ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Technologists assail federal Net-tapping rules

Declan McCullagh CNET News.com Anne Broache CNET News.com

Published: 13 Jun 2006 10:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Federal regulations saying that police must be able to tap into Internet phone conversations with ease are coming under renewed attack from academics, engineers and one of the Net's founding fathers.

A 21-page study to be released on Tuesday says it's impossible for the government to expect all products that use voice over Internet protocol, or VoIP, to comply with the Federal Communications Commission's September 2005 requirement mandating wiretapping backdoors for government surveillance. That requirement is backed by the Bush administration.

The study, organised by the Information Technology Association of America, says that because VoIP relies on a fundamentally different network architecture from that of traditional phone lines, such a mandate would pose "enormous costs" to the industry and could even introduce significant security risks.

The nine contributors included Vint Cerf, Google's chief Internet evangelist and one of the Net's founding fathers; Steven Bellovin and Matt Blaze, both prominent computer security professors who specialise in security; Clinton Brooks, a former National Security Agency official; and engineers from Sun Microsystems and Intel.

The report follows a ruling Friday by a federal appeals court in Washington, DC that upheld the legality of the FCC's wiretapping regulations. Librarians, community colleges, and companies including Sun had challenged the rules, saying the FCC did not have the authority to extend the Communications Assistance for Law Enforcement Act, or CALEA, to the Internet. (The decision may be appealed.)

Even without the FCC rules that are scheduled to take effect in May 2007, police have the legal authority to conduct Internet wiretaps — that's precisely what the FBI's Carnivore system was designed to do. Still, the FBI has claimed, the need for "standardised broadband intercept capabilities is especially urgent in light of today's heightened threats to homeland security and the ongoing tendency of criminals to use the most clandestine modes of communication".

The controversy over the FCC mandatory wiretapping regulations comes as the Bush administration is facing increasing congressional pressure, especially from Senator Arlen Specter, a Pennsylvania Republican, over its telephone and Internet surveillance programme overseen by the National Security Agency. AT&T is being sued in a separate case in San Francisco over allegations that it cooperated in a way that violated federal privacy laws.

The nature of VoIP could also elevate the risk that authorities aren't eavesdropping on the person they originally had in mind, the ITAA report's authors argue. Because it's theoretically simple for an individual to acquire multiple VoIP phone numbers, "recognising and tracking the multiple identities that are so natural to the Internet lifestyle would be taxing".

In addition, the study says, allowing full access by law enforcement would almost certainly require overhauling inherently decentralised networks to allow for certain points where interception would take place — and that could open up new security risks. That's because such an arrangement would arguably make it easier for hackers to capture identity information and passwords, engage in "man-in-the-middle alteration of data", or potentially spoof the communications going on.

"It's sort of like if you were chasing someone and you knew they had to go over a particular bridge," said Mark Uncapher, a senior vice president at ITAA.

Though there may be some security concerns, the benefits of mandating wiretapping access outweigh the costs, said Tim Richardson, senior legislative liaison for the Fraternal Order of Police. (Many police organisations, including the National Sheriffs' Association, the Police Executive Research Forum, the Illinois State Police and the Tennessee Bureau of Investigation petitioned the FCC in favour of the wiretapping rules.)

"If that was going to increase the propensity for crime, that's something that law enforcement would take a look at," Richardson said. "But the adaptability of technology is so great in this day and age that I have a high degree of faith in the initiative that (companies would employ to find something) that's not as costly and doesn't compromise the security of their networks."

Complexities involved in meeting such a mandate exist on a number of levels, the ITAA report said. One problem is that, in contrast to traditional telephones, whose calls can virtually always be traced to a centralised switching location, VoIP users are often nomadic.

"The paradigm of VoIP intercept difficulty is a call between two road warriors who constantly change locations and who, for example, may call from a cafe in Boston to a hotel room in Paris and an hour later from an office in Cambridge to a gift shop at the Louvre," the report says, and adds that building in mandatory wiretapping hubs for real-time interception is so expensive that it could put smaller companies out of business.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
65 out of 103 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Cisco VoIP / IPT Engineer - Oxfordshire

Cisco VoIP / IPT Engineer - Oxfordshire 35,000 - 50,000 basic + 5% bonus + comprehensive benefits Abingdon, Oxfordshire An exciting opportunity for a ...

Homelessness Housing Officer/ Housing Association/ West Midlands

Homelessness Officer/ Housing Association A Housing Association in the West Midlands is looking to recruit a new Homelessness Officer to join their ...

Contract Specialist - Newcastle-00051050

Will be required to work in a client facing environment, with senior management levels Responsible for educating the project team on contract terms ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment