EU Approves Data Retention
submanifold writes "The EU have ratified rules that will force ISP's and other telecommunication companies to retain data for two years. This data includes the time, date and locations of both mobile and landline calls (as well as whether or not they were answered) along with logs of internet activity and email.
Apparently the content itself would not be accessible, merely the data concerning it. However, despite being touted as an anti-terrorist measure, the record industry has already admitted interest in aquiring such data."
FTA: "At the end of the day ISPs are not law enforcement agencies so they should not have to pay for it all"
At least in Finland the government is going to be paying for it. Though I believe it varies by member state, so in some countries the costs would actually fall on the ISPs and other such operators.
Afaik, it's specifically logging info they want - this ip connects to that ip on such and such port, this dynamic ip is that user, this email header was sent to that address. I doubt they want the ISP to store every packet that comes through.
Yes, it will still be an expensive PITA, but probably no worse than running a Usenet service.
Of course the music industry is interested in that data. But that doesn't mean they can just obtain it like that. As long as this is kept an anti-terrorist measure, they have no foot to stand on.
Keep in mind that data will be kept for UP TO two years; most will opt for the minimum of half a year instead.
Everything is justified in the global war on TERRA....
When the President can call the Constitution "just a goddamned piece of paper" this kind of stuff should not surprise anyone. Its a brave new world full of chickenshit people.
Service guarantees Citizenship! Questions Guarantee GITMO.... Amerika Uber Alles!
No, the way I've understood it this only applies to registered telecommunication companies(ie. internet service providers, telephone companies and such). So you should be safe from any obligations to keep such logs.
Now, the place hosting your servers/providing the net connection might be a different story..
Couple times per year.
A friend is visiting the States with us right now, her first visit. 23, female, college degree in economics. After converting from metric, she's blown away at how cheap electronics, food, gas, and even liquor is.
I'm starting a business right now in Europe (acrylics) and the pay vs taxes vs cost of living saddens me.
The Dutch government has made it clear that they won't be paying ISP's for it.
The Dutch ISP xs4all is actively campaigning against this law.
They give the realistic argument that this law will commercially cripple European ISPs, and the government paying for the storage is unrealistic.
The path I walk alone is endlessly long.
30 minutes by bike, 15 by bus.
It seems nobody has said the obvious yet ...
Encrypt your private communications.
Use anonymous remailers.
If you actually get charged, they'll require you to give up your keys, but they won't be snooping at your E-mails behind your back.
pgp.com
gnupg.org
- Michael T. Babcock (Yes, I blog)
Christian Engström, Former Member of the European Parliament 2009-2014 for The Pirate Party, Sweden
Webhosting is not caught under this, since it only applies to providers of public telecommunications services and networks as defined by the New Regulatory Framework. You do not fall under the new regulatory framework, unless you do a public offering, route your own traffic (multi-homed) etc etc. You probably don't. Your ISP is not obliged to sniff through all the traffic to filter out who has e-mailed who using private e-mail adresses, since that is content to him and it would be lawful interception. It also doesn't oblige providers of corporations to save all the e-mail that goes to and from the corporation, nor does it oblige the corporation to retain all internal mail.
GMail/Hotmail/Yahoo? anybody willing to guess?
According to their own Press Service: Deal on EU data retention law; more comprehensive version in German: Ja zur Vorratsdatenspeicherung bis zu zwei Jahren - Keine Speicherung der Kommunikationsinhalte. Incidentally, even the latter "limitation" (allegedly no storage of the contents of communications) is void in particular with respect to URLs - these being identifiers for the contents transmitted anyway.
Loopholes aplenty have already triggered plans e.g. in Poland to extend the storage even further, to a staggering 15 years (!), and remaining safeguards (if any) are not expected to last: The media industry wants access to that data, too (and a further directive is in the works, cf. the EU Legislative Observatory).
You forgot to mention that they will log every URL you visit.
There's one major problem with your scenario. It's actually fairly obvious: when you go looking through the e-mail, the only stuff identifiable as coming from an Abdullah won't have anything to do with the anthrax. Do you think the real Abdullah will be stupid enough to use an e-mail address clearly matching his name? No, his e-mail will come from something like hot18yo84172@hotmail.com or somesuch, and it'll be buried in the mountain of sex-spam e-mails your target receives and discards every day just like the rest of us. Now, if you have Abdullah and want to find out who he's been talking to, then this kind of retention might be useful. Unfortunately it's also unneccesary, since if you've already got enough to nail Abdullah you've got enough to go into court, get a warrant and tap his computer directly without having to mess with his ISP.
There's also the side-effects that've already been noted. While the retention may not be useful for tracking terrorists (it's purported justification), it'll be very useful to people whose investigations have nothing to do with terrorism and who've been unable to get anything like this on their own merits. That makes me thing the whole thing's an end-run, and "terrorism" is just an excuse.
What if someone created a screensaver that continually accessed thousands of websites, IP addresses. Basically create as much junk data as possible to pollute their logs.
g le+Search --output-file=/dev/null
Real geeks do not run screenasvers.
wget --background --spider --mirror --limitrate=2k http://www.google.com/search?hl=en&q=sex&btnG=Goo
There you are, staring at me again.
If this is the case, what if there was some sort of bot that would simply go around the Internet visiting random sites. If everybody had this installed, then the noise ratio would be too high for accurate data retention, right? After all, you don't pay for the usage of bandwidth generally, you pay per month. Just use all the bandwidth you can on useless stuff. In the end, it will push the amount of storage the ISP's have to use and their bandwidth usage through the roof.