Security Basics mailing list archives

Re: chat logs


From: Zaven <zaven () sonic net>
Date: Fri, 13 May 2005 14:00:50 -0700

Keller, Tim wrote:
The one thing you've got going for you is all of these protocols are
unencrypted.

I'm not going to get into the details because this email would get a little
long, but this is how I'd do it.

I'd take a port on the router and configure it to mirror all the traffic to
this port.  I'd then take a Linux box plug it into said port, install snort
and configure it to trap all AIM/MSN/Yahoo/email/IRC and record all URL's
that are accessed.


I think she was talking about parents doing this kind of thing, at will, in their own homes. Spying on all chat communication seems, to me, to be a drastic invasion of privacy. School children are people too, and I certainly hope all the officials involved will respect their privacy to the greatest possible extent.

Consider that kids use IM a lot these days, and for many it is probably one of their main forms of communication with friends.

I think the police would rarely if ever be granted the authority to capture and monitor ALL chat/email/whatever traffic just in hopes of finding a single "suspicious" comment.

In any case, if this setup was implemented, say on the school network, who would be entrusted to snoop through every child's conversations? How much time would this take? What is the policy if something unrelated is found that the authorities think is a problem? What are the legal implications for the school district?

Zaven


Current thread: