ITU: Hands off our Internet!

Yuma504

fear mongering asshat
Feb 14, 2011
752
19
0
New Orleans,LA
I remember this place was on fire about SOPA and PIPA. And not a mention at all about ITU's closed door meeting regarding the fate of the internet and its openness and freedom.

Avaaz - ITU: Hands off our Internet!

Posted: 10 December 2012
Right now at a UN meeting in Dubai, authoritarian regimes are pushing for full governmental control of the Internet in a binding global treaty -- if they succeed, the internet could become less open, more costly and much slower. We have only 2 days to stop them.

The Internet has been an amazing example of people power -- allowing us to connect, speak out and pressure leaders like never before. That's largely because it's been governed to date by users and non-profits and not governments. But now countries like Russia, China and United Arab Emirates are trying to rewrite a major telecom treaty called the ITR to bring the Internet under its control -- the web would then be shaped by government interests and not by us, the users. Tim Berners Lee, one of the "fathers of the Internet," has warned that this could increase censorship online and invade our privacy. But if we object with a massive people-powered petition, we can strengthen the hand of countries fighting this power grab.

We have stopped attacks like this before and can do it again before the treaty text is locked this week. A wave of opposition to a new ITR is already building -- sign the petition to tell governments hands off our Internet! and then share this campaign with everyone you know -- when we hit 1 million signers, it'll be delivered straight to the delegates at this cozy meeting.


The Open Internet Is Threatened by UN's Closed-door Meeting in Dubai

Don Tapscott: The Open Internet Is Threatened by UN's Closed-door Meeting in Dubai

Representatives of more than 190 governments have convened a profoundly important closed-door meeting this week in Dubai to hammer out how the Internet should be run and who should pay for its operation.

The International Telecommunication Union, a low-profile United Nations agency that's sponsoring the meeting, sets out the technical standards for the world's communication technologies. The last time the group met was in 1988, when the information superhighway was geek talk and the World Wide Web didn't exist. The Internet's subsequent explosive growth occurred not so much because of the ITU but despite it.

Private and state-owned telecommunications companies spent billions of dollars in response to user demand, and most governments took a hands-off approach. In less than two decades, two billion people were able to go online.

Letting an obscure "one vote per country" UN technical agency decide who does what next in the Internet's development is the antithesis of what the Internet has achieved. Much of the documentation to date is secret, and it's hard to figure out the agendas of many players. The blogosphere is buzzing about proposals by repressive governments and money-grabbing telecommunications companies. One paper by Russia would see the ITU take over the Internet from the global ecosystem of volunteer organizations that currently govern it. Another by European telecommunications companies would let operators charge content providers such as YouTube that use a lot of bandwidth.

Defenders of an open Internet are concerned about a dark agenda at the Dubai meeting. "Many states and corporations would like to get a stranglehold on the Internet," says Tim Berners-Lee, the Web's inventor. "The multi-stakeholder system that governs the Internet works well and we need to preserve its openness."

It's farcical that little effort was taken by the ITU to include the people who actually use and run it in deciding how tomorrow's Internet will function. Of all organizations, the ITU should be able to see that the Internet has made the ITU obsolete. But it's not alone. Ironically, it's only one of many organizations the Internet itself is rapidly rendering anachronistic.

Throughout the 20th century, nation-states co-operated to build global institutions to address global problems. This led to the creation of the International Monetary Fund, the World Bank and, ultimately, to the UN (1945), the G8 (1975) and the World Trade Organization (1995). But, increasingly, they seem unable to solve global problems. Are climate change, poverty and war too hard to solve, or does the world need a new approach to global co-operation and governance?

These failures are often caused by national self-interests taking priority when the challenges demand solutions that transcend traditional nation-state boundaries. These groups make little room for the inclusion of authentic citizen voices, despite the fact that self-organized civic networks are congealing around every major international issue.

The successful governance of the Internet to date suggests a completely different form of global co-operation to supplement or even succeed those based on the nation-state, just as the nation-state itself was built on the foundations of earlier forms of government.

The Internet radically drops collaboration costs on a global basis, enabling new models of problem-solving. It's increasingly clear that governance will be co-owned by a variety of stakeholders, including NGOs, transnational corporations, emerging countries and traditional government entities. Even individuals have an unprecedented ability to participate in global activities. As former UN secretary-general Kofi Annan once put it, "We live in a world where human problems do not come permanently attached to national passports." Global governance isn't owned by any one governing body. It's a challenge owned by all of us.

Advocacy networks such as the Alliance for Climate Protection are working to educate and mobilize millions, changing the policy of governments and global institutions. Some networks act as platforms for those who seek change. A great example is Ushahidi, the website established to map reports of violence in Kenya after the post-election fallout of 2008 that evolved into a global network to enable people to share information and organize for change. Watchdog networks such as Human Rights Watch scrutinize the behaviour of governments. Global knowledge networks such as Wikipedia exist to produce and distribute knowledge to the world. Operational networks such as CrisisCommons intervene in crises such as Hurricane Sandy.

More elaborate multi-issue networks such as the World Economic Forum or the Clinton Global Initiative address a variety of issues but, unlike formal state-based institutions, are self-organizing and act as meta-networks trying to help other networks succeed.

The battle in Dubai is really an epochal showdown between the old and new models of co-operating and governing ourselves on this ever-shrinking planet. If the ITU wants to be helpful, it should back off and simply reaffirm the principles of competition, openness, neutrality and the independent regulation of national telecommunications that made the Web possible.

