you are viewing a single comment's thread
view the rest of the comments
[–] 74 points 5 months ago (4 children)

This tells me any equipment that is classified as acceptable by these requirements is immediately suspect, and should not be permitted to connect to, or communicate with, equipment you need to trust.

  • source
  • hideshow 4 child comments
  • [–] 35 points 5 months ago (3 children)
  • [–] 13 points 5 months ago (2 children)

    I’m well versed in the CALEA capabilities of DOCSIS equipment, hence my comment.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 5 months ago (1 child)

    How do you have internet without a DOCSIS modem? Is this a problem of where I live that the only option requires it? Or do you just have a strong firewall between it and the rest of your network (assumably on the router)?

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 5 months ago

    The CALEA functions aren’t in the modem, they’re in the CMTS, the router the modems talk to/through at the head end. I’d expect similar demarcation with other access technologies, but they’re not my area.

    I see this new requirement as an attempt, at least partially, to bring CPE (Customer Premises Equipment) into CALEA scope.

    My take is they’ve made the network a more hostile environment, and elevated the need and justification to build a more resilient overlay layer of encrypted and obfuscated channels.

    HTTPS, QUIC, DoT/DoH and such have been piecemeal attempts which make sense over a neutral network. An actively hostile environment needs to be treated as a dumb pipe, preferably one of many diverse paths.

  • source
  • parent