Showing posts with label Internet Watch Foundation. Show all posts
Showing posts with label Internet Watch Foundation. Show all posts

Wednesday, August 03, 2011

Site Blocking: What the UK Government would prefer you not to see

It's well known that internet blocking is easy to circumvent. Ofcom in today's report "Site Blocking" to reduce online copyright infringement admits as much, saying that:
For all blocking methods circumvention by site operators and internet users is technically possible and would be relatively straightforward by determined users. (p.5)
Despite this, however, one branch of the UK Government still appears determined to keep its head in the sand, and according to that report:
The Department for Culture, Media and Sport has redacted some parts of this document where it refers to techniques that could be used to circumvent website blocks.
Unfortunately, the technical competence of the DCMS appears to be somewhat limited, and the redaction was (ironically?) also easily circumvented, by measures as simple as copy/paste. Needless to say, a department which is unable to censor a single PDF does not exactly inspire confidence when it proposes to introduce blocking for the entire UK internet, and it is just as well that the UK government has today announced plans to abandon the blocking provisions of the Digital Economy Act.

[Updated - 1.15pm]

The full, unredacted version now appears on Scribd. As can be seen from that document, the material which was redacted was all improperly removed. The tactics discussed to circumvent blocking are all well-known, even to a mere lawyer such as myself, and the redactions appear to be motivated more by considerations of security theatre than anything else.Ofcom Site Blocking Report With Redactions Removed

[Previously]

Here are the individual portions of the report which the DCMS attempted to quash. Text in italics was not redacted but appears for context:

pp.28-29
Robustness

Bypassing IP address blocking is technically straightforward for those who have an incentive to do so.
The blocked site operator may:

• change IP address but stay on the same network (i.e. on the same hosting provider);
• move to an entirely new network (to a previously unobserved IP address);
• offer encrypted network services which obscure the true network address/destination such as Virtual Private Networking;26,27 or
• server operators may institute a Fast Flux network (where users run software on behalf of blocked site which hides the true network address of the blocked site).

There are other methods available to site operators. When moving to a new IP address a site operator may register multiple IP addresses for a given site in order to maintain service in the event that some of those individual IP addresses are blocked. This approach has legitimate purposes also.28 Furthermore, by setting a low “Time to Live” (TTL) Domain Name System (DNS) record value, determining the length of time that the IP address for a particular domain (expressed in seconds) remains in remote name server caches, it is easier for a site operator to move IP addresses without end users losing access. Where a low TTL is expressed the ISP DNS name server resolution cache is purged quickly thereby ensuring that newly assigned site IP addresses are retrieved from the authoritative name server and site accessibility is maintained. Figure 13 below shows that the TTL value for "kickasstorrents" is one hour, demonstrating that any changes to IP address to DNS name are refreshed and propagated within ISP DNS servers in just over an hour.

Figure 13: Kickasstorrents DNS record Time to Live (1 hour) Name TTL Class Record Address
www.kickasstorrents.com. 3600 IN A 95.215.60.37
www.kickasstorrents.com. 3600 IN A 93.114.40.112
www.kickasstorrents.com. 3600 IN A 193.105.134.81
www.kickasstorrents.com. 3600 IN A 95.143.195.138
www.kickasstorrents.com. 3600 IN A 76.76.107.90

26 Ipredator - Surf anonymously with VPN and proxy https://www.ipredator.se/?lang=en
27 UK based VPN services facilitating access to copyright infringed material may be subject to site blocking injunctions. UK VPN operators may institute site blocking at the VPN egress point. NB: we are not aware of any UK based VPN service marketed or positioned for such activity. Such services are likely to be non-UK based.
pp.33-34
DNS blocking robustness

For site operators and end users with a sufficient incentive to engage in circumvention DNS blocking is technically relatively straightforward to bypass:


• the blocked site may offer services such as Virtual Private Networking, which is where encryption and other security measures are deployed to ensure that the data cannot be viewed by third parties (DNS name resolution may occur within the VPN providers network thereby bypassing the ISP based DNS site-blocking);
• the end-user can change their DNS name servers to 3rd party DNS name servers;32,33
• users may use anonymous web proxy or other anonymising services which are not reliant on the ISP DNS servers; or
• name resolution may be performed locally by adding an entry to a hosts file (IP address resolution information can be obtained from websites running a web-enabled equivalent of “nslookup” command).

