<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.expertiza.ncsu.edu/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ntnguyen</id>
	<title>Expertiza_Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.expertiza.ncsu.edu/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ntnguyen"/>
	<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Special:Contributions/Ntnguyen"/>
	<updated>2026-09-13T06:52:07Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_5,_Group_5&amp;diff=2159</id>
		<title>CSC 379:Week 5, Group 5</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_5,_Group_5&amp;diff=2159"/>
		<updated>2007-08-05T20:45:59Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Why was the Milstar satellite damaged although the components of the Inertial Navigation Unit (INU) operated correctly with respect to the instructions, including constraints, and data provided?  W&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Software Safety: Accident Models - Systems Theory vs. Chain of Events=&lt;br /&gt;
'''Skim through the following paper (focus on sections 1, 2.3, and 3, skip figures and tables) entitled [http://sunnyday.mit.edu/papers/tdsc.pdf &amp;quot;A Systems-Theoretic Approach to Safety in Software-Intensive Systems&amp;quot;] by Nancy G. Leveson, a Professor of Aeronautics and Astronautics at MIT, then answer the following questions:'''&lt;br /&gt;
&lt;br /&gt;
The majority of the content you need to form an informed response to the above questions is included in the paper.  Bring in outside resources and topics discussed in class lectures as appropriate to support your response.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are some shortcomings of traditional methods of accident reporting when applied to complex systems like software systems?==&lt;br /&gt;
*Event-chain models tend to stop once something to blame is found. &amp;quot;reports stopped after assigning blame—usually to the operators who interacted with the software—and never got to the root of why the accident occurred&amp;quot;&lt;br /&gt;
*Event chain models were not designed to handle complex systems such as software. &amp;quot;in dealing with software in safety-critical systems is the result of inappropriately attempting to extend the techniques that were successful in simpler, electromechanical systems and were based on models of accident causation that no longer apply&amp;quot;&lt;br /&gt;
**Software can be very complex&lt;br /&gt;
&lt;br /&gt;
==How does the STAMP model improve accident prevention efforts?  Explain some general concepts of the model.==&lt;br /&gt;
&amp;quot;Systems theory allows more complex relationships between events to be considered&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Accident models based on systems theory consider accidents as arising from the interactions among system components and usually do not specify single causal variables or factors&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The STAMP model provides more information in terms of how to prevent future accidents rather then trying to place blame.&lt;br /&gt;
&lt;br /&gt;
Hazard analysis using STAMP rather then traditional methods can prevent accidents from happening in software based systems&lt;br /&gt;
&lt;br /&gt;
==Why was the Milstar satellite damaged although the components of the Inertial Navigation Unit (INU) operated correctly with respect to the instructions, including constraints, and data provided?  Why would use of the STAMP model more thoroughly prevent problems such as those that occurred with the INU compared to traditional accident reporting?==&lt;br /&gt;
&lt;br /&gt;
There was a miscommunication (or the lack of) between the different agencies responsible for the different components of systems control.  Specifically, the Flight Control Software and the Inertial Measurement System were not colaborating properly.  Individually, each of the subsystems worked properly; it was only when working together that miscommunication and problems manifested.  If the STAMP model was used, the model would allow a particular system/process to be broken down, thus better understanding of the process itself, and how  the process interacts with other components.&lt;br /&gt;
&lt;br /&gt;
==What are some appropriate applications of the STAMP model (both current and past)?  Explain.==&lt;br /&gt;
The STAMP model is especially useful in analyzing complex socio-technical and software-based systems where accidents can occur due to complex human decision making, component interaction rather than single component failure, and accidents that occur because slow shifts toward an accident prone environment.&lt;br /&gt;
&lt;br /&gt;
===Walkerton, Ontario: Water Contamination Accident===&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The stage for the accident had been set over a large number of years by actions at all levels of the socio-technical system structure.&amp;quot;[2]&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Degradation in the water safety control structure had occurred over time, without any particular&lt;br /&gt;
single decision to do so but simply as a series of decisions that moved the public water system&lt;br /&gt;
slowly toward a state of high risk where any slight error or deviation from the normal could lead&lt;br /&gt;
to a major accident. Degradation of the safety control structure may be related to asynchronous&lt;br /&gt;
evolution, where one part of a system changes without the related necessary changes in other&lt;br /&gt;
parts. Changes to subsystems may be carefully designed, but consideration of their effects on&lt;br /&gt;
other parts of the system, including the control aspects, may be neglected or inadequate.&amp;quot;[2]&lt;br /&gt;
&lt;br /&gt;
[http://archives.cnn.com/2000/HEALTH/05/26/canada.ecoli.01/ CNN Article on the Outbreak]&lt;br /&gt;
&lt;br /&gt;
===The Mars Polar Lander Loss===&lt;br /&gt;
&amp;quot;The software did not adequately control the descent speed of the aircraft - it misinterpreted noise from a Hall effect sensor as an indication the spacecraft had reached the surface of the planet&amp;quot;[1]&lt;br /&gt;
&lt;br /&gt;
The components did not fail in terms of not satisfying their specified requirements, the failure occurred due to an unplanned effect of the system's interacting components.&lt;br /&gt;
&lt;br /&gt;
[http://www.cnn.com/TECH/space/9909/30/mars.metric.02/ CNN Article on the Mars Polar Lander Loss]&lt;br /&gt;
&lt;br /&gt;
===The Space Shuttle Challenger===&lt;br /&gt;
The O-rings did not adequately control propellant gas release and there were inadequate controls in the launch-decision process. The failures occurred due to a complex socio-technical interaction.&lt;br /&gt;
&lt;br /&gt;
[http://history.nasa.gov/rogersrep/genindex.htm The Rogers Commission Report]&lt;br /&gt;
&lt;br /&gt;
==What are some ethical concerns of assigning blame for accidents?==&lt;br /&gt;
An investigation into an accident has two main objectives: &lt;br /&gt;
&lt;br /&gt;
1. to assign blame/responsibility for the accident&lt;br /&gt;
&lt;br /&gt;
