I can do for you today?

    --
    example.org - powered by Linux!
  24. Re:Question: How Long Do US Telecos Retain "data" by Anonymous Coward · · Score: 0

    That's funny, that's exactly how the PHBs in office think computers work!

  25. Just hold onto this ... by Anonymous Coward · · Score: 0

    Show up at the council's headquarters with a few hundred thousand pages of traffic logs and say, "Hey, we want to comply with your data retention policy. Just hang onto this for a year or so, OK?"

  26. Noise Generators illegal? by sllort · · Score: 0, Offtopic

    If/when this becomes law, will so-called "noise generators" become legal? Overflowing an IDS by generating a bunch of false positives (ala Stick/Snot) is a technique used by folks attacking corporate networks... what happens if I buy cable modem access in the UK and choose to spend my bandwidth sending a continuous stream of garbage packets to random IPs from random IPs? It wouldn't be hard for a single user to consume entire gigabytes of storage per month in such a "traffic retention" system.

    Makes you wonder if they'll outlaw generating bogus traffic as a defense mechanism.

    KWTCMA

    1. Re:Noise Generators illegal? by tve · · Score: 2

      ... sending a continuous stream of garbage packets to random IPs from random IPs?

      Any halfway decent ISP should filter all outbound traffic from IPs outside of its assigned IP space, so you can't actually spoof random IPs.

      --

      If there is hope, it lies in the trolls.
  27. Worried? Just ask for your file... by ianscot · · Score: 4, Interesting
    Point nine of this draft gets to our privacy worry:

    Such a priori retention of data and access to this data constitutes an interference in the private life of the individual; however, such an interference does not violate the international rules applicable with regard to the right to privacy and the handling of personal data contained, in particular, in the European Convention on the Protection of Human Rights of 4 November 1950, the Convention of the Council of Europe no.108 on the protection of persons in respect of the automated handling of personal data of 28 January 1981, and the Directives 95/46/ce and 97/66/CE, where it is provided for by law and where it is necessary, in a democratic society, for the prosecution of criminal offences.

    They admit it's a compromise of individual privacy rights, but say it's allowed under those conventions. I was just looking for the spots in those documents:

    that allow mandatory storage of information in the absence of ongoing criminal investigation -- a priori.

    The 1950 one includes a very general passage seeming to allow anything "preventive" if it might abridge the rights or freedoms of others. Doesn't make me feel safe. (Hey, someone might want to prevent me using my TiVo in naughty ways. That'd abridge Jack Valenti's right -- or is it a freedom? -- to rake in money.)

    The 1981 thing's much more specific to the question, and opens up a world of hurt we could inflict on our various surveillance agencies:

    The purpose of this convention is to secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him ("data protection").
    ...
    Any person shall be enabled:

    a) to establish the existence of an automated personal data file, its main purposes, as well as the identity and habitual residence or principal place of business of the controller of the file;

    b) to obtain at reasonable intervals and without excessive delay or expense confirmation of whether personal data relating to him are stored in the automated data file as well as communication to him of such data in an intelligible form;

    Imagine the /. effect as we all demand access to the records being kept of all our packet traffic, all our phone calls... Hey, people ask for their credit reports. If the European agreement says it has to be "transparent" in this way, just start asking.

    --
    "Fundamentalism" isn't about divine morality. It's about human authority.
    1. Re:Worried? Just ask for your file... by Anonymous Coward · · Score: 0

      As far as the UK is concerned anyway, there is no written constitution and no bill of rights therefore anything in the European Convention on Human Rights can and has been overturned by Order of Parliament.

  28. Peer to Peer email flooding? by Contact · · Score: 3, Interesting
    There are two possibilities. Either this will work by simply archiving the information from the ISP mail server (in which case, just use a mailserver in another country...) or they're going to have to sniff all traffic to check whether it's SMTP / POP / IMAP etc.

    So, for a little civil disobedience:

    1. Option 1. If you're using an external mail server, you're not using the ISP mail server, right? So that gives you a "junk" email box. Why not set up a peer to peer system along the lines of SETI@home, which uses idle cycles to exchange email at the rate of a few hundred a minute.

