Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Might be dumb question, but won't this configuration need admin ssh access to add required rules and local server to log that traffic?


The whole point of the law was to add the ability to tap in, which is what this is. You still need someone to log into the router and setup the account which can do the tap, it can't be remotely activated by spooks.

Though if there are other remote access vulnerabilities, someone may be able to use the feature maliciously once they're in.


Not admin access:

> Calea provided options are available only for specific RouterOS user, as Calea server configuration as "tap" configuration. Specific user should have 'sniff' policy enabled at RouterOS user configuration

So the admin has to set up a user account on the device.


On RouterOS, the default 'admin' user is a member of the 'full' group, which has 'sniff' policy enabled.

So it can be both - dedicated user with the appropriate permission, or admin himself.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: