Slashdot Mirror


Broad Bills to Protect 'Communications Services'

mttlg writes "According to Freedom to Tinker, MA, TX, SC, FL, GA, AK, TN, and CO have introduced similar bills that would make it illegal to possess, use, etc. "any communication device to receive ... any communication service without the express consent or express authorization of the communication service provider" or "to conceal ... from any communication service provider ... the existence or place of origin or destination of any communication." (Additional legalese removed for the sake of brevity.) This would seem to outlaw NAT, VPNs, and many other security measures. In other words, don't secure your communications, just sue if you don't like who receives them." The bills define 'communication service' as just about any sort of telecom service that is provided for a charge or fee. In effect, they would extend the already-extant laws relating to theft of cable TV services to any telecom service. For example, if your ISP charges per computer connected, using a router/NAT device would be illegal if these became law.

36 of 524 comments (clear)

  1. Ouch by DeadSea · · Score: 5, Insightful
    This law would make it illegal to do several things that I currently do:
    1. Run a proxy server at home and connect to it via ssl so that my employer can't tell what web pages I visit at work.
    2. SSH chaining - Use ssh to log into a remote computer and use ssh to log into another computer since this makes both endpoints unaware of the address of the other.
    3. Use a remailer as a whistleblower. A remailer stips all headers off a message before sending it out to a new specified sender. This provides anonymous mail which is important for people who are afraid of retribution if the note could be traced back.
    4. Post to slashdot anonymously.
    1. Re:Ouch by Carbonite · · Score: 4, Insightful

      While I can certainly see legitimate uses of each of those things, they do seem rather questionable. Even if you're using these methods for the right reasons, I'd suspect that many people aren't. The real debate is whether a law prohibiting these activities is necessary. I believe that in virtually all cases, the answer is no.

      --
      ich muß mehr Kuhglocke haben
    2. Re:Ouch by diablobynight · · Score: 3, Insightful

      I think this bill is probably not so much directed at us, IP geeks, as much as it is directed at people stealing sattelite TV, and people stealing cell phones

      --
      Anonymous Cowards - Oh God, How I hate you
    3. Re:Ouch by jgerman · · Score: 4, Insightful

      It doesn't matter who it's directed AT. What matters is that it can be used against anyone that it covers. Which include people doing the things the poster suggested. Things that should not be legislatable (matbe I just made that word up). I contantly ssh from box to box in what may be a long chain of ssh sessions. This bill is ridiculous and has no business even being up for a vote. It's nother example of how current lawmakers get involved in things they have absolutely no comprehension of.

      --
      I'm the big fish in the big pond bitch.
    4. Re:Ouch by warmcat · · Score: 4, Insightful

      The DMCA wasn't aimed at printer cartridges. But there it is.

    5. Re:Ouch by B1 · · Score: 5, Insightful

      I think this bill is probably not so much directed at us, IP geeks, as much as it is directed at people stealing sattelite TV, and people stealing cell phones

      It may not be directed at IP geeks--maybe the spirit of the bill is that it's supposed to go after satellite TV pirates and cellular fraud.

      The problem though is that once the law is in the books, it's the letter of the law that matters. And right now, the wording of the bill leaves it open to potential abuse.

      The law may not target IP geeks, but if some ISP wanted to go after NAT users, they would now have a broken law on their side. As with the DMCA, the road to hell is paved with good intentions.

    6. Re:Ouch by kableh · · Score: 5, Insightful

      The real debate is if this will stop real criminals, as opposed to those of us who have work to get done, from doing any of these things. I believe that in all cases, the answer is no.

    7. Re:Ouch by Creep73 · · Score: 5, Insightful

      If an ISP can regulate the amount of computers I have hooked up to that ISP's pipe can the water company charge for the amount of faucets installed in my house? Can the electric company charge me for the amount of electrical sockets installed in my home? Can the phone company charge me per phone? The logic used in coming up with these policies is flawed to the core. I thank the companies for this and the gullible lawmakers we have in this country. Instead of making money by creating and proving viable services they will make their current services and products make them more money through bad legislation. Unfortunately it is the current trend. Just ask Disney's Mickey.

