The journal Index on Censorship has published an article I wrote. In it I argue that there is a failure to recognise Internet censorship and surveillance as a growing global concern. There is a tendency instead to criticise the most infamous offenders-notably China and Iran-and to overlook repressive practices elsewhere. There is, however, a growing resistance to Internet censorship and surveillance, although it is often characterised as a struggle confined to dissidents in a few select authoritarian regimes.
Battles are being fought all over the globe, while the development and use of technologies that protect privacy and make it possible to circumvent censorship are rapidly increasing. The same tools helping dissidents to evade censorship in repressive countries are also being used by citizens in democratic countries-to protect themselves from unwarranted Internet surveillance. Focusing on the global character of both the practice of Internet censorship and surveillance, as well as the resistance to it, provides for both a better understanding of this important trend as well as for the possibility of creating global alliances to combat its spread.
The full article is available below.
Saturday, December 15, 2007
Wednesday, December 12, 2007
Rogers & Content Substitition
The Canadian ISP, Rogers, is inserting content into the web pages of its customers. In effect, Rogers is, probably, illegally intercepting the content destined for a user and modifying it to display information some of which looks like an advertisement. In the case that's been cited the most, the webpage that was hijacked was Google, although it could be any webpage. Google is "concerned".The Toronto Star reports:
Some bloggers noted the Rogers notice on Google's search page seemed more like free advertising than a customer-service bulletin, since it suggested the user "upgrade to another level of service which provides higher usage limits and speeds by visiting rogers.com."
Critics say Rogers' move, though perhaps well-intentioned, could set a dangerous precedent that says it's okay for the companies that pipe the Internet into people's homes and offices to exercise control over their subscribers' activity online.
Lauren Weinstein posted a screen shot as well as the code used to insert the content and suggests that the technology used is developed by PerfTech:
While Rogers' current planned use for this Deep Packet Inspection (DPI) and modification system (reportedly manufactured by "In-Browser Marketing" firm "PerfTech") is for account status messages, it's obvious that commercial ISP content and ads (beyond the ISP logos already displayed) would be trivial to introduce through this mechanism.
This is a truly unfortunate development. Not just because it's probably illegal. The Telecommunications Act states:
Except where the Commission approves otherwise, a Canadian carrier shall not control the content or influence the meaning or purpose of telecommunications carried by it for the public.
I fear that "mission creep" is occurring. Many Canadian ISP's are engaging in significant interference with the delivery of content -- for a variety of reasons -- including filtering of child abuse images (and in the case of Telus the a website set up by members of their Union during a labour dispute), the traffic shaping by Rogers and Sympatico to restrict Bittorrent and now the outright interception, modification, and distortion of content. These practices are being implemented with little transparency or accountability and are becoming the industry standard.
Canadian "DMCA" On Hold
Jim Prentice (Conservative), Minister of Industry, has delayed the introduction of amendments to the Copyright Act that are being called a Canadian "DMCA".
The Fair Copyright for Canada Facebook group now has over 17,000 members and the opposition is growing. The public is concerned that the balance that copyright legislation is supposed to maintain between the interests of creators and the interests of the general public is being distorted. The new amendments reportedly introduce "anti-circumvention" measures which prevent Canadians from using legally purchased media and technology in the ways they want. Also, it includes no flexible fair dealing and exceptions for parody, time shifting and device shifting or expanded backup provision. Finally Canadians are pissed off, that's a technical term, because the public was never consulted while industry lobby groups were.
The issue has caught fire in personal and consumer blogs on the Internet, led by Michael Geist, the Canada Research Chair of Internet and E-Commerce Law at the University of Ottawa.
The Fair Copyright for Canada Facebook group now has over 17,000 members and the opposition is growing. The public is concerned that the balance that copyright legislation is supposed to maintain between the interests of creators and the interests of the general public is being distorted. The new amendments reportedly introduce "anti-circumvention" measures which prevent Canadians from using legally purchased media and technology in the ways they want. Also, it includes no flexible fair dealing and exceptions for parody, time shifting and device shifting or expanded backup provision. Finally Canadians are pissed off, that's a technical term, because the public was never consulted while industry lobby groups were.
Sunday, November 25, 2007
Bureau warns on tainted discs
Hard disks sold in Taiwan contained trojan horse programs. The Taipei Times reports:
Chinese spying or manufacturer's blunder? It seems odd that hard disks would have been infected before even being sold.
Portable hard discs sold locally and produced by US disk-drive manufacturer Seagate Technology have been found to carry Trojan horse viruses that automatically upload to Beijing Web sites anything the computer user saves on the hard disc, the Investigation Bureau said.
Around 1,800 of the portable Maxtor hard discs, produced in Thailand, carried two Trojan horse viruses: autorun.inf and ghost.pif, the bureau under the Ministry of Justice said. The tainted portable hard disc uploads any information saved on the computer automatically and without the owner's knowledge to www.nice8.org and www.we168.org, the bureau said.
Chinese spying or manufacturer's blunder? It seems odd that hard disks would have been infected before even being sold.
Skype encryption and surveillance
German police are unable to decrypt Skype, but rather than asking the company to provide keys to decrypt the transmissions, or implement a backdoor, they are seeking to intercept communication before they are encrypted:
Trojaning the computer, however, does allow for much more surveillance than just Skype communications. In many respects these are not technology issues but policy issues. See, for example, the privacy issues with the US carnivore/dcs1000 and the increased concern now that they've switched to private, commercial applications.
This also raises some interesting questions with regard to Skype and China. While the text message is filtered -- although I could only find one censored word, fuck, when I checked it out -- I'm not convinced this supports the allegations of surveillance.
"We can't decipher it. That's why we're talking about source telecommunication surveillance -- that is, getting to the source before encryption or after it's been decrypted."...
Ziercke said there was a vital need for German law enforcement agencies to have the ability to conduct on-line searches of computer hard drives of suspected terrorists using "Trojan horse" spyware.
Trojaning the computer, however, does allow for much more surveillance than just Skype communications. In many respects these are not technology issues but policy issues. See, for example, the privacy issues with the US carnivore/dcs1000 and the increased concern now that they've switched to private, commercial applications.
This also raises some interesting questions with regard to Skype and China. While the text message is filtered -- although I could only find one censored word, fuck, when I checked it out -- I'm not convinced this supports the allegations of surveillance.
Friday, November 23, 2007
A Few Important Echoes
Do you have any idea who last looked at your data? Seth Finkelstein brings up some some great points in this article but the one I want to focus on concerns the use of privacy protecting technology:
I think the point is well taken. Not only should we be making these technologies easier to use (and I think the Tor folks doing so) but we should also recognize that the problem is embedded in a host of other issues. Technology may help us in the short run, but it does not solve the problem. (Oh, and I too like the phrase Seth coined "The price of total personalisation is total surveillance.").
Catspaw also picks up on a similar theme in response to esquire's nomination of psiphon as one of the six ideas that will change the world.
She writes:
Note that while it's a common recommendation to use technical means to protect one's privacy (such as the "Tor" anonymity system, at torproject.org), such measures are frequently not workable for any but the most knowledgeable and dedicated people. They are often inconvenient and shift a burden on to citizens to be constantly on guard, as opposed to not requiring such guarding in the first place. Using privacy/anonymity programs is good advice, but in overall terms, a bad solution.
I think the point is well taken. Not only should we be making these technologies easier to use (and I think the Tor folks doing so) but we should also recognize that the problem is embedded in a host of other issues. Technology may help us in the short run, but it does not solve the problem. (Oh, and I too like the phrase Seth coined "The price of total personalisation is total surveillance.").
Catspaw also picks up on a similar theme in response to esquire's nomination of psiphon as one of the six ideas that will change the world.
She writes:
I'm glad that the issues around internet censorship are getting mainstream attention, as every additional mention helps, but I worry when software programs like Psiphon are advertised as a magic bullet that's going to make the problem go away. It won't. This is a complicated issue with very deep social, political and legal structures supporting the censorship, and no piece of software is going to be able to counter that; it's not just a technical issue.
Monday, November 19, 2007
Oh Canada... China's Human Rights Record Improving?
A report by Canadian diplomats obtained via Access to Information by the Globe and Mail suggests that China's Human Rights record is improving. In addition to suggesting that that China is treating dissidents better because they are now only getting 5 years instead of 15-20 it states:
Tell that to Shi Tao and Wang Xiaoning who are doing 10 years, thanks in part to Yahoo!.
The report also maintains that Chinese scholars "continue to enjoy increasing intellectual freedom." It praises the "steady increase in personal freedoms of the average person." And it argues that the Chinese authorities "may be losing the battle to control the Internet."
Tell that to Shi Tao and Wang Xiaoning who are doing 10 years, thanks in part to Yahoo!.
Wednesday, November 14, 2007
Times are hard for Iran's online free-speech pioneer
There is a nice article about Hossein Derakhshan in the Ottawa Citizen. It documents his shift in thinking and the troubles it has caused him. back when his blog was shutdown few of his former allies supported him.What changed? Hossein became very concerned about the demonization of Iran, a possible attack on Iran, and the manipulation of human rights issues to support the former.
A while back Hossein shut down the stop.censoring.us site that he was running that was focused on Internet censorship in Iran as a protest against the use of the issue to demonize Iran. He wrote:
This reminded me of an earlier case regarding China, "The Great Chinese Censorship Hoax". Two Chinese bloggers closed their blogs and waited for the news media, bloggers and anti-censorship groups to assume, which they did, that the government shut the blogs down. one of the bloggers involved stated:
These are only two cases but I'm wondering if these cases are a signal of an incubating trend.
All this has left him isolated from the community of politically active expatriate Iranians who formerly supported him. Some bloggers have removed links to his blog. Others have actively urged readers to boycott him. Interview requests from western-based Iranian media have dried up, as have invitations to ex-pat events and panel discussions.
It's quite a change for someone once widely viewed as a free-speech techno-hero.
A while back Hossein shut down the stop.censoring.us site that he was running that was focused on Internet censorship in Iran as a protest against the use of the issue to demonize Iran. He wrote:
Internet censorship exists in Iran, as it does in many other parts of the world, especially in the Middle East.
But it has recently become another pretext for the United States and its allies to further demonise and delegitimise the government of Iran.
This reminded me of an earlier case regarding China, "The Great Chinese Censorship Hoax". Two Chinese bloggers closed their blogs and waited for the news media, bloggers and anti-censorship groups to assume, which they did, that the government shut the blogs down. one of the bloggers involved stated:
"I just wanted to make fun of Western journalists? [content] doesn't need to be serious on the Internet. I don't like it that Western media take a distorted view of China, though China does have problems," Wang told Interfax in an emailed statement, "I thought that if I closed my blog, it would stir their imagination and then they would begin blah blah. It really is as expected. So let's they have an April Fool's day in advance."
These are only two cases but I'm wondering if these cases are a signal of an incubating trend.
Yahoo! Settles Law Suits
Yahoo has reportedly settled the law suits brought forward on behalf of Chinese citizen's who were convicted in China with evidence provided by Yahoo playing a part in their conviction.
The World Organization for Human Rights (WOHR) USA, which brought the case on behalf of Shi Tao and Wang Xiaoning, said Yahoo had agreed to the settlement after "intense pressure" from lawmakers during a congressional hearing last week.
The terms of the settlement are to remain confidential, but Yahoo Chief Executive Officer Jerry Yang said in a statement the company would provide the Shi and Wang families with financial, humanitarian and legal support, and create a relief fund for other political dissidents.
Saturday, November 10, 2007
Demonoid down again
The bittorrent tracker site demonoid.com:
The Register has more.
The CRIA threatened the company renting the servers to us, and because of this it is not possible to keep the site online. Sorry for the inconvenience and thanks for your understanding.
The Register has more.
Anti-Censorship/Privacy Enhancing Technologies
This article in Foreign Policy is representative of accounts of the development and use of anti-Censorship/privacy enhancing technologies that only tell part of the story. While technologies such as Tor and psiphon are given great treatment, the frame used to contextualize their use gives the misleading impression that they are only used in "repressive" countries:
This partial picture ignores the global use of these technologies. More and more countries are censoring the Internet -- not just China and Iran.
Here's an interesting anecdote. When psiphon was released the CBC, Canada's national public broadcaster, covered it but the reporter working on the story had to phone me at the Citizen Lab because she could not access the psiphon website from CBC because it was blocked by their filtering software, aka censorware. This is not the first time I've heard this. Reporters at CBC need to use tools like psiphon to do their jobs!
The other missing piece is surveillance. The U.S., which has the most sophisticated electronic surveillance program in the world, has been caught illegally spying on citizens. Anti-Censorship/privacy enhancing technologies are used all over the world. Even the Privacy Commissioner of Canada recommends that Canadians use anonymous communications technologies. These are tools developed for and used by people all over the world. To pitch them as something that's only used in repressive countries is misleading and inaccurate.
One software program called Psiphon, which was developed by researchers at the University of Toronto's Citizen Lab, allows any person with a computer to serve as a proxy for someone living behind a firewall. Since it was launched a year ago, more than 100,000 people have turned their personal computers into proxies.
The most sophisticated proxy technology may be Tor, developed jointly by the U.S. Naval Research Laboratory and the Electronic Frontier Foundation, an Internet freedom advocacy organization. Tor is a downloadable software that routes an Internet surfing session through three proxy servers randomly chosen from a network of more than 1,000 servers run by volunteers worldwide. "Tor is state of the art," says John Mitchell, an expert on Internet security at Stanford University. For citizens of repressive regimes, it may be the best hope or evading the cat's paw.
This partial picture ignores the global use of these technologies. More and more countries are censoring the Internet -- not just China and Iran.
Here's an interesting anecdote. When psiphon was released the CBC, Canada's national public broadcaster, covered it but the reporter working on the story had to phone me at the Citizen Lab because she could not access the psiphon website from CBC because it was blocked by their filtering software, aka censorware. This is not the first time I've heard this. Reporters at CBC need to use tools like psiphon to do their jobs!
The other missing piece is surveillance. The U.S., which has the most sophisticated electronic surveillance program in the world, has been caught illegally spying on citizens. Anti-Censorship/privacy enhancing technologies are used all over the world. Even the Privacy Commissioner of Canada recommends that Canadians use anonymous communications technologies. These are tools developed for and used by people all over the world. To pitch them as something that's only used in repressive countries is misleading and inaccurate.
Wednesday, November 7, 2007
Google Handing Over IPs
After a request from Indian Law Enforcement, Google handed over the IP address of an Orkut user. The Indian Law Enforcement asked the ISP Airtel for information about the "owner" of that IP and Lakshmana Kailash K. was arrested. However, it turns out that Airtel did not hand over the correct information to Indian police, Mr. Kailash was released three weeks later. Google hasn't had much to say:
Initially, Yahoo didn't have much to say either, then they "misspoke", now they've been taking a beating.
When contacted for comment, a Google spokesperson told me that, "Google has very high standards for user privacy and a clear privacy policy, and authorities are required to follow legal process to get information. In compliance with Indian legal process, we provided Indian law enforcement authorities with IP address information of an Orkut user." This was the only comment that Google's PR people would give me in response to a lengthy set of questions that I sent over. In particular, I asked if they had received a court order for the information, or merely a polite request from the police. Their response leaves things very hazy.
Initially, Yahoo didn't have much to say either, then they "misspoke", now they've been taking a beating.
Monday, November 5, 2007
Bell Sympatico Traffic Shaping
Bell Sympatico is now admitting to traffic shaping during peak usage periods:
For more see P2PNET.
“During peak periods of Internet usage, Internet Traffic Management is used to balance bandwidth fairly between P2P file sharing and other applications so that all customers receive fair use of the network”.
For more see P2PNET.
P2P & the Purchase of Music
In The Impact of Music Downloads and P2P File-Sharing on the Purchase of Music: A Study for Industry Canada researchers found "no direct evidence to suggest that the net effect of P2P file-sharing on CD purchasing is either positive or negative for Canada as a whole." However, when it comes to the "Canadian P2P file-sharing subpopulation" the study found that Canadians who engage in P2P file-sharing actually buy more music. For every 12 downloaded songs, CD purchases increase by 0.44.
This "'market creation' effect of P2P file-sharing" is interesting indeed. Through P2P file sharing one can access content that is not available for purchase.
It will be interesting to see how the Music Industry responds. The Industry presents correlative evidence, that in the last five sales have decreased by $465 million while P2P file sharing has increased, to suggest that they've been losing money due to file-sharing but this report dismantles that claim. This report may also be helpful in reaffirming the "private copying" prevision in the Copyright Act that enables Canadians to legally copy and share music.
With respect to the other effects, roughly half of all P2P tracks were downloaded because individuals wanted to hear songs before buying them or because they wanted to avoid purchasing the whole bundle of songs on the associated CDs and roughly one quarter were downloaded because they were not available for purchase.
This "'market creation' effect of P2P file-sharing" is interesting indeed. Through P2P file sharing one can access content that is not available for purchase.
It will be interesting to see how the Music Industry responds. The Industry presents correlative evidence, that in the last five sales have decreased by $465 million while P2P file sharing has increased, to suggest that they've been losing money due to file-sharing but this report dismantles that claim. This report may also be helpful in reaffirming the "private copying" prevision in the Copyright Act that enables Canadians to legally copy and share music.
The Copyright Act contains a special exception for “private copying”: it permits the copying of music files “onto an audio recording medium for the private use of the person who makes the copy”, but does not permit copying for the purpose of “distributing” or “communicating to the public by telecommunication” (s.80). It is generally accepted that downloading music for personal use is legal under this section.
ONI: Myanmar/Burma Internet Closure
The OpenNet Initiative released a report documenting the Internet shutdown in Myanmar/Burma. Similar to the shutdown in Nepal after the King assumed power in a coup in 2005. Both of the ISPs cut their Internet access from September 29 to October 4 with the exception of a few brief periods of access. Also, the shutdown was gradual:
ONI also looked for signs of how the infrastructure was turned off during these outages. The Burmese Autonomous System (AS), which, like any other AS, is composed of several hierarchies of routers and provides the Internet infrastructure in-country. A switch off could therefore be conducted at the top by shutting off the border router(s), or a bottom up approach could be followed by first shutting down routers located a few hops deeper inside the AS.
A high-level traffic analysis of the logs of NTP (Network Time Protocol) servers indicates that the border routers corresponding to the two ISPs were not turned off suddenly. Rather, our analysis indicates that this was a gradual process: traffic fell to 14 percent of the previous week’s average on September 28, going down to 7 percent of the average on September 29 and zero traffic on September 30. This matches with the BGP data coming from AS 9988 and AS 18399 belonging to MPT and BaganNet respectively.
Tuesday, October 23, 2007
Canada Losing Ground
The headline of Reporters Without Borders' 2007 Press Freedom Index reads:
A G8 member other than Russia also lost ground: Canada. In this year's survey Canada ranks 18th with a score of 4,88 while in 2006 Canada ranked 16th with a score of 4,50. While it may only be a small dip, it is a slide nonetheless. As Canadian it is embarrassing and I want to highlight three trends that I see:
1) Government Surveillance of Journalists
Last September it was revealed that the names of journalists who had filed Access To Information as well as the content of their requests were being discussed on conference calls and circulated to the Prime Minister's Office as well the the departments who were the target of the forthcoming article. In this particular case it was a reporter who had asked for information regarding the landing of CIA planes in Canada:
2) A "Controlled" Press Centre
Although it was shelved upon becoming public the Prime Minister's plan to build a new press centre has serious negative consequences for journalism in Canada. Annoyed with the questions asked by journalists the Prime Minister sought to have his staff select which reporters could ask questions but was refused so he resurrected the Liberal's plan to build a new media centre in which his staff would control who asked questions. The ability to manipulate and control what questions are asked is a serious threat to democracy. As The Star notes: "If reporters can't freely question political leaders, press freedom is diminished, and so is democracy."
3) Media Consolidation
AdBusters reports that "just four corporations now control 70 percent of the country’s newspaper circulation" and my hometown, Vancouver, is the worst in the country. In Vancouver one company owns "70 percent of the entire media market and is the only voice of record for the city."
UPDATED: Nov, 10, 2007
4) Non-Compliance with Access to Information requests
- What right does the public have to know?
- Access to information system too often a barrier to transparency:Newspaper group
- 2007 FREEDOM OF INFORMATION AUDIT
The National Freedom of Information Audit conducted by the Canadian Newspaper Association concluded:
Eritrea ranked last for first time while G8 members, except Russia, recover lost ground
A G8 member other than Russia also lost ground: Canada. In this year's survey Canada ranks 18th with a score of 4,88 while in 2006 Canada ranked 16th with a score of 4,50. While it may only be a small dip, it is a slide nonetheless. As Canadian it is embarrassing and I want to highlight three trends that I see:
1) Government Surveillance of Journalists
Last September it was revealed that the names of journalists who had filed Access To Information as well as the content of their requests were being discussed on conference calls and circulated to the Prime Minister's Office as well the the departments who were the target of the forthcoming article. In this particular case it was a reporter who had asked for information regarding the landing of CIA planes in Canada:
During that call, and minutes of others like it obtained by The Gazette, officials freely discuss media requests for information their departments have received. They also exchange information on who intends to submit a request and who is about receive documents under the access law.
"Noted there will shortly be another Bronskill/CIA Planes article, as new ATIP info is going out from PSEP," the public safety and emergency preparedness department reported. "The info essentially reiterates that normal procedures were followed and nothing abnormal was discovered."
2) A "Controlled" Press Centre
Although it was shelved upon becoming public the Prime Minister's plan to build a new press centre has serious negative consequences for journalism in Canada. Annoyed with the questions asked by journalists the Prime Minister sought to have his staff select which reporters could ask questions but was refused so he resurrected the Liberal's plan to build a new media centre in which his staff would control who asked questions. The ability to manipulate and control what questions are asked is a serious threat to democracy. As The Star notes: "If reporters can't freely question political leaders, press freedom is diminished, and so is democracy."
3) Media Consolidation
AdBusters reports that "just four corporations now control 70 percent of the country’s newspaper circulation" and my hometown, Vancouver, is the worst in the country. In Vancouver one company owns "70 percent of the entire media market and is the only voice of record for the city."
[CanWest] now owns both of Vancouver’s daily newspapers (the Sun and the tabloid Province), the city’s top-rated television station (GlobalTV), 12 community newspapers, eight analog and digital television stations, and one of two national papers. For good measure, it also owns the only daily in the nearby provincial capital, Victoria’s Times Colonist.
- Feds must examine Irving media empire: Fraser
- Media consolidation continues as Quebecor buys Osprey
- Media consolidation
UPDATED: Nov, 10, 2007
4) Non-Compliance with Access to Information requests
- What right does the public have to know?
- Access to information system too often a barrier to transparency:Newspaper group
- 2007 FREEDOM OF INFORMATION AUDIT
The National Freedom of Information Audit conducted by the Canadian Newspaper Association concluded:
Clearly, most Canadian jurisdictions continue to demonstrate confusion, inconsistency and a flawed understanding of the importance of transparency to the democratic system and how access to information rights are a public right that underpins the transparency principle.
Monday, October 22, 2007
Canada: What Questions Get Asked?
The Toronto Star has an article about the free speech ramifications of the now shelved plan to build a new press centre in which the Prime Minister would get to choose which reports -- which questions -- would be asked. (The Liberals under Martin tried to do this too).
The background: Shortly after he was elected Prime Minister, Stephen Harper tried to change the rules for press conferences at the National Press Theatre in Ottawa, which is controlled by the press gallery. He insisted that his staff be allowed to choose which reporters could ask him questions, instead of the reporters themselves deciding.
... the Prime Minister's Office asked civil servants to draw up a $2 million plan to renovate a vacant shoe store in downtown Ottawa into a new press conference centre, this one to be controlled by the Prime Minister. The plan has been shelved, at least for now.
This is the system used by the president of the United States – and many other countries. It is a bad one, and here's why. The real issue is not who gets to ask questions, but what questions get asked. If Canada adopts the U.S. style, the Prime Minister will be able to call on friendly reporters and avoid reporters who ask difficult, necessary questions.
Saturday, October 20, 2007
The GFW of Comcast?
There have been a number of recent reports stating that Comcast is interfering with file-sharing traffic including BitTorent, Gnutella, and Lotus Notes. The reports state that the technique used is the TCP RST packet technique that the GFW of China has made (in)famous. (An intermediary send RST packets to both ends of a connection, effectively terminating it. For more technical info see Ignoring the Great Firewall and ConceptDoppler.)
Interesting.
Interesting.
The geopolitical stakes of 'Saffron Revolution'
Asia Times Online has an interesting article on the 'Saffron Revolution':
In fact the US State Department admits to supporting the activities of the NED in Myanmar. The NED is a US government-funded "private" entity whose activities are designed to support US foreign policy objectives, doing today what the CIA did during the Cold War. As well, the NED funds Soros' Open Society Institute in fostering regime change in Myanmar. In an October 30, 2003 press release the State Department admitted, "The United States also supports organizations such as the National Endowment for Democracy, the Open Society Institute and Internews, working inside and outside the region on a broad range of democracy promotion activities." It all sounds very self-effacing and noble of the State Department. Is it though?
In reality the US State Department has recruited and trained key opposition leaders from numerous anti-government organizations in Myanmar. It has poured the relatively huge sum (for Myanmar) of more than $2.5 million annually into NED activities in promoting regime change in Myanmar since at least 2003. The US regime change effort, its Saffron Revolution, is being largely run, according to informed reports, out of the US Consulate General in bordering Chaing Mai, Thailand. There activists are recruited and trained, in some cases directly in the US, before being sent back to organize inside Myanmar. The US's NED admits to funding key opposition media including the New Era Journal, Irrawaddy and the Democratic Voice of Burma radio.
Thursday, October 11, 2007
China: Media Shift
US-made 'censorware' ends up in iron fists
CS Monitor reports:
The software companies involved sell this technology primarily to private companies in the US and abroad. Companies use these tools to keep employees from accessing pornography sites and websites infected with viruses.
Repressive governments also turn to these American systems, not only to filter out porn and viruses, but also to block political, religious, and other websites.
AT&T Retracts Censor Clause
AT&T has retracted a censorship clause in their ToS which allowed them to "pull the plug" on anything that "tends to damage the name or reputation of AT&T, or its parents, affiliates and subsidiaries." They've now amended the ToS to say:
5.1 Suspension/Termination. AT&T respects freedom of expression and believes it is a foundation of our free society to express differing points of view. AT&T will not terminate, disconnect or suspend service because of the views you or we express on public policy matters, political issues or political campaigns.
BYPASSING CENSORSHIP
The Citizen Lab has released "Everyone's Guide to Bypassing Internet Censorship (pdf)". It was a team effort to produce the guide and I'm very pleased to have contributed to it. I've long argued that users can benefit from circumvention technology the most when the carefully select the technology that meets their specific needs. The guide walks users through the process of assessing their needs and and capabilities and lists clusters of circumvention technology options for users to choose from.
Wednesday, October 10, 2007
Syria: Censorship Concerns
The Angry Arab reports:
(The Arabic article is available here.)
Al-Akhbar newspaper has decided to stop distributing the paper in Syria due to censorship and irregularities from the Syrian government.
(The Arabic article is available here.)
Child Protection Online
The Privacy Commission's blog has an interesting post about the protection of children online. The context is in terms of privacy and not the usual implementation of filtering technologies.
It is interesting because all these sites would not be blocked by filtering software (ostensibly implemented to block pornography etc...) because they are kids sites. It not only demonstrates that throwing technology at a social problem will not "fix" it as well as need for parents and children to communicate and educate themselves about Internet safety.
There are increasingly deep levels of intimacy between marketers and children – there’s a thin line between content and commerce
All the major children’s playsites comply with data protection laws – in fact they all market themselves as champions of children’s privacy
In these children’s sites, the pervasive market research invades privacy – seamless surveillance – colonizing their play – constraining the identities available to them – recasting things like citizenship, friendship, autonomy, choice and control within the framework of the marketplace
It is interesting because all these sites would not be blocked by filtering software (ostensibly implemented to block pornography etc...) because they are kids sites. It not only demonstrates that throwing technology at a social problem will not "fix" it as well as need for parents and children to communicate and educate themselves about Internet safety.
Privacy Commissioner Investigates Harper
The Edmonton Sun reports:
How did the Prime Minister get a list of Jewish constituents?
The federal privacy commissioner is examining a public complaint over greeting cards sent from the Prime Minister's Office specifically to Jewish constituents.
Several recipients have reportedly questioned whether the Prime Minister's Office used government data to pinpoint Jewish residents.
How did the Prime Minister get a list of Jewish constituents?
Canadians deserve better ISP transparency
Michael Geist writes about the lack of transparency surround the traffic shaping conducted by Canadian ISPs. A recent survey found that most Canadians are unaware of net neutrality issues but support net neutrality principles when informed.
Most Canadians can hardly be faulted for being unaware of the issue since ISPs have done their best to keep it off the radar screen. While solving the Net neutrality issue will not happen overnight, addressing the lack of transparency associated with Internet services would go a long way toward creating a more informed debate.
Monday, October 8, 2007
China not blocking RSS/Feeds
EDIT: the focus here is on the fact that China is not dynamically blocking ALL RSS Feeds, however, feeds hosted on already blocked sites are, of course, also blocked.
This article claims that RSS feeds are being blocked in China.
I've tested and they are not blocked.
As Danwei points out "Ars Technica feed are inaccessible in China because it is run through Feedburner's server (feeds.feedburner.com), which is blocked."
GV Advocacy has a nice round-up here.
This article claims that RSS feeds are being blocked in China.
More recent reports tell us that the PSB appears to have extended this block to all incoming URLs that begin with "feeds," "rss," and "blog," thus rendering the RSS feeds from many sites—including ones that aren't blocked in China, such as Ars Technica—useless.
I've tested and they are not blocked.
As Danwei points out "Ars Technica feed are inaccessible in China because it is run through Feedburner's server (feeds.feedburner.com), which is blocked."
GV Advocacy has a nice round-up here.
Sunday, October 7, 2007
"Cyber Jihadist" Trial
The trial of a man accused of "virtual jihad" is about to start in Germany, reports dw-world.de. The case will focus on whether the (re) posting of audio and video files on the Internet along with the occasion appeal for jihad constitutes "attempting to recruit members" for terrorist organizations.
"It's an important trial because it will shed light on whether what happens in closed chat groups on the Internet falls under freedom of expression or whether you can penalize it if there's proof of planned attacks," said Carstensen.[press spokesman for Germany's criminal investigators' union (BdK) ]
Wednesday, October 3, 2007
Plan to tighten identity theft laws
The Toronto Star reports that the Canadian government plans to tighten up efforts to fight identity theft by adding amendments to the Criminal Code:
Always read the fine print.
Justice Minister Rob Nicholson was short on details on the severity of the amendments but said sharpening the Criminal Code will give police better tools to combat the rapidly growing theft trend that is constantly growing thanks to technology.
Always read the fine print.
EU Wants to block searches for "bomb"
"I do intend to carry out a clear exploring exercise with the private sector ... on how it is possible to use technology to prevent people from using or searching dangerous words like bomb, kill, genocide or terrorism," Frattini told Reuters.
Wow.
Searching for such words brings up quite a number of non-bomb-making-instruction sites, forcing search engines to not allow searches for such generic terms is ridiculous. The top results for a Google search for "genocide" for example returns a Wikipedia entry, a site dedicated to stopping genocide in Darfur among others. That much is obvious.
Perhaps EU Justice and Security Commissioner Franco Frattini meant that specific sites, such as sites with instructions on how to make a bomb, should be removed from search engines. In this scenario it is not that a user cannot search for the word "bomb" but if such a designated web site were to appear in the results it would not be shown to the user. This is what is already done by search engines in regard to copyright violations, hate speech, libel/defamation an any other "legal" request (such as news & politics websites that the Chinese government deems illegal). It would be fairly simple for the EU to request that search engines de-list certain sites, but of course, this comes with all the baggage of filtering systems (over-blocking, under-blocking & circumvention).
The above concerns aside the proposal is actually even more misguided. It assumes that search engines are the only way to access information. Such a policy would not take into account direct access to such sites, links fro other sites, especially forums, chat rooms, IM's and so on. It is a shortsighted policy that appears to be mostly for show in the same vein as Seth Finkelstein argues about the deployment of censorware:
...governments end up giving money to these companies for the political benefits of being able to Do Something About The Problem (no matter the flaws).
The "wanting to do something" sentiment appears strong in this case as does the lack of careful consideration.
Labels:
Free Expression,
Internet Censorship,
Search Engines
Spy planes used for surveillance
The Guardian reports that "intelligence agencies are using military aircraft equipped with sophisticated surveillance equipment to eavesdrop on and monitor the movements of suspected terrorists" by flying over cities in the U.K. The plane is thought to be equipped with technology to monitor telephone calls and automatically recognize license plate numbers. The plane's have also been used by police to "identify people speeding, driving when using mobile phones, overtaking on double white lines, or driving erratically."
Saturday, September 29, 2007
Legal Threats and Takedowns
EFF reports that two blogs that posted information about Uzbek billionaire Alisher Usmanov were shut down after legal threats were sent to their hosting companies.
Lawyers representing Usmanov contacted the blogs' webhost, Fasthosts, and after threats to sue under Britain's expansive libel laws, the blogs were removed. The sites included Tim Ireland's popular "Bloggerheads" site, and site of Craig Murray, the ex-Ambassador for Uzbekistan. Murray's hosting provider even intervened to take down individual entries and alter the text of Murray's blog to avoid further legal action.
Myanmar/Burma
Media coverage of Internet censorship is usually framed through one of two lenses: The "1984" approach overstates censorship capabilities claiming that legions of internet police monitor everything in "real time" and are just one kick away if you make the wrong click. The "technoptimist" approach understates censorship capabilities and claims that circumvention technology is proliferating and the internet is a democracy-battering-ram chipping away at the crumbling walls of oppressive regimes.
