Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Standing Up Against German Laws - Project HayNeedle Nov 10 2007 05:28PM
Paul Sebastian Ziegler (psz observed de) (2 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 12 2007 05:55PM
johan beisser (jb caustic org) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 12 2007 07:27PM
Matt D. Harris (mdh solitox net) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 12 2007 09:15PM
johan beisser (jb caustic org) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 13 2007 09:59AM
Florian Echtler (echtler in tum de) (4 replies)
RE: Standing Up Against German Laws - Project HayNeedle Nov 17 2007 03:05AM
Quark IT - Hilton Travis (Hilton QuarkIT com au)
Re: Standing Up Against German Laws - Project HayNeedle Nov 14 2007 03:20AM
Raj Mathur (raju linux-delhi org) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 14 2007 09:01PM
imipak (imipak gmail com)
Re: Standing Up Against German Laws - Project HayNeedle Nov 13 2007 10:03PM
Stefano Zanero (s zanero securenetwork it)
Re: Standing Up Against German Laws - Project HayNeedle Nov 13 2007 08:39PM
Paul Wouters (paul xtdnet nl) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 13 2007 09:07PM
johan beisser (jb caustic org) (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 13 2007 09:38PM
Valdis Kletnieks vt edu (1 replies)
Re: Standing Up Against German Laws - Project HayNeedle Nov 14 2007 09:34PM
Frank Guthausen (fg-bugtraq nsv-server de)
Re: [Full-disclosure] Standing Up Against German Laws - ProjectHayNeedle Nov 10 2007 06:53PM
Jan Newger (memger gmx net) (2 replies)
Re: [Full-disclosure] Standing Up Against German Laws - Project HayNeedle Nov 13 2007 10:13AM
Peter Conrad (conrad tivano de)
Re: [Full-disclosure] Standing Up Against German Laws - Project HayNeedle Nov 11 2007 09:26PM
Duncan Simpson (dps simpson demon co uk) (1 replies)
Re: [Full-disclosure] Standing Up Against German Laws - Project HayNeedle Nov 13 2007 09:03PM
johan beisser (jb caustic org)

On Nov 11, 2007, at 1:26 PM, Duncan Simpson wrote:

> The signal-to-noise logic probably does work, but I am not sure the
> legal
> angle does. If you were *deliberately* ran the software that acidently
> downloaded that kiddie porn the suggested angle might not work.

That's been an ongoing question for me with regards to things like
TOR gateways.

As has been recently posted on Risky Business[1] and The Age[2], TOR
doesn't prevent sniffing of the traffic leaving its gateway. If a
running gateway connects to a server with "information of interest" -
child porn, bomb making information, a known criminal forum - that
brings authorities investigating to your house, it isn't a very good
way to cover ones own tracks with noise. On a similar note, randomly
connecting and pushing network data may create noise that obscures
important data, but it may be easily filtered out from the logs
during analysis.

>
> A law requiring log data to be retained for 6 momths should be a
> major problem
> to enforce. Last time I think the UK mooted this it did not happen
> (disclaimer: this might have been a trial balloon designed to
> generate flak).
> My reaction at the ISP end was "OK, will you buy us the extra hardware
> required?" with the intention the answer would be "no" and the plan
> quietly
> killed. (Thinking that plain daft things will not be enacted is not
> always
> reliable, unfortunately).

That's been my first question as well. Storage, at least for
compliance purposes, has gotten cheaper. 6 months of log data for
most ISPs will still be under the 500GB range of disk. The harder
part of the stored logs is making it easily analyzed and relevant.
There are, of course, several companies in the data retention
compliance arena already, most have offerings for PCI, SOx and HIPAA.
It's not a stretch to think there are smaller offerings to handle
this German laws lighter retention requirement for logs.

[1] http://www.itradio.com.au/security/?p=48
[2] http://www.theage.com.au/news/security/the-hack-of-the-year/
2007/11/12/1194766589522.html

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus