Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • D.N.J.: Strip search must be on reasonable suspicion
  • Virgin Mobile USA reps refuse to take a simple step to help block SMS SPAM for its wireless customers
  • Bradbury (Head of DoJ's Office of Legal Counsel/OLC) Memos on enhanced interrogation methods: Not Quite Ready to Release
  • Bloggers Respond to WSJ's NSA Surveillance Article
  • Melanie Ann Pustay Appointed to Director of the Office of Information and Privacy - April 2007
  • Secret Crush Facebook App Installing Adware, Security Firm Charges
  • Spy Chief Admits Telcos Collaborated With NSA Spying

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Why IP addresses are no longer enough to identify internet users

Submitted by MacRonin on January 12, 2010 - 2:01pm
  • Anonymity
  • Court
  • Europe
  • Hmmm
  • ID
  • Infrastructure
  • Ireland
  • Privacy
  • Remember
  • Security

Why IP addresses are no longer enough to identify internet users: Via IT Law in Ireland.

Richard Clayton has an excellent post explaining (in terms even a lawyer can understand) why the traditional formula of IP address plus timestamp is increasingly inadequate as a way of identifying internet users:

The basics are that you record an IP address and a timestamp; use the Regional Internet Registry records (RIPE, ARIN etc) to determine which ISP has been allocated the IP address; and then ask the ISP to use their internal records to determine which customer account was allocated the IP address at the relevant instant. All very simple in concept, but hung about — as the thesis explained — by considerable caveats as to whether the simple assumptions involved are actually true in a particular case.

One of the caveats concerned the use of Network Address Translation (NAT), whereby the IP addresses used by internal machines are mapped back and forth to external IP addresses that are visible on the global Internet. The most familiar NAT arrangement is that used by a great many home broadband users, who have one externally facing IP address, yet run multiple machines within the household.

Companies also use NAT. If they own sufficient IP addresses they may map one-to-one between internal and external addresses (usually for security reasons), or they may only have 4 or 8 external IP addresses, and will use some or all of them in parallel for dozens of internal machines.

Where NAT is in use, as my thesis explained, traceability becomes problematic because it is rare for the NAT equipment to generate logs to record the internal/external mapping, and even rarer for those logs to be preserved for any length of time. Without these logs, it is impossible to work out which internal user was responsible for the event being traced. However, in practice, all is not lost because law enforcement is usually able to use other clues to tell them which member of the household, or which employee, they wish to interview first.

Treating NAT with this degree of equanimity is no longer possible, and that’s because of the way in which the mobile telephone companies are providing Internet access.

The shortage of IPv4 addresses has meant that the mobile telcos have not been able to obtain huge blocks of address space to dish out one IP address per connected customer — the way in which ISPs have always worked. Instead, they are using relatively small address blocks and a NAT system, so that the same IP address is being simultaneously used by a large number of customers; often hundreds at a time.

This means that the only way in which they can offer a traceability service is if they are provided with an IP address and a timestamp AND ALSO with the TCP (or UDP) source port number. Without that source port value, the mobile firm can only narrow down the account being used to the extent that it must be one out of several hundred — and since those several hundred will have nothing in common, apart from their choice of phone company, law enforcement (or anyone else who cares) will be unable to go much further.

Read Original Article:(Via IT Law in Ireland.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • EFF to Urge True Transparency in Congressional Hearing Thursday
  • Investigators: Businesses buying your credit card number
  • Global Internet Freedom and the U.S. Government
  • The dark side of DNA
  • EFF Experts to Speak at Privacy Roundtable in Washington, D.C.
  • Telling Friends Where You Are (or Not) - NYT
  • To Stop Crime, Share Your Genes - NYTimes.com ( Op-Ed Contributor )
  • FBI Hoaxes Boost Online Fraud
  • NetFlix Cancels Recommendation Contest After Privacy Lawsuit
  • Advertising - Instant Ads Set the Pace on the Web
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.