Tuesday, December 9, 2008

The Mirror Question

Defacement mirrors have been around for a long time and the question of whether mirroring encourages defacements has been around for just as long. The basic argument is that defacement mirrors encourage defacement by allowing the attackers to look "cool" and compete to be the most prolific defacers (in terms of high profile targets and numbers of defacements etc...). A recent post on the SecuriTeam blog got me thinking about it again, particularly about how I use these mirrors in my research.

Attrition started mirroring defacements in 1995 but stopped doing so in 2001 (as did Safemode) leaving Alldas as the largest mirror. Alldas eventually stopped mirroring as well leaving Zone-h as only major active mirror (there are still some smaller ones and some specialized (usually regional) ones). The mirrors closed for a variety of reasons such as the increase in defacements and burn out on the part of the volunteers who run the mirrors. But another key issue is that the mirrors themselves come under attack. Attrition has been defaced and subjected to Denial of Service attacks and Alldas was also defaced and suffered sustained ddos attacks. Zone-H has been defaced in the past. Zone-H has also thought about stopping their mirror, but continues to mirror.

Early on Attrition was blamed for encouraging defacements. Their response (and here) was:


# Odds are we have berated and insulted most defacers for their activities - we've questioned them, encouraged them to STOP, etc.
# We are not the only mirror. If we close up shop, the other mirrors will pick up our role...


Zone-H has a similar response:

Our usual answer to this claim is that Zone-H is not the first mirror archive website, others appeared before it, others will be after it. And the first defacement mirror website, appeared AFTER defacements became very popular.
But sure, a lot of defacers are using Zone-H archive capability just to satisfy their ego-driven needs, using Zone-H as a stage for their own lack of personality or social skills.


Since I am most interested in politically motivated, targeted attacks I find the defacement mirrors useful for a variety of reasons. When servers are defaced (particular high profile targets) there is often an immediate assumption of some kind of god-like haxoring skills or government/military involvement on the part of the attackers. Since the attacks are interpreted contextually (dissident group X has been repressed by government X for years or "cyber war has erupted between count and country y) the source behind the attacks and their abilities are often a forgone conclusion. Whenever a defacement I am interested in occurs the first thing I do is look it up in the defacement mirrors.

Do the attackers have other defacements? Are any of their previous defacements politically motivated, are they random(ish)? The fact that they even report the defacement to a mirror is often an indication that the group is in the defacement "scene" not part of a "cyber war" or "cyber crackdown." What information can be gleaned from the defacement, names, groups, email addresses, IRC channels, similarity in the code etc...?

Have the targets been defaced before? If a web site has bee defaced many times (sometimes even through the same method) it is a good indication that security was lax rather than that the attackers possessed some amazing skillz. Just because a site is a "gov" or "mil" and it gets defaced is not surprising when you look it up in a defacement mirror only to find that it had been defaced in the past.

The mirrors help provide texture to analysis of defacements and are a valuable resource. Recently the so-called "India/Pakistan Cyberwar" has received a good deal of media attention. However, a quick browse through zone-h showed that it was more of a defacement "flare-up" than a "cyber war". These mirrors continue to be a valuable resource.

Monday, December 8, 2008

Wikipedia, Cleanfeed & Filtering

IWF classified a Wikipedia page as containing a pornographic image of a child. As a result UK ISP's that participate in the cleanfeed program are now blocking access to the Wikipedia page of the band the Scorpions because of a controversial album cover that is potentially child pornography and thus illegal under UK law. The IWF states:

A Wikipedia web page, was reported through the IWF’s online reporting mechanism in December 2008. As with all child sexual abuse reports received by our Hotline analysts, the image was assessed according to the UK Sentencing Guidelines Council (page 109). The content was considered to be a potentially illegal indecent image of a child under the age of 18, but hosted outside the UK. The IWF does not issue takedown notices to ISPs or hosting companies outside the UK, but we did advise one of our partner Hotlines abroad and our law enforcement partner agency of our assessment. The specific URL (individual webpage) was then added to the list provided to ISPs and other companies in the online sector to protect their customers from inadvertent exposure to a potentially illegal indecent image of a child.


But why didn't they just block access to the specific URL of the offending image? Instead they block the entire page, the text (and other images) of which are completely legal. There is no technical reason why they cannot block URLs to specific offending images in exactly the same way as they can block a specific Wikipedia page and not the entire Wikipedia site.

The IWF collects URLs that are potentially illegal for containing child pornography and sends them to participating ISP's in the U.K. as part of the cleanfeed program. The ISPs then block access to these URLs. These URLs may be shared with other agencies through the IN HOPE network and possibly with commercial filtering companies as well. Canada has a similar cleanfeed program in which Cyberip collects the potentially illegal URLs and send them to Canadian ISPs who then block access to them. One of the main why cleanfeed has been successful and replicated in oher countries is that it was supposed to elegantly avoid the pitfall of overblocking, the key objection that was consistently raised civil libertarians and others with respect to filtering. This is why filtering at the URL level is so important: one offending page can be blocked while the rest of the site remains available.

One of the questions I've often raised (in the Canadian context) concerns what precisely is blocked. We know that cleanfeed systems can block at the URL level, so why block access to the web page containing the offending image and not the the URL to the offending image itself? There is no technical reason for not doing so. If IWF added the URL to the specific offending image embedded in the Scorpions Wikipedia page the text of the article, which is perfectly legal, along with all the other legal images would still be available. Only the one offending image would have been blocked.

For a system that was designed to not overblock I find it hard to understand why they don't the specific offending images. If an entire website was devoted to showing images of child abuse then it would be understandable, but Wikipedia?

Tuesday, November 25, 2008

Keyword Lists

A while back I put together various lists of keywords that have been found to be censored in some way in China. I noticed that they've been floating around the Net so here's a post explaining where each of the lists came from.


  • badwords.txt - This is a list that was found on 163.com, a popular Chinese portal. It is unclear to me what the exact purpose of the list is.
    Date: November 6, 2008
    Source: http://sports.163.com/special/00051DT9/badwords.txt


  • banword.txt - This is a list that I found on TOM Online's Skype servers. This is is not the list used in Tom-Skype (the actual Skype client), but appears to be part of another product, possibly "web chat" software of some kind.
    Date: September 17, 2008
    Source: http://tcc.skype.tom.com/


  • keyword.txt - This is a keyword list from a blog provider in China.
    Date: March 18, 2005
    Source: Blog Provider in China


  • condopper.txt - This is the list of keywords found to be censored at the "gateway" level by the Concept Doppler project.
    Date: June 18, 2008
    Source: http://www.cs.unm.edu/~crandall/cd/GETRequestBlocked18June.html


  • qqdll.txt - This is the list of keywords found in QQ (Program Files\Tencent\QQGame\COMToolKit.dll) a popular Chinese instant messaging program.
    Date: July 31, 2004
    Source: http://bbs.omnitalk.org/arts/messages/3824.html

Monday, November 24, 2008

Alternative Explanation Redux

livejournal.com is now accessible in Kazakhstan and Kyrgyzstan. Why? Because it appears that Livejournal was not actually blocked by ISP's in those countries in the first place. Instead, it appears that the Sixpart network, on which Livejournal was formerly hosted, firewalled requests from IP addresses in those countries.

Livejournal was reported as blocked by ISP's in Kazakhstan after bloggers noted that the site had become inaccessible. There was speculation that the blocking was politically motivated and linked to the Livejournal blog of the the Kazakh President's former son-in-law who is very critical of the government.

The Kazakh ISP's denied that they had blocked access to it.


"We do not block access in Kazakhstan to any internet resource, including this portal. As a profitable company, our primary concern is to have our subscribers provided with Internet services to the fullest extent," head of Kazakhtelecom's PR department Balzhan Ilbisinova told Interfax...

"We have found out that Internet users in Kyrgyzstan and Uzbekistan also do not have access to this resource. Therefore, I think the lack of access may be attributed to technical problems at LiveJournal?s end," Ilbisinova indicated.


Last year I wrote about the case of dailymotion.com being temporarily blocked in Tunisia as a result of a mis-categorization by SmartFilter. I suggested that sometimes "there are often mundane, alternative explanations" that explain blocking, let alone inaccessibility.

Here is a traceroute to livejournal from KG. It is interesting because it passes through KZ (other traceroutes from the same ISP do not pass through KZ but display the same behavior) but even more so because the last hop is not in KZ or KG but on the first hop on Sixapart's network. That is the traceroute suggests the problem is on Livejournal/Sixapart's end.