2. to prevent future accidents&lt;br /&gt;
&lt;br /&gt;
An ethical dillema may occur if, based on chain-of-event reasoning, blame is assigned to a &amp;quot;root cause&amp;quot; without taking into account for instance a situation that had become slowly unstable and anything could have set off an accident.&lt;br /&gt;
&lt;br /&gt;
==Outside Links==&lt;br /&gt;
1. [http://sunnyday.mit.edu/papers/tdsc.pdf &amp;quot;A Systems-Theoretic Approach to Safety in Software-Intensive Systems&amp;quot;] - Nancy G. Leveson&lt;br /&gt;
&lt;br /&gt;
2. [http://shemesh.larc.nasa.gov/iria03/p13-leveson.pdf Applying STAMP in Accident Analysis] - Nancy Leveson, Mirna Daouk, Nicolas Dulac, and Karen Marais&lt;br /&gt;
&lt;br /&gt;
==Relevant Class Website Links==&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/risks/safety/ http://ethics.csc.ncsu.edu/risks/safety/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1940</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1940"/>
		<updated>2007-07-28T01:46:47Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  Video conferencing and Voice Over IP ([http://en.wikipedia.org/wiki/VOIP VOIP]) has enriched and eased the process of how one communicates with another.  With that enrichment and ease comes the issue of usage and ethical interpretation.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Echelon:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Carnivore:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packet as it traverses the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology that spawned SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection (which primarily inspected the packet headers). Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links for DPI:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;br /&gt;
&lt;br /&gt;
=Resources=&lt;br /&gt;
==Relevant External Links:==&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
==Relevant Class Website Links:==&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1939</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1939"/>
		<updated>2007-07-28T01:43:33Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  Video conferencing and Voice Over IP ([http://en.wikipedia.org/wiki/VOIP VOIP]) has enriched and eased the process of how one communicates with another.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Echelon:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Carnivore:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links for DPI:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;br /&gt;
&lt;br /&gt;
=Resources=&lt;br /&gt;
==Relevant External Links:==&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
==Relevant Class Website Links:==&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1938</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1938"/>
		<updated>2007-07-28T01:38:25Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Echelon:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Carnivore:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links for DPI:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;br /&gt;
&lt;br /&gt;
=Resources=&lt;br /&gt;
==Relevant External Links:==&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
==Relevant Class Website Links:==&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1937</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1937"/>
		<updated>2007-07-28T01:36:51Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Echelon:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Carnivore:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links for DPI:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1936</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1936"/>
		<updated>2007-07-28T01:35:14Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Echelon:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links for Carnivore:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links for DPI:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1935</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1935"/>
		<updated>2007-07-28T01:33:09Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
One possible solution to the weary individual is the use of strong encryption (such as [http://en.wikipedia.org/wiki/Elliptic_Curve_Cryptography ECC] and [http://en.wikipedia.org/wiki/Advanced_Encryption_Standard Rijndael]).  To address government issues, there needs to be more control and legislation on the uses of these technology.  Although there are great potential of these technologies to preserve individual rights and freedoms, there is also great potential for abuse.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1934</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1934"/>
		<updated>2007-07-28T01:28:15Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* DPI */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but current DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1933</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1933"/>
		<updated>2007-07-28T01:26:59Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
Due to the fact that public and government are dependent upon each other, there are many issues regarding the boundaries of where one ends and begins.  At one side, the government by definition is to exist and provide laws for the masses.  Yet, not all laws are capable of defining boundaries for all citizens; as such, the best it can do is to address the majority at large (thus the democracy).  Yet on the other side, how does one define when that &amp;quot;majority at large&amp;quot; is no longer sufficient?  Additionally, it could be said that certain types of civil rights are not as important as others.  Yet, one individual may value certain &amp;quot;rights&amp;quot; more than others, thus how would one address such issues?  &lt;br /&gt;
&lt;br /&gt;
At times there are no specific boundaries, the interpretation of whether a technology is ethical is dependent upon the utilization of said technology.  Thus, the issue becomes one of not addressing the technology but how it is used (potential for good/bad).  And how it is used is dependent upon interpretation.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1932</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1932"/>
		<updated>2007-07-28T01:12:48Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  Another potential good is to inspect and if there exists some mailicious payload (like a virus) then deal with it properly before getting to the user.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.securityfocus.com/infocus/1716 Security Focus Primer on DPI]&lt;br /&gt;
* [http://www.esoft.com/pdf/White%20Paper%20-%20Migration%20to%20DPI.pdf Whitepaper by ESoft (a supplier of DPI products)]&lt;br /&gt;
* [http://www.linuxdevices.com/articles/AT8138920604.html Review of Bivio 7000, a Linux based DPI network appliancel.]&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1931</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1931"/>
		<updated>2007-07-28T01:06:11Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* DPI */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Again, the technology of DPI is not something new.  Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections with hardware that is not too cost prohibited.  For instance, some types of analysis required supercomputer number crunching capabilites, but DPI hardware only costs in the range of hundreds of thousands.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
Again the ethical issue is how the technology is used.  For instance, one could prioritize traffic to meet specific needs.  Such an example is to inspect the traffic and allocate the bandwidth to needs, such as lowering BitTorrent traffic priority to VOIP traffic during business hours.  The other side is one of potential abuse, such as the issue of Net Neutrality.  The consumer is hurt if specific traffic is steered and manipulated not based on the needs of the consumer.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1930</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1930"/>
		<updated>2007-07-28T00:58:43Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* DPI */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1. Again, the technology of DPI is not something new.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.  What makes DPI implementations dangerous is the fact that current technology allows these inspections to be done in real time on hundreds of thousands of simultaneous connections.  What makes the potential for abuse even more dangerous is that it applies to all network traffic, everything from application specific to services such as [http://en.wikipedia.org/wiki/VOIP VOIP].  Along with the potential abuse of civil rights, the issue of [http://en.wikipedia.org/wiki/Network_Neutrality Net Neutrality] comes into play.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1929</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1929"/>
		<updated>2007-07-28T00:52:29Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.  DPI spawned from the same technology as SPI (Stateful Packet Inspection), first made prominent by Check Point Software's Firewall-1. Again, the technology of DPI is not something new.  With the speed of computers increasing at such a rapid pace, it has allowed DPI to dig down from [http://en.wikipedia.org/wiki/Application_layer Layer 7] to [http://en.wikipedia.org/wiki/Data_link_layer Layer 2] and reconstruct whole transmissions; compared to the static packet inspection, which primarily inspected the packet headers. Network tools and analysis have had these types of capabilities for many years.  The only difference now is how deep the inspection is going and scale of the inspection.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1928</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1928"/>
		<updated>2007-07-28T00:41:31Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
&lt;br /&gt;
====DPI====&lt;br /&gt;
DPI (Deep Packet Inspection) is essentially an examination of the IP packets as it traversed the [http://en.wikipedia.org/wiki/OSI_model OSI] layers.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1927</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1927"/>
		<updated>2007-07-28T00:39:00Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
The Carnivore system (aka DCS1000) also became prominent during the 1990's when the FBI and other government agencies began to install the devices at major ISP locations.  Carnivore is another analysis tool that allowed the system to sniff out and analyze network traffic.  The commotion became apparent at the time primarily because of the scope of the abilities of the device in question.  At the time, there were available network sniffers and analysis tools that served the same functions as Carnivore, but not at the same scale.  Additionally, at the time most emails were sent over the network in plaintext.&lt;br /&gt;
&lt;br /&gt;
The primary issue here is again the same as Echelon; the technology by itself has no ethical value, it is the use of it.  The same argument was used for or against Carnivore.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Carnivore Carnivore - SourceWatch]&lt;br /&gt;
* [http://r-s-g.org/carnivore/ The actual program itself.]&lt;br /&gt;
* [http://www.google.com/search?q=Carnivore Google Search for Carnivore]&lt;br /&gt;
* [http://www.google.com/search?q=DCS1000 Google Search for DCS1000]&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1926</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1926"/>
		<updated>2007-07-28T00:18:36Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Some useful links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
* [http://www.google.com/search?q=echelon Google Search for Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1925</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1925"/>
		<updated>2007-07-28T00:17:33Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
* [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1924</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1924"/>
		<updated>2007-07-28T00:16:42Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] and other underground communities became aware of such surveillance systems.  It was speculated that the Echelon system was essentially an array of supercomputers designed to sniff out and analyze all forms of electronic communications with primary interest in telephone systems.  The belief was partly fueled by huge increases in government spending on buying supercomputers during the 1990s.  Due to the conflict with civilian rights, some believe the U.S. government was able to bypass the law by moving the monitoring offshore (thus no longer under U.S. privacy laws).  It should be noted that the U.S. is believed to be one of the contributers to the system.  The main Echelon installation is believed to reside in Australia.&lt;br /&gt;
&lt;br /&gt;
One of the issues is not the technology itself but how it is used.  From the standpoint of national security, it could be argued that it may intrude on some &amp;quot;rights,&amp;quot; but the benefits outweigh the costs and infringments on personal liberties.  From the individual point of view, it could be argued that it is in fact an invasion, and with that invasion, the information obtained may be used with malice.&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
     [http://www.sourcewatch.org/index.php?title=ECHELON Echelon - SourceWatch]&lt;br /&gt;
     [http://en.wikipedia.org/wiki/ECHELON Wiki of Echelon]&lt;br /&gt;
     [http://cryptome.org/echelon-60min.htm 60minute transcript 60-Minutes Transcript discussing Echelon]&lt;br /&gt;
&lt;br /&gt;
====Carnivore====&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1923</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1923"/>
		<updated>2007-07-28T00:00:49Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Echelon */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
====Echelon====&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] community became aware of such surveillance systems.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1922</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1922"/>