  2. This is frightening by joebagodonuts · · Score: 4, Insightful

    "In effect, they would extend the already-extant laws relating to theft of cable TV services to any telecom service."

    It does more than that. The language of the bills uses the word "harm" instead of "fraud". The language is vague enough that it could be twisted to be used against anyone. Just having a firewall that does nat translation is a violation of these bills.

    All brought to us by the friendly folks at the MPAA. Jerks

    --
    "Give a woman two glasses of wine and some pad thai, and they'll agree to just about anything." the Sports Guy
  3. Where is your Freedom going? by ShwAsasin · · Score: 3, Insightful

    Is it just me, or are these new laws being passed over the last couple years seem to really deprive the average citizen of regular rights and freedoms?

    With a country that seems to tout freedom at every corner, it's unfortunate that many rights and freedoms are being destroyed by people who have no clue about the general consequences of their actions.

  4. Yeah, but the cow's already out of the barn... by Bonker · · Score: 4, Insightful

    While not having quite the range of people using services in violation of these statutes as say, people downloading mp3's, there are already so many people doing these things, and profiting on them, that it will be pointless to try to enforce this law.

    Imagine for a second Bestbuy's reaction to the fact that it's popular cable-modem routers and wireless access points have all become illegal. I don't exactly see them pulling millions of dollars of hardware off the shelves without a legal fight. Nor do I see the manufacturers of those devices just giving up either.

    I NAT and I'm proud of it!

    --
    The next Slashdot story will be ready soon, but subscribers can beat the rush and slashdot the links early!
    1. Re:Yeah, but the cow's already out of the barn... by SpaceLifeForm · · Score: 4, Insightful
      Not to mention that SBC *provides* routers for home DSL users that have multiple computers.

      I also NAT as do many others. The PTB still don't have a fsck'n clue when it comes to home networking. For some reason they believe that home networks are costing Large Corps money, when in fact, most people doing NAT at home probably have a clue and actually reduce problems (ex: CodeRed) due to firewalling.

      A proud member of the NAT terrorist group!

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
  5. I Am Not Sure How To React by Jerk+City+Troll · · Score: 5, Insightful

    It seems to me that the likelihood of these bills getting passed is next to nothing (of course, one can never be so sure). They were clearly introduced by technology-clueless law makers, but once they are subject to a vote, their silliness should become obvious. So I am not entirely afraid that they will succeed. If they do pass, other states are likely to pick up and follow the trail.

    What is really scary to me is that, even though these bills were introduced by the ignorant, the fact that lots of legislators had the mind to introduce them in the first place is shocking. Particularly on the note of encryption, this is largely unconstitutional and hopefully, if ever passed, these bills will be challenged by (financially) enabled individuals.

    How can such a thing even hold up when it not only criminalizes most existing telecom infrastructure, violates the 4th Amendment by tangent? Of course, we do live in a DMCA-cursed USA...

    1. Re:I Am Not Sure How To React by jonabbey · · Score: 3, Insightful

      Wow, is the weather very nice on your planet?

      This kind of legislation could easily pass. If something like this is proposed in your state, you need to write your legislators and let them know that this language could potentially criminalize a lot of straight-forward Internet gear, if a communications provider decides to require a per-CPU charge, or the like.

    2. Re:I Am Not Sure How To React by regen · · Score: 3, Insightful
      What is really scary to me is that, even though these bills were introduced by the ignorant, the fact that lots of legislators had the mind to introduce them in the first place is shocking.

      The fact that these bills are being introduced in multiple states at the same time, indicates that it was probably crafted by a lobbyist.

      The question you should be asking is who wants this legislation? Who hired the lobbyist?

  6. DMCA? by Limburgher · · Score: 3, Insightful

    Wouldn't it be illegal for ISP's to bust SSL users?