    2. Option 2 - if they're sniffing all traffic, even better - write something similar, but do all the inter-client communication using SMTP. You should be able to simulate a few hundred messages per second. Get enough people on board (using SETI like marketing tactics - email chain letters encouraging people to "fight the spies" etc) and you could utterly dwarf "real" email under a storm of junk data. Even if they can somehow parse out the "real" data, the cost of storing the information has risen exponentially - and all you have to do after that is work out a way to embed real messages in the "fakes", and you've got unmonitored communications again!

    PGP only helps hide content, which this legislation doesn't ask for. Remailers would work, of course, but would look "suspicious"....

  29. NO NO NO NO NO! by Anonymous Coward · · Score: 1, Interesting

    I will NOT live within a community that supports this flagrent disregard for my human right to privacy. Whilst I realise this information is probably already accessable to see this type of legistation even REACHING the stage of open discussion is disquieting.
    This is nothing to do with the 'war on terrorism' it is nothing less than control.

    knowledge == power

    and power corrupts.
    QED

    1. Re:NO NO NO NO NO! by Nfnitloop · · Score: 1

      I agree completely. This is *exactly* the same as keeping records on our own "real lives" (where we drive, who we speak to, what we read, watch, and listen to) It's just because it's so much easier (relatively) to watch us online that they think it's okay.

  30. For all the Europeans .. by i_want_you_to_throw_ · · Score: 3, Funny

    that rightfully thought the US was backwards with Fritz Holling, DMCA, etc: Welcome!

    I got karma to burn. Mod me down if you must.

  31. Who is responsible for this logging? by Anonymous Coward · · Score: 1, Insightful

    If I SSH in to a development machine at an ISP that I don't use for dial-up, and E-Mail somebody from it with a question - who is responsible for logging that E-Mail?

    This really is a concern, because small co-location facilities, etc, really don't have the facilities to do this. It's OK for large ISPs, but a nightmare for smaller ones.

  32. What if you encrypted and lost the key? by Anonymous Coward · · Score: 1, Interesting

    I might run a home brew system which is designed to not leave the keys anywhere in the ned. All they keep is complete bollocks for anyone, including me.

    Or what happens if someone transfers something illegal, can you prosecute the telecom company for having illegal documents/child pornography etc? What if they stole it/produced it in the first place, is it all of a sudden legal then, or what?

    This is like making thoughts illegal because I might be thinking up a masterplan to steal the gold at fort knox and produce an elite army of terrorists...

  33. Completely infeasable by jpmorgan · · Score: 4, Informative

    I think this would definately tempt me to put any websites I run onto https and leave http with a simple redirector. Be nice if other people would do the same. I wonder how much they'd enjoy trawling through a few terrabytes of session encrypted traffic...

    Seriously though, the sheer data management problem this would pose would be extraordinary. For every 1mbps, you're talking ~4TB of traffic per year! Consider how much traffic there actually is going across the wires:

    T1 (1.54mbps): 6.07TB
    DS3 (45mbps) : 177.39TB
    OC3 (155mbps) : 611.01TB
    OC48(2.48gbps): 9,776.16TB

    Just for the hell of it, 9,776.16TB is 48,881 200GB drives. Now, you can buy one of those from Western Digital for ~$400US (retail). You'd be buying a lot of drives, so lets say you get a discount, and can get one for $300 (I don't know how big a discount you'd really get). That's almost $15 million dollars in hard drives per year for an OC48. That's about three times as much as the actual cost of an OC48 (even worse for peering arrangements).

    Of course, scale that kind of hard drive usage up across Europe, and I don't think there is the manafacturing capacity to supply that kind of demand. Oh well, I guess we've found holographic storage's killer app, eh?

    Also, who records what? Does every router have to record everythign that passes through it? Or only the ISPs that serve end users? What about businesses? What about co-located servers? If you don't want to miss anything, you'll have to cover all of those, and end up grabbing 2-3x as much data as you really have to. Otherwise it'd be trivial to setup a colocated server at a company or a hosting provider, and tunnel an encrypted connection through to that.

    On top of that, there's the problem of how you sift through ~10,000TB of data for something useful. We're talking raw data on a totally unmanageable scale.

    Why not just record all voice communications too? I'm sure that'd be invaluable in any police investigations. Ah well, nothing to worry about since neither's going to happen. Both are totally infeasable.

    1. Re:Completely infeasable by Nfnitloop · · Score: 1

      I don't think they're going to retain the actual data that was transferred, they want to keep track of who (not just xxx.xxx.xxx.xxx but Joe Smith from Sometown), sent to who (again a site or another person, not just IP), how they sent it (FTP, HTTP, SMTP), and when they sent it. They're not retaining the actual content that was sent. But still the amount of data to be sifted through is enormous.

    2. Re:Completely infeasable by Anonymous Coward · · Score: 0

      That's 488KW (assuming 10W per HDD) to keep everything online or you have to swap out 42 HDD per day.

  34. three-step solution to terrorism by Anonymous Coward · · Score: 3, Funny
    1. Deny rights.

    2. ???

    3. Security!

    Seriously, what is needed is some civil disobedience. Set up weird accounts like yarafat@hamas-resistance.il, exchange suspicious e-mails with your friends (in case they don't retain the body, make sure they get to read the subject), get as many people as possible to do it. The more false positives, the more impossible the system will be to maintain.

    Remember, they're trying to make you f33r. When only one person stands up, he has a damn good reason to be afraid. When 10,000 stand up, the opposition has a damn good reason to be afraid.

    Oh, and in case it needs to be said.. use PGP as much as possible, and try to run your own mailserver.

    Just for the record: Osama Project Iraq Desert Storm Hailstorm Bush GWB kill maim murder torture Mossad oil Kuwait Iraq Iran Saudi Arabia we have the assassination plans praise Allah one hundred virgins FBI CIA Hoover Dyson MI5 MI6 James Bond Dr Evil one million pounds safety deposit box Switzerland Nazi gold bank account launch code RSA DSA NSA BSA

    1. Re:three-step solution to terrorism by Anonymous Coward · · Score: 0

      excellent point.. i'm guessing he posted ac for obvious reasons, mods please do him justice.

  35. The mad punster what puns at midnight! by mark_space2001 · · Score: 1
    "...Mandatory Data Retention..."

    Sounds like somebody's being "retentive" alright.

  36. Re:Question: How Long Do US Telecos Retain "data" by konchog · · Score: 2, Informative

    In the US, ISPs can keep traffic data as long as they wish, according to Marc Richards, US DoJ at EU Cybercrime Conference, Nov 2001.

    He's there to urge the EU to reverse its mandatory data destruction policy. In the EU, traffic data must be erased or made anonymous at end of communication or end of period in which invoice could be contested.

    The metric for how long US ISPs/telco keep traffic data can probably be guessed from anecdotal data. Reading newspaper accounts about prosecutions of net child pornographers or adults soliciting minors suggests a year or two. I'll look for the case of a VA police chief who was after young boys & see how long prosecutors watched and the motions the Chief's counsel made to suppress traffic data evidence.

    We have statutory protections against telco passing on traffic data--somewhere in Title 18, Section 2702 (?). US Patriot probably eases the exemptions: IOW, by default it is illegal for a data controller to let this or that party rifle through your data. OTOH, we are almost signing waivers--at the bank, credit apps, insurance apps, and personal finances in US would be near impossible if you didn't grant waivers.

    Most important: Your employer can snoop all he wants if your are using his computers. The Administrative Office of the Courts--the management agency for the entire Federal judiciary--last year thought it should begin monitoring Judges' net use. Same logic.

  37. There would be a positive side to this by gmcraff · · Score: 1

    All those hard drive platters, ~50K drives per OC48, times all the OC48s (and fractions as appropriate to the lesser pipes) will add up to enormous amounts of spinning matter.

    If properly mounted in line with the Earth's axis, maybe we could make a teensy-tiny little adjustment to the revolution speed when they spin 'em all up and get us a 25 hour day to match our 25 hour biological clock. I tell you, I could use an extra hour per day, and I really wouldn't mind having 15.2 less days per year.