		<updated>2007-07-28T00:00:21Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Echelon */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
===Echelon===&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] community became aware of such surveillance systems.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1921</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1921"/>
		<updated>2007-07-27T23:59:36Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy]).  Three such cross boundary issues are the Echelon Project, Carnivore System, and DPI.&lt;br /&gt;
&lt;br /&gt;
==Echelon==&lt;br /&gt;
The Echelon Project first became prominent during the 1990's as the [http://www.google.com/search?hl=en&amp;amp;q=telephone+freaking&amp;amp;btnG=Search &amp;quot;freaking&amp;quot;] community became aware of such surveillance systems. &lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1920</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1920"/>
		<updated>2007-07-27T23:51:04Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: /* Public and Government Surveillance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
When discussing the issues of Internet surveillance, there are times when the boundaries between public and government are indistinguishable.  For instance, how does one determine the ethical &amp;quot;rightness/wrongness&amp;quot; when the issue in question is pertinent to both sides?  Some of these issues are addressed at [http://www.sourcewatch.org/index.php?title=SourceWatch SourceWatch] (a subset of the [http://www.prwatch.org/ Center for Media and Democracy].&lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1919</id>
		<title>CSC 379:Week 4, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_4,_Group_1&amp;diff=1919"/>
		<updated>2007-07-27T23:44:50Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Internet Surveillance (e.g. AT&amp;amp;T’s NSA Rooms)=&lt;br /&gt;
==The issues concerning internet surveillance==&lt;br /&gt;
Most of us are aware of government surveillance as it pertains to wiretapping to listen in on phone conversations. This type of government surveillance has had many laws developed around it and how and when it may be done. With the growth of internet traffic, similar surveillance has appeared in the realms of email, voice over IP (VOIP), and general internet traffic. The same problems that occurred years ago for the telephone communications networks have been approached for internet communications.&lt;br /&gt;
&lt;br /&gt;
The first issue that surrounds internet surveillance is how to make it possible. In order to conform to Communications Assistance for Law Enforcement Act (CALEA), phone networks had to be designed so that wiretapping was an easy thing to do if an appropriate government organization requested it. However, much internet traffic is optical instead of electrical. When electricity travels through a wire, it emits a small magnetic field. Something very close to the wire could intercept the electrical communication without affected it. Optical communication doesn't &amp;quot;leak&amp;quot; any of the light, so the communication has to be disturbed in order to intercept it. This is usually done with a splitter which diverts a percentage of the light down another path.&lt;br /&gt;
&lt;br /&gt;
The second issue is authority. Mainly, who decides whether and how much internet surveillance can take place. Should there be a different authority or amount of evidence in order to intercept foreign communications as opposed to domestic? Does the person whose information is being gathered have to be notified? Does the court have to issue a warrant for a government agency to investigate internet traffic? If so, how much information can be gathered without a warrant?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.sourcewatch.org/index.php?title=Internet_surveillance Basics of internet surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with CALEA==&lt;br /&gt;
Making it possible to intercept internet communications has several privacy issues surrounding it. A large amount of information passing through the internet is encrypted making it difficult to intercept. &amp;quot;Wiretapping&amp;quot; optical lines involves splitting which degrades the signal strength unlike typical phone line wiretapping. Because the information is essentially anonymous once it leaves the local network and enters the world wide web, is it even possible to filter out a single person's communication? If there is a backdoor for government internet surveillance capabilities, how can the typical American be assured that this backdoor is only used by the government?&lt;br /&gt;
&lt;br /&gt;
===Encryption===&lt;br /&gt;
Especially when talking about VOIP, much communication is encrypted. Even the networks serving such content cannot decrypt the content without the decryption key. The United States government has requested a backdoor to such communication in the past, but it could not be provided by the VOIP networks that supported such encryption. If these networks can allow for criminal communication without a method for the government to intercept the communication, should they be allowed to exist? Or should citizens be allowed to have a form of communication that they can be reasonably assured is completely private?&lt;br /&gt;
&lt;br /&gt;
===Splitting optical communication===&lt;br /&gt;
With electrical communications, government organizations could easily start intercepting information without affecting that communication in any way. This can not be done with optical communications. Therefore, in order to allow surveillance effectively, the intercepting of information must have already been started before it was requested. This means that average citizens of the United States will have the information intercepted (even if not recorded) regardless of whether the citizen is under suspicion. Shouldn't unsuspected people be allowed privacy of their communications?&lt;br /&gt;
&lt;br /&gt;
===Difficulty of filtering===&lt;br /&gt;
Most legal surveillance depends upon the governments right to intercept communication from or to a particular person or organization. However, in many circumstances, this is impossible without intercepting a large amount of communication between other people. Since this information is intercepted, a government agent could stumble upon private communications. The only method preventing this accidental invasion of privacy is programs that attempt to filter out only certain types of data. Since it cannot be proven that such filters will actually prevent invasion of privacy, should the government be allowed to intercept communications when they can't intercept only the suspected persons' data? What if the program could filter out all unsuspected individuals? Would it not still be an invasion of privacy for those communications to be intercepted and stored even if they are later filtered out?&lt;br /&gt;
&lt;br /&gt;
===Backdoor security===&lt;br /&gt;
