The Register Home Page

back to article Traffic to government domains often crosses national borders, or flows through risky bottlenecks

Internet traffic to government domains often flows across borders, relies on a worryingly small number of network connections, or does not require encryption, according to new research. PhD student Rashna Kumar reached the conclusions above after mapping paths for traffic to government websites in 58 countries, research …

  1. Anonymous Coward
    Anonymous Coward

    So what about borders

    "Internet traffic to government domains often flows across borders"

    So what? If there is appropriate security it shouldn't matter. People travel. I assume we're worrying about individual personal information not intra government traffic? If an individual wants to use a government website from overseas it should be allowed. 86% of Albanian traffic tells a story in itself. Probably from London.

    1. katrinab Silver badge
      Boffin

      Re: So what about borders

      The study was about whether if, you are in a particular country, and visit that country's government website, your internet traffic will remain within the country, or go to another country at some point along the way.

      1. FirstTangoInParis Silver badge

        Re: So what about borders

        > The study was about whether if, you are in a particular country, and visit that country's government website, your internet traffic will remain within the country, or go to another country at some point along the way.

        Exactly. So if you’re accessing your own country’s gov services and the traffic routes through $neighbour-country, and there’s no https, that’s a problem as it opens up MiTM attack potential. Organised crime and oligarchs will be all over that.

        1. Anonymous Coward
          Anonymous Coward

          Re: So what about borders

          Yes but the fix is not to restrict which countries you can access from! It's to provide **appropriate** security wherever. To allow citizen's to travel and still conduct personal business. There are criminals in every country and it is not hard for them to use a proxy in this country. To restrict use from outside is dumb as. If they are talking about sensitive government traffic be that national security or batched personal data I sincerely hope they haven't been lax in securing it. They used to have approved government encryptors and architectures, is that no longer the case?

          1. AndrueC Silver badge
            Stop

            Re: So what about borders

            Yes but the fix is not to restrict which countries you can access from!!

            You're still missing the point of the article. It isn't about accessing government services from outside the country. It's not about where you travel to. It's saying that data isn't staying within a country even when both end points are. Someone sat at home communicating with their government's website might be sending/receiving data via a different country.

      2. Tron Silver badge

        Re: So what about borders

        The study was all about nudging our internet to a system that is stuck within its borders, unless foreign websites are licensed by your government, and ending the open nature of the internet.

        There are plenty of government funded scientists out there working on ways of keeping data inside a nation and keeping foreign-origin data out of it.

        That is what they will move us to, to protect national security and the children etc etc. It is a progressive war on the global internet to allow governments to take back control of their digital borders.

        Try reading between the lines once in a while. Our glorious leaders hate it that the internet empowers us, and they want that power vested back with them, Chinese style.

        And no, it shouldn't matter where your data goes if it is encrypted. But govts want to get rid of secure encryption too, don't they.

        1. Anonymous Coward
          Anonymous Coward

          Re: So what about borders

          100% correct.

          The government needs to do its job which is serving the people. We were once a democracy.

  2. xyz Silver badge

    It's called the internet

    I think that's how it's supposed to work.

    1. David Harper 1

      Re: It's called the internet

      According to the NSA, anyway.

    2. Pascal Monett Silver badge

      Re: It's called the internet

      In the absolute, you're right.

      Unfortunately, some organizations (NSA) and some countries (USA, China among others) do everything they can to hoover up every bit of data they can get their hands on, whether or not they have a court order authorizing them to do so.

      So it is becoming useful, if not imperative, to control where the data flows in you own country.

      1. Anonymous Coward
        Anonymous Coward

        Re: It's called the internet

        No, it is becoming imprerative to secure the data but not by restricting where it flows unless you want to censor the people and stop access outside the country. If the government had its way we would be locked down like the old Soviet Union and China after the Cultural Revolution. Our government is not pursuing our best interests, they are pursuing theirs with their bureaucratic & meglomaniac mindset. There is a reason the Americans created their constitution the way they did and it was to control government overreach. I doubt they foresaw all but it was a fine attempt. You do not stop foreign powers and determined criminals by blocking Internet traffic from outside, they can proxy unless you prevent all traffic flow. The only way you can stop them physically being within network reach is to institute total physical lockdown on movements ... and they will do that if we let them.

  3. Anonymous Coward
    Anonymous Coward

    When your own government is sending your data to be processed offshore anyway, does the first hop between you and them even matter?

  4. JessicaRabbit Silver badge

    The issue here isn't really that traffic is routed externally, it's the lack of HTTPS. There also seems to be an assumption that the government websites aren't just being hosted in some American vendor's cloud and thus open to interference in that way regardless of how the traffic is routed.

    1. Anonymous Coward
      Anonymous Coward

      Exactly so controlling traffic is the objective not security for us.

    2. John Brown (no body) Silver badge

      I'd argue it's both. HTTPS, of course, but if I'm sitting in Auckland and accessing a site in Wellington, why the hell is it "better" or more efficient for my data to transit Australia adding something in the order of 1000 miles of subsea connection to the journey? Optimising the county’s internal network is as much of the point of the article as the security. Or sorting the "market" for data transit costs. After all, how can sending terrabits of data between two NZ cities be cheaper via expensive subsea cables to Oz and back than local, cheaper to install land based connections?

  5. Anonymous Coward
    Anonymous Coward

    I wonder how SWIFT is routed......

    ....would any of that traffic be on the Internet?

    ....billions of dollars going from where to where............

    ....all legit, of course!!

  6. Irongut Silver badge
    Mushroom

    Its all fun and gamers until Thiel comes along

    Who cares when your govenment is giving your data to Palantir and paying for the privelege?

    1. Anonymous Coward
      Anonymous Coward

      Re: Its all fun and gamers until Thiel comes along

      Ah but they're in the club.

  7. Muisterdam

    Path-aware networking

    The Internet Society's study is mostly about local traffic unnecessarily being sent out of a country to reach another ISP in the same country because of a lack of national peering. That's usually more expensive and introduces more latency than ISPs simply exchanging traffic within their own country, especially in particular parts of the world.

    However, whilst the Internet offers ubiquitous access by design, there's certain data that should either not leave the country, or where it's not desirable for it to do so - for example, certain government, healthcare, military, or various critical infrastructure traffic. Even if it's encrypted, a hostile actor can still gain significant information from where traffic is headed to and from, and there's also the possibility of capturing the encrypted data and later being able to decrypt it in a post-quantum environment. Some data will still be valuable even years later.

    This is why there's increased interest in path-aware networking (e.g. SCION, but there are other initiatives) whereby users or at least organisations can determine how their traffic is sent across the Internet - for example preferring routes within a particular country or region.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like