  38. Re:Hey, it's worse here in Canada by Anonymous Coward · · Score: 0

    Hottest Canadien babes for 500km? That's really not saying much ;)

    J/k

  39. The pattern is clear by Anonymous Coward · · Score: 0

    It doesn't matter where you live.. big bro is movin in

  40. scary development by karm13 · · Score: 1

    privacy nowhere you can run but can not hide oops, wrong discussion

    --

    --
    making up good sigs is a hard thing to do.
    1. Re:scary development by karm13 · · Score: 1
      oh no, forgot again
      to include the B-R tags
      must be the haikus

      --

      --
      making up good sigs is a hard thing to do.
  41. This sounds like a good idea by DotComVictim · · Score: 2

    Especially if you own stock in any of several large corporate entites currently pushing SAN data centers. And of course, since this will have to be government subsidized (ISPs balk at the cost), they can lock in contracts with only "government approved" vendors.

    This is not a story about rights or law enforcement. Do you seriously think that volume of data can actually be useful? Oh, such and such person sent an e-mail around the beginning of January, maybe after bouncing through a SSH tunnel. Oh, and the e-mail was encrypted with 2048-bit RSA encryption.

    If you can't solve that problem, this "exploitation" of privacy is nothing more than writing some giants check to several government members and corporate bigwigs. Folks, this is why the stock market was invented!

  42. Offtopic ??? by Macka · · Score: 2


    What nutter voted this down as offtopic? It is totally relevant to subject at hand. I was thinking exactly the same thing and scanned down to see if someone had already covered it before posting the same comments myself.

    The volume of data this would generate is enormous and just who do the egg heads in the EU think is going to foot the bill for all this extra hardware? The Telcos? They already have their backs against the wall cash flow wise and many are up their eyeballs in debt.

    This proposal is sheer stupidity.

    1. Re:Offtopic ??? by Anonymous Coward · · Score: 0

      It's not ENTIRELY offtopic, but the post WAS totally stupid, and author obviously has not read the article, or any of the comments. No one's asking to save all data going down the wires. Just the headers. There, you've cut down your data set to, what, less than 1%?

  43. Thank God they didn't do this earlier by TrollsamaBinLaden · · Score: 1

    Imagine seeing a list of old surfing habits from BBS systems of the past?

    I would be afraid to see some of the filenames of pictures that I downloaded from old BBS systems come back to haunt me. Oh the days of youthful curiosity and innocence. Goatse.gif? ...hmm I bet that picture would go good with my show and tell on farm animals......downloads with X-modem......opens picture.... Oh my God! My eyes! They are burning! Then somewhere along the line the shock and horror turns into "I had to see this garbage, so I'm making sure everybody else has to as well".

    I don't think I could ever recreate the shock or the look on my face the first time I saw it...but I enjoy the look on a coworkers face the first time they see it.

    Wow I really have become a warped little bastard haven't I. Damn those addictive BBS systems!

  44. Dump to paper! by Anonymous Coward · · Score: 0

    Next time your local comes around asking for your records, point them at the back room of your datacenter, filled with neatly files dot matrix printouts. When they ask for electronic files, shrug, and say "You never said HOW I had to keep the records..."

    Might bring back the dot-matrix industry, too. Probably piss off the environmentalists, so everyone wins.

  45. How would this effect the European ISP community?

    One way it would affect the Europeans is to create a big incentive for individuals to adopt internet telephony. B-)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  46. use the force for good, Luke by Anonymous Coward · · Score: 0

    It seems that with all this monitoring the only thing that seems to happen is public crucifictions of people like Charles, Di and Lewinsky for their phone calls. Have you ever noticed that company management never apply their appropriate email/internet surfing policy equally to everyone. They only pick on the selected sad sucker they wanted to sack all along. Same goes for govt "law enforcement".

    Meanwhile, back in the real world, the really nasty kiddie-porn, neo-nazi-racists, stalkers, serial killers, black market barons, arms dealers, corrupt politicians, corporate board fraudsters and other highly organised criminals slide right under the radar again and again. All they really need to do is open chains of internet cafes, have a couple of free mail servers on some pacific island, and a couple of spam enterprises out of the same pacific island. Then would the government spooks nail them with internet traffic?

    This is how: the stuff's all ones and zeros anyway, completely prone to fabrication as opposed to recording. How can anyone know what is on those backups wasn't generated to specification.

