and so on for Web requests; data about the originating e-mail server, the ‘‘from:’’
e-mail address, the date, and so on for e-mails) and the content proper of the communication. This content includes, but is not limited to, any data submitted to Web sites,
any Web pages retrieved, and any e-mails sent or received.
Users can encrypt the content of their network communications to hide their activities from network monitoring. Encryption is most effective when it is applied end-toend, as by using Hypertext Transfer Protocol Secure (HTTPS). In this case, the entire
stream of data from the client to the server is encrypted, allowing no one on the network between the sender and the receiver to read the content. But end-to-end encryption has to be supported by both the client and the server, and many servers do not
support encrypted communication at all or for all pages. In these cases, a user can connect through a proxy like Relakks or HotSpot Shield to encrypt the data from the client
to the proxy. But such encrypting proxies still use unencrypted channels to talk to
servers that do not support encryption. As a result, the proxied content remains readable to any intervening routers on the network. For instance, even though content between Relakks and the user is encrypted, the requests and responses between Relakks
and Google.com are not encrypted.
These apparently secure connections between Internet users leak other, contextual
forms of information as well. The information about those requests and responses—
think of it as ‘‘metadata’’ to the ‘‘data’’ of the communication itself—can be observed
by anyone on the network in between. Communications that are both encrypted and
proxied can hide both the routing information for, and the content of, a communication from the network between the client and the proxy. But even proxied and
encrypted data leaks some of its metadata: information about the timing, number,
and size of the packets as well as the fact that the communication is proxied and
encrypted, may be observed. Different sorts of traffic generate different signatures of
packet size and timing that can allow easy identification of the nature of the communication. These signature-based monitoring methods have reportedly been used, for
example, to block proxied file-sharing traffic.
The Internet consists of billions of links between clients, servers, and routers, making
comprehensive surveillance of the entire network very difficult. But in practice, all
Internet traffic flows through a much smaller number of links between routers, and
those routers are controlled by a much smaller yet number of autonomous systems
(ASs). These ASs are the independent entities (mostly ISPs) that have the ability to
route traffic on the Internet. There are fewer than 100,000 of these ASs in the world.
In practice, the vast majority of Internet traffic flows through an even much smaller
number of those ASs. For instance, virtually all 300 million Internet users in China
connect to the Internet through only five big ISP ASs. 15 For a combination of technical, business, and policy reasons, a disproportionate amount of global Internet traffic
flows through a few very large ASs in the United States, including most traffic between
Europe and Asia. 16 Traffic between ASs within a given country (or sometimes even a
The EU Data Retention Directive in an Era of Internet Surveillance
39
Précédent

- 56/635

Suivant