Apr 10 2007

More Ludicrous Marketing Claims About P2P Filtering

  • Written by soulxtc
  • No Comments

A few years ago, EFF debunked an anti-P2P packet filtering technology sold by Audible Magic. Twice. The notion that universities can just buy a piece of software to end file sharing on their networks forever is false. But it keeps coming back.

The latest product of this sort is from a company called SafeMedia. Its website is covered in dramatic marketing newspeak and includes a weird appeal to the Congress to install its software in “every public and private institution receiving Federal funds”. So what are they selling, really?

SafeMedia’s flagship filtering product is called Clouseau — suggestively named after the hillariously incompetent detective played by Peter Sellers in the Pink Panther movies.

The press release makes some grand and misleading claims:

“Pirates are smart and innovative, and so is Clouseau®. Our technology is dynamic, sees through all multi-layered encryptions, adaptively analyzes network patterns and constantly updates itself. Packet examinations are noninvasive and infallible. There are no false positives.”

Wow. We wonder if it sees through the encryptions with a comically big magnifying glass?

It’s hard to be certain from marketing-speak on their website, but it appears that «Clouseau» works in two ways:

1. Recognizing protocol-identifying “magic numbers” or other distinctive patterns inside individual packets from a particular protocol (like Gnutella, or eDonkey, etc).
2. Building up a “profile” of traffic by looking at a series of packets.

A system like this could indeed block many of the p2p protocols that are widely used today (including some encrypted protocols, without breaking the encryption). It certainly isn’t, and will never be, “infallible.” In fact, the claim is ludicrous. Detecting encrypted file sharing networks is very difficult, and blocking them without interfering with other encrypted protocols like HTTPS, IMAP/S, or SSH is next to impossible.

To illustrate this, suppose that SafeMedia attempts to block a program like Allpeers. They might succeed in doing so briefly, because the program tries to make its encrypted SSL conections over TCP port 36000 at first and only later switches to port 443 (the HTTPS port). On a TCP/IP network like the Internet, eavesdroppers can see the port numbers even if they can’t decrypt the traffic. So if Clouseau was clever enough, it would remember the initial 36000 connection and stop that machine from using port 443 later (blocking https websites as a side-effect).

But if Clouseau started doing this, Allpeers could change their software to use port 443 from the beginning. If the SafeMedia engineers were really good, there might be another round of cat-and-mouse as Clouseau tried to perform traffic analysis on the sizes and timings of the encrypted packets, and Allpeers started changing their sizes and timings to look like a more typical https website.

Filtering tools merely drive the development of sharing tools that are resistant to monitoring (including small networks like Allpeers, and encrypted versions of BitTorrent and eMule), and drive students to start using them. They don’t get us any closer to a real solution that gets artists paid while letting fans continue to share music. Universities are already being forced to expend significant resources doing the RIAA’s dirty work, and they should think very carefully before implementing expensive tools like SafeMedia’s.

Looking for more stuff to watch or download?
TVU, Free P2P Cable TV
3 Quick Ways to Watch Movies for FREE!
3 quick ways to watch TV shows for FREE
BitTorrent torrent sites & search engines
Azureus – A Beginner’s Guide to BitTorrent Downloading
uTorrent – A Beginner’s guide to BitTorrent downloading

SOULXTC: “walkin’ the streets of P2P”

Related Posts

  1. Anti-piracy company tells Congress it can eliminate College P2P
  2. New P2P Study Says that 20% of Europeans are File-Sharers
  3. Witnesses tackle Kazaa filtering claims
  4. New AllPeers v0.60 bundled with Firefox
  5. AT&T Gearing Up for Network Filtering
Zeropaid on Facebook
Trackbacks url:

Leave a Comment...

  • Advertisement

    Giganews Newsgroups

1 Star2 Stars3 Stars4 Stars5 Stars Loading ... Loading ...

  • mountain_rage: That is the downside to the radio model, all artist are tied in, and can't choose to give away their music for free to e...
  • DrewWilson: It's not entirely a surprise this is happening if you ask me. I haven't been around to witness the music scene for 20 y...
  • CHRIS: It's sad that people can make money off of you, but won't take the time to answer any of your questions. I think VUZE, I...
  • Neil: I don't think it's unreasonable to ask venues a small fee for radio, jukeboxes, and live music, but it really needs to b...
  • mountain_rage: The sad part is that even with all 3 licenses the facility can still be sued, since those 3 don't cover all artist. Pers...
  • Publishers Demand Royalties for Open Mic Nights | Headliner: [...] In a ridiculous abuse of music industry power BMI, SESAC, and ASCAP have started demanding that venues that hold o...
  • bulldawg: Hello Xtremezone members im very intrested in ur site, have heard nothing but great reviews about Xtremezone. im Xtrem...
  • “Three Strikes”: A Model to Follow, Thinks Fox Films - P2P Talk?: [...] In a recent statement Fox Films Entertainment CEO Jim Gianopulos said that the US needs to follow France’s examp...
  • sdsd