Friday, May 28, 2004

Filtering in India

After reading a report about new filtering in India and varied compliance among ISP's (India delegates filtering responsibilty to the ISP and send them notices about which web sites to block). Previously India ordered a particular Yahoo! Group (kynhun) to be blocked which resulted in many ISPs blocking the entire groups.yahoo.com domain. As part of my work with ONI, checked the web site in question (an inflammatory anti-Islamic website, hinduunity.org). The website was in fact blocked, even by SIFY, an ISP named in the article that had expressed concerns over the authority under which the blocking order was delivered. In addition, at least 2 other websites were also blocked because they share the same IP address as hinduunity.org, a practice that Ben has written about in the past. Finally, one of the websites blocked due to IP sharing, kahane.org, is on the US Foreign Terrorist Organizations list. A strange coincidence. You can read the entire ONI bulletin here.

Thursday, May 27, 2004

Open Source Censorship?

A NewsForge article on the ONI raises the issue of open source censorship, something that we have discussed in the past. Internet filtering technologies are plagued by two inherent flaws under-blocking (content that should be blocked is accessible) and over-blocking (content that should not be blocked is inaccessible); this has been pointed out time and time and time again. Most filtering systems use a block list method where administrators configure the filtering software to block categories of pre-selected URLs. In the case of proprietary filtering technologies these block lists are kept secret. Efforts to legally obtain the contents of these secret lists have failed because the lists are the intellectual property of the censorware vendors. When using proprietary filtering technology neither users nor administrators know exactly what is and is not blocked. Furthermore, countries/administrators may be blamed when URLs are unintentionally blocked because they have been mis-classified by the censorware vendor. But unlike proprietary filtering technology, open source filtering software (DansGuardian, SquidGuard) can be configured to use open block lists. These open block lists can be scrutinized and users and administrators are thus fully informed as to what exactly is being blocked. When applied at the national level, this means that censorship can be implemented in an open and transparent manner by using open source censorware. But is this good enough?

Wednesday, May 26, 2004

Mis-Takes?

rumsfeld-saddam-small.jpg Well, after the Brits have been exposed for plagiarism, the Bush Administration admits to being wrong about mobile biological weapons factories in Iraq, wrong about Saddam Hussien's links to Al Qaeda and proven wrong about African uranium and aluminum tubes and after the fraudster/crook turned scapegoat Chalabi has fallen from grace the New York Times has admitted that they were wrong concerning WMD's in Iraq:
... we have found a number of instances of coverage that was not as rigorous as it should have been. In some cases, information that was controversial then, and seems questionable now, was insufficiently qualified or allowed to stand unchallenged. Looking back, we wish we had been more aggressive in re-examining the claims as new evidence emerged — or failed to emerge.


A sample of the coverage in question is available here. In related news, the "War on Terror" received a sound blasting from Amnesty International which stated that "Governments are losing their moral compass, sacrificing the global values of human rights in a blind pursuit of security" and that "global security agenda promoted by the US Administration is bankrupt of vision and bereft of principle". Canada also received a deserved blasting for police brutality, the detaining of individuals for more than 2 years on the basis of a "security certificate", and Canada's role in the deportation of Maher Arar to Syria where he was tortured.

Friday, May 21, 2004

Terrorism, the Law and Research

This story caught my attention. During the trial of a Saudi computer science student at the University of Idaho a "terrorism expert" testified that the defendant had published material that helped "to recruit and encourage financial support for terrorists." What caught my attention was that under cross-examination the terrorism expert admitted that "he published some of the same information on his own website without being prosecuted" but that his motivation for publishing the same material was "solely for the purposes of academic research into militant Islamic groups." Aside from the fact that the end user, in this case the potential "recruit", cares about accessing the information and not what the publishers motivations are, this raises issues about potential legal threats arising from sensitive research.

Thursday, May 20, 2004

Vietnam Crackdown

I've looked at filtering in Vietnam some time ago, but given recent government order to crackdown on "bad and poisonous information" on the Internet I have been taking a closer look and I spoke with BBC/NPR about it today. (Ben Edelman is also interviewed in the report, listen to the report in MP3 format here.)I have not noticed any significant changes in filtering in Vietnam since I did some research on Vietnam's filtering of the IFEX website. IFEX and VNN are blocked from most, but not all, remote computers used for testing in Vietnam (Tests were conducted using remote computers with connection on Vietnam Posts and Telecommunications (VNPT) -- users on other networks may have different levels of filtering). This indiactes that the filtering is not centralized and is being implemented at various levels of access using varying methods. In addition, the behaviour when accessing blocked content varies from a blockpage to basic authentication (with a unique ID number):
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="Your Information (ID41322)"
Connection: Close

From my limited tests, blocking seems to generally focus on Vietnam-specific content and dissident groups. However, news websites such as BBC Vietnamese and VOA News Vietnamese are accessible.

e-everything

Now I've put an "e" in front of ithings before, but never 3 in one sentence. While I agree with the sentiment, this quote is outta hand.
Moreover, they allow undemocratic regimes to evolve into e-dictatorships dedicated to e-censorship and e-repression.

Saturday, May 15, 2004

Spam tracking

Some recent spam statistics prompted a couple of interesting articles about spam that both sourced a study by commtouch.com which reports that 71% of the URLs in spam messages have their web sites hosted in China. (Additional statistics from brightmail.com analyze the total number and the content of spam.) However, less emphasis was placed on another statistic: 60.5% of spam originates in the USA. An article on internetnews.com prominently reported this statistic whereas a businessweek.com article, under the headline “A New Chinese Specialty: Spam” did not report this fact but rather casually stated that the actual spammers are “probably American or European”. This provides a nice intro to a project that has been incubating for the last two weeks and is still under development: Spice: The Spam Tracker.

Friday, May 14, 2004

The Current

The Current, a CBC Radio show, aired a segment on the OpenNet Intiative and the Citizen Lab today. Ron Deibert, Rafal Rohozinski and I were all interviewed. It was a somewhat wild ride of disparate tales including apparent milions of dollars of funding from George Soros (we are funded by OSI but not with millions), Rafal's sobering screwdriver story, my apparent breaking into foreign computer networks the moldy sandwich in the Lab's fridge and a soup con of porno. But interspersed in all of it was a good sense of the work the ONI/CL does with Internet censorship/filtering and why I call my self a hacker in the original sense of the word (and no I don't mean "someone who makes furniture with an axe"). Listen to the rather lengthy show here.

Thursday, May 13, 2004

Spyware/Google/Copyright

Spyware make WhenU has been caught using search engine cloaking in order to redirect users to content that is favorable to WhenU. Ben Edelman found that WhenU redirected users to copies of copyrighted articles if the HTTP referer was from Google. This also caused sites critical of WhenU to be pushed down in Google's ranking. Ben's disclosure led both Google and Yahoo to remove WhenU from their search results.

Thursday, May 6, 2004

Where credit is and is not due

Where credit is due:
In light of the "IBB Anonymizer" report, Seth Finkelstein has pointed out that Bennett Haselton had previously discovered that Anonymizer blocks by keyword and that some domains are whitelisted. I was not aware of Bennett's discovery when I was conducting the research and I have added a note at the bottom of the report acknowledging Bennett's discoveries.

Where credit is not due:
When things need to be "sexed-up" some (often reporters) will sometimes state that certain websites are blocked in certain countries without actually checking if that information is correct. In this article it is suggested that news.bbc.com is blocked in Iran when no such domain exists and in this article its suggested that "BBC News, MIT and Amnesty International" are blocked in China and Iran.

Monday, May 3, 2004

Happy World Press Freedom Day

On request from International Freedom of Expression Exchange (IFEX) I tested to see if there site www.ifex.org was blocked. I tested from mutliple remote computers in 78 different countries and found that the site was filtered in Vietnam. The IFEX release states:

The organization recently asked the OpenNet Initiative (ONI), a joint project of the Universities of Toronto, Cambridge and Harvard, to test if any countries were blocking the IFEX site. The ONI ran four rounds of testing on 18 servers in Vietnam and found it impossible to log on to the IFEX site. The servers were all run by Vietnam's main Internet service provider, Vietnam Posts and Telecommunications (VNPT).

ONI Advisory 001

Well, after a lot of hard work my research on International Broadcasting Bureau (IBB)/Anonymizer's circumvention tool has been released. It contains porn filters that block by keyword -- such as ASS. So domains that have ASS in them, such as usembassy.state.gov, are blocked even though they are not pronographic. Besides poorly designed porn filters, the IBB/Anonymizer works in plain text. Therefore the content of a user's sesion can easily be sniffed. The story has been picked up by CNET/News.com and New Scientist.