Having a backdoor for internet surveillance must be extremely secure. If a government agency can use the backdoor to intercept communications when given the appropriate authority, how can we be sure that such a backdoor can't be used without appropriate authority? Especially when dealing with the NSA, citizens fear that given an inch, they will take a mile. Allowing the backdoor to exist gives them the opportunity to use it at their own discretion no matter what the legal authority says. Just as well, building a backdoor into a system that doesn't intrinsically have such a backdoor lowers the security of the entire system. It may be possible for criminals to use the backdoor created in order to combat them for their own cybercrime.&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://www.securityfocus.com/news/8394 Conforming to CALEA]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
&lt;br /&gt;
==Ethical issues with the limits of internet surveillance==&lt;br /&gt;
Internet surveillance is a very touchy issue for many people. There is a wide range of thought and laws regarding the limits to which such surveillance can go. Especially recently and due to the Patriot Act, their is an increasing difference between how much surveillance can be done on foreign communications versus domestic communications. There is a question, especially due to the NSA's recent actions to make it easier for them to intercept data, about how much data can be acquired before a warrant or other such authority is given. Along with how much data, is what type of data. Can government agencies freely collect information about where you send emails as long as they don't collect the content?&lt;br /&gt;
===Foreign and domestic communications===&lt;br /&gt;
There is a general idea that foreign communications should be closely monitored in order to prevent terrorism. However, most Americans also value their personal privacy and think that unsuspected citizens shouldn't have their everyday communications recorded and scrutinized by government officials. Therefore, there exists the Foreign Intelligence Surveillance Act (FISA) which allows a great deal of intelligence gathering for foreign communications that are not allowed for domestic law enforcement. In recent times, many citizens believe that the NSA is gathered information on internet traffic that is unrelated to international matters. Another interesting international surveillance issue deals with the Council of Europe Cybercrime Convention. This would have allowed foreign governments to request the NSA to intercept Americans. Should foreign governments be allowed to intercept internet data of Americans? Should domestic government agencies be allowed to investigate crimes through internet communications? Should the United States have different policies regarding international communications and domestic communications?&lt;br /&gt;
&lt;br /&gt;
===Requiring a warrant===&lt;br /&gt;
Naturally, requiring a warrant to intercept internet communication is desired by most Americans. However, much surveillance or alledged surveillance has occurred specifically by the NSA without such a warrant being given. Some people have pursued a [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 lawsuit] against the NSA for such information gathering. However, the lawsuit was thrown out because the people could not show that the NSA's gathering of information damaged them in any way regardless to whether the NSA had gathered the data. The EFF also [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html sued] AT&amp;amp;T for allowing the NSA to illegally gather data through the use of secret rooms. Should a warrant be required for putting the technology in place for surveillance? Or should a warrant simply be required for using such surveillance technology? If the NSA is brought to court for gathering data, shouldn't the proof needed to find the NSA guilty simply be the gathering of data without warrant rather than whether the data gathered caused any harm to the individual?&lt;br /&gt;
&lt;br /&gt;
===What types of data can be collected?===&lt;br /&gt;
During police investigations, what types of information can be gathered about an individual's internet communication before a warrant is issued? This is an especially important question because the data that can be collected without getting a warrant is the data that can be used as evidence to request a warrant. The typical idea is that meta-data about the communications can be collected whereas the content of the communication can not. This meta-data typically consists of who sent the communication, to whom the communication was sent, the time and date of the communication, and (where applicable) the length of communication. This is all information that can be gathered about email and VOIP communication without the ability to intercept the actual content of the message. Are these types of data invasion of privacy? Should such data require a warrant as well? Should such data require at least suspicion of one of communicators in a currently investigated crime?&lt;br /&gt;
&lt;br /&gt;
'''Links'''&lt;br /&gt;
* [http://www.eweek.com/article2/0,1895,1895253,00.asp ACLU against 'wiretapping' of VOIP]&lt;br /&gt;
* [http://news.com.com/2100-1030_3-6037598.html Allowing email surveillance without warrant]&lt;br /&gt;
* [http://www.commondreams.org/headlines04/0121-01.htm International law enforcement agreements]&lt;br /&gt;
* [http://blogs.abcnews.com/theblotter/2007/03/whistleblower_h.html Whistle-blowing about NSA rooms]&lt;br /&gt;
* [http://www.correntewire.com/nsa_spying_on_all_internet_traffic Full information on AT&amp;amp;T secret rooms]&lt;br /&gt;
* [http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9026379 Recent dismissal of case against NSA]&lt;br /&gt;
* [http://pressesc.com/01178899253_bill_bans_eavedropping_NSA Recent bill passed against NSA surveillance]&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF sues AT&amp;amp;T for helping NSA]&lt;br /&gt;
&lt;br /&gt;
=Prompt=&lt;br /&gt;
During the mid 1990s, one would consider himself/herself lucky to find what one was looking for though an internet search.  As internet usage has grown, better search technologies has emerged displacing many human created directory-based search engines with ones providing a vast array of dynamically-created and helpful results.  Technologies such as Google Alerts allows the tracking of yourself and others content on the internet based on keyword identifiers.  Voluntary technologies such as blogs, online photo albums, and social networking have added a wealth of information available about us online.&lt;br /&gt;
&lt;br /&gt;
AT&amp;amp;T has come under scrutiny by members of the public for allegedly constructing “NSA rooms” containing equipment that has the capability to monitor large amounts of internet traffic and are only accessible special US Government-affiliated staff members.&lt;br /&gt;
&lt;br /&gt;
'''Examine a variety of ethical concerns related to tracking of both voluntarily and non-voluntarily provided information on the internet by members of the public, employers, government, and schools.  Cite relevant laws, policies, and/or actions taken that are related to these concerns.'''&lt;br /&gt;
