European tech leaders reject calls for ISP vigilance as 'scaremongering'

By Sharon Fisher | Published July 2, 2008, 6:45 PM

European ISP organizations are concerned that the cost of implementing proposals intended to reduce cybercrime could put them out of business, but a leading security vendor said the cost of not doing anything could be even higher.

As we reported yesterday, a report for the European Parliament suggests that ISPs pool together to conduct pro-active measures against systems that maliciously impact IP traffic, and that ISPs be held responsible if they fail to do so. That proposal garnered comments from European organizations and from states' government representatives.

Generally, the written comments -- 15 of them from a wide variety of European countries, most of whom wrote individual responses rather than using the response form provided -- were supportive of the proposals, but were concerned about some of them. In particular, the ISP organizations are concerned about a proposal that Internet exchange points, or connections between two ISPs, be more closely regulated.

A number of them seemed to take offense at the recommendations, citing their many years of robust operation. "We do not believe that scaremongering about network resilience is a helpful activity," seethed Euro-IX, the European association for the operators of IXPs.

ISP organizations also expressed concern about the practical business realities of implementing some of the suggestions, particularly ones that could affect a commercial business' confidentiality. "To define [security standards for network-connected computers] should not be difficult, but to implement and enforce them could be a nightmare," responded the Ministry of Foreign Affairs in Poland.

"[A]t any one time there are millions upon millions of compromised hosts on the Internet," the Malta Communications Authority chimed in. "Establishing real-time monitoring mechanisms to monitor this huge number of hosts is a real challenge."

In addition, a special interest group made up of 28 vendors expressed concern that vendors had not been consulted. "We believe that imposing further liability on vendors will have a stifling effect on the industry," FIRST Vendor SIG said. "This effect would be especially devastating to open source vendors and small vendors in general."

Other suggestions from a number of ISP organizations included more incentives and fewer penalties.

But ISPs may not have a choice, said John Maddison, vice president of core technology solutions for Trend Micro, in Cupertino, Calif. ISPs need to become both more proactive and more reactive now, he said, particularly as bandwidth increases. "Once you have that bandwidth, botnets can cause some pretty substantial damage," he told BetaNews. "More bandwidth is like providing more powerful guns to the bad guys."

Part of the problem is that users cannot be counted on to implement security patches and programs correctly, Maddison acknowledged. And while some of that could be done remotely by the ISP, that gets into privacy issues. Instead, he suggested that ISPs should look for ways to implement them on the ISP network itself rather than on the endpoints.

Comments

Smacks of censorship to me!

Score: 0

|

What the hell is the European Parliament? Gotta stop writing though. smiletrain.org is putting me off.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET