Inside Comcast's Surveillance Policies
Monk writes "The Federation of American Scientists has obtained a recently disclosed Comcast Handbook for Law Enforcement which details its policies for divulging its customers' personal information. (Here's the handbook itself in PDF form.) All of Comcast's policies seem to follow the letter of the law, and seem to weigh customer privacy with law enforcement's requests. This is in apparent contrast to AT&T and a number of other telecommunication companies, which have been only too happy to give over subscriber records. According to the handbook, Comcast keeps logs for up to 180 days on IP address allocation, and they do not keep all of your e-mails forever (45 days at most). VoIP phone records are stored for 2 years, and cable records can only be retrieved upon a court order. The document even details how much it costs law enforcement to get access to personal data (data for child exploitation cases is free of charge)."
That's odd. I'd have thought it cost "do it or be fined/arrested".
Complying with requests from "Law Enforcement" is quite a bit different from complying with requests to assist a US government agency with an anti-terror program. Local law enforcement is far removed from the latter.
/.'ers? They still haven't changed thier undocumented policies related to bandwidth limitations on "unlimited bandwidth" accounts.
Is this an attempt to improve Comcat's poor reputation among
I'll trot this pony out one more time:
(Mac OS X 10.3+) http://www.joar.com/certificates/
(Windows) http://www.marknoble.com/tutorial/smime/smime.aspx
While I appreciate the idea and all, why? It's really not worth the time to encrypt my email. Do you think that if the feds are monitoring your line, they are just going to say, "Damn! He's encrypted. Let's move on to the next." I'm going to guess not. If anything, seeing that you email is encrypted might be enough to peak their interest to make you MORE watched, not less. This also takes precious manpower away from the people who are trying to stop the next terror attack in the US. Regardless of you political opinions, I don't see how anyone could think that impeding these guys is a good thing.
Me on the other hand, I don't care. There is nothing incriminating in my email beyond sending stupid YouTube links to a buddy or bitching to the wife about who chooses whats for dinner. I'm really not interesting enough for the Feds to care about. Please take no offense when I say that I doubt anyone else here is either.
There is no "I disagree" mod for a reason. Flamebait, Troll, and Overrated are not substitutes.
I have the capability of using both S/MIME and GPG for email (using Apple Mail, it's a matter of installing gpg, getting the Sente Software gpg addon for Mail, and getting a S/MIME certificate to activate the built-in S/MIME support), but overall I think S/MIME is probably better positioned to succeed in the marketplace. It's more idiotproof.
As much as I really despise the centralized philosophy behind S/MIME and x.509, there's something to be said for avoiding the 'web of trust' models that lie underneath GPG as its currently used, because most users just don't want to have to deal with it.
Getting people to use encryption is always a tough sell, because most people, to be perfectly frank, lead lives that are so completely boring that nobody would ever want to read their mail, and they know it. Therefore, they're not going to expend much effort getting it working. Either it works all automagically, or they don't use it at all.
I've yet to see a GPG implementation that comes as close to being foolproof as some S/MIME implementations (like Apple's), once you get the certificates set up. Once you've received a signed message from someone, you have their public key. Once you have that, the encryption button is magically enabled, and you can send encrypted stuff to them. Even Sente's Mail frontend to GPG isn't that easy to use.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
Yay for viral PR provided by Comcast... nice handbook... how much different is it from the "real" handbook?
They did a distributed computing project a few years back to break a 64 bit encryption method and it took them a little over 5 years. Most encryption keys these days are 128 bits or higher and every bit you add doubles the number of possibilities they'd have to check, so for 128 bit using the same level of resources brute force would take 92,233,720,368,547,758,080 years(assuming that the five years case was an average case). Computers are a lot faster than they were, but not that much faster.
To sum up, if encryption works at all, no one is going to get in without knowing your password, and the shows are bollocks. That said some encryption algorithms do contain backdoors for the US government, and some algorithms are badly written(WEP for instance), P may equal NP and the US government will probably have a quantum computer as soon as they're available so YMMV.
There are approaches faster than brute force, in which a 128-bit key does not mean 2^128 possible combinations. Depending on the algorithm, the key space is smaller than the key size (parity bits, weak keys, etc).
"All of Comcast's policies seem to follow the letter of the law, and seem to weigh customer privacy with law enforcement's requests. This is in apparent contrast to AT&T and a number of other telecommunication companies, which have been only too happy to give over subscriber records."
Apples and oranges. "Monk" is comparing Comcast's words to AT&T's actions..
It's nice to know that Comcast is able to write a policy manual that follows the law, but surely a written policy telling employees to break the law would trigger a minor scandal.
Anyone who's ever been in a large organization is familiar with lip-service CYA written policies.
How seriously does Comcast take this policy? Do they give training sessions to the people who need to implement it? Do they back up or undercut the people who go "by the book?"
"How to Do Nothing," kids activities, back in print!
Therefore the aggregate effect of large numbers of people using encryption would be to render large-scale electronic surveillance systems useless, since they are only practical for plaintext traffic. (In fact, you don't really even need to be using state-of-the-art crypto; if everyone were using even keys that took a few days to break on a supercomputer, it would prevent most types of high-speed/real-time analysis and force authorities to take much more fine-grained, targeted approaches.
Your argument against taking an individual step to prohibit mass surveillance is the same argument that many people make against voting: your action, taken singularly, has virtually no effect. It is only as part of a group that it is significant. But just as many people deciding to vote the same way can change a government, a large number of people deciding to make the snoopers' jobs (even slightly more) difficult would quickly outpace their resources available for the task.
I don't think the solution is either-or, personally. As concerned citizens, we need to vote. As people with technological knowledge and capabilities, we have a responsibility to not make it easy for those in power to abuse it, through our passivity.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
It's like being robbed in your home when you're out. It doesn't matter if you have an alarm system or not, if someone wants property of yours, they will get it.
You can double lock your doors, put bars on the windows, pay for a monitoring service, or whatever, it will not stop a determined person from getting whatever they want to get.
But in this instance it is like having someone in your house at all times who is allowed to go through your stuff at any given time for any particular reason. They aren't supposed to steal anything or do anything illegal to your home, but the thought of having them there and having that ability is what annoys me.
As they say... Locks are there to keep honest people honest. When you don't have any at all or have someone on the inside who you can implicitly trust is when things get hairy.
"I am the king of the Romans, and am superior to rules of grammar!"
-Sigismund, Holy Roman Emperor (1368-1437)