Detection of the most advanced client surveillance tools requires the use of some other
monitoring tool, such as an anti-virus system, designed specifically for this purpose.
The latest versions of malware and other surveillance tools change themselves constantly to avoid detection even by sophisticated anti-virus systems. This cycle of increasingly sophisticated detection and evasion requires constant monitoring of every
networked client, by anti-virus tools, by mal- or spyware, or often by both.
In a strict sense, the EU data retention directive applies directly only to network and
server monitoring. But the routers that will be used in the implementation of the directive to collect network data are client devices themselves. As such, they are vulnerable
to a stack of hardware, operating system, and applications just like any other client.
Any actor within that network may potentially have access to the data, so adding the
monitoring box to the ISP network potentially adds all those actors to the network
trusted with the client data. Most of those actors (including hardware manufacturers,
operating system developers, application developers) have access to all the data potentially collected through network surveillance and not just the legally monitored data,
so we have to consider the flow of both the actual and potential data mandated by
the directive through this network of trust around the monitoring tools. The sophistication of client surveillance tools at both collecting data and hiding themselves from
detection demonstrates the possibility of an attacker installing such code undetected
on a data retention tool. The number of well-publicized, active exploits against a range
of routers (not to mention counterfeit routers) means that the risk of this occurring is
high.
Conclusion
This chapter provides a typology of the different sorts of Internet surveillance through
cases about Internet surveillance tools. For each set of cases, it is important to focus on
the actual and potential data monitored and networks of trust through which the data
necessarily flow. This typology is intended to serve as a starting point for analysis
of the steady stream of cases about Internet surveillance; for the analysis of those
cases not only from a technical frame but also from social, political, legal, and other
frames; and for the application of the resulting road map to specific questions about
surveillance that arise over time. As new stories about surveillance emerge, this road
map can provide a context for determining whether and in what ways those
stories tell us anything new about Internet surveillance. For example, one might ask
whether recently reported iPhone viruses represent a new sort of surveillance or
how the monitoring required for Comcast’s BitTorrent throttling (described in the
U.S.-Canada Overview presented later in this book) compares to existing examples of
surveillance.
This typology also provides a frame for considering the impact of the EU data retention directive, which is likely to have important effects beyond its explicit scope. These
The EU Data Retention Directive in an Era of Internet Surveillance
49
monitoring tool, such as an anti-virus system, designed specifically for this purpose.
The latest versions of malware and other surveillance tools change themselves constantly to avoid detection even by sophisticated anti-virus systems. This cycle of increasingly sophisticated detection and evasion requires constant monitoring of every
networked client, by anti-virus tools, by mal- or spyware, or often by both.
In a strict sense, the EU data retention directive applies directly only to network and
server monitoring. But the routers that will be used in the implementation of the directive to collect network data are client devices themselves. As such, they are vulnerable
to a stack of hardware, operating system, and applications just like any other client.
Any actor within that network may potentially have access to the data, so adding the
monitoring box to the ISP network potentially adds all those actors to the network
trusted with the client data. Most of those actors (including hardware manufacturers,
operating system developers, application developers) have access to all the data potentially collected through network surveillance and not just the legally monitored data,
so we have to consider the flow of both the actual and potential data mandated by
the directive through this network of trust around the monitoring tools. The sophistication of client surveillance tools at both collecting data and hiding themselves from
detection demonstrates the possibility of an attacker installing such code undetected
on a data retention tool. The number of well-publicized, active exploits against a range
of routers (not to mention counterfeit routers) means that the risk of this occurring is
high.
Conclusion
This chapter provides a typology of the different sorts of Internet surveillance through
cases about Internet surveillance tools. For each set of cases, it is important to focus on
the actual and potential data monitored and networks of trust through which the data
necessarily flow. This typology is intended to serve as a starting point for analysis
of the steady stream of cases about Internet surveillance; for the analysis of those
cases not only from a technical frame but also from social, political, legal, and other
frames; and for the application of the resulting road map to specific questions about
surveillance that arise over time. As new stories about surveillance emerge, this road
map can provide a context for determining whether and in what ways those
stories tell us anything new about Internet surveillance. For example, one might ask
whether recently reported iPhone viruses represent a new sort of surveillance or
how the monitoring required for Comcast’s BitTorrent throttling (described in the
U.S.-Canada Overview presented later in this book) compares to existing examples of
surveillance.
This typology also provides a frame for considering the impact of the EU data retention directive, which is likely to have important effects beyond its explicit scope. These
The EU Data Retention Directive in an Era of Internet Surveillance
49
