RFC 7258: Pervasive Monitoring Is an Attack
An anonymous reader writes with news that the IETF has adopted a policy of designing new protocols taking into account the need to mitigate pervasive monitoring of all traffic. From the article: "...RFC 7258, also known as BCP 188 (where BCP stands for 'Best Common Practice'); it represents Internet Engineering Task Force consensus on the fact that many powerful well-funded entities feel it is appropriate to monitor people's use of the Net, without telling those people. The consensus is: This monitoring is an attack and designers of Internet protocols must work to mitigate it."
The NSA will try to infiltrate the IETF.
The "pen register" part of the Smith v. Maryland makes their monitoring legal in this meta way. Even Hayden says they've killed people based on metadata alone.
I don't see how you're going to "mitigate" anything until you get the 9 robed activists to pull heads out.
I think your question calls for a multi-context response:
Greatest combined offensiveness and pervasiveness today: NSA, though GCHQ gets a solid nod for being more offensive and nearly as pervasive (especially if you count cooperation with NSA, but that cuts both ways).
Most pervasive today / greatest potential psy-ops threat: US corporations (Google and Facebook so far out in front that it doesn't even look like a competition)
Most offensive monitoring program today: Corporations monitoring public school students.
Most scary if I thought they posed a credible threat: North Korea
Most scary based on capability and recent offensive behavior: Russian government.
Most scary based on capability and mid-term offensive behavior: Chinese government.
Most scary based on capability and long-term offensive behavior: Russian government.
I echo your sentiment about the difficulty of separating Chinese and Russian thugs/corporations/government.
Stop-Prism.org: Opt Out of Surveillance
of the Internet. The big corporations collect data of everyone and everything. Its too easy for an NSA to walk in at google and demand for their data. However, if they walk into your home, and ask politely to install a monitoring application on your computer, you will probably decline. They do exactly this thing with the corporations, but let them do the dirty work of getting the data from the people. It will be much harder for the NSA and alike if they have to face a truly decentralized internet.
When you download an NSA trojan, there won't be the eagle on it. Instead it will perhaps be an angry birds logo. Or a blue box. Or a blue f. Or a blue twittering bird.
From the RFC, so delicious it must be fattening:
In particular, the term "attack", used technically, implies nothing about the motivation of the actor mounting the attack. The motivation for PM can range from non-targeted nation-state surveillance, to legal but privacy-unfriendly purposes by commercial enterprises, to illegal actions by criminals. The same techniques to achieve PM can be used regardless of motivation. Thus, we cannot defend against the most nefarious actors while allowing monitoring by other actors no matter how benevolent some might consider them to be, since the actions required of the attacker are indistinguishable from other attacks. The motivation for PM is, therefore, not relevant for how PM is mitigated in IETF protocols.
Stop-Prism.org: Opt Out of Surveillance
Open source community: this is excellent and we welcome the opportunity to enhance common protocols like smtp and http with this new mandate.
Microsoft: we havent met an RFC we cant mangle. Exchange is so broken as to be unusable, Internet Explorer is more exploit than browser, and we hold patents on sharps and plusses for a clone of every major programming language in existence. dont expect this one to go anywhere fellas.
Google: we'll add an option in chrome that you can click to disable monitoring. Clicking this option will cause a checkmark to appear. This checkmark will make the user feel feelings, and should probably do something with google plus. its a clickable option for google plus really. buy some of our neat glasses too.
NSA: you realize Russ Housley and Brian Carpenter, both IETF former chairs, have worked with companies that rolled over when we asked for them to spy on you without telling anyone. Jari Arkko has only been around for a year, and we have enough IETF members in our pocket to keep it that way if we want. Go back to sleep, vote the two parties, and buy magnetic bumper ribbons during the next war to support what we tell you.
Good people go to bed earlier.