32 Google Public DNS - http://code.google.com/speed/public-dns/
33 OpenDNS Store > Sign up for OpenDNS Basic: - https://store.opendns.com/get/basic/

For end users who want to bypass blocks there are several options. For instance, there are many legitimate alternative DNS providers to ISP DNS registries. Examples include OpenDNS and Google DNS. We consider the changing of DNS servers to alternative providers to require low technical skills, as the providers offer clear instructions using plain English. For instance, switching to Google DNS requires 11 steps for Windows users and only 8 for those using MAC OS.

With a modest understanding of internet technologies it is possible to access a site by entering the site IP address (if multiple websites are hosted at the same IP address the user will be displayed the default web site or page for that web server/IP address). Site operators can draw attention to online web based and alternative sources of DNS name resolution within emails to their user base or via online forums.

Other channels that site operators could use to widely distribute advice on how best to circumvent DNS blocking could include posting to online forums, Really Simple Syndication (RSS) or updates via micro blogging sites such as Twitter ®. The advice could include changing to unblocked DNS name servers, Virtual Private Networks and proxy services or other anonymising systems. Similarly, site operators may quickly mirror or make copies of a blocked site on new top level or country code domains pointing towards new IP addresses e.g. www.blockedsite.cc; www.blockedsite.ru; www.blockedsite.vn; www.blockedsite.net.
p.38
Techniques that may undermine URL blocking include:

• web site operators providing encrypted access to their web sites via Secure Sockets Layer/ Transport Layer Security i.e. https connectivity https://www.example.com/downloads/pirate.zip;
• a site operator may run a website on a network port other than port 80;
• the site operator changing the IP address and bypassing the network routing announcements;
• a site operator registering a new domain name e.g. www.example.net or www.example.org;
• the blocked site offering services such as Virtual Private Networking;
• the use of anonymous web proxy or other anonymising services;
• the site operator reorganising the site structure if the blocking is conducted against specific URLs; and
• the site operator or end user encoding URLs to bypass blocking.
p.40
Packet inspection blocking robustness

Both shallow and deep packet inspection can be bypassed by site operators using the following means:


• changing the IP address but staying on the same network;
• moving to an entirely new network (to a previously unobserved IP address);
• the site may use network encryption techniques such as Virtual Private Networking to render scrutiny of the IP packet‟s payload or real IP address destination impossible, given the technology available today; or
• the site operator may add or remove site IP addresses from a pool of IP addresses.

End users who wish to circumvent packet inspection may opt to use anonymous web proxies or other anonymsing services.
p.41
As with the deployment of any of the single primary techniques, the hybrid approach is also susceptible to circumvention by the use of anonymising tools such as The Onion Router, VPNs or anonymous proxy services.
p.44 (Column marked "Difficulty of circumvention" originally redacted)


p.45 (Column marked "Difficulty of circumvention" originally redacted)




p.52
Technical Glossary

Anonymous Web Proxy Service that allows users to place web requests via an intermediary server. The proxy server makes the connection on behalf of the user thereby hiding originating IP address and bypassing blocking network techniques.

The Onion Router (ToR) Anonymity network originally developed by the United States Navy. Used in many countries to bypass state censorship.

Friday, July 29, 2011

Newzbin2: Did BT shoot itself in the foot - and will Irish ISPs do the same?

Yesterday's decision in Twentieth Century Fox v. BT (PDF) introduces mandatory web blocking for the first time in the UK and unsurprisingly has already received a great deal of attention (BBC|Guardian|IPKat).

Lilian Edwards has provided a comprehensive legal analysis, while Richard Clayton tackles the technical implications of the judgment, so I won't attempt to duplicate their work. But a separate blog post might be useful on one point which has received less attention - the significance of the fact that BT had already voluntarily adopted a system - Cleanfeed - to block child abuse images.