Recent coverage of the protests in Myanmar/Burma have generally been falling into the latter camp. Noting that, according to ONI, Myanmar/Burma has one of the most restrictive Internet filtering systems in place this article wonders why information about the protests is getting out. It claims that "the cyber-reality in Myanmar is actually much less restricted than ONI's research indicated" because circumvention technologies are available to citizens.
Filtering technologies seek to keep citizens inside Myanmar/Burma from have access to sites hosted outside -- it does not say much about keeping information from moving in the opposite direction. Why? Because sites are filtered when they are contextually important, become well known, and/or can reach a large audience. For information to flow from a few to these sites if far harder to control than the information from these few sites to the many.
Similarly, while there are censorship circumvention technologies readily available these are used by the few not the many for a variety of reasons including fear of being caught, lack of technical ability, or just now knowing (or caring) about them.
Internet censorship regimes, such as Myanmar/Burma's, are effective not because they can filter out all the content they want but because their filtering systems are backed up by other forms of repression that force users into a condition of self-censorship where they will not seek out banned content (the filter is just a reminder) let alone seek to violate their countries laws and put themselves at risk by using circumvention technologies.
So the reality is actually somewhere in between. While the majority are kept in line by the filtering matrix, there is a still resistance. Determined Internet users can use a variety of methods to bypass censorship while others speak out publicly and risk repression. All of this slowly widens the scope of accepted speech within these confined spaces -- not cataclysmic event.
Recent coverage of the protests in Myanmar/Burma have generally been falling into the latter camp. Noting that, according to ONI, Myanmar/Burma has one of the most restrictive Internet filtering systems in place this article wonders why information about the protests is getting out. It claims that "the cyber-reality in Myanmar is actually much less restricted than ONI's research indicated" because circumvention technologies are available to citizens.
Filtering technologies seek to keep citizens inside Myanmar/Burma from have access to sites hosted outside -- it does not say much about keeping information from moving in the opposite direction. Why? Because sites are filtered when they are contextually important, become well known, and/or can reach a large audience. For information to flow from a few to these sites if far harder to control than the information from these few sites to the many.
Similarly, while there are censorship circumvention technologies readily available these are used by the few not the many for a variety of reasons including fear of being caught, lack of technical ability, or just now knowing (or caring) about them.
Internet censorship regimes, such as Myanmar/Burma's, are effective not because they can filter out all the content they want but because their filtering systems are backed up by other forms of repression that force users into a condition of self-censorship where they will not seek out banned content (the filter is just a reminder) let alone seek to violate their countries laws and put themselves at risk by using circumvention technologies.
So the reality is actually somewhere in between. While the majority are kept in line by the filtering matrix, there is a still resistance. Determined Internet users can use a variety of methods to bypass censorship while others speak out publicly and risk repression. All of this slowly widens the scope of accepted speech within these confined spaces -- not cataclysmic event.
Labels:
Circumvention,
Free Expression,
Internet Censorship
Wednesday, September 12, 2007
Cyber-Cafe Monitoring in India
It is being reported that Mumbai police are looking into installing monitoring software -- including a keystroke logger -- to catch terrorists who use the Internet in cyber-cafe's.
The Mumbai police are in dialogue with M/s Micro Technologies for procuring a software called CARMS (Cyber Access Remote Monitoring System), a powerful monitoring tool that seeks to curb cyber crime. CARMS monitors web browsing, file transfers, news, chats, messaging and e-mail, including all encoded attachments..
All cyber cafes in the city will now need a police license to keep their business going. All cafes need to register at the police headquarters and provide details on the number of computers installed, type of computers and technical details like the IP address of each machine.
Judge orders removal of rant on YouTube
Stan Hall was angry at his lawyer and posted a rant about it on YouTube. An Ontario judge has ruled that the video must be removed:
When accessing two videos that were uploaded under the username "stanhalll" YouTube displays the message "This video has been removed by the user." however, the text description of the messages remains:
Superior Court Justice William Jenkins reviewed the computer postings.
"I find that it includes unproven allegations that Mr. Ledroit and his law firm are incompetent and dishonest," Jenkins said in his decision.
Jenkins ruled the postings would cause lawyer Paul Ledroit and his law firm "significant and irreparable damage" if left for public viewing.
When accessing two videos that were uploaded under the username "stanhalll" YouTube displays the message "This video has been removed by the user." however, the text description of the messages remains:
It's like David and Gollieth. I will not stop I will not give up as long as I am alive. I lost everyting that meant anyting to me in my life, it is gone, and Paul Ledroit was hired to help us, but all he did was help himself to a huge legal bill
Paul Ledroit is now suing me, Why because he has the man power to do it and becuase he wants to scare me, to intimadate me, He wont scare me nor will he intiminedate me. The truth shall set you free I dont' care how much money he has freedom of speech is what I am after
Tuesday, September 11, 2007
Avoidable Risk
Not fully understanding or improperly using applications that protect your privacy and allow you to bypass censorship can seriously affect your online security. A researcher recently revealed that he was able to gather sensitive data including the user names and passwords of government email accounts by snooping on the traffic of five Tor exit nodes he controlled. If you are not using end to end encryption the Tor exit node can see your traffic in plain text. as the researcher notes:
This reminds me of the "trick" a lot of people use in which they set up an email account but don't actually send email but rather just store email in the drafts folder thinking that this protects them from government surveillance. Unless the full session is encrypted, and many using this technique are using web mail account which only encrypt the login not the rest of the traffic, it can still be snooped even though you are not "sending" the email.
ToR isn’t the problem, just use it for what it’s made for.
This reminds me of the "trick" a lot of people use in which they set up an email account but don't actually send email but rather just store email in the drafts folder thinking that this protects them from government surveillance. Unless the full session is encrypted, and many using this technique are using web mail account which only encrypt the login not the rest of the traffic, it can still be snooped even though you are not "sending" the email.
Saturday, September 8, 2007
Caught in the throttle
The Ottawa Business Journal is reporting that Canadian ISP's are "throttling" or "traffic shaping" in order to prioritize traffic. The primary target is actually to degrade performance for bittorrent traffic.
In response users have begun to encrypt their bittorrent traffic so that it is not easily distinguishable from other traffic so Rogers has reportedly begun "to simply degrade all encrypted traffic, legal or not."
In Canada, Rogers and Shaw in Vancouver have responded by reducing the high speed of users downloading and uploading (or seeding) torrents. Rogers admitted to what it called "prioritizing" "real-time use" such as surfing and e-mail transfers ahead of large file transfers in a December 2005 article in the Globe and Mail.
In response users have begun to encrypt their bittorrent traffic so that it is not easily distinguishable from other traffic so Rogers has reportedly begun "to simply degrade all encrypted traffic, legal or not."
Friday, September 7, 2007
Canada imposters crash APEC
An Australian comedy group impersonated the Canadian delegation to APEC and managed to drive their motorcade into a restricted area before they were arrested:
Eleven of the pretend Canadians -- all cast or crew from the satirical Australian television show The Chaser's War on Everything, including one comic in an Osama bin Laden get-up -- were eventually stopped and arrested under special security laws adopted in advance of the week-long Asia-Pacific summit.
Tuesday, September 4, 2007
Thailand: YouTube Ban Lifted
Thailand has decided to lift the ban on YouTube after Google agreed to "filter" videos that insult the King.
The Southeast Asian Press Alliance (SEAPA) criticized the collaboration between Google and the government to censor YouTube:
Information and Communications Technology Minister Sitthichai Pookaiyaudom this week instructed the website ban be lifted after YouTube owner Google installed filters to stop Thais from accessing clips insulting the 79-year-old monarch, a ministry official said.
The Southeast Asian Press Alliance (SEAPA) criticized the collaboration between Google and the government to censor YouTube:
"Any such collusion could potentially be open for abuse, and thereby only exacerbate concerns over free speech over the internet," SEAPA said.
"The cooperation between Google/YouTube and the Thai government could conceivably become a template sought by other governments that have had run-ins with sensitive content on the video-sharing site," it said.
Saturday, September 1, 2007
Immunity for Telecoms
The Bush Administration is seeking to shield telecom's that participated in its illegal wiretapping scheme from privacy law suits being brought forward against them. However, they do not want to name the dozen or so companies involved. AP reports:
The article also hints at the scope of the surveillance, not just covering telephone calls but email traffic as well:
The vaguely worded proposal would shield any person who allegedly provided information, infrastructure or "any other form of assistance" to the intelligence agencies after the Sept. 11, 2001 terror attacks. It covers any classified communications activity intended to protect the country from terrorism.
The article also hints at the scope of the surveillance, not just covering telephone calls but email traffic as well:
Conventional wisdom has long been that the bulk of the surveillance operations — groundbreaking because they lacked judicial oversight — involved primarily telephone calls. However, officials say the Bush administration's program frequently went after e-mail and other Internet traffic, which al-Qaida has embraced as a key means of communication.
Thursday, August 30, 2007
China's Web Police

It appears that "Jingjing" and "Chacha" are being brought to Beijing. Two "virtual cops" will be appearing on users screen when they visit major news portal such a sohu and sina and warn them about illegal content. User's can click the images and be redirected to the police website "where they can report illegal activities and harmful information".
Dong Lin, chief technology officer of Xirang, a Beijing-based hosting service provider, said police have mobilized all forces, from China Netcom, the country's second largest fixed-line operator, to information security companies such as Symantec, to jointly combat online harmful information.
That's right, its says Symantec.
It seems that AP's report missed that detail and also stated that users can click the police images if they need "help" while Xinhua makes it clear the intent is to get users to report information to the police. The AP article also does not mention Symantec.
CENTCOM's blog team.
It seems that I missed this article from 2006. The article discusses the creation of CENTCOM's blog team.
The blog team also contacts or comments on blogs to correct "inaccurate or untrue information" or provide addition information for "incomplete" blog entries.
The team's motto is "Engage," and Flowers and others work with more than 250 bloggers to try to disseminate news about the good work being done by U.S. forces in the global war on terror.
The blog team also contacts or comments on blogs to correct "inaccurate or untrue information" or provide addition information for "incomplete" blog entries.
A waste of everyone's time and money?
A column in The Guardian asks if web filters are just a waste of everyone's time and money and a 16 year old Australian cracked the countries filtering software. Rather than implement a national firewall-type filtering system Australia makes filtering software available for free hoping that parents will restrict what their children can view online.
Which raises the question: wouldn't traditional parenting skills - such as talking to your children and teaching them about safe searching and surfing and being honest about sex and internet content - be a lot more effective, better-tailored and cheaper than huge government initiatives?
Wednesday, August 29, 2007
Yahoo! wants suit dismissed
A suit against Yahoo was filed in the U.S. on behalf of Chinese dissidents who were imprisoned based on convictions in which Yahoo! provided some evidence. Yahoo! is now seeking to have the suit dismissed. Rebecca has posted the full legal documents of the case.
State Secrets
China isn't the only one hiding behind "state secrets", it is now the defense in the law suit brought on by EFF on behalf of AT&T customers who were victims of illegal NSA spying.
EFF is representing the plaintiffs in Hepting v. AT&T, a class-action lawsuit brought by AT&T customers accusing the giant telco of violating their rights by illegally assisting the National Security Agency in domestic surveillance. The U.S. government is fighting to get the class-action lawsuit thrown out of court, contending that the litigation jeopardizes state secrets.