Tracing route to livejournal.com [204.9.177.18]
over a maximum of 30 hops:

1 237 ms 226 ms 226 ms *.elcat.kg [212.42.*.*]
2 227 ms 226 ms 226 ms *.elcat.kg [212.42.*.*]
3 226 ms 227 ms 226 ms 213.145.131.145
4 229 ms 235 ms 229 ms 92.46.59.161
5 246 ms 246 ms 245 ms alma-core-l2-6.online.kz [92.47.151.157]
6 246 ms 246 ms 245 ms alma-core-l1-6.online.kz [92.47.145.17]
7 246 ms 246 ms 245 ms asta-core-l1-1.online.kz [92.47.145.10]
8 246 ms 246 ms 245 ms asta-core-l2-1-2.online.kz [92.47.145.42]
9 246 ms * 246 ms asta-gate-1.online.kz [92.47.151.166]
10 258 ms 258 ms 258 ms clk15.transtelecom.net [217.150.58.70]
11 350 ms 351 ms 351 ms xe-3-3.r01.londen05.uk.bb.gin.ntt.net [83.231.146.85]
12 667 ms 529 ms 544 ms xe-3-2.r01.londen03.uk.bb.gin.ntt.net [129.250.2.72]
13 352 ms 351 ms 351 ms xe-2-3-0.r22.londen03.uk.bb.gin.ntt.net [129.250.2.65]
14 350 ms 350 ms 351 ms ae-0.r23.londen03.uk.bb.gin.ntt.net [129.250.4.86]
15 358 ms 358 ms 358 ms p64-2-0-0.r22.amstnl02.nl.bb.gin.ntt.net [129.250.4.105]
16 358 ms 360 ms 364 ms ae-1.r23.amstnl02.nl.bb.gin.ntt.net [129.250.4.222]
17 443 ms 440 ms 436 ms as-0.r20.asbnva01.us.bb.gin.ntt.net [129.250.5.46]
18 437 ms 441 ms 441 ms ae-0.r20.asbnva02.us.bb.gin.ntt.net [129.250.2.61]
19 478 ms * 482 ms as-1.r20.dllstx09.us.bb.gin.ntt.net [129.250.3.42]
20 483 ms 482 ms 482 ms ae-0.r21.dllstx09.us.bb.gin.ntt.net [129.250.2.59]
21 512 ms 513 ms 517 ms as-3.r21.snjsca04.us.bb.gin.ntt.net [129.250.4.25]
22 528 ms 524 ms 525 ms ae-0.r20.plalca01.us.bb.gin.ntt.net [129.250.4.118]
23 523 ms 523 ms 520 ms ae-0.r21.plalca01.us.bb.gin.ntt.net [129.250.5.118]
24 520 ms 523 ms 523 ms xe-3-4.r03.plalca01.us.bb.gin.ntt.net [129.250.4.246]
25 529 ms 523 ms 523 ms 140.174.28.110
26 526 ms 525 ms 525 ms v102-sf-core1.sixapart.com [204.9.176.19]
27 * * * Request timed out.
28 * * * Request timed out.
29 * * * Request timed out.
30 * * * Request timed out.

This behavior matches many traceroutes to livejournal from KZ that I have seen posted on forums and blogs.(I don't have direct access to KZ myself.)

[root@localhost ~]# traceroute livejournal.com
traceroute to livejournal.com (204.9.177.18), 30 hops max, 40 byte packets
1 192.168.0.1 (192.168.0.1) 5.056 ms 4.973 ms 6.254 ms
2 92.46.31.32 (92.46.31.32) 37.094 ms * *
3 92.46.31.9 (92.46.31.9) 39.176 ms 42.572 ms 42.705 ms
4 alma-core-l2-6.online.kz (92.47.150.5) 45.835 ms 46.633 ms 49.597 ms
5 alma-gate-6-2.online.kz (92.47.151.158) 49.578 ms 51.314 ms 51.293 ms
6 62.105.145.81 (62.105.145.81) 120.029 ms 81.211.8.53 (81.211.8.53) 119.194 ms 62.105.145.81 (62.105.145.81) 85.843 ms
7 cat01.Frankfurt.gldn.net (194.186.157.138) 150.126 ms 152.341 ms 141.199 ms
8 TenGigabitEthernet7-4.ar1.FRA4.gblx.net (64.208.222.201) 203.801 ms 203.788 ms 206.627 ms
9 te7-4-10G.ar3.FRA3.gblx.net (67.17.111.178) 348.909 ms 350.545 ms 350.517 ms
10 ge-6-11.car2.Frankfurt1.Level3.net (195.122.136.245) 187.929 ms 201.878 ms 191.595 ms
11 ae-32-56.ebr2.Frankfurt1.Level3.net (4.68.118.190) 189.552 ms ae-32-52.ebr2.Frankfurt1.Level3.net (4.68.118.62) 215.396 ms ae-32-54.ebr2.Frankfurt1.Level3.net (4.68.118.126) 148.874 ms
12 ae-2.ebr1.Dusseldorf1.Level3.net (4.69.132.137) 195.665 ms 187.249 ms 190.874 ms
13 * * *
14 ae-2.ebr1.Amsterdam1.Level3.net (4.69.133.89) 217.906 ms 215.069 ms 211.648 ms
15 ae-1-100.ebr2.Amsterdam1.Level3.net (4.69.133.86) 203.764 ms 205.056 ms 214.713 ms
16 ae-2.ebr2.London1.Level3.net (4.69.132.133) 160.643 ms 173.771 ms 174.483 ms
17 ae-42.ebr1.NewYork1.Level3.net (4.69.137.70) 235.561 ms ae-43.ebr1.NewYork1.Level3.net (4.69.137.74) 242.350 ms ae-44.ebr1.NewYork1.Level3.net (4.69.137.78) 242.053 ms
18 ae-61-61.csw1.NewYork1.Level3.net (4.69.134.66) 243.298 ms ae-71-71.csw2.NewYork1.Level3.net (4.69.134.70) 254.401 ms ae-81-81.csw3.NewYork1.Level3.net (4.69.134.74) 231.585 ms
19 ae-94-94.ebr4.NewYork1.Level3.net (4.69.134.125) 233.414 ms ae-64-64.ebr4.NewYork1.Level3.net (4.69.134.113) 224.338 ms ae-74-74.ebr4.NewYork1.Level3.net (4.69.134.117) 243.520 ms
20 ae-2.ebr4.SanJose1.Level3.net (4.69.135.185) 304.158 ms 312.587 ms 314.754 ms
21 ae-74-74.csw2.SanJose1.Level3.net (4.69.134.246) 301.834 ms ae-84-84.csw3.SanJose1.Level3.net (4.69.134.250) 306.405 ms ae-94-94.csw4.SanJose1.Level3.net (4.69.134.254) 297.681 ms
22 ae-62-62.ebr2.SanJose1.Level3.net (4.69.134.209) 300.430 ms ae-82-82.ebr2.SanJose1.Level3.net (4.69.134.217) 315.784 ms ae-92-92.ebr2.SanJose1.Level3.net (4.69.134.221) 300.655 ms
23 ae-5-5.car1.Oakland1.Level3.net (4.69.134.37) 306.771 ms 306.578 ms 294.600 ms
24 SIX-APART-L.car1.Oakland1.Level3.net (4.71.200.18) 306.504 ms 294.604 ms 295.527 ms
25 v102-oak-core2.sixapart.com (204.9.176.82) 310.375 ms 321.391 ms 316.173 ms
26 * * *
27 * * *
28 * * *
29 * * *
30 * * *

In both cases the last hop is on Sixapart's network.

On November 18 2008 Livejournal moved off Sixpart's network and is now accessible in KG and KZ. Since they have new IP addresses they would be accessible until the KZ ISP updated their blocking, but so far this has not occurred. Since the traceroutes clearly show that packets passed through KG and KZ to Sixpart's network my sense is that some network admin at Sixapart firewalled some IP addresses (or ranges of IPs) that corresponded to ISPs in KG and KZ, perhaps due to "bad" behaviour, such as scans, originating from those IP's. In any case it appears that the KZ and KG ISP's had nothing to do with the inaccessibility of Livejournal in those countries.

In any case I'm glad it is now accessible and hope it remains that way.

Circumvention Tools

FLOSS Manuals has put together a great guide to censorship circumvention tools. It combines some great existing guides with new information and presents it in a way that's nice and easy to understand. It's a great projects, check out and contribute too!

Wednesday, November 19, 2008

Free Hoder

There are reports that Hossein Derakhshan has been arrested in Iran. Hossein is a friend, a blogging pioneer, and a supporter of freedom of expression and human rights. Hossein Derakhshan should be released immediately and I hope that the Canadian government takes action to secure his release.

After he became very concerned about the demonization of Iran in the media, a possible attack on Iran, and the manipulation of human rights issues to support an attack on Iran Hossein alienated many of his former supporters. It is unfortunate that some are now so critical of him (see the comment sections here and here) that they are dismissing his arrest and not supporting calls for his release.

If you believe in freedom of expression and human rights -- even if you disagree with Hossein's opinions -- support calls for his release.

Tuesday, October 28, 2008

Perspectives

The Breaching Trust report that investigated the filtering and surveillance of Tom-Skype continues to generate interest. Today both the Globe and Mail and the New York Times mention the report.

The Globe focused on innovation in research coming our of Canadian Universities, which is a very interesting perspective. One of things that make research at the Citizen Lab so exciting is the ability to use unconventional methods.

The NYT article is about the "global code of conduct" that technology companies and human rights groups have been working on for some time now. It provides guides, for companies like Skype, that aim to "avoid or minimize the impact of government restrictions on freedom of expression." It also sets up "accountability mechanisms" so that compliance can be evaluated.

In effect this is what I have been doing (see Search Monitor and Breaching Trust) independently. While rightfully labeled as a "first step" the significance of this initiative should not be minimized. I'll have to wait and see the official documents scheduled to be released tomorrow, but I believe that these principles will help my research by providing benchmark -- to which these companies have voluntarily agreed -- with which I can evaluate their actual behavior. Hopefully, it will also encourage companies to be more transparent about their practices which definitely helps me interrogate their practices with increased accuracy.

Snips from the articles:

In shadowy Web world, schools are on the case - The Globe and Mail

Through its monitoring, the Citizen Lab discovered swaths of text that failed to make it to intended recipients. The messages had been stored in databases run by the Chinese partner of Skype, Tom Online Inc. Citizen Lab found this thanks to Tom's apparent lax security, which allowed the Lab to find both encrypted information and the key that would allow them to decrypt it on a publicly accessible Web page.


Big Tech Companies Back Global Plan to Shield Online Speech - The New York Times

Currently Google, Microsoft’s MSN division and Yahoo’s Chinese affiliate are all cooperating with the Chinese government’s demands that search results be filtered. This month, Canadian researchers revealed that the Chinese version of the Skype Internet chat and telephony client had been modified to permit the logging of chat sessions and storage of the information on server computers belonging to Skype’s Chinese partner, Tom, a wireless and Internet company.

Wednesday, October 8, 2008

TOM-Skype Trojan.Addclicker

One of the links on skype.tom.com points to http://www.skycn.com/skype1/index.html where another version of TOM-Skype is available for download. When I install this version, I receive a Trojan warning from Norton. The file promote.dll (http://skypetools3.tom.com/download/promote/promote.dll) is installed by TOM-Skype and is flagged by Norton as Trojan.Addclicker:

Trojan.Adclicker is a generic class of Trojan Horses that are designed to artificially generate traffic to certain Web sites. These Trojans send HTTP requests to simulate clicks on banner advertisements, or to inflate Web counter statistics.




According to VirusTotal two other Anti-Virus products identify this file as a trojan (Ikarus: Trojan-Spy.Win32.Mslagent & TrendMicro: TROJ_ADCLICKE.IX).

While this is nothing like the report I recently released, it is another indicator that Skype needs to do something about their relationship with TOM.

Sunday, October 5, 2008

Notable Quotes on TOM-Skype Story

Josh Silverman, President of Skype


What have you learned from TOM about the uploading and storing of certain chats, and what are you doing about it?

What we have discovered in our conversations with TOM is that they in fact were required to do this by the Chinese government.


Josh Silverman, President of Skype


In April 2006, Skype publicly disclosed that TOM operated a text filter that blocked certain words in chat messages, and it also said that if the message is found unsuitable for displaying, it is simply discarded and not displayed or transmitted anywhere. It was our understanding that it was not TOM's protocol to upload and store chat messages with certain keywords, and we are now inquiring with TOM to find out why the protocol changed.


Skype


In 2006, Skype publicly disclosed that Tom operated a text filter that blocked certain words on chat messages but that it did not compromise Tom customers’ privacy. Last night, we learned that this practice was changed without our knowledge or consent and we are extremely concerned. We deeply apologize for the breach of privacy on Tom’s servers in China and we are urgently addressing this situation with Tom.



TOM Online


"As a Chinese company, we adhere to rules and regulations in China where we operate our businesses. We have no other comment,"


Ronald J. Deibert, an associate professor of political science at the University of Toronto.


“This is the worst nightmares of the conspiracy theorists around surveillance coming true. It’s ‘X-Files’ without the aliens.”



Rebecca MacKinnon, Hong Kong University


"We may never know whether some of those people whose conversations were logged have gone to jail or have had their lives ruined in various ways as a result of this," said Rebecca MacKinnon, an Internet expert at Hong Kong University.


Isaac Mao


"The problem with Skype is that they did more than what people expected. They over-satisfied the government," said Isaac Mao, one of China's earliest and best known bloggers.


Danny O'Brien, EFF


While it might disclaim responsibility, arguing that this political spyware was not directly written by its own coders, the company is directly implicated by its close relationship with TOM. When Chinese visitors go to the Skype homepage, they are redirected to a page offering a download of TOM's compromised client version.



Leslie Harris, president of the Center for Democracy & Technology


"Companies have to start looking at their human rights risks as part of their bottom line when they go into difficult markets -- and plainly they are not doing it,... It's not enough to say that we have to comply with local laws. It's not clear to me that any of this complies with China's law. It's just the perfect example of what not to do at every level."


Marc Rotenberg, executive director of the Electronic Privacy Information Center


"For users of Skype, this is not good news," Marc Rotenberg, executive director of the Electronic Privacy Information Center, told the E-Commerce Times. "Skype was supposed to enable more secure communications. It's largely prevented this kind of interception from occurring."


Bruce Schneier, the chief security technology officer of BT Group PLC


"For a couple of years, maybe more, people have had the suspicion ... that Skype pretends to be secure but actually isn't," said Bruce Schneier, the chief security technology officer of BT Group PLC, the British telecom carrier. "The Chinese eavesdropping on Skype text messages only adds to the PR problems, the image problems, that Skype has among those who care about security," Schneier added.


Vincent Brossel, Reporters Without Borders


According to Vincent Brossel, in charge of Asian affairs for the news organisation Reporters Without Borders, these revelations are not surprising. “We knew this for months, but this is the first time that a report provides concrete proof”, Brossel told FRANCE 24. “Chinese dissidents have been telling us for a while now that their communications (on the Chinese version of Skype) do not get through, or are subject to interference.”


ImageThief


It's your brand at stake, regardless of whether you're a minority shareholder, you simply licensed the core technology, or you simply had no idea what was going on. This was true for Yahoo, who surrendered all control of what happened with their brand in China when they sold their China operations to Alibaba.com. It's true for Skype's JV with Tom.com in China. A visit to the home page of the Skype-Tom home page reveals tons of Skype branding, while TOM appears only in text links at the top and bottom of the page.

Your Chinese JV partner doesn't care what your stakeholders back home think. This is especially true if you've surrendered control of the technology or hold only a minority stake. It's concerns first and foremost will be 1) the Chinese authorities, 2) profitability or potential thereof and 3) winning Chinese customers. The concerns of your overseas stakeholders will be somewhere way down the list of priorities.

The Chinese government will be involved somehow. They will set censorship guidelines, listen in, demand personal information on users who cross the line or all of the above. Now refer back to the first point in the previous paragraph.


Derek Bambauer

eBay (which has thus far eluded the scrutiny that Microsoft, Google, and others have faced over operations in China) has responded by saying they’ll have TOM-Skype fix the “security breach.” No, not the one that stores all these messages - the one that let Nart access them. This is like spotting a sewage leak like by the flies above it, and vowing to do something about those flies.


Rebecca MacKinnon


Skype is now learning the lesson Yahoo! already learned the hard way: that if you leave your users' privacy and security to your local partner to sort out without paying too much attention to details or thinking through how things might play out, you could burn your users badly and badly damage the credibility of your global brand.


Ross Anderson, University of Cambridge, U.K


"The real issue here is that if you're an American company and you value your public image, you should be very careful about who your partners are in foreign countries," says Ross Anderson, a professor of security engineering at the University of Cambridge, U.K. "It used to be the case that surveillance was done more or less on a per-country basis," he adds. "But more and more, the censorship may be on a per-company basis."

Surveillance was a Chinese Gov't Requirement -- Skype

I raised questions in the "Breaching Trust" report regarding why TOM-Skype started to log their users' messages and who had access to the data? Skype now says that the monitoring was a Chinese government requirement. Now we know why it was done and who had access to the captured messages.

Skype President Josh Silverman writes:


What have you learned from TOM about the uploading and storing of certain chats, and what are you doing about it?

What we have discovered in our conversations with TOM is that they in fact were required to do this by the Chinese government.

Thursday, October 2, 2008

"Extremely Concerned" -- Skype

UPDATE: Skype President Addresses Chinese Privacy Breach -- Josh Silverman's statement on the Skype blog.

The AFP reports:

Skype said it learned just Wednesday that a previously disclosed text filter operated by TOM-Skype, a joint venture between Chinese mobile firm TOM Online and Skype, had been altered.