&lt;br /&gt;
=Public and Government Surveillance=&lt;br /&gt;
With the convenience of electronic communication via the Internet, it has become very apparent more and more services are moved over to the Internet.  For instance, it is fairly common to pay one's bills online instead of waiting for the bill and mailing a check.  The ethical issues of Internet surveillance, as with most technologies, is determined by how it is used and by whom.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
==Resources==&lt;br /&gt;
===Relevant External Links:===&lt;br /&gt;
* [http://boingboing.net/2006/01/31/eff_suing_att_for_he.html EFF suing AT&amp;amp;T for helping NSA]&lt;br /&gt;
===Relevant Class Website Links:===&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/web/ http://ethics.csc.ncsu.edu/privacy/web/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/mining/ http://ethics.csc.ncsu.edu/privacy/mining/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/surveillance/ http://ethics.csc.ncsu.edu/privacy/surveillance/]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/privacy/financial/ http://ethics.csc.ncsu.edu/privacy/financial/]&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1447</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1447"/>
		<updated>2007-07-07T01:12:50Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study provides an overview of spam countermeasures currently used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, he claims one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.  It could be argued that this is not so much a &amp;quot;system&amp;quot; as it is more of a &amp;quot;HowTo&amp;quot; implementing regular expression (like Perl) with Postfix to filter out spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt-in commercial e-mail&lt;br /&gt;
&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm FTC's CAN-SPAM Act]  The Federal Trade Commission's page providing information on the CAN-SPAM Act for businesses.  Provides an overview of the existing laws and penalties regarding spam and commercial emailers.  Although the site is a federal site, the specifics are lacking.  Specifically, under the &amp;quot;What the Law Requires,&amp;quot; the statements are very open-ended that leaves many interpretations.  For instance, &amp;quot;It prohibits deceptive subject lines,&amp;quot; is very open-ended.  How does one go about determining what is deceptive?  What sort of metric is used?  Additionally, the law specifies the use of Opt-out, but the specifics are again very open-ended.  Under the &amp;quot;Penalties&amp;quot; section, it is again very vague.  For example, &amp;quot;Relay emails through a computer or network without permission..,&amp;quot; is somewhat too broad.  How would one go about proving that someone intended to relay emails when he/she could easily say a multitude of excuses (such as &amp;quot;A virus used my computer as a relay,&amp;quot; which has been known to happen before).&lt;br /&gt;
&lt;br /&gt;
** [http://en.wikipedia.org/wiki/Email_marketing Wikipedia on E-mail Marketing]  Provides an overview of E-mail marketing.  What the advantages and disadvantages of email marketing.  The CAN-SPAM Act of 2003 that authorizes a $11,000 penalty for each spam violation to each spam recipient.  To help with compliance, several third-party companies are available to help with email marketing compliance.  Wiki also provides an overview of Opt-in advertising.  For those interested in knowing some of the spam jargon, the Wiki does provide a [http://en.wikipedia.org/wiki/Email_marketing#Terms glossary of terms].&lt;br /&gt;
&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html The European Coalition Against Unsolicited Commercial Email]  The EuroCAUCE is a group of users (ranging from end-users to corporations) trying to find a solution to the spam problem.  Their solution is for an Opt-in list.  They provide the risks/benefit discussion of Opt-In vs Opt-Out.  Additionally, their is [http://www.euro.cauce.org/en/links.html link to resources] that may be helpful to those who are tired of spam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1445</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1445"/>
		<updated>2007-07-07T01:09:04Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study does not directly deal with top-level blocking, but only indirectly.  This study provides an overview of spam countermeasures used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt-in commercial e-mail&lt;br /&gt;
&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm FTC's CAN-SPAM Act]  The Federal Trade Commission's page providing information on the CAN-SPAM Act for businesses.  Provides an overview of the existing laws and penalties regarding spam and commercial emailers.  Although the site is a federal site, the specifics are lacking.  Specifically, under the &amp;quot;What the Law Requires,&amp;quot; the statements are very open-ended that leaves many interpretations.  For instance, &amp;quot;It prohibits deceptive subject lines,&amp;quot; is very open-ended.  How does one go about determining what is deceptive?  What sort of metric is used?  Additionally, the law specifies the use of Opt-out, but the specifics are again very open-ended.  Under the &amp;quot;Penalties&amp;quot; section, it is again very vague.  For example, &amp;quot;Relay emails through a computer or network without permission..,&amp;quot; is somewhat too broad.  How would one go about proving that someone intended to relay emails when he/she could easily say a multitude of excuses (such as &amp;quot;A virus used my computer as a relay,&amp;quot; which has been known to happen before).&lt;br /&gt;
&lt;br /&gt;
** [http://en.wikipedia.org/wiki/Email_marketing Wikipedia on E-mail Marketing]  Provides an overview of E-mail marketing.  What the advantages and disadvantages of email marketing.  The CAN-SPAM Act of 2003 that authorizes a $11,000 penalty for each spam violation to each spam recipient.  To help with compliance, several third-party companies are available to help with email marketing compliance.  Wiki also provides an overview of Opt-in advertising.  For those interested in knowing some of the spam jargon, the Wiki does provide a [http://en.wikipedia.org/wiki/Email_marketing#Terms glossary of terms].&lt;br /&gt;
&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html The European Coalition Against Unsolicited Commercial Email]  The EuroCAUCE is a group of users (ranging from end-users to corporations) trying to find a solution to the spam problem.  Their solution is for an Opt-in list.  They provide the risks/benefit discussion of Opt-In vs Opt-Out.  Additionally, their is [http://www.euro.cauce.org/en/links.html link to resources] that may be helpful to those who are tired of spam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1441</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1441"/>