In 2004 - when BT initially adopted Cleanfeed - it was even then obvious that there was a risk of function creep and in particular that copyright holders would seek to use the system. In a briefing to LINX at the time (link now broken), however, BT appeared to believe that it was unlikely to be sued and could mitigate this risk by discontinuing the use of Cleanfeed if scope creep became a reality. According to the then Director of Internet Services for BT Retail: "if the pressure to extend the scope of Cleanfeed became too great [BT] would simply cancel the project" and "BT is unlikely to be the defendent of choice for a copyright holder or other party attempting to hold an ISP legally responsible for Internet traffic".

Yesterday's ruling has shown the limits of this reasoning. Once Cleanfeed provided a proof of concept then function creep was inevitable and the idea that BT could unilaterally turn off the blocking system unrealistic. Instead, it painted a target on its back. According to a representative for the movie industry "BT was chosen because it's the largest and already has the technology in place, through its Cleanfeed system, to block the site".

The use of Cleanfeed also prevented BT from asserting two defences that might otherwise have applied - that there was no clear legal basis for imposing a blocking system and that their obligations would be unclear. Instead, according to the High Court:
the order sought by the Studios is clear and precise; it merely requires BT to implement an existing technical solution which BT already employs for a different purpose; implementing that solution is accepted by BT to be technically feasible; the cost is not suggested by BT to be excessive. (para. 177)
In light of this, therefore, it's hard not to conclude that BT shot itself in the foot by adopting a blocking system which could easily be repurposed for the benefit of Hollywood.

"No good deed goes unpunished" - this case proves the truth of this statement, and will undermine other voluntary initiatives to block child pornography by showing how easily those initiatives can be coopted by the movie industry or music industry. There's also a lesson here for Irish ISPs who are coming under police pressure to introduce similar blocking systems. Will they now do so, knowing that these systems will make them a happy hunting ground for the content companies, defamation plaintiffs, and others who may wish to block access to the web in Ireland?

Tuesday, February 09, 2010

Home Office terrorist material reporting site - some thoughts


The Home Office launched a new Directgov site last week, which "provides members of the public with information about what they can do if they come across violent extremist, terrorist and hate content online" (press release). The site takes reports and forwards them to a specialist unit within Association of Chief Police Officers (ACPO), which will take action if the material is illegal. Unsurprisingly there has been a good deal of media coverage (e.g. The Register | The Inquirer | BBC News).  So far, though, there doesn't seem to have been any assessment of how this fits into the broader matrix of internet regulation in the UK. This post asks what effect it might have.
  
Reducing the role of the IWF?

One of the more significant aspects of this story is that it appears to be the first time that the UK government has set up a specific site to which internet content can be reported. Until now, the government has effectively devolved that function to the Internet Watch Foundation (IWF). Although this is a private body, official policy has been to designate the IWF as the first port of call for online content. The Surrey Police website is typical:
If you come across offensive or illegal material, please DO NOT contact Surrey Police directly.
Instead, you can make a report on the Internet Watch Foundation (IWF) web site.
If they decide any action is needed, they will contact the ISP or the police, who can take appropriate action. (It's worth remembering that evidence of illegal or offensive material can be detected even after it has been deleted from a computer.)
The Internet Watch Foundation are qualified to judge the illegality of material and will report matters to the relevant police force. They are the only authorised organisation in the UK that provides an Internet hotline for the public to report their exposure to illegal content online.
Despite this, however, the IWF has never had a remit to receive complaints in relation to all illegal material online. For example, while there have been proposals from the Home Office that the IWF's remit should be extended to cover extremist websites, these have never come to fruition. Similarly, when the Terrorism Act 2006 created a system of notifying ISPs to take down terrorist material, that system bypassed the IWF entirely and required that notices be given via the police.

Consequently, the setting up of this site may be significant - does it indicate a trend which moves away from government reliance on the IWF and towards the use of separate (and public) reporting mechanisms?

Content control as a means of protecting vulnerable people?

The rhetoric used in announcing the site is also interesting. According to Lord West:
We want to protect people who may be vulnerable to violent extremist content and will seek to remove any unlawful material.
If this sounds familiar, that's because it echoes the justifications for introducing the Cleanfeed child abuse image blocking system and later for criminalising extreme pornography - in each case, a central component was the argument that harm would be caused to the viewer (by simply viewing the material, or by predisposing them to commit crimes). Is this approach - focusing on harm to the viewer - becoming more common in controlling content in the UK?

Using consumer pressure as a regulatory tool?

Quite apart from illegal content, the site also sets out to encourage users to challenge content which is  legal. According to Lord West:
This is also about empowering individuals to tell them how they can make a civic challenge against material that they find offensive, even if it is not illegal.

The internet is not a lawless forum and should reflect the legal and accepted boundaries of society.
Consequently, the site provides information on how to make complaints:
What you can do about online hate or violence that is not illegal

Most hateful or violent website content is not illegal. While you may come across a lot of things on the internet that offend you, very little of it is actually illegal.

UK laws are written to make sure that people can speak, and write, freely without being sent to prison for their views.

To be illegal, the content must match the descriptions at the top of this page.

Still, even if what you’ve seen does not seem to be illegal, you can take the steps below to have it removed if it upsets, scares or offends you.

Report it to the website administrator

Most websites have rules known as ‘acceptable use policies’ that set out what cannot be put on their website. Most do not allow comments, videos and photos that offend or hurt people...

If what you’ve seen is on a site with a good complaints system, you should report it to the website’s owners. Look out for their ‘contact us’ page, which should be clearly linked...

Report it to the hosting company


If the website itself is hateful or supports violence or terrorism let the website’s hosting company know. Hosting companies provide a place where the website sits, and often have rules about what they are willing to host.

Let the hosting company know they are hosting a website that breaks their rules, and ask them to stop.

You can find out which company hosts a website by entering their web address on the ‘Who is hosting this?’ website.
This approach - by encouraging community pressure to force ISPs to change their behaviour - matches policy in relation to blocking, where the Home Office has abandoned plans to legislate and has instead stated its intention to rely on public pressure instead:
For the first time the IWF will publish the list of ISPs who are certified as having implemented its blacklist. "Hopefully consumer and public pressure will encourage the ISPs who aren't on the list to comply," said Carr. A Home Office spokesman said: "We will continue to urge ISPs to implement blocking, and ask consumers to check with their suppliers that they have done so."
Does this mark the start of a trend towards greater use of consumer pressure by the UK government as a means of regulating what ISPs do?

Friday, October 16, 2009

UK Government abandons plans for mandatory web filtering

Just over a month ago the Independent on Sunday reported that:
The Home Office is drawing up plans for what, in effect, would be the first form of state intervention in Britain in relation to the internet.

British ISPs would face heavy fines for failing to block sites containing images of child sexual abuse, according to the contents of a leaked Home Office document seen by The Independent on Sunday...

The leaked Home Office letter says a clause in the Police, Crime and Private Security Bill in the Queen's Speech would "compel domestic ISPs to implement the blocking of illegal images of child sexual abuse".
This was far from new policy - since 2006 the Home Office has consistently said that it would legislate for mandatory filters unless ISPs "voluntarily" filtered against the IWF blacklist. But according to The Register, it has now rather abruptly changed its position:
The government has abandoned its long-standing pledge to force 100 per cent of internet providers to block access to a list of child pornography websites.

The decision to drop the policy will be finalised at a meeting on Monday to be attended by internet industry representatives, children's charities and Alun Michael MP.

The former minister had aimed to pressurise small ISPs to implement the Internet Watch Foundation's (IWF) blacklist with the threat of legislation, but the Home Office has now backed down. A lobbying campaign argued costs were too high for small companies to bear and that the blocking technology can be easily circumvented by determined paedophiles.
Instead the Home Office will attempt to use consumer pressure to encourage the remaining ISPs to filter:
For the first time the IWF will publish the list of ISPs who are certified as having implemented its blacklist. "Hopefully consumer and public pressure will encourage the ISPs who aren't on the list to comply," said Carr. A Home Office spokesman said: "We will continue to urge ISPs to implement blocking, and ask consumers to check with their suppliers that they have done so. The Government recognises the work done by most of the internet industry to tackle this problem."
Why the about-face? One factor may have been that the Home Office didn't enjoy wide support for its plans even amongst official bodies. The Chief Executive of the Child Exploitation and Online Protection Centre (CEOP) recently said that he was not convinced of the need to introduce mandatory filtering, while apComms had come out strongly against mandatory web filters. Key to both views was the recognition (which was slow in dawning at the Home Office) that web filters are increasingly irrelevant to the wider problem. Or, as The Register put it:
One likely factor in the softening of stance of both the government and charities is the fact that on the frontline of online child protection, websites carrying images of abuse are no longer seen as a priority.