"Last night, we learned that this practice was changed without our knowledge or consent and we are extremely concerned," Skype, which is owned by US online auction house eBay, said.

"We deeply apologise for the breach of privacy relating to chat messages on TOM's servers in China and we are urgently addressing this situation with TOM," the company said.


AFP

Skype president Josh Silverman said in a statement that TOM Online "just like any other communications company in China, has established procedures to meet local laws and regulations.

"These regulations include the requirement to monitor and block instant messages containing certain words deemed 'offensive' by the Chinese authorities," Silverman said.

"It is common knowledge that censorship does exist in China and that the Chinese government has been monitoring communications in and out of the country for many years," he said.

He recalled that in April 2006, Skype admitted that TOM Online "operated a text filter that blocked certain words in chat messages" and unsuitable messages were to be "discarded and not displayed or transmitted anywhere."

"It was our understanding that it was not TOM's protocol to upload and store chat messages with certain keywords, and we are now inquiring with TOM to find out why the protocol changed," he said.

"We are currently addressing the wider issue of the uploading and storage of certain messages with TOM," Silverman said, stressing that the millions of people around the world using standard Skype software were unaffected.

TOM-Skype Q & A

I have been getting a lot of questions and feedback on the "Breaching Trust" report. I'll try to post more details and answer questions. Here are some of the common questions people have been asking.

How were you able to determine that messages containing keywords were being uploaded to a web server? How did you find and decrypt the messages?

Wireshark. Every time I typed the word "fuck" an HTTP connection was made to a TOM Skype server. I visited the URL directly in Firefox, cut off the file name and was able to view the contents of the directory. With a little poking around I found the encryption key. A few lines of Python and voila. I did not "crack" anything nor was there any "elite" hackery -- just plain, simple stuff.

Is "normal" Skype affected?

No. The Skype software downloaded from skype.com is not affected by the behavior. The only time "normal" Skype users are affected is when they communicate with TOM-Skype users.

What is TOM-Skype and what is the difference between it and Skype?

If you go to www.skype.com from China, you are redirected to skype.tom.com -- so that's version most Chinese people will use.

In 2004 Skype developed a relationship with TOM Online, a leading wireless provider in China, and announced a joint venture in 2005. Skype and TOM Online produced a special version of the Skype software, known as TOM-Skype, for use in China.

What is Skype saying, have they said anything to you?

I contacted Skype to have the security issue fixed before the report was released. So, they have configured the servers so that one can no longer view the logs and they have deleted sensitive files, such as the one containing the encryption key. Other than that contact, I've only seen the
statements they've made to reporters.

The NYT:

Jennifer Caukin, an eBay spokeswoman, said, “The security and privacy of our users is very important to Skype.” But the company spoke to the accessibility of the messages, not their monitoring. “The security breach does not affect Skype’s core technology or functionality,” she said. “It exists within an administrative layer on Tom Online servers. We have expressed our concern to Tom Online about the security issue and they have informed us that a fix to the problem will be completed within 24 hours.” EBay had no comment on the monitoring.


To the WSJ

Jennifer Caukin, a spokeswoman for Skype, said in an emailed statement that the security problem had been remedied as a result of the new report. The idea that China's government "might be monitoring communications in and out of the country shouldn't surprise anyone," Ms. Caukin said. "Nevertheless, we were very concerned to hear about the apparent security issue" that enabled people to view user information, and "we are pleased that, once we informed TOM about it, that they were able to fix the flaw."

In a separate statement, TOM Group said that "as a Chinese company, we adhere to rules and regulations in China where we operate our businesses."


The WSJ blog, has the statement in full.

In the past Skype stated:

The text filter operates on the chat message content before it is encrypted for transmission, or after it has been decrypted on the receiver side. If the message is found unsuitable for displaying, it is simply discarded and not displayed or transmitted anywhere.


What I found directly contradicts this.

How does this relate to Corporate Social Responsibility (and the voluntary Principles of Free Expression and Privacy process)?

This case demonstrates the critical importance of the issues of transparency and accountability by providers of communications technologies. It highlights the risks of storing personally identifying and sensitive private information in jurisdictions where human rights and privacy are under threat. It also illustrates the need to assess the security, privacy and human rights impact of such a decision.

Some companies, such as Google, has stated that while the censor some search results they "will not maintain on Chinese soil any services, like email, that involve personal or confidential data."

In this case Skype appears to have delegated all of the censorship and surveillance responsibilities to TOM - I don't think they read Rebecca's paper; they should. While examining the Yahoo! China - Shi Tao case she warned:

Companies that choose to ignore the broader human rights implications of their business practices are gambling with their long-term global reputations as trustworthy conduits or repositories of people’s personal communications and information.


Are the "key words" censored? Or are the messages just logged?

The only key word that I could use to trigger the content filter (the messages is not displayed to the user) and have logged in the content filter logs (uploaded to the tom-skype server) was "fuck" (and variations like f*ck). If a message contains the word "fuck" it is not displayed to the user (the entire message is not displayed) and the entire message is uploaded and logged.

In the same content filter logs I found that the majority of the logged messages did not contain obscenities, like fuck. However, many of the messages contained words like "Communist Party", I counted the number of logged messages that contained these words, from that I identified what I think are key words. It is unclear if these messages are just logged, or are censored and logged.



Post questions in the comments and I'll try to answer them :)

Wednesday, October 1, 2008

Breaching Trust: An analysis of surveillance and security practices on China’s TOM-Skype platform

[UPDATE: New York Times coverage of the report here.]

Our investigation reveals troubling security and privacy breaches affecting TOM-Skype—the Chinese version of the popular voice and text chat software Skype. It also raises troubling questions regarding how these practices are related to the Government of China’s censorship and surveillance policies.

The questionable security practices of TOM-Online led to the disclosure of millions of records containing personal information regarding mobile phone accounts, SMS messages, and the usage of TOM-Skype. However, this disclosure also confirms that TOM-Skype is censoring and logging text chat messages that contain specific, sensitive keywords and may be engaged in more targeted surveillance.

These findings raise key questions. To what extent do TOM Online and Skype cooperate with the Chinese government in monitoring the communications of activists and dissidents as well as ordinary citizens? On what legal basis is TOM-Skype capturing and logging this volume and detail of personal user data and communication, and who has access to it?

Full Report (mirror)

Thursday, September 25, 2008

Censorship and Trade

A while back I wrote some thoughts about re-framing Internet censorship as a trade barrier. While I'm still uncertain about the consequences of doing so, I recently found this article (via freedom4internet) arguing:

Internet censorship is effectively preventing thousands of American and European e-commerce websites from reaching Chinese consumers, declare Internet marketing consultants Backbone IT Group in a recent study.


I cannot find a "study", but did find a press release by a search engine optimization company that provides services in China.

The main argument seems to be that sites hosted outside of China take 20 times as long to load as they do inside China. I don't doubt that foreign hosted websites take longer to load in fact that is why Google and others now have servers in China. But I'd like to know how these load times stack up to other countries. Is it because of China's filtering? Or is it something else.

I ran a few tests from websitepulse (see below) and China seemed to lead sites faster than Singapore and Australia. Rigorous tests would definitely be more appropriate, but I think these anecdotal tests indicate that a closer look at the methodology and data for this study would be prudent.

I am also wondering just how many ecommerce sites accept payment from China, from Chinese credit cards. In the past, Godaddy confirmed that they don't process transactions from China (this was a while ago, it could be different now). I'm not sure how widespread this practice is but I wouldnt be surprised if many ecommerce sites don't accept payment from China.

Some load times from websitepulse.com:

Tested From: Beijing, China
Tested At: 2008-09-25
08:43:47 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 2.331 sec
DNS: 0.001 sec
Connect: 0.218 sec
Redirect: 0.000 sec
First Byte: 1.126 sec
Last Byte: 0.986 sec
Size: 147825 bytes

Tested From: Seattle, WA
Tested At: 2008-09-25
08:43:47 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 0.473 sec
DNS: 0.001 sec
Connect: 0.040 sec
Redirect: 0.000 sec
First Byte: 0.231 sec
Last Byte: 0.201 sec
Size: 147825 bytes

Tested From: Beijing, China
Tested At: 2008-09-25
08:38:29 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 5.958 sec
DNS: 0.571 sec
Connect: 3.218 sec
Redirect: 0.000 sec
First Byte: 1.133 sec
Last Byte: 1.035 sec
Size: 147824 bytes

Tested From: Singapore
Tested At: 2008-09-25
08:38:29 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 7.000 sec
DNS: 1.605 sec
Connect: 3.232 sec
Redirect: 0.000 sec
First Byte: 1.199 sec
Last Byte: 0.964 sec
Size: 147824 bytes

Tested From: Beijing, China
Tested At: 2008-09-25
08:41:02 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 3.296 sec
DNS: 0.001 sec
Connect: 0.218 sec
Redirect: 0.000 sec
First Byte: 2.182 sec
Last Byte: 0.894 sec
Size: 147825 bytes

Tested From: Brisbane, Australia
Tested At: 2008-09-25
08:41:02 (GMT -04:00)
URL Tested: https://www.godaddy.com/
Resolved As: 208.109.132.201
Status: OK
Response Time: 5.277 sec
DNS: 0.352 sec
Connect: 3.187 sec
Redirect: 0.000 sec
First Byte: 0.986 sec
Last Byte: 0.752 sec
Size: 148034 bytes

Friday, September 12, 2008

Tunisia: Law Suit over Fake 404

The ONI Blog reports that a journalist/blogger in Tunisia is suiing the government over the blocking of Facebook.

