Wednesday, November 30, 2005

Hacking Ghost Stories

There have been a variety of reports lately on "Titan Rain", an apparent cracker attack on US military computers that may have originated in China. The story orginally surfaced in the Washinton Post which reported that "Web sites in China" (1) were being used attack "hundreds of unclassified networks" run by the DoD and the US Government. Complete with the usual whispers and officials refusing to comment the articles notes that China may only be the last traceable hop and that only "low risk" computers were compromised.

TIME Magazine (pdf , local archive) then picks up the story and focuses on Shawn Carpenter, a mid-level analyst at Sandia National Laboratories, who claims to have counter-cracked the attackers and pinpointed their location to three routers in China's Guangdong province. TIME then states the following:

TIME has obtained documents showing that since 2003, the hackers, eager to access American knowhow, have compromised secure networks ranging from the Redstone Arsenal military base to NASA to the World Bank. In one case, the hackers stole flight-planning software from the Army.


It is unclear if "the hackers" are the same alleged Chinese hackers or if this is just a summary of the many attacks on DoD and US Government systems that Lt. Col. Mike VanPutte, vice director of operations of the Joint Task Force for Global Network Operations under the U.S. Strategic Command, attributes to the increased used of downloadable attack tools, which presumably, there are security patches for. In effect, there are increased attacks (i.e. scans or attempts to use known exploits) against Internet-connected, low risk, computers.

This story is eerily familiar.

Moonlight Maze is a continuing story that surfaced in July 1999 about a secret cyber-war aimed at the Pentagon and possibly conducted by the Russians or Chinese. It first appeared in the London Sunday Times in an article by James Adams. The story relied on unnamed sources and claimed that "some of the nation's most sensitive military secrets, including weapons guidance systems and naval intelligence codes" had been stolen. However, a story in Federal Computer Week refuted these claims by citing yet more unnamed DOD and pentagon officials as calling recent media coverage of Moonlight Maze "a combination of outright fabrications, distortions and incorrect quotations," and that military secrets had not been compromised.

The Moonlight Maze story re-surfaced after the Sept 11 attacks. USA Today ran a story about Moonlight Maze but in this version the theft of secret data "may be the work of terrorists" or someone working with terrorists.

Titan Rain and Moonlight Maze are amazingly similar ghost stories. In effect, the same story had been told and re-told, with substituted attackers, since at least 1999. I call FUD.

(1) Websites? Hmm... thats some badass HTML :)

Tuesday, November 29, 2005

Online Censorship in the Middle East and North Africa

Human Rights Watch has released a report on Internet Censorship in the Middle East. It contains case studies on Egypt, Iran, Syria and Tunisia. The technical testing was conducted by the OpenNet Initiative and the report was written by my friend and colleague Elijah Zarwan at HRW. It was a great pleasure to work with Elijah on this report.

Given recent events in Egypt, where the government has cracked down on the Muslim Brotherhood during Parliamentary elections, HRW's case study is extremely relevant. The banned Muslim Brotherhood has captured 76 seats (its candidates run as independents) in Parliament. The New York Times reports that the Muslim Brotherhood is now "the only significant opposition voice in the next Parliament, and the only opposition group likely to qualify to nominate a candidate to run for president in future elections."

However, the website of the Muslim Brotherhood, http://www.ikhwanonline.com/, is blocked by the largest ISP in Egypt. HRW reports that the Muslim Brotherhood has changed their IP several times to avoid the blocking and now operate a mirror site that is not blocked. (The Labor Party’s website http://www.alshaab.com is also blocked.) Despite the blocking, the Internet is still a key tool in organizing.

Banned groups are now using third-party sites they do not officially endorse—public bulletin boards, chat rooms, and so on—to coordinate their activities.


I think that this case shows that the effectiveness of filtering is its use in combination with overlapping mechanisms -- technical, legal and political -- of social control. The technical filtering is a reminder of what content is acceptable -- what the range of debate should be. But the technology loses its effectiveness when the other mechanisms of this control fade.