"The courts cannot permit the government to evade responsibility for unconstitutional activities with thin claims of 'state secrets.' Without judicial review, there is no way to stop abuses of power," said EFF Legal Director Cindy Cohn. "The courts are well equipped to protect state secrets while determining whether the spying is illegal and if so, to put a stop to it."
DCSNet
Wired reports that the FBI has created DCSNet, "a comprehensive wiretap system that intercepts wire-line phones, cellular phones, SMS and push-to-talk systems". Agents can remotely begin tapping communications and send the data for translation and link analysis. DCSNet leverages CALEA compliant technology that mandates FBI backdoors in telephone switching equipment. The FBI is now targeting communications tools such as Skype.
Tuesday, August 28, 2007
Target: Wordpress
wordpress.com -- a blog hosting service which hosts nearly 1.4 million blogs -- is now blocked in Turkey and Thailand.

Wholesale blocking of blog hosting services is unfortunately becoming more common place. Ethiopia, Pakistan, Iran, Syria and China block all of blogspot, for example, and India, Tunisia and UAE selectively block some blogspot blogs.

Wholesale blocking of blog hosting services is unfortunately becoming more common place. Ethiopia, Pakistan, Iran, Syria and China block all of blogspot, for example, and India, Tunisia and UAE selectively block some blogspot blogs.
U.S. Suspends Data Mining Program
The U.S., which has the most sophisticated electronic surveillance program in the world, has suspended yet another program, ADVISE (Analysis, Dissemination, Visualization, Insight and Semantic Enhancement), after it was found to violate privacy laws. The CMS which uncovered the program in 2006, reports:
This is the third shutdown following the closure of the Pentagon's TALON database -- which monitored peace activists among others -- and the infamous Total Information Awareness project.
From its earliest days, the system's pilot programs used "live data, including personally identifiable information, from multiple sources in attempts to identify potential terrorist activity," but without taking steps required by federal law and DHS's own internal guidelines to keep that data from being misused, the DHS Office of Inspector General (OIG) said in a June report to Congress, which was made public Aug. 13.
This is the third shutdown following the closure of the Pentagon's TALON database -- which monitored peace activists among others -- and the infamous Total Information Awareness project.
Monday, August 27, 2007
Agents Provocateurs
Faced with video uploaded to YouTube the Sûreté du Québec have been forced to admit that they infiltrated the protest the summit in Montebello. Armed with rocks the fake protesters pushed their way to the police line and were confronted and uncovered by peaceful protesters. The SPP have now promised, after initial resistance, to conduct a review of its practices.
Wednesday, August 15, 2007
Red Flags
The legal notice that resulted in the deletion of some of Hossein Derakhshan's blog posts by his hosting company and lead to the termination of his blog's hosting service should raise red flags within the Anti-Censorship community.
First, the notice claims that in addition to Hossein, both the domain Registrar and the web hosting company are implicated in and/or liable for activities conducted on Hossein's blog.
In fact the notice seems to imply that each of the three named in the notice (the registrar, the hosting company and Hossein) "published" defamatory information.
Secondly, the notice asks for the IP addresses of everyone who visited the websites of Hossein.
Clarification by any lawyers out there would be appreciated, but to me the first seems to be clearly misguided. Holding a registrar responsible for the content hosted at a domain name?
On the second, I feel that this presents a grave privacy concern. Handing over the IP addresses of the visitors to Hossein's blog? I fail to see how that is related to the alleged defamatory claims.
First, the notice claims that in addition to Hossein, both the domain Registrar and the web hosting company are implicated in and/or liable for activities conducted on Hossein's blog.
In fact the notice seems to imply that each of the three named in the notice (the registrar, the hosting company and Hossein) "published" defamatory information.
Secondly, the notice asks for the IP addresses of everyone who visited the websites of Hossein.
Clarification by any lawyers out there would be appreciated, but to me the first seems to be clearly misguided. Holding a registrar responsible for the content hosted at a domain name?
On the second, I feel that this presents a grave privacy concern. Handing over the IP addresses of the visitors to Hossein's blog? I fail to see how that is related to the alleged defamatory claims.
Tuesday, August 14, 2007
Chilling Effects
The use of legal threats is not unique to hoder's case. Libel and defamation are being used to silence critics around the world. Fresh from GV Advocacy:
Monaco: webmaster accused of defaming the Head of State
... the owner of a new satirical website, featuring cartoons allegedly defaming and ridiculing the Prince...
Tunisia: online writer freed and website editor to appear in court
...the editor of the online news website Kalima (censured in Tunisia) Omar Mestiri is facing a libel suit...
Monaco: webmaster accused of defaming the Head of State
... the owner of a new satirical website, featuring cartoons allegedly defaming and ridiculing the Prince...
Tunisia: online writer freed and website editor to appear in court
...the editor of the online news website Kalima (censured in Tunisia) Omar Mestiri is facing a libel suit...
Monday, August 13, 2007
Censored in Iran, Deleted in USA
The blocking of websites by national filtering systems make content unavailable to those in such countries, but the deletion of content makes it unavailable to all. The blog of my friend Hossein was recently shutdown due to legal threats, making it unavailable to all while it was previously only censored in Iran.
(Hossein's update on the situation follows below.)
Threatening ISP's with "take down" requests is one of the most undocumented methods of censoring Internet content. Some sites, such as ChillingEffects document this to some degree but most cases occur in silence. Since much of it is related to copyright violations or terrorism few are paying close attention. Libel and defamation cases are more notable especially the cases in Malaysia and Singapore.
While it is possible to detect and monitor censorship via internet filtering, as I do for the OpenNet Initiative, it is much more difficult to enumerate content that is simply removed by service providers.
(Hossein's update on the situation follows below.)
Threatening ISP's with "take down" requests is one of the most undocumented methods of censoring Internet content. Some sites, such as ChillingEffects document this to some degree but most cases occur in silence. Since much of it is related to copyright violations or terrorism few are paying close attention. Libel and defamation cases are more notable especially the cases in Malaysia and Singapore.
While it is possible to detect and monitor censorship via internet filtering, as I do for the OpenNet Initiative, it is much more difficult to enumerate content that is simply removed by service providers.
Thursday, August 9, 2007
Media Lens
There are two primary "filters" the colour media coverage on Internet censorship in China: the "1984" and the "technoptimist". I wrote about this a while back
Recently there's been a cluster of "technoptimist" articles:
As the Olympics draw near, the tone will likely shift.
Recently there's been a cluster of "technoptimist" articles:
- China trembles at the power of the blog
- Censors powerless against the Net
- Web censorship is failing, says Chinese official
As the Olympics draw near, the tone will likely shift.
Tuesday, July 24, 2007
Photo Filtering
UPDATE: photobucket responded to my email and restored the censored photo. They did not answer my questions, but simply stated that the image was removed in error.
Recently the filtering system of flickr has been receiving a lot of attention. flickr has enabled regional (Singapore, Hong Kong, Korea, Germany) filtering policies that restrict access to different photos based on a users' geolocation. Earlier today I was browsing through my family photos in my photobucket account when I noticed that one of my photos had been censored.
This photo of me and my daughter at the Toronto Blues Festival

has been replaced with

I've emailed photobucket asking for an explanation. From the FAQ it appears that they actually delete the photos found (by a software or a human?) to be in violation of their terms of use. That may explain why there appears to be no "appeals" or review process. Also, there was no notification of any kind or any reason given as to why the photo violated the terms of use. I am hoping that photobucket gets back to me with some answers to my questions.
Recently the filtering system of flickr has been receiving a lot of attention. flickr has enabled regional (Singapore, Hong Kong, Korea, Germany) filtering policies that restrict access to different photos based on a users' geolocation. Earlier today I was browsing through my family photos in my photobucket account when I noticed that one of my photos had been censored.
This photo of me and my daughter at the Toronto Blues Festival
has been replaced with

I've emailed photobucket asking for an explanation. From the FAQ it appears that they actually delete the photos found (by a software or a human?) to be in violation of their terms of use. That may explain why there appears to be no "appeals" or review process. Also, there was no notification of any kind or any reason given as to why the photo violated the terms of use. I am hoping that photobucket gets back to me with some answers to my questions.
Wednesday, July 11, 2007
Badware Hosting Companies
Following some POC analysis, stopbadware.org issued a press release of analysis of the badware URLs in their database.
IPowerWeb responded positively and "has located and removed badware-distributing code from thousands of its sites".
StopBadware.org analyzed 49,296 sites - sites submitted by trusted third parties to the StopBadware.org Badware Website Clearinghouse - and identified the following web hosting companies with the largest number of infected sites residing on their servers:
* iPowerWeb, Inc., (10,834)
* Layered Technologies, (2,513)
* ThePlanet.com Internet Services, Inc, (2,056)
* Internap Network Services, (1,437)
* CHINANET Guangdong province network, (786)
IPowerWeb responded positively and "has located and removed badware-distributing code from thousands of its sites".
Tuesday, July 10, 2007
DNS tampering in China
So, I was doing some searching in google and baidu and noticed two sites (that appeared to be the same) voanews.cn and voanews.com.cn. Upon visiting voanews.com.cn I was surprised to find myself end up at google. voanews.com.cn, like voanews.cn should resolve to 218.25.59.214, not google.
The other thing that stood out was that these sites did not appear to be the Voice of America. And they are not. You can lookup the registrar here. The Registrant Name is 慢速英语 which babel translates as "Slow English" which gave me a chuckle.
I did some more tweaking and voanews.com.cn is being subjected to a form of DNS tampering because it has "voanews.com" in it. It looks like China is bringing back an improved version of their old DNS spoofing. Rather than messing around with individual DNS servers, China has implemented a system which appears to operate like the RST/Keyword filtering system (see this paper for technical details).
DNS lookups for voanews.com (or voanews.com.cn) will return one or more of the following 4 IP's:
The last two by the way are google IP addresses. Weird.
But if you sniff the connection you'll see that what happens is after the request is made 4 spoofed results are received although eventually the correct result is received. But by the time the true result is received applications relying on a dns lookup (e.g. a web browser) have already accepted the initial spoofed result.
A variety of other domain names are affected, not just voanews.com.
The other thing that stood out was that these sites did not appear to be the Voice of America. And they are not. You can lookup the registrar here. The Registrant Name is 慢速英语 which babel translates as "Slow English" which gave me a chuckle.
I did some more tweaking and voanews.com.cn is being subjected to a form of DNS tampering because it has "voanews.com" in it. It looks like China is bringing back an improved version of their old DNS spoofing. Rather than messing around with individual DNS servers, China has implemented a system which appears to operate like the RST/Keyword filtering system (see this paper for technical details).
DNS lookups for voanews.com (or voanews.com.cn) will return one or more of the following 4 IP's:
voanews.com has address 213.169.251.35
voanews.com has address 209.36.73.33
voanews.com has address 72.14.205.99
voanews.com has address 72.14.205.104The last two by the way are google IP addresses. Weird.
But if you sniff the connection you'll see that what happens is after the request is made 4 spoofed results are received although eventually the correct result is received. But by the time the true result is received applications relying on a dns lookup (e.g. a web browser) have already accepted the initial spoofed result.
ME -> CN DNS Standard query ANY voanews.com
CN -> ME DNS Standard query response A 72.14.205.99
...