Tunisian journalist and blogger Zied El-Hen filed a suit this week in a Tunisian court against the Tunisian Internet Agency for blocking the social networking Web site Facebook, according to a report by Reuters (Arabic).


An interesting twist concerns the claim that he was mislead:

In an interesting technical argument he said that the the agency mislead him by serving the message 404 (Not Found) error message instead of the 403 message (Access Forbidden), which the agency serves to users who attempt to access banned sites.


Here is a screen shot I took during WSIS in Tunisia in 2005. You can see that the 404 page is taken from Internet Explorer, but I was using Firefox! You can see from the HTTP headers that the 404 is fake.

One important issue to remember in this case is that Tunisia is using SmartFilter, a filtering product developed by the U.S. company Secure Computing. This product is used in many countries including in Saudi Arabia, Oman, Sudan, United Arab Emirates, and previously in Iran. In these other countries they use SmarFilter to show users a blockpage that indicates to the user that the content is intentionally blocked. Instead, Tunisia uses this blockpage functionality to fake a 404 error page.

Tunisia uses SmartFilter to block access to categories of websites, such as pornography, but also adds their own targets, often political web sites, to the blocking lists. Sometimes content that was not intended to be blocked is blocked in all of Tunisia due to miscategorizations by SmartFilter.

Thursday, September 11, 2008

Yahoo, MSN Censor More than Baidu

China unblocked many usually censored web sites following intense international pressure and scrutiny after having promised uncensored access during the Olympics. Five days later (August 6, 2008) I tested the search engines that Google, Yahoo! and Microsoft customize for the Chinese market as well as the leading domestic search engine Baidu. I found that all of the search engines were still censoring content that was unblocked by China. one interesting find was that Yahoo! was censoring less than all the others and Baidu (and Google) were censoring much less than Microsoft.

For purposes on comparison Google and Microsoft make a good match because both have to de-list web sites form search results while Yahoo! and Baidu index form within China and thus do not (usually) index sites already censored by China. (For more read my report on search engine comparison.)

Now over a month later things have changed. While these sites remain accessible in China some are still censored by the search engines. Google has dropped to only censoring two sites and is now censoring the least amount of content. Baidu is next with three censored sites. Microsoft remained steady, but Yahoo! has shifted from censoring the least amount of sites to the most!

The divergence between Yahoo! and Baidu is very interesting. If both crawl from within China and are subject to China's filtering why is Yahoo! censoring so much more than Baidu? It could be that the conclusion that Yahoo! and Baidu do not de-list content is not fully accurate. If the sites are accessible in China then Yahoo! is likely de-listing the sites. Because of the suboptimal method of censorship notification employed by Yahoo! (a standard disclaimer on every page regardless of whether any of the results are censored or not) I cannot fully distinguish between sites that are de-listed and sites that have not been indexed (e.g. because China blocks them).

I'm still struck by the fact that over a month later sites that are available and uncensored in China are still censored by these search engines.





















































































































































DOMAINS Google Yahoo Microsoft Baidu
ip =
"203.208.39.99"
host = "www.google.cn"
ip =
"202.165.102.243"
host = "one.cn.yahoo.com"
ip =
"202.89.236.206"
host = "cnweb.search.live.com"
ip =
"202.108.22.43"
host = "www.baidu.com"
chinese.wsj.com OK OK OK OK
cn.reuters.com OK OK OK OK
news.chinatimes.com OK CENSORED (0) CENSORED (0) OK
olympics.scmp.com OK OK OK OK
udn.com OK OK OK OK
www.amnesty.org OK CENSORED (0) CENSORED (0) CENSORED (0)
www.atchinese.com OK CENSORED (0) CENSORED (0) OK
www.ftchinese.com OK OK OK OK
www.hrw.org OK) CENSORED (0) CENSORED (0) CENSORED (0)
www.libertytimes.com.tw CENSORED (0, message) OK OK OK
www.mingpaomonthly.com OK OK OK OK
www.mingpaonews.com OK CENSORED (0) CENSORED (0) OK
www.rfa.org CENSORED (0, message) CENSORED (0) CENSORED (0) OK
www.rsf.org OK CENSORED (0) CENSORED (0) OK
www.scmp.com OK OK OK OK
www.voanews.com OK CENSORED (0) CENSORED (0) CENSORED (0)
www.yzzk.com OK CENSORED (0) OK OK
www1.appledaily.atnext.com OK CENSORED (0) OK OK
zh.wikipedia.org OK CENSORED (0) CENSORED (0) OK

Wednesday, September 3, 2008

DNS and the GFW

While the ability to the GFW to send RST packets in an attempt to terminate a connection between a source IP and a destination IP based on keywords appearing in packets (keyword in GET requests and possibly the HTML responses) has been documented in http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf and http://www.cs.unm.edu/~crandall/concept_doppler_ccs07.pdf China also employs a similar system to interfere with DNS. If a DNS request to resolve a hostname is sent in to an IP in China, an intermediary will respond with a DNS response containing an incorrect IP. This is not totally new, it has been documented from inside China already.

I start with a "UDP Traceroute" (DNS packets with no qname with incrementing TTL's) in order to find the first hop inside China. The IP address of contained in the ICMP response is checked in Team Cymru's IP lookup service to find the AS, Country and Network Name.


1|192.168.2.1|time-exceeded NA
2|64.230.*.*|time-exceeded CA NA
3|64.230.*.*|time-exceeded CA NA
4|64.230.*.*|time-exceeded CA NA
5|64.230.*.*|time-exceeded CA NA
6|64.230.147.14|time-exceeded CA NA
7|206.108.103.138|time-exceeded CA NA
8|160.81.109.193|time-exceeded US SPRINTLINK - Sprint
9|144.232.10.19|time-exceeded US SPRINTLINK - Sprint
10|144.232.8.169|time-exceeded US SPRINTLINK - Sprint
11|144.232.9.224|time-exceeded US SPRINTLINK - Sprint
12|144.232.9.32|time-exceeded US SPRINTLINK - Sprint
13|144.232.2.171|time-exceeded US SPRINTLINK - Sprint
14|144.223.148.2|time-exceeded US SPRINTLINK - Sprint
15|219.158.4.193|time-exceeded CN CHINA169-BACKBONE CNCGROUP China169 Backbone


For me the first CN hop to the IP address 202.165.102.247 (www.yahoo.cn) is 15. So I send a DNS request for "www.citizenlab.org" to 202.165.102.247 (which is not a DNS server) with a TTL of 15, its IP is 219.158.4.193 (CHINA169-BACKBONE CNCGROUP China169 Backbone).


###[ IP ]###
version = 4
ihl = 0
tos = 0x0
len = 0
id = 1
flags =
frag = 0
ttl = 15
proto = udp
chksum = 0x0
src = 192.168.2.11
dst = 202.165.102.247
options = ''
###[ UDP ]###
sport = domain
dport = domain
len = 0
chksum = 0x0
###[ DNS ]###
id = 0
qr = 0
opcode = QUERY
aa = 0
tc = 0
rd = 1
ra = 0
z = 0
rcode = ok
qdcount = 0
ancount = 0
nscount = 0
arcount = 0
\qd \
|###[ DNS Question Record ]###
| qname = 'www.citizenlab.org'
| qtype = A
| qclass = IN
an = 0
ns = 0
ar = 0


The ICMP response comes back from hop 15:


###[ IP ]###
version = 4L
ihl = 5L
tos = 0x0
len = 56
id = 5984
flags =
frag = 0L
ttl = 241
proto = icmp
chksum = 0xf52
src = 219.158.4.193
dst = 192.168.2.11
options = ''
###[ ICMP ]###
type = time-exceeded
code = 0
chksum = 0xc2d7
id = 0xeacf
seq = 0x3af8
###[ IP in ICMP ]###
version = 4L
ihl = 5L
tos = 0x0
len = 64
id = 1
flags =
frag = 0L
ttl = 1
proto = udp
chksum = 0xc55c
src = 192.168.2.11
dst = 202.165.102.247
options = ''
###[ UDP in ICMP ]###
sport = domain
dport = domain
len = 44
chksum = 0xbca


While this is occurring I also sniff the wire to see if other packets are being sent my way, and they are. Four bad DNS responses were sent my way claiming to be from 202.165.102.247.