Monday, November 28, 2005

Vietnam Strikes Back

Vietnam has lashed out at Reporters Without Borders after RSF listed Vietnam as one of the 15 enemies of the Internet. Vietnam blocks access to many web sites and has imprisoned those who use the Internet to speak out against the government. Vietnam's response to charges of silencing online expression includes a listing of the accomplishments of Vietnam in terms of boosting access to the Internet as well as a strange admission that their filtering is actually not that good:

Viet Nam has also failed to introduce effective measures to prevent hostile and reactionary forces and political opportunists at home and abroad from using the Internet and on-line forums to speak ill of achievements gained by the people.


After an admission that Vietnam "puts firewalls on websites that are not suitable to the morals and fine customs of oriental people" they endorse "the establishment of a UN Internet Surveillance Agency". But the conclusion is the most telling:

The RWB's conclusion might lead to readers' understanding that the exercise of freedom of speech in a country means its government must allow the free distribution of terror threats and pornographic information on the Internet to poison the mind of the young generation.


Terrorism is the new porn. Increasingly, countries that filtering will claim "terrorism" as the excuse of the day -- replacing porn as the most common stated reason for Internet filtering. But, regardless of the initial reason for implementing Internet filtering, there is increasing pressure to expand its use once the filtering infrastructure is in place. Governments seem to be unable to resist the temptation to use it as a tool of political censorship.

See, I am wondering what "terror threats and pornographic information" is contained in the Vietnam Human Rights Network which is blocked in Vietnam? What about these sites: http://www.fva.org/ , http://vietforum.org/ , http://www.vpac-usa.org/ or http://www.montagnards.org/? And there are many more.

Today information is not borderless.

Monday, November 21, 2005

Expression Under Repression

Thanks to some negotations by HIVOS the "Expression Under Repression" event at WSIS was a success. It was unclear whether the event was to be held at all after the Tunisian authorities threatened to shutdown the session, claiming that the topic had nothing to do with ICT for Development. On the morning of the event a "cancelled" notice appeared on the door of the room where the event was scheduled to take place. And during the first panel there was some coomotion as a Tunisian camera crew and assorted plainclothes agents entered the conference room. I began my presentation as negotiations continued in the hallway outside. While giving an overview of Internet filtering trends worlwide, based on the OpenNet Initiative's ongoing research, I tried to emphasize three key issues: Transparency/Accountability, Unintended Consequences and Mission Creep. Here are the slides from my presentation.

Wednesday, November 16, 2005

Internet Filtering in Tunisia in 2005

The OpenNet Initiative is proud to announce the release of Internet Filtering in Tunisia in 2005, a country study that documents Tunisia's attempts to control Internet information, including the filtering of political opposition Web sites, human rights groups, and sites that provide access to privacy-enhancing technologies. ONI research reveals that Tunisia’s government Internet agency, ATI, uses SmartFilter -- filtering software produced by Secure Computing, a US-based company -- as the basis of its filtering regime. The state falsifies the information provided to users who try to reach filtered sites; the error page received claims the site is not accessible for technical reasons. Click Here for the full report.

WSIS

The WSIS summit in Tunisia is now well underway and the issue of freedom of expression online is emerging as an important issue. In his opening address, UN Secretary General Kofi Annan stated that freedom of expression was a key issue. During the opening ceremony, Kofi Annan was joined by Nobel Prize winner Shirin Ebadi, representing the Civil Society delegation, who stated that fundamental respect for freedom of expression is integral to an information society. She called on WSIS to have an official inquiry into Internet filtering.

The fact that WSIS is even in Tunisia has been the subject of much controversy. In the official WSIS space it is considered the UN, and the Internet is not filtered. But across the hall, in the ICT4D area, where countries, NGO, and companies have booths, it is Tunisian space, and the Internet is filtered. A website for the Citizen's Summit, an alternative parallel event, was available two days ago, but it is now blocked.

As shown in the just released ONI report on Filtering in Tunisia the block page appears to be a 404 File not Found error, but it is in fact a 403 Forbidden error generated by SmartFilter.