CN -> ME DNS Standard query response SOA auth00.ns.uu.net MX 20 ibb2.ibb.gov MX 30 ibb1.ibb.gov MX 10 voa2.voa.gov A 128.11.143.113 NS auth00.ns.uu.net NS auth100.ns.uu.net
Domain Name System (response)
voanews.com: type SOA, class IN, mname auth00.ns.uu.net
voanews.com: type MX, class IN, preference 20, mx ibb2.ibb.gov
voanews.com: type MX, class IN, preference 30, mx ibb1.ibb.gov
voanews.com: type MX, class IN, preference 10, mx voa2.voa.gov
voanews.com: type A, class IN, addr 128.11.143.113
voanews.com: type NS, class IN, ns auth00.ns.uu.net
voanews.com: type NS, class IN, ns auth100.ns.uu.net
ME -> CN ICMP Destination unreachable (Port unreachable)
A variety of other domain names are affected, not just voanews.com.
Thursday, June 28, 2007
".yahoo.com" briefly blocked in China
For the most part* the GFW blocks in two ways:
1) IP blocking
2) Keyword in url blocking
IP blocking is pretty easy to spot, traceroute will fail at the backbone level in China, and there will only be outgoing syn packets to the IP, the 3-way tcp handshake will never be established. (Note: all domains hosted on that IP are affected).
"Keyword-in-URL" blocking is different and sometime s a bit awkward. First, the keyword-in-url filtering is bi-direction so you can trigger it from outside -> to -> China or from China -> to -> outside.
Second, "keywords" can be domains themselves, I've even seen URLs used as a "keyword". If these keywords appear in the HTTP Host header or in the GET request they will be "blocked".
Third, the way the blocking works is that the 3-way TCP handshake will be established but when the GET request goes through the GFW sends RST packets to both the requester and the host (spoofed to appear as if they were from one another) to tear down the connection then host and the requester respond to each other with more RST packets. (There is some additional variation, but thats the basic version, see Steven Murdoch et al's paper http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf for more details).
The tricky part is that depending on the GFW (maybe related to the load) some of the transaction will go through. So for example, you may get half (or more!) of the html before the RST packet. Also, part of the page may load because, for example, it is not until an image with a keyword in its file name is loaded that the RST packet is sent.
Finally, the most tricky part. Because of the combination of additional RST packets from the GFW (and then the RST from the requester and host in response) further connections between the requester and host (not the internet as often reported) are disrupted for sometime. This means that if you are in China and you connect to Google (hosted outside of China) and you search for a banned keyword (the keyword goes into the GET request) you'll be blocked. If you hit the back button in your browser and get the cached copy of Google and then search for a NOT blocked keyword it will appear to be blocked because your connection to Google is still being subjected to RST packets. This sometimes results in reports that certain keywords are blocked when in fact they are not.
Another important point to recognize is that this is dependant upon IP address. So, if the site you connect to has multiple IP addresses the behaviour may seem even more consistent and you requests may be being server by different IP addresses. For testing purposes it is best to connect directly to an IP rather than a domain name to ensure that you are always connecting to the same IP.
On June 27 2007, I captured traffic between myself and yahoo.cn (hosted in China, as well as some other hosts in China) using ".yahoo.com" (yes, that starts with a period, e.g. if affects all *.yahoo.com domains including mail.yahoo.com) and can confirm that it was subjected to the "keyword-in-url" blocking behaviour with ".yahoo.com" as the keyword.

However, and this is my opinion, the RST packet were quite slow to respond. In some cases the RST did not come until after the page loaded successfully (future connection were subjected to RST's). It is possible that many requests for ".yahoo.com" were causing the GFW to slow down, anecdotaly the RST packets were not being received as fast as they usually are.
On June 28 2007".yahoo.com" is no longer blocked by China.
1) IP blocking
2) Keyword in url blocking
IP blocking is pretty easy to spot, traceroute will fail at the backbone level in China, and there will only be outgoing syn packets to the IP, the 3-way tcp handshake will never be established. (Note: all domains hosted on that IP are affected).
"Keyword-in-URL" blocking is different and sometime s a bit awkward. First, the keyword-in-url filtering is bi-direction so you can trigger it from outside -> to -> China or from China -> to -> outside.
Second, "keywords" can be domains themselves, I've even seen URLs used as a "keyword". If these keywords appear in the HTTP Host header or in the GET request they will be "blocked".
Third, the way the blocking works is that the 3-way TCP handshake will be established but when the GET request goes through the GFW sends RST packets to both the requester and the host (spoofed to appear as if they were from one another) to tear down the connection then host and the requester respond to each other with more RST packets. (There is some additional variation, but thats the basic version, see Steven Murdoch et al's paper http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf for more details).
The tricky part is that depending on the GFW (maybe related to the load) some of the transaction will go through. So for example, you may get half (or more!) of the html before the RST packet. Also, part of the page may load because, for example, it is not until an image with a keyword in its file name is loaded that the RST packet is sent.
Finally, the most tricky part. Because of the combination of additional RST packets from the GFW (and then the RST from the requester and host in response) further connections between the requester and host (not the internet as often reported) are disrupted for sometime. This means that if you are in China and you connect to Google (hosted outside of China) and you search for a banned keyword (the keyword goes into the GET request) you'll be blocked. If you hit the back button in your browser and get the cached copy of Google and then search for a NOT blocked keyword it will appear to be blocked because your connection to Google is still being subjected to RST packets. This sometimes results in reports that certain keywords are blocked when in fact they are not.
Another important point to recognize is that this is dependant upon IP address. So, if the site you connect to has multiple IP addresses the behaviour may seem even more consistent and you requests may be being server by different IP addresses. For testing purposes it is best to connect directly to an IP rather than a domain name to ensure that you are always connecting to the same IP.
On June 27 2007, I captured traffic between myself and yahoo.cn (hosted in China, as well as some other hosts in China) using ".yahoo.com" (yes, that starts with a period, e.g. if affects all *.yahoo.com domains including mail.yahoo.com) and can confirm that it was subjected to the "keyword-in-url" blocking behaviour with ".yahoo.com" as the keyword.

However, and this is my opinion, the RST packet were quite slow to respond. In some cases the RST did not come until after the page loaded successfully (future connection were subjected to RST's). It is possible that many requests for ".yahoo.com" were causing the GFW to slow down, anecdotaly the RST packets were not being received as fast as they usually are.
On June 28 2007".yahoo.com" is no longer blocked by China.
Friday, May 11, 2007
cDc's Oxblood has a new tfile
My old friend Oxblood has a new tfile out. Read it here. I'll add a couple of things, the first is that Yahoo! and MSN (live.com) censor their search engines for China as well and also that the results you get back for certain searches are heavily populated with content that is either hosted in China or ends in .cn (100% for "西藏独立", tibet independence, for example).
Monday, April 9, 2007
Tunisia, SmartFilter & DailyMotion
Tunisia uses commercial filtering software called SmartFilter , which is produced by the U.S. company Secure Computing, to filter Internet access in Tunisia. This software is configured to blocked pre-defined categories of content – content classified by SmartFilter – including at least four SmartFilter categories: Anonymizers, Nudity, Pornography, and Sexual Materials.Tunisia’s Internet filtering is done in a non-transparent way. When users attempt to access a blocked page, they are not informed that the page is filtered, but instead merely receive a standard error message, a 404 “File Not Found” error. However, the actual HTTP header, is not a 404, but a 403 Forbidden error generated by the filtering system SmartFilter, in conjunction with NetCache caching servers. SmartFilter can be configured with a blockpage that indicates to users that the site has been blocked and why, however, unlike other countries using this exact same filtering system, Tunisia has copied the text from the Internet Explorer 404 page, and used this as a blockpage to make the filtering appear to be an error.
(See Astrubal's detailed explanation here).
Recently, the video-sharing web site dailymotion.com was blocked in Tunisia. It was blocked because SmartFilter categorized the web site as pornography, and, since Tunisia blocks the pornography category the web site was blocked. Some time bewteen April 4, 2007 and April 9, 2007 SmartFilter removed dailymotion.com from the pornography category.

It is being reported that access to the site is available through at least one ISP in Tunisia. Depending on how frequently the various filtering and cache server's update there wil likely be some variation acroos ISPs for sometime. Eventually, full acess should be restored. (Tunisia could, as they do with a varity of other content including humrn rights information, add the website as a custom url on top of their SmartFilter categories and intentionally block the site if they choose to do so).
This is a very significant case as it demontrates how the decisions made by filtering companies affect Internet access in entire countries.
Wednesday, April 4, 2007
Alternative Explanations
As someone who tests Internet censorship for a living I receive a lot of requests such as "is my website blocked in country x" or "why is my website blocked in country x, I don't have anything on my site that country x would want to block" and so on. Determining that a website is inaccessible is different than determining if it is being deliberately blocked. And even when it is blocked there are often mundane, alternative explanations. There is also the country's filtering infrastructure to account for. In countries that deploy a centralized filtering system blocked content is generally uniform. But other countries delegate filtering responsibilities to individual ISPs, in those cases there can be considerable differences.
In places such as Saudi Arabia, which has centralized filtering, when you visit a blocked site you receive a "block page" that informs you that the site has been deliberately blocked. Pretty straightforward. Still, there is one additional factor to consider. Saudi Arabia, Tunisia and several other Middle eastern and North African countries, use the commercial product SmartFilter (by U.S. company SecureComputing) to filter. Some of the sites are blocked because they appear on SmartFilter's proprietary block list while others have been added by the Saudi authorities.
To account for this one can lookup a site in SmartFilter's database and see how it is categorized. In countries that block the category pornography, for example, sites that are classified -- or incorrectly classified -- as porn will be blocked. (In Saudi Arabia specifically, they have added a tag to the blockpage that differentiates between SmartFilter blocked sites and sites the Saudi's have added -- it is reasonably accurate).
Although Tunisia deploys the same filtering software as Saudi Arabia they attempt to disguise their blockpage as a generic "Internet Explorer" 404 error. In the past ONI/HRW identified,tested and confirmed that misclassified sites -- categorized as porn -- were blocked in Tunisia because they filter SmartFilter's pornography category.

The website http://www.dailymotion.com/ reported to be blocked in Tunisia. Although there are political videos hosted on the site that are critical of Tunisia the site is also categorized by SmartFilter as pornography. It is very easy to add websites -- including specific URLs -- to SmartFilter to block. This is what countries do when they add their own content to block -- usually political content -- on top of SmartFilter. If Tunisia added the block (they have to unblock it first because it is blocked as part of the pornography category) they could have just added the specific URLs, however, countries often do not care about collateral blocking. (See Thailand's blocking of YouTube.) Still, I think that the more mundane -- over-blocking as a result of SmartFilter categorization -- applies to the Tunisian case.
In other countries, such as China and Pakistan, they block IP addresses. This causes all other sites hosted on that IP address to be blocked. If your site is hosted on a huge server farm it is quite possible that it is sharing a single IP with tens of thousands of other sites. If one of those sites is targeted, and they block the IP, your site will be blocked too. (A corollary of this is that if the host changes the IP your hosted on you will be accessible (sometimes mistaken for unblocking).
A recent report notes that the site www.communication-sensible.com is blocked in China. It is blocked in China, the IP address it is hosted on is blocked. However, It is hosted on a massive server farm. According to domaintools.com there are 39140 domains hosted on this IP address (213.186.33.19).
This IP has been flagged as hosting phishing sites and hosts porn sites (the IP is on squidguard's block list and the IP is also on ProtectiveParenting's proxy host list, proxies are used to circumvention censorship.)
In addition to blocking IP addresses China also uses uses tcp reset packets to terminate connections based on keywords. (See Richard Clayton, Steven J. Murdoch, and Robert N. M. Watson's paper "Ignoring the Great Firewall of China")After triggering the filtering mechanism further connections between the two hosts will also be blocked for a varying period of time. The filtering is bi-directional — it affects in-bound traffic to China as well as outbound traffic from China.
I've found that for sites that are of particular concern, the domain itself (sometimes even a url path!) are added as keywords. It is important to remember that the keywords in the body content of a page do not trigger filtering, keywords that appear in a url path (get request, host header) trigger the filtering. By adding the domain name itself searches that contain the domain, unencrypted/unencoded proxies, search engine cache links, mirror sites that have the domain in the url and so forth are also all blocked. The domain www.communication-sensible.com is not blocked in this way.
Here is a post from 2005 showing that a traceroute request to 213.186.33.19 does not go past the Chinese backbone/gateway (where the filtering takes place). It is possible that this IP has been blocked since 2005.
Sometimes things are a bit more complicated than they seem, but hey, other times they are not.
In places such as Saudi Arabia, which has centralized filtering, when you visit a blocked site you receive a "block page" that informs you that the site has been deliberately blocked. Pretty straightforward. Still, there is one additional factor to consider. Saudi Arabia, Tunisia and several other Middle eastern and North African countries, use the commercial product SmartFilter (by U.S. company SecureComputing) to filter. Some of the sites are blocked because they appear on SmartFilter's proprietary block list while others have been added by the Saudi authorities.
To account for this one can lookup a site in SmartFilter's database and see how it is categorized. In countries that block the category pornography, for example, sites that are classified -- or incorrectly classified -- as porn will be blocked. (In Saudi Arabia specifically, they have added a tag to the blockpage that differentiates between SmartFilter blocked sites and sites the Saudi's have added -- it is reasonably accurate).
Although Tunisia deploys the same filtering software as Saudi Arabia they attempt to disguise their blockpage as a generic "Internet Explorer" 404 error. In the past ONI/HRW identified,tested and confirmed that misclassified sites -- categorized as porn -- were blocked in Tunisia because they filter SmartFilter's pornography category.

The website http://www.dailymotion.com/ reported to be blocked in Tunisia. Although there are political videos hosted on the site that are critical of Tunisia the site is also categorized by SmartFilter as pornography. It is very easy to add websites -- including specific URLs -- to SmartFilter to block. This is what countries do when they add their own content to block -- usually political content -- on top of SmartFilter. If Tunisia added the block (they have to unblock it first because it is blocked as part of the pornography category) they could have just added the specific URLs, however, countries often do not care about collateral blocking. (See Thailand's blocking of YouTube.) Still, I think that the more mundane -- over-blocking as a result of SmartFilter categorization -- applies to the Tunisian case.
In other countries, such as China and Pakistan, they block IP addresses. This causes all other sites hosted on that IP address to be blocked. If your site is hosted on a huge server farm it is quite possible that it is sharing a single IP with tens of thousands of other sites. If one of those sites is targeted, and they block the IP, your site will be blocked too. (A corollary of this is that if the host changes the IP your hosted on you will be accessible (sometimes mistaken for unblocking).
A recent report notes that the site www.communication-sensible.com is blocked in China. It is blocked in China, the IP address it is hosted on is blocked. However, It is hosted on a massive server farm. According to domaintools.com there are 39140 domains hosted on this IP address (213.186.33.19).
This IP has been flagged as hosting phishing sites and hosts porn sites (the IP is on squidguard's block list and the IP is also on ProtectiveParenting's proxy host list, proxies are used to circumvention censorship.)
In addition to blocking IP addresses China also uses uses tcp reset packets to terminate connections based on keywords. (See Richard Clayton, Steven J. Murdoch, and Robert N. M. Watson's paper "Ignoring the Great Firewall of China")After triggering the filtering mechanism further connections between the two hosts will also be blocked for a varying period of time. The filtering is bi-directional — it affects in-bound traffic to China as well as outbound traffic from China.
I've found that for sites that are of particular concern, the domain itself (sometimes even a url path!) are added as keywords. It is important to remember that the keywords in the body content of a page do not trigger filtering, keywords that appear in a url path (get request, host header) trigger the filtering. By adding the domain name itself searches that contain the domain, unencrypted/unencoded proxies, search engine cache links, mirror sites that have the domain in the url and so forth are also all blocked. The domain www.communication-sensible.com is not blocked in this way.
Here is a post from 2005 showing that a traceroute request to 213.186.33.19 does not go past the Chinese backbone/gateway (where the filtering takes place). It is possible that this IP has been blocked since 2005.
Sometimes things are a bit more complicated than they seem, but hey, other times they are not.
Monday, March 26, 2007
Badware URL Analysis
One of the projects I am affiliated with in an advisory capacity is the Berkman Center's StopBadware.org project. Over the weekend (2007-03-25) I scraped and analyzed the 18328 badware URLs from StopBadware.org's Badware Website Clearinghouse, a "a collaborative effort to build a comprehensive list of websites that host, link to, or otherwise distribute badware". The results are available here.
The source of all of the URLs (100%) was Google, one of the corporate sponsors of StopBadware.org. Although there are 18328 URLs there were only 6856 distinct IP addresses and 0.4% of the URL's were given a decision of "Badware" -- "Sites that StopBadware has tested itself and determined to contain or link to badware" --, with the balance being listed as "Undetermined".
An interesting note is that Google appears as the 13th (GOOGLE - Google Inc.: 169) network name with 169 badware URLs all of which appear to be *.blogspot blogs.
The source of all of the URLs (100%) was Google, one of the corporate sponsors of StopBadware.org. Although there are 18328 URLs there were only 6856 distinct IP addresses and 0.4% of the URL's were given a decision of "Badware" -- "Sites that StopBadware has tested itself and determined to contain or link to badware" --, with the balance being listed as "Undetermined".
- The top TLD's were .com: 10710, .org: 1550, .info: 1352, .net: 1300 followed by the ccTLD's cn: 1216, .ru: 352, .uk: 275, .ua: 226, .it: 129 and .pl: 118.
- The top countries (based on IP allocation) in which badware URLs are hosted are US: 10037, CN: 4336, ?? (unknown): 1357, DE: 433, RU: 361, GB: 349, UA: 210, IT: 186, CA: 154 and NL: 81.
- The top AS number are AS30380: 3435, AS4134: 1819, AS17233: 1537, ASNA (unknown): 1315 and AS21844: 734.
- The top network names are IPOWER - iPowerWeb, Inc.: 3435, CHINANET-BACKBONE No.31,Jin-rong Street: 1819, ATT-CERFNET-BLOCK - AT&T Enhanced Network Services: 1537 NA (unknown: 1315 and THEPLANET-AS - THE PLANET: 734.
An interesting note is that Google appears as the 13th (GOOGLE - Google Inc.: 169) network name with 169 badware URLs all of which appear to be *.blogspot blogs.
Thursday, March 22, 2007
30,000 Internet Police in China Myth, Please Not Again!
UPDATED (28 Mar 07)
BBC:
Nearly two years after the "30,000" myth was exposed it is still being repeated by reputable news media.
I searched LexisNexis (and Googled) and collected articles that discussed Internet police in China and those that specifically stated the magic 30,000 number. The earliest reference I can find (if you have an earlier one, please send it to me) is an Ethan Gutmann article in The Weekly Standard 02/15/2002
Note that it states it is a rumor and that it was in Beijing, not all of China. Following that, on the 27th of February 2002, Amnesty International releases a report which states:
Rumored has turned in to reportedly, but at least there is a qualifier. But by the 25th of August 2002 the LA Times dropped the modifier:
On November 7, 2002 the Washinton Post decides to leave out the "rumored" and "laughed at" part:
And so it begins. Rumor turned into fact. Some publications have and continue to include references to "rumored" or "estimated" along with the 30,000 figure. (An interesting sidenote is that publications continue to reference 30,000 (no change since 2002) despite a huge rise in China's number of Internet users). However, the New York times has upped the number to 50,000 and dropped all qualifiers:
I guess there were some massive firing because in 2006 the number was back down to 30,000. This time however, USA Today claims that China Internet Network Information Center is the source of the number (I cannot find it on their website, email me if you can). But the part that gets me is the "shadowy force" -- so shadowy that they have their own websites? Why yes, try www.cyberpolice.cn or any of the numerous local sites.
This is an analysis from EastSouthWestNorth:
EastSouthWestNorth touches on a very interesting point. Media reports seem to merge together the self-censorship practices by forums, portals, blog hosting companies and so forth with the Internet police.
An old article in The Guardian I missed earlier does discuss this issue:
There are Internet police in China, they have websites, lots of them. They engage in law enforcement duties. They also investigate websites. It is also, in my view, safe to assume that they investigate and arrest dissidents. In fact the Beijing cyberpolice accept reports (appears to be via SMS) from the public against persons who want to split the nation, or attack the party and the government, and people with "wrong doctrines opinion"/ falungong. (babelfish). Seems quite clear to me that the cyber police's mandate is to investigate reports of people who criticize the government or belong to falun gong -- it is right in their incident report form.
However, its the manufactured number and the near godlike capabilities assigned to China's Internet police and filtering/monitoring technology in most news reports that infuriates me. There is definitely a lot going on in this area in China, there is a lot left to investigate. However, reporting rumor as fact is not the way to go about this. It doesn't help people better understand what is really going on in China, but it does re-enforce a climate of self-censorship in China.
Please, stop repeating the "30,000" myth.
BBC:
Hundreds of millions of dollars have been spent on building what is known as the Great Firewall Of China - a network of state-licensed internet access providers, and around 30,000 internet police censors who filter sites between China and the rest of the world.
Nearly two years after the "30,000" myth was exposed it is still being repeated by reputable news media.
I searched LexisNexis (and Googled) and collected articles that discussed Internet police in China and those that specifically stated the magic 30,000 number. The earliest reference I can find (if you have an earlier one, please send it to me) is an Ethan Gutmann article in The Weekly Standard 02/15/2002
Although it was widely rumored in Beijing that up to 30,000 state security employees were monitoring the Internet in that city alone, the monitoring was also laughed at.
Note that it states it is a rumor and that it was in Beijing, not all of China. Following that, on the 27th of February 2002, Amnesty International releases a report which states:
30,000 state security personnel are reportedly monitoring websites, chat rooms and private e-mail messages.
Rumored has turned in to reportedly, but at least there is a qualifier. But by the 25th of August 2002 the LA Times dropped the modifier:
More than 30,000 state security employees are currently conducting surveillance of Web sites, chat rooms and private e-mail messages--including those sent from home computers.
On November 7, 2002 the Washinton Post decides to leave out the "rumored" and "laughed at" part:
But Beijing, with 30,000 "Internet police," has acted swiftly to clamp down on dissent through the ethers.
And so it begins. Rumor turned into fact. Some publications have and continue to include references to "rumored" or "estimated" along with the 30,000 figure. (An interesting sidenote is that publications continue to reference 30,000 (no change since 2002) despite a huge rise in China's number of Internet users). However, the New York times has upped the number to 50,000 and dropped all qualifiers:
Stern instructions like those are in keeping with a trend aimed at assigning greater responsibility to Internet providers to assist the government and its army of as many as 50,000 Internet police, who enforce limits on what can be seen and said. -- New York Times, March 4, 2005
I guess there were some massive firing because in 2006 the number was back down to 30,000. This time however, USA Today claims that China Internet Network Information Center is the source of the number (I cannot find it on their website, email me if you can). But the part that gets me is the "shadowy force" -- so shadowy that they have their own websites? Why yes, try www.cyberpolice.cn or any of the numerous local sites.