    I like this idea. If I was an ISP, in order to maintain speed and bandwidth, I think I'd run my backup system standalone, recording fictional traffic.

    Is monitoring like this going to get all authors of spy fiction locked up? I can't tell fiction from fact on the net anyway. Even my own emails can contain vast quantities of fiction. Nobody swears on the bible that they'll only send stuff over the net that can be used as fact in a court of law.

    BTW creating more traffic to hide your stuff in is completely unnecessary. We're already carrying the millstone of spam and internet advertising. Online casinos aren't legal here, but does that stop geocities from hogging my bandwidth with advertising for it?

    Coherent not today.

    Anonymous Paranoid Coward

    1. Re:use the force for good, Luke by jabens · · Score: 1

      The point being that the traffic can be monitored *retroacively* via law. Espionage and corruption are endemic anyway as a result of greed. BUT if everyone who cares starts spamming the net with letters of protest, even a watered-down law would fail per se, eh? Partcularly liked that rhyme....

      --
      There's just no telling....
  47. fuckin idiots...worse than the US for once by Anonymous Coward · · Score: 0

    The only thing worse than the fuckin freedom chomping US is the fuckin we never had freedom to begin with european fuckheads.

    jeesh..

    GLOBAL REVOLUTION. We need a distributed synchronized revolution.

  48. Traffic data by mrogers · · Score: 2
    Some readers have dismissed the threat to privacy on the basis that it would be impractical to retain all internet data for a period of 24 months. To clarify the situation: the decision only covers the retention of "traffic data", defined as "all data processed which relate to the routing of a communication by an electronic communications network" (emphasis added). In theory this could mean the retention of every IP header, but consider the requirements of law enforcement agencies: they want to know who communicated with whom, and when. They don't need to know the exact route taken by each packet in order to identify the parties involved, or the web page that was seen. So what is a more realistic set of traffic data?

    Minimal set:

    • Telephone calls and faxes: caller, recipient, time, duration. Already retained by telephone companies for billing purposes. Possible means of circumvention: use a prepaid international calling card to route your calls through a call centre outside the EU. Could be expensive.
    • Emails: sender, recipient, time. Require every SMTP server to log the RCPT and FROM fields. Possible means of circumvention: use POP and SMTP servers outside the EU. Use an anonymous remailer (effectively hiding traffic data inside the body of the message).
    • Websites: user, domain name, time. Unlikely to rely on webserver logs. Instead, require every DNS server to log every request. Of course this doesn't prove that the user actually looked at the content of the site, but try explaining that to a jury. Possible means of circumvention: use a DNS server outside the EU.
    More effective set:
    • Emails: in addition to logging connections to the ISP's mail server, monitor all traffic on TCP port 25. Parse the traffic as SMTP, extract RCPT and FROM lines. Small performance penalty for users. Possible means of circumvention: find a mail server outside the EU that operates on a non-standard port (unlikely) or uses a non-standard mail protocol (unlikely).
    • Websites: user, URL, time. In addition to DNS logs, monitor all traffic on TCP port 80. Parse the traffic as HTTP, extract GET string, use a reverse DNS lookup to complete the URL. Serious performance penalty for users. Illicit websites will simply use non-standard ports or HTTPS.
    Paranoid set:
    • In addition to all of the above, traffic on IRC and IM ports will be monitored and parsed to extract user identities. All TCP SYN packets will be logged. Anyone using a mail or DNS server outside the EU in order to protect their privacy will be assumed to be hiding something. All their traffic will be monitored and examined for known protocols. Man-in-the-middle attacks will be used to decrypt SSL connections in order to extract "traffic data".
  49. Troll? by oliverthered · · Score: 1

    there be no troll here.

    "If you went to a kiddie porn site they could find out from your network traffic and get a search warrant."

    and

    "If you were frequently on a chat room the same time as xx who was later found dead they'd be round the next morning."

    are the kind of arguments that government boddies would use to 'justify' holding and searching of logs.

    which is not that different to:
    "If you were connecting to predominantly Jewish sites then the secret police would be round and take you away."

    --
    thank God the internet isn't a human right.
  50. Re:Hey, it's worse here in Canada by Anonymous Coward · · Score: 0

    I know a canadian babe.