If XeroBank doesn log, how do they know if someone is abusing the network?
We have lots of ways we can discover abuse without violating the privacy of our clients. Our pro-active methods are by using hueristic algorithms that notify us if someone attempts to do network scanning, perform malicious activities such as Denial of Service attacks, mail spamming, etc. We take client privacy very seriously: in the case that malicious traffic is suspected, it is then reviewed by a human auditor. If it is not clear that it is abusive traffic, an ethics advisor will be consulted. If deemed not to be malicious, the log is wiped.