Encryption Could Starve Carnivore
Developers make server-level technology that could hamper law enforcement's e-mail surveillance.
Sean Captain, PCWorld.com
Even as the FBI slowly releases details of its Carnivore e-mail wiretap technology, software developers are readying schemes to starve Carnivore of meaningful data.
ChainMail and Sigaba are among the companies promoting encryption technology designed to render any captured e-mail meaningless to third parties. Meanwhile, developers like Privada and Zero-Knowledge offer anonymity to both sender and recipient, so a third party has no idea whose e-mail it is reading. In most cases, you need to rely on your Internet service provider to implement this level of technology, which keeps private your e-mail--right down to its address.
Digital Bloodhound
Carnivore, so named for its capability to "get at the meat" of electronic communications, is a Windows-based "packet-sniffer" program that also runs on an ISP's systems. The FBI uses it to pick out e-mail communications from a party that is under investigation.
Carnivore is the online equivalent of a telephone wiretap, but its capability to snoop is much more pervasive, according to Stephen Satchell, a consultant on Internet performance and security issues. Because no discrete "e-mail line" corresponds to individuals on the Internet, Carnivore actually scans every data packet from every party that uses the ISP. Privacy advocates are concerned that law enforcement could easily abuse this system to spy on people who are not covered by the warrant. (See "ACLU Challenges FBI E-Mail Taps.")
The FBI claims that Carnivore looks only at address information on e-mail, not its content, until it finds correspondence from the party under investigation. Then, Carnivore copies the whole message. But critics doubt that Carnivore ignores content entirely.
"The only reason they could not look at content is because they chose not to look at content, not because they can't," says Richard Bliss, a Sigaba spokesperson.
ISPs Wary of Sharing Servers
Some ISPs seem to have similar regard for both the FBI and encryption vendors. America Online, for example, lets no one near its servers without a court warrant, according to Nicholas Graham, AOL spokesperson.
The FBI has not approached AOL about using Carnivore on its network. But if it did, "Carnivore would not be allowed on our system and would be against our goal and mission of protecting our members' privacy," Graham says. That policy similarly prohibits use of server-based encryption programs. Graham says AOL has not decided whether to offer its own encryption solution to members.
EarthLink, takes a similar position, and has spurned advances of at least one encryption vendor, says Steve Dougherty, director of technology acquisition. Customers may use their own encryption or anonymity scheme, but he does not expect EarthLink will provide such services.
Subscribers don't seem interested, Dougherty adds, but that could change. "This is so new, it's too early to tell what anyone will be doing," he says.
That's what the software developers are banking on as they prepare their server-level tools to thwart Carnivore.
- Page 1 of 3
- Next ยป
Laptop Showcase
The Best of PC World
Featured APC Accessories
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2010 - 3 UsersPrice: $27.90
Norton 360 Version 3Price: $38.98
Norton Internet Security 2010 - 3 UserPrice: $27.90
Internet Security 2010Price: $24.95
Internet Security 2010Price: $33.54
Internet Security 2009Price: $15.99
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage








