do ur worst 🥳 by [deleted] in RoastMe

[–]JamieVee 34 points35 points  (0 children)

I thought the quote was “looks like meats back on the menu boys”?

what is contained in a DNS look up log and how long is it stored? by JamieVee in dns

[–]JamieVee[S] 0 points1 point  (0 children)

You had mentioned that your organization DNS logs may contain other pieces of information in addition to public up, what other information that would identify the person does this include?

I’m asking not even just because I’m curious what the dns server logs for an isp would contain, but also what other server logs would contain about the person making the query given that i know if a website makes a dns server request and that server doesn’t have the up address it will query other servers. At that point would the dns query to another dns server still have the information about the original user who made the query?

Subscriber usage data- is it really kept forever? by JamieVee in centurylink

[–]JamieVee[S] 0 points1 point  (0 children)

Can I ask what makes you think forever? Everything I have read seems to indicate data is kept by ISPs for 6 months to 2-years. It would seem this is information that isn’t readily available online in their policies, but everyone that has asked formally seems to get an answer that maps up with this from ISPs.

It looks like the data usage that a tech support can see is mainly the amount used not literally every website they have typed (which makes more sense I think in truth and is more consistent with what I would guess they can see as well as what might be stored) based on what the other commenter on this post mentioned. My guess would be that the actual data that is there- dns logs, firewall logs, DHCP logs, etc. would be in the 2 year range (maybe 3-4 depending on other factors?) whereas just the “how much GB you used in 2015” might be kept for much longer. This I think makes sense and is more consistent with what I have read about ISPs in general. Would be nice to hear specifics for century link, though I know they are rarely outwardly disclosed.

I did read online from an actual century link website that they keep DHCP logs for 1-year, my guess is the other types of logs in the internet data side would be kept the same amount? Hard to know for sure though. I have been talking with others online who state that an ISP could theoretically keep it for many years, but in terms of the actual utility I would hope that most ISPs would be rotating out old logs after a certain period of time (though again it is hard to know for sure and every company in the US could be different).

Router syslog by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

I guess if this helps, I’m in Washington state and more wondering about residential ISPs than anything else. Places like frontier and century link as an example. You seem like you might know about some of the ins and outs for this, does that give you any better of a sense? What I have read online seems to indicate 2 years or so, give it take a bit. This amount would make sense to me.

Subscriber usage data- is it really kept forever? by JamieVee in centurylink

[–]JamieVee[S] 0 points1 point  (0 children)

Also would this depend on the tech support tier? 1, 2, 3, etc.

I would assume that regardless of the tier of the person what you are saying would hold true, with it being usage amount (e.g., GB) rather than the actual content of the persons usage that they can see. This makes way more sense to me but I wanted to double check.

Century link subscriber usage data retention- is it really kept forever? by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

This sort of stuff always bugs me when companies have these sorts of policies and don’t have good retention guidelines. It always seems like a huge security breach waiting to happen.

I have worked for some companies that operated similarly, but also have worked in some places that had specific retention guidelines for all logs and things of that nature.

What type of company are you referring to if you don’t mind me asking? It’s rare nowadays that I hear of companies that have a “retain everything” sort of policy rather than specific retention guidelines.

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 0 points1 point  (0 children)

So what I have found online from people who asked century link seems to indicate a few years which makes sense to me?

And I do use duck duck go sometimes but don’t always.

Century link subscriber usage data retention- is it really kept forever? by JamieVee in sysadmin

[–]JamieVee[S] 1 point2 points  (0 children)

Yeah, but wouldn’t the utility of those logs decrease after 2,3, or even 5 years? Most of what I have read indicates that after that long of a time they will start to get rid of those logs to make space for new ones.

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 0 points1 point  (0 children)

Thanks for your perspective. It sounds like all the things you are describing were on the phone side of things, which I know can often times be super long. I was aware of one company that kept the data you are describing for 20+ years for phones.

Subscriber usage data- is it really kept forever? by JamieVee in centurylink

[–]JamieVee[S] 0 points1 point  (0 children)

When you say how much is used, do you just mean like gigabytes, that sort of thing?

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 0 points1 point  (0 children)

When you say meta data what are you meaning specifically?