The Child Exploitation and Online Protection Centre is focussed on paedophile peer to peer networks as they are much more likely to carry recent images, potentially indicating ongoing abuse. The IWF's website blocking is seen as yesterday's issue.
Coincidentally, Germany is also having second thoughts about mandatory filtering, with post-election negotiations for a new coalition government featuring demands that the proposed filtering system be halted.

Thursday, October 15, 2009

apComms come out for worldwide IWF system; against mandatory internet filtering

apComms - the influential UK All Party Parliamentary Communications Group - have now issued the Report from their inquiry "Can we keep our hands off the net?". This inquiry commenced in April and focused on five questions:
#1 Can we distinguish circumstances when ISPs should be forced to act to deal with some type of bad traffic? When should we insist that ISPs should not be forced into dealing with a problem, and that the solution must be found elsewhere?
#2 Should the Government be intervening over behavioural advertising services, either to encourage or discourage their deployment; or is this entirely a matter for individual users, ISPs and websites?
#3 Is there a need for new initiatives to deal with online privacy, and if so, what should be done?
#4 Is the current global approach to dealing with child sexual abuse images working effectively? If not, then how should it be improved?
#5 Who should be paying for the transmission of Internet traffic? Would it be appropriate to enshrine any of the various notions of Network Neutrality in statute?
The full report is an interesting document, and is squarely at odds with current government policy in several areas. Here's what it has to say on filesharing, for example:
We do not believe that disconnecting end users is in the slightest bit consistent with policies that attempt to promote eGovernment, and we recommend that this approach to dealing with illegal file-sharing should not be further considered.
What interests me most is what apComms have to say about dealing with online child pornography. Here they've adopted what seems to be a sensible approach (no doubt influenced by their advisor, Richard Clayton) warning against over-reliance on filters, rejecting government policy to introduce mandatory filters and instead recommending an international extension of IWF-type voluntary cooperation on notice and take-down systems:
We recommend that the Government does not legislate to enforce the deployment of blocking systems based on the IWF lists. This has the potential to damage future attempts to fix problems through self-regulation, and will thus, in the long term, be counterproductive...

It seems quite clear from the evidence that we received that a great deal more could be done to promptly request ISPs to remove child sexual abuse image websites. The IWF are clearly doing a good job along these lines within the UK, but they tell us that they are unable to extend this activity to key countries such as the US and Russia.

In our view, this is an unacceptable situation. If the IWF are unable to perform this important function on a global basis, then some other organisation will need to be given the task. Although there is no particular reason why such a global body should be UK based, the long history of leadership in this area makes the UK a natural candidate to develop a new approach.

We recommend that the Government, in consultation with the EU Commission, establish whether the Internet Watch Foundation (IWF) should extend its “notice and take-down” mechanisms to the whole world, and if not, work to establish such a global system.
More from Andres and The Register.

Thursday, June 18, 2009

Digital Britain and the Internet Watch Foundation

The long awaited Digital Britain Report (pdf) has stirred up a great deal of comment - particularly in relation to filesharing - though little of it complimentary. (E.g. Andes Guadamuz | Chris Marsden | Lilian Edwards | The Register.)

But one aspect of the report which has received less attention (with the notable exception of the Register) is its discussion of the Internet Watch Foundation (pp. 202-203). This is relatively short so it's worth posting in full:
Criminal Material on the Internet

64. The Internet Watch Foundation, based in Cambridge and with just 15 employees, is tasked with minimising the availability of criminal content – specifically, child sexual abuse content hosted anywhere in the world and criminally obscene and incitement to racial hatred content hosted in the UK. It works with law enforcement agencies worldwide and operates a "notice and take down" procedure in relation to content on UK sites and a list of international child abuse sites that ISPs can block at the network level. The vast majority of UK networks use this list and discussions are under way to ensure that relevant consumer networks are comprehensively covered.

65. As a result of the partnership approach adopted by the IWF, less than 1% of child sexual abuse content, known to the IWF, has been hosted in the UK since 2003, down from 18% in 1997. The IWF’s work remains invaluable to every part of the value chain in the UK’s Internet industry. And, in a world of universal availability, increasing take-up and enhanced services on the network the work of the IWF will become more and more important.

66. IWF’s current income includes a contribution from the EU Safer Internet Action Plan with the bulk being derived from voluntary membership subscriptions. Its current income equates to some £1m per annum. This voluntary structure means that there is no certainty that the level of funding received now from the EU or from its membership will continue at this level in the future. In the current economic climate a voluntary funding base carries with it increased uncertainty over funding. Whereas having secure funding would allow the IWF to consider expanding its internal skill base, especially with regard to hiring additional technical expertise and raising greater awareness amongst Internet users about their role and remit. The IWF model of self-regulation is a success and is admired internationally, but if the regulation of criminal content is not adequately funded by industry, Government would need to consider statutory intervention. We therefore call on the IWF membership to propose a more secure funding model for the future.

67. The IWF has also been a model for international hotlines for reporting child abuse material, especially across the EU. Some operators already use its list of illegal sites internationally. Since most child abuse material originates outside the EU, there is a case for its operations to cover at least the whole of the EU. We will therefore explore with the IWF and the European Commission the scope for a pan-European model with commensurate funding.
What to make of this discussion? First, it's noticeably uncritical. For example, the claim that the "IWF model ... is a success and is admired internationally" simply ignores the criticisms that have been voiced of the IWF model by observers such as Lilian Edwards, Frank Fisher, Richard Clayton (pdf) and others.

In part, this flows from a second problem with the report - it doesn't differentiate between the role of the IWF in dealing with illegal material hosted in the UK (which is generally regarded as successful) with its role in providing a blacklist against which ISPs can/must filter (a much more controversial and ineffective endeavour). By conflating the two it attempts to use the success of the hosting remit to justify expansion of the very different filtering remit.

Third, the report - by referring to exploring "a pan-European model" - appears to be unaware of the fact that there are already proposals at an EU level for internet filtering. In fact, far from exporting the IWF model to Europe those proposals - by requiring the involvement of "judicial or police authorities" and "adequate safeguards ... to ensure that the blocking is limited to what is necessary, that users are informed of the reason for the blocking and that content providers are informed of the possibility of challenging it" - would if adopted require the IWF model to be entirely rebuilt.

Overall, therefore, the report's analysis of the IWF is quite flawed - undermining the recommendations it makes in respect of funding. It will be interesting to see how IWF members respond.

Incidentally, it's also been a busy week elsewhere in Europe in relation to internet filtering as proposed German legislation to require blocking of child pornography appears to be agreed between the main parties.

Friday, May 01, 2009

IWF Annual Report: Wikipedia blocking and more

The Internet Watch Foundation has just issued its 2008 Annual Report (PDF) where it offers this defence of its role in the Wikipedia blocking saga, along with an indication that it will review its procedures in light of this case:
Wikipedia on the IWF list

In December our hotline received a report regarding an indecent image of a pre-pubescent girl on a Wikipedia page. The image was assessed according to current UK legislation, in accordance with the UK Sentencing Guidelines Council thresholds (see page 8, Figure 5) and was considered to be potentially illegal.

Our procedures require us to pass details of every URL considered to be in breach of UK legislation to law enforcement and hotline associates around the world for further investigation, in accordance with the laws in the hosting country. If the URL is hosted outside the UK, it is also added to our URL list which is provided to companies in the online sector that have voluntarily committed to blocking access to these URLs to help protect their customers from inadvertent exposure to indecent images of children online.

These procedures and policies are approved by our Board of Trustees and Funding Council, and our hotline systems, security and processes, including the handling of the URL list, are periodically audited by external independent inspectors, including forensic, academic and law enforcement professionals identified by our Board.