###[ IP ]###
version = 4L
ihl = 5L
tos = 0x10
len = 98
id = 45372
flags =
frag = 0L
ttl = 45
proto = udp
chksum = 0xe7ee
src = 202.165.102.247
dst = 192.168.2.11
options = ''
###[ UDP ]###
sport = domain
dport = domain
len = 78
chksum = 0xe286
###[ DNS ]###
id = 0
qr = 1L
opcode = QUERY
aa = 1L
tc = 0L
rd = 1L
ra = 1L
z = 0L
rcode = ok
qdcount = 1
ancount = 1
nscount = 0
arcount = 0
\qd \
|###[ DNS Question Record ]###
| qname = 'www.citizenlab.org.'
| qtype = A
| qclass = IN
\an \
|###[ DNS Resource Record ]###
| rrname = 'www.citizenlab.org.'
| type = A
| rclass = IN
| ttl = 86400
| rdlen = 0
| rdata = '216.234.179.13'
ns = 0
ar = 0


Summary:


192.168.2.11 > 202.165.102.247 <DNSQR qname='www.citizenlab.org.' qtype=A qclass=IN |> 0
219.158.4.193 > 192.168.2.11 time-exceeded
202.165.102.247 > 192.168.2.11 <DNSQR qname='www.citizenlab.org.' qtype=A qclass=IN |>
<DNSRR rrname='www.citizenlab.org.' type=A rclass=IN ttl=300 rdata='64.33.88.161' |>
202.165.102.247 > 192.168.2.11 <DNSQR qname='www.citizenlab.org.' qtype=A qclass=IN |>
<DNSRR rrname='www.citizenlab.org.' type=A rclass=IN ttl=86400 rdata='216.234.179.13' |>
202.165.102.247 > 192.168.2.11 <DNSQR qname='www.citizenlab.org.' qtype=A qclass=IN |>
<DNSRR rrname='www.citizenlab.org.' type=A rclass=IN ttl=86400 rdata='216.234.179.13' |>
202.165.102.247 > 192.168.2.11 <DNSQR qname='www.citizenlab.org.' qtype=A qclass=IN |>
<DNSRR rrname='www.citizenlab.org.' type=A rclass=IN ttl=86400 rdata='216.234.179.13' |>


64.33.88.161 and 216.234.179.13 are not IP addresses that "www.citizenlab.org" should resolve to.

I used 38 IP addresses on 38 different AS's in China as targets. A DNS packet was sent to the first CN hop from a udp traceroute to each of these IPs. The IP's returned from the ICMP packet received from each hop are distributed across 11 AS's in China.

In total, I received 8 unique bad IP addresses.


211.94.66.147 24403 CN CNNIC-CNCITYNET-AP Beijing Kuanjie Net communication technology Ltd
209.145.54.50 6428 US CDM - CDM
203.161.230.171 9925 HK HKTHOST-AP Powerbase DataCenter Services (HK) Ltd.
64.33.88.161 19916 US ASTRUM-0001 - OLM LLC
202.181.7.85 7489 AU FIRSTLINK-AS-AP First Link Internet Services
4.36.66.178 3356 US LEVEL3 Level 3 Communications
216.234.179.13 13911 CA TERA-BYTE - Tera-byte Online Services
202.106.1.2 4808 CN CHINA169-BJ CNCGROUP IP network China169 Beijing Province Network


Two of the IP's are in Mainland China and one is in Hong Kong; three are in the US and one in Australia. Only one of the CN IP's, 211.94.66.147, has a web server running when I checked which means that this server could log IP addresses that connect to it and host name in the requests. Why these IPs?

I don't know. It is pretty strange.

64.33.88.161 was the IP for falundafa.ca, the IP was blocked so an domains that resolved to it were also blocked. Seems to be legacy blocking.

If you $host bbs.hygung.com you'll get back most of these IP's, along with a bunch of others. Many of these IP's also appear on some kind of IP blocking list (another one), RobotDog anyone? Seems to be a list for a Router OS by http://www.mikrotik.com.cn/. Another site has a post about dns cache poisoning/phishing and one of these IP's, this time affecting an ISP in Taiwan.

Anyone?

Thursday, August 28, 2008

The "iTunes Blocked in China" Takeaway

The iTunes Store, the portal page used to puchase media from Apple, was briefly blocked in China. This meant that iTunes users in China were unable to view, search, sample and purchase media available through Apple's iTunes Store. (I recently spoke with The World's Cyrus Farivar about this story (mp3), below I expand on some of the details.)

How? China has a multi-layered filtering system. One of these layers is "key word" filtering that occurs near the main international gateways that connect China to the rest of the Internet. When packets are found in requests (or responses) that contain certain keywords, China's filtering system sends reset (RST) packets to the computer that issued the request as well as the computer to which the request was sent effectively terminating the connection between the two. China added a portion of the iTunes Store URL as a keyword; whenever a request was seen to contain this keyword the request was reset.

Why? China does not disclose the official reasons why content is blocked but the reason is most likely due to the "Songs for Tibet" album available through the iTunes Store. The album contains songs by popular artists and those who purchase the entire album get access to a video of the Dalai Lama. While other content the Government of China would likely find objectionable is available in iTunes, including Tibet and Dalai Lama related content, downloading the "Songs for Tibet" album became a form of protest.

The Art of Peace Foundation issued a press release on August 19, 2008 stating that Olympic athletes were downloading the album "as an act of solidarity with Tibet." On August 21, 2008 Stephen Hutcheon of the Sydney Morning Herald reported:

Access to Apple's online iTunes Store has been blocked in China after it emerged that Olympic athletes have been downloading and possibly listening to a pro-Tibetan music album in a subtle act of protest against China's rule over the province.


Access to the Tunes Store was quickly reinstated, but access to the specific album was reportedly still blocked. Shortly thereafter reports emerged stating that the album itself was also accessible from within China. It is still unclear whether full access to the album has been restored.

Where? How is it possible that some Internet users in China have access to the "Songs for Tibet" album in the iTunes Store while others do not? China has a multi-layered filtering system; it is not always identical in all parts of China. While the album is no longer blocked in all of China, at the gateway points for example, it may still be blocked at local or regional levels or on specific Internet Service Providers.

The Takeaway? The blocking of the iTunes store itself, and the blocking of the specific "Songs for Tibet" album, is important even though it was brief. Not so much in terms of the Government of China, we know that they will continue to block content they find threatening but i terms of what Apple will do. It turns out that normal Internet users in China can't purchase and download the "Songs for Tibet" album, only foreigners with credit cards and billing addresses outside of China can. (They can listen/watch the short clips available for free however, it they set their iTunes Store to a different location, such as Canada). iTunes does not currently have a full iTunes Store for China -- but they will!

When Apple opens "iTunes Store China" will "Songs for Tibet" be available through it? Will they restrict access to content by geographical locations? Well for copyright reasons they already do, will they do so for politically sensitive content as well?

Internet Censorship: Malaysia

Malaysia has become the latest country to begin filtering the Internet. The news web site www.malaysia-today.net is being blocked by Malaysia largest Internet Service Provider, TMnet, after the Malaysian Communications and Multimedia Commission ordered the web site blocked.

TMnet has configured their DNS serverssuch that they do not properly resolve the correct IP addresses for www.malaysia-today.net or malaysia-today.net.


$ dig @202.188.1.5 www.malaysia-today.net

; < <>> DiG 9.4.2-P1 < <>> @202.188.1.5 www.malaysia-today.net
; (1 server found)
;; global options: printcmd
;; Got answer:
;; ->>HEADER< <- opcode: QUERY, status: NXDOMAIN, id: 18677
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;www.malaysia-today.net. IN A

;; AUTHORITY SECTION:
malaysia-today.net. 3600 IN SOA ns1.blocked. blocked.tm.net.my. 1 900 600 86400 3600

;; Query time: 270 msec
;; SERVER: 202.188.1.5#53(202.188.1.5)
;; WHEN: Thu Aug 28 09:20:20 2008
;; MSG SIZE rcvd: 104

$ dig @202.188.1.5 malaysia-today.net

; <<>> DiG 9.4.2-P1 < <>> @202.188.1.5 malaysia-today.net
; (1 server found)
;; global options: printcmd
;; Got answer:
;; ->>HEADER< <- opcode: QUERY, status: NOERROR, id: 15429
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;malaysia-today.net. IN A

;; ANSWER SECTION:
malaysia-today.net. 3600 IN A 127.0.0.1

;; AUTHORITY SECTION:
malaysia-today.net. 3600 IN NS ns1.blocked.

;; Query time: 292 msec
;; SERVER: 202.188.1.5#53(202.188.1.5)
;; WHEN: Thu Aug 28 09:20:42 2008
;; MSG SIZE rcvd: 77

Friday, August 22, 2008

iTunes Store Blocked in China

UPDATE: I can now access the iTunes store from China.