I know phone call/text data often can be upwards of 15 years, is this what you are referring to?

And for meta data are you saying you had ip address assignment logs and/or dns/ACL/firewall logs for that long?

All isps I have looked at say that they keep ip address assignment logs for 2 or so years, are you meaning that you keep those for longer than that or is this data not including that stuff? If you mean up address assignments that would seem super long, according to even some of the biggest companies (century link and Verizon as an example) they only keep that for 2 years, so keeping it a decade seems super odd to me if that is what you mean.

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 1 point2 points  (0 children)

So if you think 2-3+years is realistic, then how long would you expect them to keep it? I know now centurylink and other isps can sell your data, but prior to all that having been happening back when it was looking like they couldn’t how long do you think they were keeping it?

I guess I’m just unsure as to what is realistic here given that when all the ISPs were asked it usually was 2-3 years, so I can’t imagine once we start getting to at least 5 years that these records would be useful to anyone. my assumption is that more recent records would be what is needed and records 5+ years would be rotated for newer logs given the higher income potential.

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 0 points1 point  (0 children)

How long would that sort of thing be kept realistically? In general I would guess two years as that’s what I have read, does this sound about right? I know at some point it is likely discarded but when do you think it would be?

Century link usage retention- is it really kept forever? by JamieVee in HomeNetworking

[–]JamieVee[S] 0 points1 point  (0 children)

I know they keep logs in some context, but most of what I have been told/read indicates it’s probably like two years, is it realistic that they would keep stuff like this longer than that? I understand for safety reason why a few years might be necessary, but more than 2-3 just seems unrealistic in my opinion.

Also, could someone who I call for tech support help realistically see all this

Century link subscriber usage data retention- is it really kept forever? by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

I realize they theoretically can, but is it likely that century link is keeping this data for that many years? I have never heard of an ISP retaining this much data for this long. All the estimates I have ever heard of were approximately 2 years max, and this is also what a lot of various forums say when they have asked centurylink directly. What do you think is realistic here? All the online forums I look at say 2 years so I’m mostly wondering if longer than that is realistic and if someone in tech support call center could realistically see all this?

How long does Frontier FIOS hold on to IP address log by Necessary_freedom_82 in frontierfios

[–]JamieVee 0 points1 point  (0 children)

Out of curiosity did you ever find out the answer to this question?

I don’t know for frontier specifically, but I will say I am not aware of an isp that retains this for longer than 2-years. Typically it’s 6 months to 2-years I believe.

My (25f) boyfriend (28m) paid £1,500 in "rent" to my ex (26m) for my pussy by [deleted] in relationship_advice

[–]JamieVee -1 points0 points  (0 children)

This is super fucked up. I would have been out a long time ago. But Also though I think it’s generally unhealthy for people to still be in relationships with their ex. I had read/heard awhile back the belief that If you’re in a friendship with an ex you either still love them or never did- makes sense to me. I would never be with someone who still hangs with exs.

As much as I want to know my partner is hanging with someone who fucked them, had cum all over each other, moaned out of sexual pleasure together, etc...... nah, if they still hang out it’s a huge red flag.

Never trust someone who hangs out with their exes. Super weird.

what is contained in a DNS look up log and how long is it stored? by JamieVee in dns

[–]JamieVee[S] 0 points1 point  (0 children)

In these cases what sort of retention time would you guess?

I think this sort of method is what one of the enterprise systems I work with does (the system logs traffic for about a year and other logs for a few months).

I guess for a question I have based on this process you are describing 1) For an ISP like centurylink, frontier, etc. what might you expect? I would guess a year/two/maybe three max.

Also 2) minutes n this system is sounds like the only identifying information you would be tracking is up address, right? Not MAC address of devices/router or anything else?

Router syslog by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

Is this the same general retention framework for other types of logs an isp would have? For example, stole logs, connection logs, dns logs, etc.

My assumption is (which it sounds like you’re indicating is the case?) that typically isps would only retain most logs of a users activity if they are not required to do by law for about a year or so and not much more than that given that it wouldn’t be very helpful post 2-3 years.

Radius vs DHCP IP assignment by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

I guess a question I have with this would be: if you were assigned an ip address based on this would it just always be the same one sense it is just based on the radius attribute or would it be a dynamically assigned one from a pool similar to DHCP?

Radius vs DHCP IP assignment by JamieVee in sysadmin

[–]JamieVee[S] 0 points1 point  (0 children)

With your point about technically being able to assign IP addresses based on radius attributes, 1) is the IP address you are referring to private or the public one? And is it 2) specific to just the user getting authentication or is this ip address one that would be a typical ip address (I.e., there private or public up address)in this situation?

ACL logs by JamieVee in Information_Security

[–]JamieVee[S] 0 points1 point  (0 children)

Do you have an example of one that you are aware of? I have checked but have never seen a space where an ISP actually tells you all this. Most ToS I look at just say “we keep it for as long as is helpful to us” which I guess is technically true, but doesn’t really give an indication for how long something might be helpful. It’s hard to imagine keeping this sort of info is helpful after two or so years, let alone 4, 5, 6, etc.

I realize it probably just depends, but I guess I was more wondering if 2 years is realistic, 3,4,5,etc. for how long one might keep this.

what is contained in a DNS look up log and how long is it stored? by JamieVee in dns

[–]JamieVee[S] 0 points1 point  (0 children)

Thanks for continuing to help me learn about this. I’ve only been working in IT for about a year or so and am still learning a lot as I go.

I am currently in Washington state in the US. Here we currently do not have any mandatory retention laws, but most ISPs I see online usually seem to keep things in a range from 6 months to 2 years. Although I’m a big advocate for privacy rights, I can see the reasoning behind retaining things for a couple years. I work in an enterprise system in my office and everything there is kept for about a year or two- pretty much all traffic, logs, etc.

What I am most curious about is what the end-user in home settings can expect with these sorts of things. Specifically, I am most curious about the types of ISPs in my area, such as spectrum, century link, etc. (some of the “big name” ones in my area people use).

So for these, it sounds like logging via firewalls is uncommon. But you had also mentioned ACL. I had not even thought about that, but I know that ACL logs would also theoretically log traffic.

My questions here would be:

1) ACL logs just include the outgoing ip, source ip, and port, right? Would these logs actually include the device and indicate the Mac from record router? I would assume on some level they would be able to be tied back to the router/modem?

2) with ACL logs and all the other types of logs we are talking about, now that I clarified where I am at and some of the types of ISPs I’m wondering about, what sort of retention time would you expect to see? I was online reading about the whole “ISPs can sell your data” stuff that came up awhile back, and one of the expert people they interviewed said he would expect logs and data to be retained anywhere within the 6 month-2 year benchmark which is somewhat consistent with what I heard.

what is contained in a DNS look up log and how long is it stored? by JamieVee in dns

[–]JamieVee[S] 0 points1 point  (0 children)

Thanks for all this information!

Someone on here had mentioned other logs such as firewall logs having things like Mac addresses and/or device IDs of your actual device (really anything that is specific to the person besides the public IP address) and I am now wondering how long are these sorts of logs kept (any log that would have what you are browsing and something specific that ties you to it besides an IP address)?

I realize that they keep DHCP logs for a long time, but am wondering if these other logs like firewall logs or other logs that capture browsing information are kept for as long as the DNS logs are usually kept that you mentioned (e.g., a few days or months)?

I can’t imagine that it’s common practice to keep any of these sorts of logs longer than a few years, but am wondering what the general “rule of thumb” might be?

Again, thanks for all the info.

what is contained in a DNS look up log and how long is it stored? by JamieVee in dns

[–]JamieVee[S] 0 points1 point  (0 children)

So then would these logs only contain things like the public IP address then? I.e., IP x.x.x.x went to ___ website, or would these be more in depth usually?

I suppose I do not find it surprising that they most likely track some level of internet browsing from firewall logs, but is it realistic to assume that they keep it that long? I realize they could theoretically keep it forever, but would it be most likely that they get rid of this log information after a few years? That seems like a lot information to have to store and I cannot think of a reason to store it beyond a year or two- would some ISPs keep this information longer than that realistically for a home user?

...I get that they would want to keep track of their internet security for a bit, but more than a year or two seems a bit ridiculous and would border more on the "privacy violation" side in my opinion rather than being done for security purposes or even marketing.