Even though it could be considered to be “old news,” by now, the April 6 Federal Court ruling in a case concerning Comcast and an FCC ruling could have long-term and quite serious impact on enterprise networks.
Comcast vs. the FCC: Predictable loss for a fair Internet
It’s our understanding that the court ruling has, for the moment at least, essentially stripped the FCC from jurisdiction over ISPs, leaving them basically unregulated. And while we’ll remain neutral on the merits of that decision, we’re not sure that there is sufficient completion among ISPs, especially in the access arena, to merit a total lack of regulation.
The crux of the issue is whether ISPs may treat different traffic types and traffic with specific destinations preferentially. (The original issue was whether peer-to-peer file sharing traffic could be given lower priority.) And while the spirit of the issue may very well have some merit, the extension – especially with corporate traffic – gives us pause.
One of the most serious issues involved here is whether ISPs are permitted to perform and possibly act on “deep packet inspection” (DPI). The technology is readily available for DPI – even for encrypted traffic in some cases – and can be a most useful tool in the corporate infrastructure. But is/can/should DPI be used for customer traffic in ISPs.
Unfortunately, we see no clear-cut answer here. For issues such as national defense, it’s a really tough call as to whether DPI can/should be used to identify and intercept messages. (In fact, we have little doubt that this is already being done to some extent.) And that’s an ethical and political question that’s not appropriate for this newsletter.
At the same time, corporate traffic has a reasonable degree of an expectation of privacy. In many ways, this is a situation that was covered quite well in traditional networks. However, with the lack of jurisdiction, it’s not so clear who’s in charge with the ISPs. There’s also at least a question of whether communications over the Internet are subject to some of the same lack of clarity as is the case with Cloud Computing. (See “The Justification for Paranoia”.)
We’ll continue this discussion in the next newsletter with a couple of specific examples. And in the meantime, we encourage you to join a discussion of this topic.