Recent reports indicate that China is blocking access to Apple's iTunes Store:

Users reported receiving an error message when attempting to reach iTunes: "iTunes could not connect to the iTunes store. An unknown error occurred.(-4) Make sure your network connection is active and try again."


While in some cases this error is associated with iTunes itself, I can confirm that in this case China was blocking access to URLs necessary to load the iTunes Store. China employs a variety of methods of filtering. In this case, all of the domains properly resolved to correct IP addresses and all of the IP addresses were accessible. Moreover, SSL access was also fine. The initial requests that iTunes makes work fine, until a particular URL is requested.

More specifically, GET requests containing "ax.phobos.apple.com.edgesuite.net/WebObjects/MZStore" are disrupted. (There were probably more ways to trigger the RST's, I did not get the chance to test more as the blocking appears to have been lifted). After making a few connections, iTunes eventually attempts to connect to:

http://ax.phobos.apple.com.edgesuite.net/WebObjects/MZStore.woa/wa/initiateSession?ix=2

This triggers spoofed RST packets.

In addition to checking from computers in China, this behaviour can be triggered by connecting into China as well. Here I've set up a 3-way TCP handshake with yahoo.cn's IP address, since yahoo.cn is located in China. I then send a packet with the payload "ax.phobos.apple.com.edgesuite.net/WebObjects/MZStore" but with a TTL that is insufficient to reach the intended destination. An ICMP packet comes back from a router (for me, at TTL 16) followed by spoofed RST packets that disrupt the connection.

See http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf and http://www.cs.unm.edu/~crandall/concept_doppler_ccs07.pdf for more on this technique.

Wednesday, August 6, 2008

Free Expression Principles

Major technology companies, including Google, Yahoo! and Microsoft, have agreed, in principle, to a voluntary set of principles designed to "guide businesses when they encounter laws and practices that may contravene international human rights standards or be at odds with law or culture in their home jurisdiction." The objective is to protect and advance freedom of expression and privacy. Included in this initiative are mechanisms to provide for ongoing learning as well as the monitoring of compliance.

Google, Yahoo! and Microsoft sent letters to Sen. Durbin announcing the agreement. The letters re-state each company's commitment to freedom of expression and highlight the core components of the initiative including the principles, the implementation guidelines and the accountability and learning framework.

Google's letter draws on my report that compared Google, yahoo! and Microsoft's search engines along with the domestic Chinese company Baidu. The most significant point centers on the impact of engagement. I found that the presence of foreign search engines resulted in an increased amount of information being available to Chinese Internet users. More specifically, I found that:

When the results from Google, Microsoft and Yahoo are combined, 20% of the sites censored by Baidu are available. However, individually they provide more information, especially Google and Microsoft which provide, on average, 51% and 55% more content (content not available in Baidu) while Yahoo! averages 25% more.


Since the search engines were censoring different content mixing searches across multiple search engine resulted in the ability to find sites censored by the other search engines.

Also, I noted that Baidu, the leading Chinese search engine, had introduced a censorship notification following the lead of the foreign search engines. Unlike foreign search engines under pressure from the home governments Baidu is not. While a still a small step, it shows that engagement can make a difference and that industry standards are important. that is why I think the principles for free expression and privacy are so important. They present a united effort and set an industry standard.

Engagement certainly presents a series of hard choices, but is a better choice than disengagement when it comes to information and communications technologies. These technologies build the bridges that connect diverse people and places, putting up barriers is what the censors do. I find it hard to believe that the promotion of free expression is served in Iran by denying Iranians access to the Java programming language.

The catch here is that this agreement and these principles are not an end point but a starting point. As I noted in my report the overall level of transparency is low -- there is work to be done in this area. The process for determining what to censor is still unclear and supports the secrecy and unaccountability of China's censorship policies. Even within a restrictive environment such as China I believe there is much more that can be done. (See below). I also showed that while the total amount of censorship may not be high, the significance of the censored sites is important.

These censored sites are often the only sources of alternative information available in the top ten results for politically sensitive search queries. Moreover, even the uncensored versions of these search engines highly rank content that is hosted in China or ends in the domain suffix .cn, both of which China retains control over and are thus unlikely to present alternative information.


China recently unblocked many censored web sites after intense international pressure and scrutiny after having promised uncensored access during the Olympics. Andrew Lih tested a sample of websites normally censored in China and found them to be accessible. The web sites of human rights groups such as Human Rights Watch, Reporters Sans Frontiers and Amnesty International are all now accessible.

Andrew posted his test results on August 1st, 2008, five days later search engines are still censoring sites that are not unblocked in China. For example, Yahoo! Microsoft and Baidu are still censoring www.amnesty.org while Google is not. Google, Microsoft and Baidu are still censoring www.hrw.org while Yahoo!s not. (Yahoo! has only one result, www.hrw.org/russian, I'm not sure how many Russian speakers there are in China, anyone know?) Only Microsoft is still censoring www.rsf.org -- even Baidu is not. In fact, Microsoft is censoring more of these newly unblocked websites than the Chinese company Baidu! Another noteworthy observation is that Yahoo! is censoring the least of these newly unblocked sites.





















































































































































DOMAINS Google Yahoo Microsoft Baidu
ip =
"203.208.39.99"
host = "www.google.cn"
ip =
"202.165.102.243"
host = "one.cn.yahoo.com"
ip =
"202.89.236.206"
host = "cnweb.search.live.com"
ip =
"202.108.22.43"
host = "www.baidu.com"
chinese.wsj.com OK OK OK OK
cn.reuters.com OK OK OK OK
news.chinatimes.com OK OK CENSORED (0) OK
olympics.scmp.com OK OK OK OK
udn.com OK OK OK OK
www.amnesty.org OK CENSORED (0) CENSORED (0) CENSORED (0)
www.atchinese.com OK OK CENSORED (0) OK
www.ftchinese.com OK OK OK OK
www.hrw.org CENSORED (0, message) OK CENSORED (0) CENSORED (0)
www.libertytimes.com.tw CENSORED (0, message) OK OK OK
www.mingpaomonthly.com OK OK OK OK
www.mingpaonews.com OK OK CENSORED (0) OK
www.rfa.org CENSORED (0, message) OK CENSORED (0) OK
www.rsf.org OK OK CENSORED (0) OK
www.scmp.com OK OK OK OK
www.voanews.com OK OK CENSORED (0) CENSORED (0)
www.yzzk.com OK OK OK OK
www1.appledaily.atnext.com OK CENSORED (0) OK OK
zh.wikipedia.org OK OK CENSORED (0) OK


* If at least one result was returned for a "site:" search on a domain, it was marked as OK.

To be fair, it does take time for search engines to respond. They have multiple servers, it may take time for them all to be updated. Also, there differences in implementation between those that crawl and index the web from behind China's filtering system and those that do not and thus have to "de-list" results. (See the report for details on this.)

Still, I find it difficult to accept that sites that are unblocked in China remain censored in these search engines.

Thursday, July 31, 2008

The Canadian DMCA: What You Can Do

Canada: Police Impersonating Journalists

Canadian Journalists for Free Expression report that Ontario police continue to impersonate journalists, in this case at a Mohawk rally.

This practice of impersonating journalists concerns CJFE for two reasons. First, this tactic compromises the media's position as an independent third party, thereby threatening reporters' safety and their ability to gain access to stories and sources.

Second, we believe that when police - city, provincial or the RCMP - pretend they are journalists they undermine a free press in Canada.

Thursday, July 17, 2008

The (b)Logosphere - Part 2

The companies that provide blogging, social networking and video hosting services are becoming aware of the fact that a core user constituency is engaged in citizen journalism and digital advocacy. And that this also presents challenges. These companies are in a position in which they are are compelled to comply with the censorship and surveillance demands of governments and corporations in addition to protecting the privacy and freedom of expression of their users. In fact many of these services, such a Youtube and Flickr, have been censored in various countries. In other cases, they have chosen to self-censor to comply with local restrictions. They have also turned over data resulting in the arrest of activists and dissidents.

But just as users can protect themselves, so can companies.

1. If you log it, they will come. What you log, how it is stored (anonymized logs), and how long you keep them for are important.

2. Censorship is a double-edged sword. If you do not censor, there is a risk that your service will be blocked. If you do censor, you will be condemned. Therefore it is important to be open and transparent surrounding what and how you censor. Derek Bambauer has a great paper that expands on what the concept of transparency really means. It is well worth the read.

3. Awareness is crucial. Internal awareness of the use of your services by political activists and citizen journalists is very important. Consider the case(starts at 14:15 in the podcast) of Wael Abbas in Egypt: he uploaded videos of police brutality and torture in Egypt to YouTube which lead to the arrest of some officers involved. YouTube suspended his account for posting "inappropriate material" and did no respond to his emails asking for clarification. Only after his case appeared on CNN and major media outlets as well as a campaign by fellow bloggers did YouTube restore his account. YouTube said that the videos did not have sufficient context. Wael says that YouTube told him that the people staffing the suspensions were new and didn't know what they were doing as all the complaints leading to the suspension of the account were from one source, most likely the Egyptian government.