    --

    You are not the customer.

  7. Depends on Definition by PhxBlue · · Score: 4, Insightful

    From the article:

    If you have a home DSL router, or if you use the "Internet Connection Sharing" feature of your favorite operating system product, you're in violation because these connection sharing technologies use NAT. Most operating system products (including every version of Windows introduced in the last five years, and virtually all versions of Linux) would also apparently be banned, because they support connection sharing via NAT.

    I'm not concealing the origin or destination of communication, in any of these cases. If I'm using a router to share my network connection, the origin/destination of my ISP's communications is whatever box is doing the routing. After that, if my router routes a copy of the data from my ISP to another PC in my home, that's okay: the transmission between my router and my ISP is complete, and the new transmission is between my router and one or more PCs on my network.

    I've always held that, as far as ISPs are concerned, they're responsible for supporting their network until it reaches the access point of my network--whether that's a single PC, a PC that shares its internet connection, a router, whatever. After that, I can accept the liability of supporting my own equipment. This should be handled the same way.

    Actually, better yet, it should be shot down outright. But that's more optimistic than I tend to be about such things.

    --
    !#@%*)anks for hanging up the phone, dear.
  8. This is intended for Radio.... by wowbagger · · Score: 4, Insightful

    This bill is intended for radio, and is to prevent you from having a scanner.

    However, unless they change the current law, having an Amateur Radio Operator's license trumps this - being a ham I can have a scanner, due to hams' role in emergency communications.

    However, this is just like the Electronic Communications Privacy Act of 1987 - it may be illegal to eavesdrop on cellular communications, but it did'nt really stop anybody from doing it. Going from an insecure system (AMPS) to more secure systems (GSM, CDMA) did that.

    However, the point of the /. post is valid - the law of unintended consequences comes to play - VPN, NAT, proxies all could be banned by wording that broad. Perhaps that is a good thing - overbroad wording might just get it thown out.

    Yeah, and moderators on /. will grow a clue. Time to start adding comms gear to my armory.

    1. Re:This is intended for Radio.... by Telastyn · · Score: 3, Insightful

      This also seems alot like something to prevent people from stealing satelite TV. People that broadcast TV realised there's no way to charge for that so they found alternative revenue in commercials. People that broadcast radio realised there's no way to charge for that so they found alternative revenue in commercials. People that boardcast satellite TV realised there's no way to charge for that, so they did it anyways and manipulated the government into policing it for them.

  9. Re:NAT by AmigaAvenger · · Score: 4, Insightful

    my linux pc IS a single PC... it routes traffic to other machines internally, but that is my own business and no one elses. I only have one machine connected to the internet, but have 6 more connected to that machine.

  10. fear causes pussies to bitch by diablobynight · · Score: 4, Insightful

    You see all the pussies that can't get over the fact that our towers came down. Are using there fear as an excuse to pass thousands of laws, that don't affect them because there non-technical ninnies, and sadly the rest of America is dumb enough to let this crap happen under the guise of patriotism I bet it was patriotic to kill a jew in Germany during world war II, patriotism isn't always a good thing.

    --
    Anonymous Cowards - Oh God, How I hate you
  11. No violations by gr8_phk · · Score: 4, Insightful
    The endpoints of a connection are specified by IP addresses. If NAT is illegal because the "source" is disguised, they're really dictating what software you can use and what you can do with it - the source is obviously the machine doing NAT. They need to understand that they operate at the packet level - they sure don't offer any higher level capabilities that I care about. If they want to regulate what's in your packet, then they can be responsible for kiddy Pr0n and any other illegal activities taking place over "their" network.

    I used to work for a small ISP/Telco, and my boss always liked the Common Carrier status because it exempted them from liability. Apparently big ISPs don't understand this yet. If you monitor it, you're taking some responsibility for what's in it.

