given city) often flows through an Internet exchange point (IXP), a physical network
node that connects geographically close ASs. There are fewer than 200 major IXPs in
the world, which together carry much of the Internet’s local traffic. 17 IXPs keep local
traffic local, so unlike the ASs responsible for routing intracountry and intracontinental
traffic, most IXPs are located in (and therefore potentially under the jurisdictional control of) the country whose traffic they carry.
This topology of the Internet has several implications for the actors trusted with access to Internet data. The first is that a large majority of users need to access the Internet through an AS (usually an ISP). The situation should be familiar by now: data from
these users is therefore vulnerable to surveillance by someone controlling that AS. The
second is that there are a relatively small number of these ASs within any given country and an even smaller number of IXPs, so monitoring all the network traffic in a
given country is a manageable task of making the small number of ASs and IXPs monitor their networks (though some of these ASs can be big complex organizations in
themselves). This rule applies doubly for international Internet traffic, which is controlled by an even smaller number of ASs disproportionately located in the United
States. 18 And the United States is capable of monitoring a large portion of international
Internet traffic through a few ASs based in the United States, including even traffic
flowing between non-U.S. countries.
A user can move her trust around from provider to provider. In the end, though, she
must ultimately trust someone on the network (barring the unlikely event of widespread adoption of end-to-end encryption of networked digital communications). In
practice, almost every user of digital networked technologies ends up trusting more
actors over time. A user who tries to get around surveillance of her local ISP connection, for instance by Phorm, has only a few choices of ISPs in the United Kingdom,
most of whom have been reported to be considering adding Phorm monitoring to their
networks. A user may choose to stay on the possibly monitored local network but use a
service like Relakks to proxy and encrypt her data as it travels through the local, Phorm
monitoring, ISP. The user will avoid Phorm monitoring in the process, but at the cost
of trusting not only Relakks but also the Swedish ISP through which Relakks talks to
the Internet and the Swedish government that monitors the data flowing through all
Swedish ISPs. And her local ISP will still be able to tell that she is proxying and encrypting all her data through a third party, which fact itself might prove suspicious to a law
enforcement agency. Finally, the user’s data are vulnerable to network monitoring at
any point along which they travel, from her local ISP to the server’s ISP to any ISPs
between. A portion of her data is likely to travel outside of Europe through one of a
few ISPs in the United States that process a disproportionate share of international
Internet traffic.
Against the backdrop of these forms of network surveillance, we can see that the EU
data retention directive has the potential to distort the network of trust through which
Internet data flows. The precise effects of these distortions are difficult to predict. Some
40
Hal Roberts and John Palfrey
Précédent

- 57/635

Suivant