US government, Net firms fail to agree on data retention

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

A meeting at the US Justice Department last week to discuss forcing Internet providers to record Americans' online activities ended without reaching an agreement, according to multiple participants.

The meeting of about 15 industry representatives and 10 government officials followed an earlier one the week before, first reported by ZDNet UK sister site CNET News.com, at which Attorney General Alberto Gonzales and FBI Director Robert Mueller pressed Internet and telecommunications companies to store data on their users for two years.

"They want to do something, but they don't have a proposal yet," said one industry representative. The participants in the two-hour meeting spoke to News.com afterward on condition of anonymity because of the sensitive nature of the negotiations. (Participants included AOL, Comcast, Google, Microsoft, Verizon Communications and trade associations.)

Another participant said it appeared that the Justice Department wanted to require Internet providers to at least record their customers' Internet Protocol addresses, which are often temporarily assigned and the logs deleted after a few months during the routine course of business. It wasn't clear whether the requirement also would apply to Web sites such as search engines, which could be forced to record what keywords their users typed in for future investigations.

In general, Internet and telecommunications companies have been less than enthusiastic about mandatory data retention, a concept that the European Union has embraced and that is the subject of a legal challenge there. They cite security concerns, privacy worries, and, of course, the cost of creating or extending databases.

"They have to make sure they do this right, and it doesn't look like they're going about this the right way," said Dave McClure, president of the US Internet Industry Association, which represents small to medium-sized companies.

McClure, who could not attend Friday's meeting because he was traveling, said: "You have to figure out what information you want, specifically, how to format it so it's useful, how to pay for it, and how to get it past all the privacy people in Congress. I have difficulty understanding why they're flailing about with all these meetings rather than going through that procedure."

One participant at the meeting said the Justice Department and FBI officials who were present talked about having piles of old cases and being able to go back and find out who somebody was and what that person did on a certain date.

No date for a follow-up meeting has yet been set. One participant said this was likely to be a long-term process that would not likely be resolved anytime soon.

In a speech last month at the National Center for Missing and Exploited Children, Gonzales called on Internet providers to retain records to aid investigations of criminals "abusing kids and sending images of the abuse around the world through the Internet". More recently, the Justice Department has invoked terrorism as the justification for data retention.

Two proposals to mandate data retention have surfaced in the US Congress. One, backed by Representative Diana DeGette, a Colorado Democrat, says that any Internet service that "enables users to access content" must permanently retain records that would permit police to identify each user. The records could only be discarded at least one year after the user's account was closed.

'Preservation' vs. 'retention'
The other was drafted by aides to Wisconsin Representative F. James Sensenbrenner, the chairman of the House Judiciary Committee and a close ally of President Bush. Sensenbrenner said through a spokesman last month, though, that his proposal is on hold because "our committee's agenda is tremendously overcrowded already".

At the moment, Internet service providers typically discard any log file that's no longer required for business reasons such as network monitoring, fraud prevention or billing disputes. Companies do, however, alter that general rule when contacted by police performing an investigation — a practice called data preservation.

A 1996 federal law called the Electronic Communication Transactional Records Act regulates data preservation. It requires Internet providers to retain any "record" in their possession for 90 days "upon the request of a governmental entity".

Because Internet addresses remain a relatively scarce commodity, ISPs tend to allocate them to customers from a pool based on whether a computer is in use at the time. (Two standard techniques used are the Dynamic Host Configuration Protocol and Point-to-Point Protocol over Ethernet.)

In addition, Internet providers are required by another federal law to report child pornography sightings to the National Center for Missing and Exploited Children, which is in turn charged with forwarding that report to the appropriate police agency.

When adopting its data retention rules, the European Parliament approved UK-backed requirements saying that communications providers in its 25 member countries — several of which had enacted their own data retention laws already — must retain customer data for a minimum of six months and a maximum of two years.

The Europe-wide requirement applies to a wide variety of "traffic" and "location" data, including the identities of the customers' correspondents; the date, time and duration of phone calls, voice over Internet Protocol calls, or email messages; and the location of the device used for the communications. But the "content" of the communications is not supposed to be retained. The rules are expected to take effect in 2008.

Also on Friday, the Center for Democracy and Technology — a civil liberties group in Washington that receives some money from corporations — released a four-page analysis critiquing data retention proposals (click for PDF).

It lists nine reasons why keeping track of Internet users' activities is a bad idea, including: "Data retention laws threaten personal privacy and pose a security risk, at the very time the public is justifiably concerned about security and privacy online."

Talkback

Oh dear! The delicate balance of security vs personal freedoms and liberty....

via Facebook 5 June, 2006 14:52
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 hour ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

3 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

3 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

5 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

7 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

8 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

9 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

10 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

12 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

17 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

20 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

21 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

22 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

23 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

23 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

23 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

24 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?