mir wroteThe good point in what you said is that you mentioned official complaints.. stuff signed from notary.. request from police !
I think anyone serious about doing illegal stuff, would at least have encryption on
I think scanning the traffic is like listening to all the ppls phone calls on ur network
Do you need papers or reasons to do a preventive scanning ?
i think the amount of data would be huge.. i am sure u ain't gonna read it all :P
i am just curious.. what kind of software is used to analyze the output
I think ISPs .. specially in the future will have more power and control .. it will be like power and Key companies in the country
and i think there are some privacy issues in here that can be discussed.. but i am not going off-topic
cuz that is completely another discussion !
mir - i will search for pattern specified by complainer. Let's say he will say customer share "XXyo_porno.jpg" or shell code patterns, there is tools to catch this.
So i will not see all customer traffic, but ISP have right to scan it for highly illegal content by software in case of complaint, which will not store his traffic, in case he didn't match suspicious patterns.
And for example, telephone compaines before was listening to phone call, if it is not dropped long time, to check - maybe customer forgot to close phone or it is his phone malfunction. My idea, that ISP can make pattern based software to catch illegal activity, like snort software, if for example in customer bandwidth appear too much phrases "(kid|child)\s*(sex|porno)", which will give him alert on such activity, and possible store traffic for this period. Also ISP have right to store always customer information like: HTTP access.logs (URL's), netflow/sflow data, and sure connect/disconnect time and traffic. Thats it, nothing more.
About encryption... well, even criminals doing mistakes. And if he run encryption, he will have some end-point host. This means complainer will call end-point host or he can ask me, that if customer connected to this end-point, but i wouldn't answer, if he dont run anything suspicious and i cannot catch "illegal" patterns. I will answer on such case ONLY to government officials and ONLY when i will have official paper.
But preventive scanning MUST happen, if there is complaint. If it is case of selling drugs, illegal pornography and etc - maybe it will save someone life or future. Each of us cannot judge someone on street and hang him, if just people talk - he is selling drugs. But if someone tell you, your neighbour abusing child, and you will not knock in his door, when abuser tell it happen, to see if it is like this? And you will not prevent him to do this again? Police is slow sometimes, and people must help one each other sometimes in such cases.
If it was fake complaint, this can be case for police too, maybe... not sure, i have to ask lawyers.