		<updated>2007-07-07T01:05:36Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study does not directly deal with top-level blocking, but only indirectly.  This study provides an overview of spam countermeasures used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt-in commercial e-mail&lt;br /&gt;
&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm FTC's CAN-SPAM Act]  The Federal Trade Commission's page providing information on the CAN-SPAM Act for businesses.  Provides an overview of the existing laws and penalties regarding spam and commercial emailers.  Although the site is a federal site, the specifics are lacking.  Specifically, under the &amp;quot;What the Law Requires,&amp;quot; the statements are very open-ended that leaves many interpretations.  For instance, &amp;quot;It prohibits deceptive subject lines,&amp;quot; is very open-ended.  How does one go about determining what is deceptive?  What sort of metric is used?  Additionally, the law specifies the use of Opt-out, but the specifics are again very open-ended.  Under the &amp;quot;Penalties&amp;quot; section, it is again very vague.  For example, &amp;quot;Relay emails through a computer or network without permission..,&amp;quot; is somewhat too broad.  How would one go about proving that someone intended to relay emails when he/she could easily say a multitude of excuses (such as &amp;quot;A virus used my computer as a relay,&amp;quot; which has been known to happen before).&lt;br /&gt;
&lt;br /&gt;
** [http://en.wikipedia.org/wiki/Email_marketing Wikipedia on E-mail Marketing]  Provides an overview of E-mail marketing.  What the advantages and disadvantages of email marketing.  The CAN-SPAM Act of 2003 that authorizes a $11,000 penalty for each spam violation to each spam recipient.  To help with compliance, several third-party companies are available to help with email marketing compliance.  Wiki also provides an overview of Opt-in advertising.  For those interested in knowing some of the spam jargon, the Wiki does provide a [http://en.wikipedia.org/wiki/Email_marketing#Terms glossary of terms].&lt;br /&gt;
&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html The European Coalition Against Unsolicited Commercial Email]  A group of users (ranging from end-users to corporations) trying to find a solution to the spam problem.  Their solution is for an Opt-in list.  They provide the risks/benefit discussion of Opt-In vs Opt-Out.  Additionally, their is [http://www.euro.cauce.org/en/links.html link to resources] that may be helpful to those who are tired of spam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1439</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1439"/>
		<updated>2007-07-07T00:56:03Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study does not directly deal with top-level blocking, but only indirectly.  This study provides an overview of spam countermeasures used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt in commercial e-mail&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm FTC's CAN-SPAM Act]  The Federal Trade Commission's page providing information on the CAN-SPAM Act for businesses.  Provides an overview of the existing laws and penalties regarding spam and commercial emailers.  Although the site is a federal site, the specifics are lacking.  Specifically, under the &amp;quot;What the Law Requires,&amp;quot; the statements are very open-ended that leaves many interpretations.  For instance, &amp;quot;It prohibits deceptive subject lines,&amp;quot; is very open-ended.  How does one go about determining what is deceptive?  What sort of metric is used?  Additionally, the law specifies the use of Opt-out, but the specifics are again very open-ended.  Under the &amp;quot;Penalties&amp;quot; section, it is again very vague.  For example, &amp;quot;Relay emails through a computer or network without permission..,&amp;quot; is somewhat too broad.  How would one go about proving that someone intended to relay emails when he/she could easily say a multitude of excuses (such as &amp;quot;A virus used my computer as a relay,&amp;quot; which has been known to happen before).&lt;br /&gt;
&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html The European Coalition Against Unsolicited Commercial Email]  A group of users (ranging from end-users to corporations) trying to find a solution to the spam problem.  Their solution is for an Opt-in list.  They provide the risks/benefit discussion of Opt-In vs Opt-Out.  Additionally, their is [http://www.euro.cauce.org/en/links.html link to resources] that may be helpful to those who are tired of spam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1436</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1436"/>
		<updated>2007-07-07T00:42:55Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study does not directly deal with top-level blocking, but only indirectly.  This study provides an overview of spam countermeasures used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt in commercial e-mail&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm The CAN-SPAM Act] US Federal laws/regulation for Opt-In Opt-Out for businesses.&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html The European Coalition Against Unsolicited Commercial Email]  A group of users (ranging from end-users to corporations) trying to find a solution to the spam problem.  Their solution is for an Opt-in list.  They provide the risks/benefit discussion of Opt-In vs Opt-Out.  Additionally, their is [http://www.euro.cauce.org/en/links.html link to resources] that may be helpful to those who are tired of spam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1435</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1435"/>
		<updated>2007-07-07T00:32:49Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Slashdot discussion of top-level domain]  Although the link is a public forum, the readers and participants of slashdot tend to be those more familiar with computer systems.  As such, many interesting perspectives are voiced, from email server administrators to the &amp;quot;power user.&amp;quot;  The discussion in this particular slashdot article does not resolve the issue at hand, it does however provide a better understanding of the current situation regarding spam.&lt;br /&gt;
&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html The Selective SMTP Rejection (S25R) System] This study does not directly deal with top-level blocking, but only indirectly.  This study provides an overview of spam countermeasures used and their success rates.  The author then presents his methodology of countermeasure using a system of filters based on regular expression and Postfix to a claimed &amp;quot;99% Block Rate&amp;quot; of spam.  Under the S25R System, one could filter something as specific as a single reverse lookup or IP address to something as broad as a top-level domain.&lt;br /&gt;
&lt;br /&gt;
** [http://www.msexchange.org/tutorials/MF014.html HowTo: Block Incoming Mail Using MS Exchange 2000]  This HowTo shows how to use the built-in filters of Microsoft Exchange 2000 to block unwanted senders.  Senders can be blocked on a single basis or with the use of wild cards, block domains.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** It is believed that charging people for every e-mail sent would virtually eliminate spam all together. E-mail would become much like the postal service in which a fee is charge for every message sent, like a stamp. The idea being that bulk e-mails would be no more economical than direct mail and would eliminate e-mail as a free form of advertising. Charging to send messages makes the costs far too high for spammers to make any profit. Many people feel however that this goes against the libertarian ideas and freedom the internet was based on. Ultimately it could be a burden to ordinary citizens and companies who rely on e-mail in every day life.&lt;br /&gt;
*** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Is it Time to Charge for E-mail?]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt in commercial e-mail&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm The CAN-SPAM Act] US Federal laws/regulation for Opt-In Opt-Out for businesses.&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html European Coalition Against Unsolicited Commercial Email]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** The Federal Trade Commission has recently proposed offering a cash bounty to any citizen who helps to arrest spammers. Under the proposal the first citizen to come forward with information leading to the arrest of a spammer will receive no less than 20% of the civil penalty the FTC would eventually collect from spammers arrested due to that information. The idea is that it would be more effective if the average citizen spent the same amount of time searching for and reporting spammers as they did preventing and deleting the spam messages themselves. This would stop the problem at the root.&lt;br /&gt;
** The main problem with this idea is if the FTC, FBI, and ISPs can’t find and prosecute spammers how are ordinary citizens supposed to do any better. Ordinary citizens are very unlikely to catch spammers. Rather than prosecuting spammers who abuse the internet it is believed so called “bounty hunters” are more likely to attack legitimate companies guilty of some minor, unintentional breach of the complicated CAN-SPAM Act. Putting justice in the hands of the people like this could lead to an error of internet vigilantism.&lt;br /&gt;
*** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Spam Bounties]&lt;br /&gt;
*** [http://www.msnbc.msn.com/id/5326107/%20 FTC Mulls Bounty System to Combat Spammers]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** With the “Goodmail” approach ISPs would sell an electronic postage stamp to companies wishing to send out bulk e-mails to their customers. This stamp guarantees companies that their e-mail will bypass all of an e-mail’s spam filters and go straight to the main mailbox as a certified message that is legitimate and safe for the reader to open. This would help people distinguish between legitimate and fraudulent e-mail by guaranteeing who the e-mail is from and that it is not a scam or virus. Also it would reduce spam by forcing companies to only contact customers likely to respond to a message in order to keep the cost of mass e-mailing down. “Goodmail” makes it unprofitable for spammers to send out bulk e-mail to which few people respond.&lt;br /&gt;
** While “Goodmail” is intended to reduce bulk e-mail and provide security from phishing and scams many people feel it is just a new revenue source for ISPs and not a valid way of fighting spam. It is possible that too many marketers will be willing to pay to have their e-mails certified, resulting in large numbers of advertisements guaranteed to bypass your spam filters and go straight to your inbox. “Goodmail” is unfair to small business and non-profit organizations who can’t afford to pay for their bulk e-mails.  Also “Goodmail” could cause users to view all e-mail that is not certified as unsafe. This could cause users to skip over requested e-mails because they are not certified.  &lt;br /&gt;
*** [http://www.pcworld.com/article/id,124762-page,1/article.html Spam Slayer]&lt;br /&gt;
*** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Postage is Due for Companies Sending E-mail]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1396</id>
		<title>CSC 379:Week 1, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379:Week_1,_Group_1&amp;diff=1396"/>
		<updated>2007-07-05T23:31:09Z</updated>

		<summary type="html">&lt;p&gt;Ntnguyen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Techniques against spam&lt;br /&gt;
&lt;br /&gt;
* Block domains or possibly top-level domans &amp;quot;known&amp;quot; to be large senders of spam.&lt;br /&gt;
** [http://en.allexperts.com/q/Microsoft-Exchange-2094/block-Top-Level-Domains.htm How to block top level domains in MS Exchange] Forum showing systems administrators how to block top-level domains in Microsoft Exchange Server.&lt;br /&gt;
** [http://yro.slashdot.org/article.pl?sid=07/01/07/2316225&amp;amp;from=rss Use of certain top-level domains] Internet n3rd5/0v3rL0rd5 of /. discussion of some interesting top level-domains.&lt;br /&gt;
** [http://www.gabacho-net.jp/en/anti-spam/anti-spam-system.html Effectiveness of top-level domain blocking] A study reporting on the effectiveness of top-level domain blocking.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Require users to request permission to send you e-mail (i.e. Earthlink spam blocker)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Charge for e-mail sent&lt;br /&gt;
** [http://opinion.zdnet.co.uk/comment/0,1000002138,39145632,00.htm Article_rename_and_comment_me_please]  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Opt in commercial e-mail&lt;br /&gt;
** [http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm The CAN-SPAM Act] US Federal laws/regulation for Opt-In Opt-Out for businesses.&lt;br /&gt;
** [http://www.euro.cauce.org/en/index.html European Coalition Against Unsolicited Commercial Email]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Doman authentication&lt;br /&gt;
** [http://www.cnn.com/2003/TECH/internet/12/05/spam.yahoo.reut/index.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://news.zdnet.co.uk/security/0,1000000189,39228023,00.htm Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
* Bounties&lt;br /&gt;
** [http://www.econtentmag.com/Articles/ArticleReader.aspx?CategoryID=3&amp;amp;ArticleID=7616 Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://www.msnbc.msn.com/id/5326107/%20 Article2_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Goodmail&amp;quot; approach&lt;br /&gt;
** [http://www.pcworld.com/article/id,124762-page,1/article.html Article1_rename_and_comment_me_please]&lt;br /&gt;
** [http://www.nytimes.com/2006/02/05/technology/05AOL.html?pagewanted=1&amp;amp;ei=5090&amp;amp;en=6efb03c8cbfac79e&amp;amp;ex=1296795600 Article1_rename_and_comment_me_please]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bonds with escrow agencies&lt;/div&gt;</summary>
		<author><name>Ntnguyen</name></author>
	</entry>
</feed>