This chapter paints a simplified picture of the technical landscape of Internet surveillance, as well as the place of the EU data retention directive within that landscape, by
taking up a series of short cases about surveillance. We examine how these cases inform (and are informed by) the technical questions of what data are being actually
and potentially monitored on the Internet and whom we are trusting to access that data.
We break Internet surveillance into three broad categories: network, server, and client. The Internet is composed of clients and servers, in essence a series of devices that
talk to one another through the network. Every bit of data on the Internet is traveling
or residing at one or more of these locations at any given time. As such, any given
Internet activity must happen at one (or more) of these locations. We treat any surveillance happening on the end user device as client-side surveillance, including both software tools like workplace keylogging systems and hardware tools like keyboard tapping
devices. We treat any surveillance happening on a machine that predominantly
accepts requests, processes them, and returns responses as server-side surveillance.
And for simplicity, we treat everything between the client and the server as the network, including the wires over which the data travel and the routers that direct the
traffic.
We argue in this chapter that the EU data retention directive introduces new risks related to the networks of trust created by each category of surveillance. In the section on
network surveillance we argue that trust can only be rerouted around the network,
rather than removed from it, and that the EU data retention directive may cause users
to reroute trust in the network in ways that both reduce the amount of useful data
available to law enforcement and encourage users to expose more of their network
data to non-EU states. In the section on server surveillance we argue that users struggle
to evaluate how the data they submit to servers are used and combined and that the
EU data retention directive is likely to increase this problem by requiring ISPs to store
more server data (which will be used and combined in ways opaque to most users). In
the section on client surveillance we argue that the client has become an intensely
complicated battleground of trust played out by sophisticated actors with their own
agendas, resulting in widespread leaks of data from the client. This section argues that
the EU data retention directive will place a large new set of private data onto this
battleground—to the detriment of people from around the world.
Network Surveillance
The most obvious kind of Internet surveillance takes place on the network between
the clients and servers. Government agencies collect data from within network ISPs,
including not only wiretap-like data about specific subjects with warrants but also entire streams of data for mining without judicial oversight. But the network is a diverse
place. There are a wide variety of different actors with different access to data. As a re36
Hal Roberts and John Palfrey
Précédent

- 53/635

Suivant