Even with an estimated 30,000 internet police, he said it was difficult to monitor bulletin boards. "The technology hasn't reached a level that will allow us to control them..." -- The Guardian February 14, 2006
China has roughly 30,000 Internet police who use Internet Detective and other tools to monitor Web users, according to the China Internet Network Information Center, an arm of China's Ministry of Information Industry. Officials at the Ministry of Public Security declined interview requests for details of this shadowy force. -- USA Today 4/3/2006
This is an analysis from EastSouthWestNorth:
Here is a myth: there are 30,000 Internet police in China who sit around all day looking for harmful information. 30,000 is a big number, since it could fill a soccer stadium. But with respect to 100 million Internet users, 30,000 is woefully inadequate to patrol all possible Internet content material (that is, one Internet police officer has to keep an eye on 3,333 users at the same time, or less than 10 seconds per user per day).
In any case, one has to ask just how well trained these 30,000 Internet police are. A fair bet is that when they come across a website with pictures of naked people, they will take action. But if they come across a copy of Anti's blog post (see Comment 200601#029) or the scholarly article History Textbooks in China, they would not have a clue what to think.
In the scheme of things, I don't think these 30,000 Internet police form the front line. Rather, it is the Internet unit administrators (such as BBS forum masters) who do the active work because they have domain knowledge. The Internet police are only there to catch the periodic leak so as to hold the Internet unit adminstrators accountable for negligence and/or sabotage. If you are a vigilant forum master that has everything under control (e.g. wiping every mention of Beijing News immediately), then you will rarely come into contact with the Internet police; if you are a progressive forum master, you will get phone calls every day and eventually you will be dismissed and your website may even be disappeared like the Yannan forum. That is why it was no surprise that nothing was found on this day by the reporter who played Internet police.
Postscript: Oh, by the way, they obviously don't read overseas English-language blogs ...
EastSouthWestNorth touches on a very interesting point. Media reports seem to merge together the self-censorship practices by forums, portals, blog hosting companies and so forth with the Internet police.
An old article in The Guardian I missed earlier does discuss this issue:
Better still is scaring users into censoring themselves. No one I spoke to could tell me where the figure of 30,000 internet policemen originated. But researchers pointed out that it was in Beijing's interests to persuade its citizens that Big Brother lurks in every cafe. Similarly, arrest a few people and you frighten many more into compliance.
There are Internet police in China, they have websites, lots of them. They engage in law enforcement duties. They also investigate websites. It is also, in my view, safe to assume that they investigate and arrest dissidents. In fact the Beijing cyberpolice accept reports (appears to be via SMS) from the public against persons who want to split the nation, or attack the party and the government, and people with "wrong doctrines opinion"/ falungong. (babelfish). Seems quite clear to me that the cyber police's mandate is to investigate reports of people who criticize the government or belong to falun gong -- it is right in their incident report form.
However, its the manufactured number and the near godlike capabilities assigned to China's Internet police and filtering/monitoring technology in most news reports that infuriates me. There is definitely a lot going on in this area in China, there is a lot left to investigate. However, reporting rumor as fact is not the way to go about this. It doesn't help people better understand what is really going on in China, but it does re-enforce a climate of self-censorship in China.
Please, stop repeating the "30,000" myth.
Wednesday, March 21, 2007
Unblocked?
Recently Google changed the IP address of its blogspot blogging service. This caused the site to become accessible in all countries that blocked the site by its IP address --including Pakistan and China. China and Pakistan did not unblock blogspot, rather it became available because of actions taken on Google's part. Well, the new blogspot IP is now blocked in China, but it is still accessible in Pakistan.
Iran has, however, unblocked Baztab, a conservative news website. Hoder wrote about this case about a month ago:
Hoder argued that "by pushing for the judiciary to take up the responsibility of internet filtering, Iranian internet users can slow down the process of filtering, hold the authorities accountable, and force them to make the behind-the-scenes process transparent.". When I linked to this article a while back, a comment was posted which stated that "[i]n Iran it is the judiciary that has spearheaded the arrest and torture of bloggers."
This is an interesting case. One of the recommendations of the HRW report on China is:
HRW reccomends that Iran "should further seek to pass new laws that affirmatively protect the right to freely access or disseminate information or opinions and clarify the narrow circumstances in which government interference would be warranted according to international standards.".
The unblocking of one website -- one run by well connected people -- is a small victory but it could be very significant. If the procedures for determining content to block become transparent, if there is an appeals process and some level of accountability I believe it becomes increasingly difficult for governments to justify censorship. I believe, as recommended by HRW, that this process needs to be accompanied by movements to affirmatively protect freedom of expression as well.
Iran has, however, unblocked Baztab, a conservative news website. Hoder wrote about this case about a month ago:
The Iranian cultural ministry has now ordered all major ISPs to block Baztab, a news website close to moderate conservatives and linked to an influential former commander of the elite revolutionary guards. It has also demanded the website to stop its activities.
But the well-connected editors of Baztab have hit back. They have refused to stop publishing new articles, have called the order illegal and illegitimate, and have also said they are going to bring the case to court.
They have argued that it is only the judiciary has the constitutional authority to decide weather a website has violated laws. They have also disputed the legality of a set of regulations passed in the governemnt cabinet last month to be executed by the ministry of culture.
Hoder argued that "by pushing for the judiciary to take up the responsibility of internet filtering, Iranian internet users can slow down the process of filtering, hold the authorities accountable, and force them to make the behind-the-scenes process transparent.". When I linked to this article a while back, a comment was posted which stated that "[i]n Iran it is the judiciary that has spearheaded the arrest and torture of bloggers."
This is an interesting case. One of the recommendations of the HRW report on China is:
Create formal, well-documented and legally transparent processes by which content censorship requests are made to companies, formal written procedures by which companies can challenge or respond to censorship requests, and formal, transparent legal procedures by which members of the Chinese public can safely and fairly challenge the legality of any act of censorship without fear of reprisal.
HRW reccomends that Iran "should further seek to pass new laws that affirmatively protect the right to freely access or disseminate information or opinions and clarify the narrow circumstances in which government interference would be warranted according to international standards.".
The unblocking of one website -- one run by well connected people -- is a small victory but it could be very significant. If the procedures for determining content to block become transparent, if there is an appeals process and some level of accountability I believe it becomes increasingly difficult for governments to justify censorship. I believe, as recommended by HRW, that this process needs to be accompanied by movements to affirmatively protect freedom of expression as well.
Monday, March 19, 2007
FT Censorship Series
FT has recently run a series of articles on internet censorship. Each touches on an interesting theme.
TOR can be used for both anonymity and censorship circumvention, but while "anonymous" proxies can be used for censorship circumvention they not really anonymous. A "proxy" may sheild your identity from the website you are visiting but it does not hide you or anything you are doing from the owner of the proxy. And if the proxy is not encrypted -- most of the "open" proxies are not -- then anyone monitoring Internet traffic can also see everything you do through the proxy. TOR, on the other hand, encrypts your traffic and hides what you are doing from the TOR network itself, it is hardly comparable to "open" proxies. I have not looked closely at GPass, but it appears to be an encrypted Socks proxy, and if so, is not anonymous -- all traffic through it can be viewed by the owners of GPass. (And you don't have to use Swedish Google, Google just redirects you to the localized version, you can always click the google.com link and use google.com).
It is not only "repressive" governments that are increasing their level of filtering and employing new techniques (new techniques for the country, not for filtering in general), countries such as India and Thailand are filtering as well. There is a tendency to analyze all regulations and restriction in particular countries, such as China and Iran, out of context. For example, there is a tendency to think of China's Internte cafe's as places teeming with cyberdissdents and therefore when China closed many and instituted restrictions after a deadly fire in an unlicensed cafe many interpretted it as a crackdown on free expression. I think that the Iranian bandwidth limitation story may prove to go this way as well -- it's more likely to do with porn than with politics. But, hey, I could be wrong.
Human rights groups and NGO's worldwide have long protested that they are often the victims of state surveillance, computer breakins and denial of service attacks. ONI has documented an attack on Kyrgyz opposition newspaper websites during that countries elections in 2005 and there have been reports of such Denial of Service attacks during elections in Belarus as well. What is new is not the technique but the correlation between the target -- important opposition website -- and the time period -- during an election. Denial of Service disrupts access to a website for everyone -- as opposed to filtering which would only block it from the affected location. It also provides deniability on the part of the government. In the Kyrgyz case, the attacks appear to have been conducted by a "botnet for hire" leaving the conection to the government circumstantial. This is a trend we will probably see more of especially in countries that don't have a national filtering system (or officially filter very little content).
A good article about the forthcoming ONI study, however, some instances listed as "new censorship techniques" are not really new at all. They may be new to certain countries, but they are standard filtering techniques. And there is not yet evidence that Zimbabwe is censoring the Internet, let alone using the same techniques as China. I have heard reports about this, but even if they are true, it has not been implemented.
TOR can be used for both anonymity and censorship circumvention, but while "anonymous" proxies can be used for censorship circumvention they not really anonymous. A "proxy" may sheild your identity from the website you are visiting but it does not hide you or anything you are doing from the owner of the proxy. And if the proxy is not encrypted -- most of the "open" proxies are not -- then anyone monitoring Internet traffic can also see everything you do through the proxy. TOR, on the other hand, encrypts your traffic and hides what you are doing from the TOR network itself, it is hardly comparable to "open" proxies. I have not looked closely at GPass, but it appears to be an encrypted Socks proxy, and if so, is not anonymous -- all traffic through it can be viewed by the owners of GPass. (And you don't have to use Swedish Google, Google just redirects you to the localized version, you can always click the google.com link and use google.com).
It is not only "repressive" governments that are increasing their level of filtering and employing new techniques (new techniques for the country, not for filtering in general), countries such as India and Thailand are filtering as well. There is a tendency to analyze all regulations and restriction in particular countries, such as China and Iran, out of context. For example, there is a tendency to think of China's Internte cafe's as places teeming with cyberdissdents and therefore when China closed many and instituted restrictions after a deadly fire in an unlicensed cafe many interpretted it as a crackdown on free expression. I think that the Iranian bandwidth limitation story may prove to go this way as well -- it's more likely to do with porn than with politics. But, hey, I could be wrong.
Human rights groups and NGO's worldwide have long protested that they are often the victims of state surveillance, computer breakins and denial of service attacks. ONI has documented an attack on Kyrgyz opposition newspaper websites during that countries elections in 2005 and there have been reports of such Denial of Service attacks during elections in Belarus as well. What is new is not the technique but the correlation between the target -- important opposition website -- and the time period -- during an election. Denial of Service disrupts access to a website for everyone -- as opposed to filtering which would only block it from the affected location. It also provides deniability on the part of the government. In the Kyrgyz case, the attacks appear to have been conducted by a "botnet for hire" leaving the conection to the government circumstantial. This is a trend we will probably see more of especially in countries that don't have a national filtering system (or officially filter very little content).
A good article about the forthcoming ONI study, however, some instances listed as "new censorship techniques" are not really new at all. They may be new to certain countries, but they are standard filtering techniques. And there is not yet evidence that Zimbabwe is censoring the Internet, let alone using the same techniques as China. I have heard reports about this, but even if they are true, it has not been implemented.
Labels:
Circumvention,
Free Expression,
Internet Censorship
Subscribe to:
Posts (Atom)