Run a large residential broadband network in the mid-2000s and you inherited a very specific frustration. Your links were congesting. Your regulators and your lawyers had opinions about what was moving across them. And the architecture you had been handed was designed, deliberately, so that the middle of the network would not know what it carried.
So equipment arrived that read further into each packet than routing required. Nothing in a packet says what it is for; there was no field for purpose then and there is none now. What the machinery actually did was infer — from packet sizes, from timing, from port numbers, from recurring shapes of bytes — probabilistic claims about somebody else's business, produced at line rate, meaning fast enough not to slow the traffic down, thousands of times a second.
A capability like that does not stay in the lane its buyer imagined. A network that can name the application can also price it, prioritize it, exempt it from a data cap, or assemble a profile of the subscriber generating it. The same faculty was sold, respectably, as intrusion detection. The box that sorts congestion from a spare bedroom will sort a country's traffic if you aim it that way. One capability, many buyers, and the buyers do not have to agree about anything.
In 2008 we got an unusually well-documented look at what that meant in practice. A large U.S. broadband operator's equipment identified peer-to-peer file uploads by inspecting their contents, then injected a fabricated packet into each connection. In TCP, the protocol underneath most web traffic, a reset packet means one thing: the far end has hit an error and the conversation is over. The fabricated packets carried the peer's apparent address and sequence numbers calculated to be believable. Both computers concluded the other had hung up.
The FCC found the practice unreasonable that August, and the reasoning outlives the outcome. The intervention was ill-tailored to the congestion it claimed to address: it selected by application rather than by congested segment, and it killed sessions rather than slowing them. Which is what you would predict from the equipment, not from the problem. The tool on the rack could classify applications, so the remedy came out application-shaped. Capability is a policy input long before anyone writes the policy.
The regulator treated the concealment itself as material. Because the injected packets spoke the endpoints' own vocabulary, no subscriber could tell that an intermediary rather than a peer had ended the session. The customer absorbed a degraded connection and a false explanation for it in the same transaction. A speed limit announces itself. This didn't.
The traffic responded by going dark. One national ISP measured roughly 10% of its web traffic encrypted in 2013; a controlled crawl in 2025 found 98.8% of mobile requests over HTTPS. In 2014 the Internet's standards body adopted a formal position that pervasive monitoring should be treated as a technical attack and designed against, while conceding in the same document that networks still have to be operable by the people operating them. The concession slowed nothing. Encrypted Client Hello, which hides even which site a browser is asking for, became a standards-track RFC in March 2026.
Nobody targeted anyone in that response, and that is the consequence I would sit with. The engineer diagnosing a failing link lost exactly the visibility that the operator quietly throttling a rival's video lost, because it was one faculty and encryption answered all of it at once. The traffic could not sort the motives, so it withdrew the privilege from everyone. Coarse inference survives — addresses, volumes, timing, the shape of a flow — but the fine reading is gone from the middle.
The impulse did not die. It moved to a place where the reading is invited.