  12. Reducing Security and Utility == Profit & Just by HeelToe · · Score: 4, Insightful
    Geez.

    This is really bad.

    I hope the states where I run networks aren't next.

    This allows companies to make more money off us by the threat of lawsuits or report to the authorities. If someone sells me internet access at a specific bandwidth, they should expect I can and may use up to that allotted bandwidth. They are selling me bandwidth, not individual ethernet ports.

    Things like ssh-tunneling to hide IM and WWW traffic while I'm at work, as well as improving the security of my networks by hiding the endpoints of my ipsec tunnels behind nat boxes also becomes illegal.

    So, in summary, we're trading utility (let's face it, a lot of these vpn/nat apps make things easier to handle - voip tunneling, smtp tunneling, very nice stuff handled with both vpns and nat), AND security (why should all my network devices sit exposed?) so that companies can make more profits, and we can be hauled to jail for making it harder to snoop our communications?

    This is ludicrous. Where will the fascism stop?

  13. What about Freenet? by Lockle · · Score: 5, Insightful

    to conceal ... from any communication service provider ... the existence or place of origin or destination of any communication.

    I believe that this item is probably not intended to go after NAT'd computers, but to try to cut back on spammers using broadband connections.

    If this is the reason, they should be applauded for trying something new. This law WOULD make forged headers illegal.

    One problem is that this also constrains anonymous peer-to-peer systems such as Freenet. One of it's strengths is that when you receive a request for a file from an IP, you don't know if that IP origionated the request. If you don't have it, you pass on the request and the node you pass it onto doesn't know if you requested it.

    This does make it impossible for a "communications service provider" to determine the origin or destination of the file or information request.

    If this is the intended outcome, it is a major violation of a civil liverty we have been appreciating lately.

  14. Re:Makes no difference to me... by jandrese · · Score: 3, Insightful

    Just because your ISP is stuck in the 90's doesn't mean you need to drag everybody else down with you. Personal servers are what make the internet great, not giant media conglomorates feeding you exactly what their advertisers want. You'll note that the most useful webpages are usually the ones put up by some devoted guy on some particular topic in his spare time, not the multi-million dollar popup/flash/trendy keyword extravaganzas that big companies bought into.

    of course you can just run your server on your ISP's website (if they offer one), but that's usually rather limited if you have a large number of infrequenty accessed files or dynamic content, and lord help you if your website needs a database backend to keep everything convienent yet manageable.

    Sorry about the rant, but I just hate when people get suckered into thinking they're nothing more than "consumers" that aren't allowed to contribute to the public good.

    --

    I read the internet for the articles.
  15. When they outlaw firewalls... by MsGeek · · Score: 4, Insightful

    ...only outlaws will have firewalls. If this bullshit spreads to California, damn straight I will keep my ipfw/nat firewall up!

    Time to make this a very uncomfortable time for your state assemblypersons and senators if you live in the affected states. Geek power stopped the Berman Bill, geek power is forcing the feds to revisit the DMCA, geek power is a pretty amazing thing when unleashed.

    The one thing that makes the least sense about these bills is that firewalling+nat is one of the tools needed to combat worms and exploits. Everyone is so damn interested in "protecting our Internet infrastructure from exploits, worms and viruses" yet these same clowns are taking away a very important tool that real people can use to make a real difference against these problems.

    And what if you are still running Windows NT4, for whatever reason? The workaround Microsoft gives people for the recent RPC vulnerability is to keep the server in the private IP space and firewall off the ports in the 13x range! You can't do that without a NAT!!!

    Time to fight this and fight it hard. Whatever you think about whatever other issues are going on around us, this is serious shit.

    --
    Knowledge is power. Knowledge shared is power multiplied.
  16. what the bills actually say by dAzED1 · · Score: 5, Insightful
    Does anyone actually read things anymore?
    From the texas bill

    (a) A person commits an offense if, with the intent to harm or defraud a communication service provider, the person:

    (1) obtains or uses a communication service without:

    (A) obtaining the authorization of the provider; or

    (B) making a payment to the provider in the
    amount normally charged by the provider for the service; or

    [(3)] tampers with, modifies, or maintains a
    modification to a communication device provided by or installed by the provider


    That is the entirity of the definition of a bad guy in this bill, as it is currently proposed as of the time I'm writing this.

    So, you have to, with "intent to harm or defraud," "[use] a communication service without""obtaining the authorization of the provider; or making a payment to the provider in the amount normally charged by the provider for the service; or tampers with, modifies, or maintains a modification to a communication device provided by or installed by the provider." I put it all together for ye who don't want to link.

    So, to be even MORE clear, this only effects people who are trying to harm or defraud an ISP, etc, by using service without authorization.

    Does a VPN "harm or defraud" an ISP? NO

    Does ssh "harm or defraud" an ISP? NO

    Does posting anonymously anywhere, or any of the other things being complained about, "harm or defraud" an ISP? NO

    I don't have the time to quote and translate each and every bill out there, but I do certainly recommed actually reading them before deciding the bills will make it illegal to brush your teeth. Knee-jerk, anyone? Know what you're having an opinion about, before forming that opinion.

    1. Re:what the bills actually say by bourne · · Score: 3, Insightful

      Does a VPN "harm or defraud" an ISP? NO

      Many Cable Modem/DSL providers exclude VPN use from their "Residential" service. That usage is covered by their "Commercial" service, which generally costs 3 times as much.

      If you are not "making a payment to the provider in the amount normally chargd by the provider for the" Commercial "service," then you are harming and defauding the ISP.

      Some cable companies have a similar rule about multiple machines - they have standard access (one machine) and "home network" access (often 3 machines). There have been limited attempts to use this to restrain use of NAT for home networks. I would hate to see such attempts with a law like this behind them.

      Another more legitimate target of this would be people freely sharing their connection via Wireless.

  17. How quickly we forget... by mabhatter654 · · Score: 3, Insightful
    Why we broke up AT&T in the first place!

    The public already decided once that the "Common Carriers" provided wires not services when they broke up AT&T and deregulated the Baby Bells. Why does it seem that there's a purposefull effort to undo all that effort? Could it be that the media companies that needed deregulation to get off the ground now don't want to play with the same rules that let them get in the game in the first place?

    What's needed is a real person in charge of the FCC [Lessing anyone!] To streamline the processes and remove some of the contradictions [i.e. ATT banned from local phone but owning cable w/o sharing, etc.]

  18. That Dog Won't Hunt by blunte · · Score: 3, Insightful

    Ignoring any issues of stupidity regarding this proposal, there is one practical point that cannot be ignored.

    The IP address space isn't big enough for all the nodes on the internet. NAT alleviates this problem by "sharing" IP addresses. Remove NAT, and you're going to have to disconnect most computers from the internet.

    --
    .sigs are for post^Hers.
  19. Try shaking your head in disgust by 87C751 · · Score: 4, Insightful
    introduced by technology-clueless law makers
    You mean there's another kind?
    What is really scary to me is that, even though these bills were introduced by the ignorant, the fact that lots of legislators had the mind to introduce them in the first place is shocking. Particularly on the note of encryption, this is largely unconstitutional and hopefully, if ever passed, these bills will be challenged by (financially) enabled individuals.
    Don't look now, but that pesky Constitution is on its way out. As soon as we see a few retaliatory terrorist actions inside our borders, the threat level will go to Red and the Feds will punch the panic buttons. All of them. By the time the dust settles on that little imbroglio, you're going to wish that encryption and NAT were all that were illegal.

    Interesting times, indeed.

    --
    Mail? Put "slashdot" in the subject to pass the spam filters.
  20. Re:Makes no difference to me... by EricWright · · Score: 5, Insightful

    You are a prime example of what's wrong with this country. It doesn't affect me, so why should I give a shit. Me me me me me... The world doesn't revolve around you. These laws (were they to become laws) would affect a lot of people, and in an adverse way.

    My ISP doesn't give a fat rat's ass if I run an email server. I don't allow open relays, so it deals with about 5 emails a day. Big whoop...

    I'm kind of surprised they haven't bitched about my 1-2 GB/day Usenet habit, though...

  21. Best buy won't help and you NEED HELP. by Erris · · Score: 4, Insightful
    Imagine for a second Bestbuy's reaction to the fact that it's popular cable-modem routers and wireless access points have all become illegal.

    The device won't be outlawed, using it without a fee will be. BestBuy sells cable modems too.

    The problem is that this outlaws anything not explcitly alowed by your telcom. While doing some things has already got people Raided by the FBI, this will extend things considerably. It essentially redefines the alrady broken definition of "common carrier" to the point where you can't do squat. Instant messaging, VoIP, secure shells and more will all be outlawed or provided as a $ervice open to your provider's clerks. Looks like we won't have to worry about the internet making a real free press or helping people protect their fourth amendment rights.

    The smarter you make the internet, the less you can do.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
  22. Re:Read these *drafts* more carefully by Specter · · Score: 5, Insightful

    "Wait, there are yet more words here..."

    The specific phrase actually says:

    "with the intent to harm or defraud a communication service"

    What's left unspecified is the definition of "harm." Is it harmful to a broadband ISP who offers a VoIP phone service if I choose to use another VoIP service vendor? Economically speaking, I think it's rather apparent that the my use of an alternate IP telephony company results in lost revenue for my ISP. That's harm; does it rise to a level prosecutable by this law?

    Am I attempting to defraud my ISP if I use intentionally use "too much" bandwidth?

    Is the mere posession of a wireless access point (where the possibility exists that someone outside of my household might be able to use it) enough to imply intent to harm or defraud? What if my WAP is running on one of those Linux boxes all those evil terrorist h4x0rs use?

    And to your point about Terms of Service from your ISP; those are often changed without any notice to you. Does that open you to "intent to defraud" if yesterday P2P was ok, but today it's not and you inexplicably weren't rereading your ToS daily?

    The problem with this is that, as usual, the reason for writing the bill (stop people from stealing things) got completely lost in the authoring process.

    Jared

  23. IAAL (I Am A Layperson) by poot_rootbeer · · Score: 3, Insightful

    What's left unspecified is the definition of "harm."

    Lawyers and lawmakers understand specific connotations of the word 'harm' as it relates to commerce, even if we laypeople don't.

    I think it's rather apparent that the my use of an alternate IP telephony company results in lost revenue for my ISP.

    That's lost potential revenue. You're not depriving the ISP of anything they would have otherwise had an inalienable claim to.

  24. Re:Should lawmakers just do nothing? by minard · · Score: 3, Insightful
    I disagree very strongly.

    The argument of "it's ok, because they won't care about your little NAT box" is absolutely, positively, definitely, not good enough. If you're ok with being made a criminal just as long as nobody comes after you, fine. But it's sure as hell not good enough for me.

    As you say, this kind of law should only apply when actions are performed "with intent to defraud". But that isn't what it says (and yes, I did read the bill. Suggest you do the same). The article written by Prof Felten points to the relevant clause, which says none of that. Possession of equipment which conceals the intended origin or destination of a communication from the communication service provided is proposed to be made an offense. Period.

    What is seems to me is, this law looks like a classic trojan horse: there's stuff about preventing theft of service, yadda yadda, with intent to defraud, all of which looks perfectly reasonable. But then there's this other, mostly unrelated and egregious stuff buried in it.

    Suggestion to ISPs: if you're really concerned about theft of service by people "splitting the bill" start charging by the megabyte actually transferred. Then it works the other way around. The more bandwidth people (or their neighbors) use, the more they pay. If people want to open up a Wi-Fi access point to passers by, ok. All good. More revenue to the ISP whenever anybody actually uses it.