The governance of the Internet ain't broken, so don't fix it.

This piece was previously published on TheGlobeandMail.com.

Don Tapscott, who released the Don Tapscott App: New Solutions for a Connected Planet on iTunes last week, is leading a program at the University of Toronto's Rotman School of Management on New Models of Global Problem Solving, Co-operation and Governance.
 


Adoption of Traffic Sniffing Standard Fans WCIT Flames

https://www.cdt.org/blogs/cdt/2811adoption-traffic-sniffing-standard-fans-wcit-flames

The telecommunications standards arm of the U.N. has quietly endorsed the standardization of technologies that could give governments and companies the ability to sift through all of an Internet user’s traffic – including emails, banking transactions, and voice calls – without adequate privacy safeguards. The move suggests that some governments hope for a world where even encrypted communications may not be safe from prying eyes.

At the core of this development is the adoption of a proposed international standard that outlines requirements for a technology known as "Deep Packet Inspection" (DPI). As we’ve noted several times before, depending on how it is used, DPI has the potential to be extremely privacy-invasive, to defy user expectations, and to facilitate wiretapping.

The adoption of this standard, officially known as "Requirements for Deep Packet Inspection in Next Generation Networks," or "Y.2770" came to light last week during the World Telecommunication Standardization Assembly (WTSA), an international meeting held every four years in which the standards-setting body of the U.N.'s International Telecommunication Union, known as the ITU-T, charts the course of its work. Like most ITU working documents, drafts of the standard are locked behind a password wall and not available to the public. While the final standard will eventually be published, the fact that no draft versions are made publicly available at any point in the process illustrates the lack of transparency of the ITU-T in contrast to other leading global standards organizations.

Although the upcoming WCIT has been garnering all the attention lately, the global telecom confab in Dubai actually began last week at WTSA. The approval of the DPI standard provides new evidence of the dangers of WCIT proposals related to mandatory standards and cybersecurity.

Standard Procedure?

The ITU-T DPI standard represents a fairly typical early step in the process of standardizing a technology: the standards participants first agree on what the technology should do before they decide how the technology should work. As such, the ITU-T DPI standard doesn’t specify exactly how DPI systems should function. But even so, several of the requirements create a real cause for concern, especially in light of WCIT proposals that would make some ITU-T Recommendations mandatory, or transfer authority over cybersecurity matters to the ITU.

The ITU-T DPI standard holds very little in reserve when it comes to privacy invasion. For example, the document optionally requires DPI systems to support inspection of encrypted traffic “in case of a local availability of the used encryption key(s).” It’s not entirely clear under what circumstances ISPs might have access to such keys, but in any event the very notion of decrypting the users’ traffic (quite possibly against their will) is antithetical to most norms, policies, and laws concerning privacy of communications. In discussing IPSec, an end-to-end encryption technology that obscures all traffic content, the document notes that “aspects related to application identification are for further study” – as if some future work may be dedicated to somehow breaking or circumventing IPSec.

Several global standards bodies, including the IETF and W3C, have launched initiatives to incorporate privacy considerations into their work. In fact, the IETF has long had a policy of not considering technical requirements for wiretapping in its work, taking the seemingly opposite approach to the ITU-T DPI document, as Germany pointed out in voicing its opposition to the ITU-T standard earlier this year. The ITU-T standard barely acknowledges that DPI has privacy implications, let alone does it provide a thorough analysis of how the potential privacy threats associated with the technology might be mitigated.

These aspects of the ITU-T Recommendation are troubling in light of calls from Russia and a number of Middle Eastern countries to make ITU-T Recommendations mandatory for Internet technology companies and network operators to build into their products. Mandatory standards are a bad idea even when they are well designed. Forcing the world’s technology companies to adopt standards developed in a body that fails to conduct rigorous privacy analysis could have dire global consequences for online trust and users’ rights.

Ironically, although the document contemplates that network operators would decrypt user traffic in order to inspect it, the document’s security considerations specify that information extracted via DPI “is required to be protected,” and that modification, theft, or loss of such information “may make it unusable for the DPI operations.” The idea that adding DPI to a network creates a potential security risk for users – not just for network operators – is utterly absent. In general, the security requirements appear to be very generic, specifying what information needs to be protected without specifying the standards to be used for authentication, confidentiality, or integrity protection. Adding DPI to a network creates a significant new attack vector; thorough threat modelling and mitigation at the standardization phase are more than appropriate – they’re absolutely necessary.

WCIT proposals from the Arab States and Africa would seek to create new authority over cybersecurity matters within the ITU, and we’ve previously explained the drawbacks of this approach. If the technical work produced by the ITU-T fails to acknowledge basic user interests in network security – and to specify comprehensive, robust mitigations against security threats – it further highlights the grave problems with trying to address cybersecurity through a closed, centralized body where ultimate authority rests with regulators and where technical experts and advocates cannot even access draft specifications.

It’s not clear whether companies will build new DPI equipment to meet the ITU-T requirements or what further DPI standards the ITU-T will approve. Regardless, the standard approved at WTSA provides further evidence of why proposals for mandatory standards and new cybersecurity authority should be struck down next week in Dubai.


Update: While the official draft of the final Recommendation has yet to be posted (check here for the latest updates), what appears to be an earlier draft is available on the Korean Telecommunications Technology Association site. (Note that this draft contains dozens of pages of appendices, which we understand may have been cut.)
 
So even if something were to happen, we still have TOR and all that shit, right?

'Cause, ya know, signing some petition isn't going to do jack shit if these people really want this to go down.