4. Communication is vital. If is very important for users to know the potential risks they face. For example, it is now well known that Yahoo! China has cooperated with Chinese authorities turning over email and account information that helped convict at least four dissidents. The use of a foreign, well known email service did not provide them with any more protection than a domestic Chinese service would have. In contrast, Google has pledged to not offer certain products in China.

5. Know where your servers are hosted and what your partners/subsidiaries are up to. See Rebecca MacKinnon's excellent paper for a thorough discussion.

Wednesday, July 16, 2008

CBC takes down Hamas, Hezbollah websites

When Jonathan Halevi found that websites affiliated with Hamas and Hezbollah were being hosted on servers owned by the Canadian company iWeb he contacted iWeb and asked for them to be taken down. He was not successful. However, when CBC translated some Arabic in the discussion forum and contacted iWeb claiming that they were hosting "a site whose content could violate Canada’s anti-terrorism act" iWeb re-evaluated and took down the sites.

It is unclear exactly which specific sites were targeted although both www.almanar.com.lb (Hezbollah affiliated) and www.aqsatv.ps (Hamas affiliated) were both previously hosted on iWeb. After the initial complaint, iWeb reviewed the English content of the web site(s) (almanar has an English section, aqsatv does not appear to have an English section it is not clear what was actually reveiwed) and determined that "the English version did not seem to have any content which could violate our policies or laws." However, after CBC's claim that they were in violation of Canada’s anti-terrorism act iWeb removed the site(s):


In this case, analysis of the site had been done on the English version of the site, a version that did not seem to include material or content that was illegal or in violation of our terms of service (these facts were confirmed by journalists involved in this case). We informed our customer of this complaint and of the conclusions we came to. We also informed the individual who made the complaint, who did not provide any feedback or additional information.


It actually appears that the offending content which lead to the removal of the web sites were actually COMMENTS posted beneath an article:

People’s comments under the article in question are a good example, several believe that the site had to be removed and others believe that this is freedom of expression; who is right?


In response to the original complaint iWeb suggested that that the RCMP be contacted and if the content violated the law they would act. But after CBC's involvement they acted to remove the content without this:

For our part, we determine that the initial complaint, which did not target a specific part or section of the site was not, at first glance, substantiated and that the version and sections of the site that we analyzed were conformed with Canadian laws and our policies. That being said, we originally specified to the person who made the complaint that if they felt the issue required legal attention, that they should voice their concern to the competent authorities like the RCMP (Royal Canadian Mounted Police) so that they can also analyze the content and that we will collaborate with their verdict. When the complaint reached us for a second time, the new information provided to us made us revise our position. We then agreed that it was not informative speech or opinion or freedom of expression anymore, but a threat to human beings who violates our policies for using this service and why we intervened by shutting down the sites in question.


The details are still a bit confusing:

  • What were the exact web sites in question? Are they in fact www.almanar.com.lb and www.aqsatv.ps?

  • What was the exact offending content that CBC felt was a violation of Canada's anti terrorism act? Was it a post in a discussion forum? Was it a comment posted below an article? On which site?

  • Were these web sites removed due to content posted by USERS and not by the owners of the sites?

  • Were the owners of the web sites given the opportunity to moderate/delete the offending user comments?

  • Were the owners of the web sites given the opportunity to keep the English version, which had no offending content?



This, of course, is not the first time this has happened. I have posted about this in the past:

Content removed for allegedly supporting terrorism is one of the least documented forms of takedown... The Internet Haganah, which calls for the removal of sites which allegedly support terrorism, had counted 600 successful takedowns by 2005. These include websites, groups hosted by Yahoo! and storefronts at Cafe Press. In 2005, the Toronto-based Friends of Simon Wiesenthal Center had several sites removed by their ISPs, one of which only contained a flag that carried the inscription, ‘There is no other God but Allah’. There was no hateful text or material advocating suicide bombing. The issue, as noted in the press release, was that the flag appeared to be the same one used by Hizb-ut-Tahrir, a group that, at the time, was not on the US State Department’s or Canada’s list of terrorist organisations.


Pending answers to the questions above, it seems that the issue here is not one of content but of association, pressure and selective enforcement.

For example, the web site of KACH www.kahanetzadak.com, which is among a handful of websites listed as terrorist entities by the U.S., is also hosted in Canada:

OrgName: In2net Network Inc.
OrgID: IN2N
Address: 3602 Gilmore Way,
Address: Suite 210
City: Burnaby
StateProv: BC
PostalCode: V5G-4W9
Country: CA


These cases raise troubling question concerning transparency and due process the lack of which leads to chilling effects on freedom of expression. While the details are still unclear, it appears that these sites were removed after CBC determined that forums posts or comment posts were in violation of Canada's anti-terrorism act. That is, not content posted by the owner's of web sites but by users. And it is unclear if the owner's of the sites were given the opportunity to moderate the offending content. This has consequences that go beyond just this case. The "vigilante model" of takedown puts the power of judge, jury and executioner in the hands of hosting providers and ISPs. The entire process lacks transparency, accountability and oversight.

Friday, July 4, 2008

The (b)Logosphere - Part 1

The explosion of citizen journalism has allowed increased access to a diversity of voices around the globe. Issues and voices that are not represented in mainstream media are providing diverse perspectives on both popular and obscure political issues. However, this phenomenon is certainly not new. While recent attention has focused on bloggers around the world, past efforts, including the creation of Indymedia nearly ten years ago, leveraged the Internet for these same purposes. The success of citizen journalism is based on a combination of personal experience, opinion and analysis with traditional news to provide a compelling account of political events that engages and connects with the reader.

While bloggers are quite aware of the danger of government censorship and surveillance, the same skepticism concerning free expression and privacy often does not extend to the corporate sector. The blogosphere looks more like the logosphere, unlike the nologosphere of earlier incarnations of independent media. While some open, decentralized elements remain, particularly the use of open source software such as wordpress and open licensing such as creative commons, most of the tools and platforms used by bloggers are corporate, proprietary products: Blogger/Blogspot, Twitter, Gkype, Gmail, Feedburner, Flickr, Technorati, Facebook, Myspace, Youtube etc... This is not necessarily a bad thing, it just presents a different set of challenges.

After setting up a fake Facebook profile of a Moroccan Prince, Fouad Mourtada was arrested and sentenced to three years in prison. Although Fouad was recently pardoned and released after an international campaign, the case has raised questions about Facebook's possible involvement:

How the Moroccan police found out Mourtada's identity remains a bit of a mystery. They could have obtained his IP address from Facebook, or from his service provider, Maroc Telecom, or from an old-fashioned snitch. But the preliminary court hearing did not include details of the police investigation, so the possibility of corporate cooperation cannot be ruled out.


In at least four cases Yahoo! cooperated with the Chinese government resulting in the imprisonment of dissidents. The use of a foreign, well known email service did not provide them with any more protection than a domestic Chinese service would have. Orkut, Google's social networking site, handed over information to the police in India which was used to arrest a person for insulting a revered figure. Youtube, despite putting up a legal battle, has been ordered to turn over user information of everyone who has ever used Youtube to Viacom. Such services collect and store information about users that can and has been handed over to others, in some cases resulting in the arrests of activists and dissidents.

In other cases companies censor their users. Skype has partnered with a domestic Chinese company to provide a censored version of its popular voip/chat software. Microsoft deleted the MSN spaces account of a well known Chinese blogger and filters its service to prevent posts from being made that contain certain sensitive words. In fact, this is exactly what domestic Chinese blogging platforms do. The Chinese version of Myspace censors posts that contain sensitive words and also encourages users to report those who engage in "misconduct." Google, Microsoft and Yahoo! all maintain censored versions of their search engines for the Chinese market.

Internet users can and should take measures to protect themselves, even Indymedia's servers were seized by police in the past. Projects such as Tor provide technical measures to enhance ones privacy online by providing a significant level of anonymity. Global Voices Advocacy has created a guide that shows users how to blog anonymously with Wordpress and Tor. The Citizen Lab has produced a guide to bypassing censorship. NGO-in-a-Box has produced a collection of security software that helps NGO's secure themselves. It is important for citizen journalists to asses the threats they face and use tools that minimize those risks. A well recognized foreign brand is not a substitute for good security practices.

However, the strength of tools such as Facebook, Flickr, and Twitter rests upon their ease of use and most users will not take the additional steps necessary to protect ones privacy. Just as users may need to implement strategies to minimize their potential risks, the technology companies on whose services bloggers and citizen journalists rely should also take proactive steps to protect their users and communicate the limits of that protection to their users.