In this particular case there was an unforeseen technical side-effect of blocking access to the Wikipedia page in question. Due to the way some ISPs block, users accessing Wikipedia from these ISPs appeared to be using the same IP address. This undermined the way Wikipedia controls vandalism therefore anonymous UK Wikipedia users were blocked from editing.

Following representations from Wikipedia the IWF invoked its Appeals Procedure. This entails a review of the original decision with law enforcement officers. They confirmed the original assessment and this information was conveyed to Wikipedia. Due to the public interest in this matter our Board closely monitored the situation and, once the appeals process was complete, they convened to consider the contextual issues involved in this specific case. IWF’s overriding objective is to minimise the availability of indecent images of children on the internet, however, on this occasion our efforts had the opposite effect so the Board decided that the webpage should be removed from the URL list.

As a learning organisation we are committed to improving our services so issues raised by this incident will be addressed, in collaboration with our industry partners, in the year ahead. (p.9)
My take? The Wikipedia debacle created a number of fundamental challenges for the IWF in relation to its reputation, procedures and legitimacy, as well as undermining the technical claims for the efficacy of internet filtering. This IWF response offers the possibility that they will address these issues - but it remains to be seen whether the outcome will be (possibly modified) business as usual or whether there will be a fundamental rethink of the IWF's role in internet filtering.

Incidentally, the annual report is also interesting in that it signals a move towards tackling child pornography by targeting a new type of intermediaries - by seeking to have domain name registries delist domain names involved in the sale of child pornography. This follows a trend I've noted before - towards domain name registrars / registries becoming the new points of control for regulators.

Monday, December 22, 2008

Some thoughts on the IWF / Wikipedia debacle

One of the highest profile internet stories of December came when the Internet Watch Foundation placed a Wikipedia page on its black list of child pornography URLs, causing the page itself to be blocked by most UK ISPs and (more significantly) causing substantial collateral damage by preventing many UK users from being able to edit Wikipedia pages.

Now, after heavy criticism from internet users, the IWF has executed a hasty about turn, backing down after just five days. Though it still claims that the image in question is "potentially in breach of the Protection of Children Act 1978", nevertheless it has stated that given the "contextual issues involved in this specific case" and "in light of the length of time the image has existed and its wide availability, the decision has been taken to remove this webpage from our list".

While it's too soon to say what the long term implications of this might be, in the short term it has certainly damaged the reputation of the IWF, perhaps irreparably. As John Ozimek has pointed out, other actions of the IWF must now come into question:
So the scene was set for the IWF to take a fall. Gone is its record for 100 per cent undisputed blocking. Gone, too, is its reputation for being the undisputed good guy. Many people have looked at the image in question and have taken the view that it is not porn, or indecent, or abuse. Having made that judgement, they have started to ask questions about other imagery that the IWF has sought to block.

The absolute certainties that underpin a view that claims indecency is always porn is always abuse are shaken. Not least by reports that the child - now an adult - whose image lies at the heart of this controversy, is reported to have no regrets at all in respect of the photo.
It has also tarnished the IWF's legitimacy. In large part this rests on claims that it operates a formal mechanism for identifying material to be blocked, along with a (semi-) independent appeals procedure. But the ad hoc nature of the decision making in this case - where the IWF board ignored the results of its own appeals procedure - suggests that there are different rules in place for high profile sites with vocal supporters. Lilian Edwards puts the point well:
Non-accountable: the IWF`applied their own appeals procedure to the decision, after media pressure, and reversed it. Effectively they changed their mind. This is not how true courts and tribunals work, where an appeal must be heard by a seperate body with an account of what factors lead to a different legal decision. The IWF may have truely reconsidered their opinion as to the law (although their own press release rather speaks against this), but they may equally well have simply bent to public pressure, or practical enforcement problems. For those who truly want an objective system which responsibly cracks down on child porn, this is surely unacceptable. Justice is a system, not an arbitrary private discretion.
The incident has also compromised claims for the technical efficiency of UK internet filtering. While at least one UK ISP has resorted to a crude form of IP blocking, the two stage filtering process pioneered by BT (as its "Cleanfeed" system) has been sold on the basis that it can effectively block specific URLs without degrading network performance and with no collateral damage to legitimate content. That has been shown not to be the case. As Richard Clayton points out in a comprehensive post on the technical aspects of the system:
To sum up the key technical matters: the IWF chose to filter text pages on Wikipedia rather than just the images they were concerned about; the use of proxies by ISPs broke Wikipedia’s security model that prevents vandalism; the previous controversy about the Virgin Killers album cover meant that IWF’s URLs were quickly identified; however different capitalisations of URLs, the different blocking technologies, and the different implementation timescales led to considerable confusion as to who blocked what and when.

Some of these matters could be described as "human error" and might be done better in any re-run of these events with any of the other questionable images hosted on Wikipedia (and many other mainstream sites). However, most of the differences in the effectiveness of the attempted censorship stem directly from diverse blocking system designs — and we can expect to see them recur in future incidents. The bottom line is that these blocking systems are fragile, easy to evade (even unintentionally), and little more than a fig leaf to save the IWF’s blushes in being so ineffective at getting child abuse image websites removed in a timely manner.
The case has also thrown up issues of selective enforcement and parity of treatment between offline and online content. The IWF blacklisted this image only when hosted by Wikipeda - despite the fact that the same image was hosted by online retailers (and, indeed, has appeared on the cover of albums in your local record shop for the last thirty years). This disparity was bound to cause criticism, and the IWF's response - that it only acts on complaints received by it - has been felt by many to be inadequate.

Many users - when made aware of the blocking - also questioned the deceptive error messages used by most ISPs. Although some (notably Demon Internet) show pages indicating that content has been blocked, most ISPs appeared to be using fake 404 pages. It is far from clear why this is done, particularly when the practice in many jurisdictions using similar systems is to use block pages telling users why content has been blocked and what they can do if they feel that this is a mistake. (E.g. Sweden | Finland.)

The approach taken by the IWF to borderline images and fair procedures also comes into question. On their own admission they blocked the image on the basis that it was "potentially illegal" - and did so without notifying Wikipedia much less offering a right to be heard. One Wikipedia admin board sums up this point well:
The image is not certain to be illegal. In the IWFs own words the image was judged to be "potentially illegal indecent image of a child under the age of 18, but hosted outside the UK". The album has been for sale in many countries with this cover for over 30 years. No one has ever been prosecuted over the image as far as is known. The FBI investigated a report of this album cover in spring 2008 and decided to take no action. The Wikimedia Foundation has not been requested by the FBI or any other law enforcement agency to remove the image and has certainly not been charged over it. The ultimate arbiter of whether an image is illegal is a court of law, in particular a jury, and not a self-selecting group, however well-intentioned their motives.

The IWF blocked access to a page on one of the world's most-visited websites without informing its owners. We understand that their policy is not to contact any of the hosts they block, but commonsense should have told them that blocking such a website might have unforeseen consequences. In particular, they failed to understand that whereas a block of the article itself may well amount to restraint on the guaranteed freedom to receive and impart information, the image itself is uploaded from a different URL which could have been separately blocked by the ISPs with whom they are in partnership; in this way, they demonstrate a complete lack of understanding of how websites work, which is chilling in the extreme for a supposed Internet Watchdog.
Taking a longer term view, this incident means that any widening of the IWF's remit is now likely to be put on hold. There have been suggestions in the past that the blacklist should be extended to e.g. websites which "glorify terrorism", while the police and Ministry of Justice have already been advising individuals to refer alleged "extreme pornography" images to the IWF for assessment - however, in light of the considerable reputational damage caused by the Wikipedia ban the IWF is likely to be more cautious before it takes on any new roles.

Of course, it's not just in the UK that these debates are taking place - in the United States for example there are striking parallels about the way in which an private body (the National Center for Missing and Exploited Children) has become an "unofficial internet regulator" carrying out internet censorship without any legislative basis, oversight or transparency. Chris Soghoian has an insightful editorial with more detail.

Monday, December 08, 2008

Internet Watch Foundation blocks Wikipedia

The internet - and more significantly the mainstream media - is abuzz with the news that the hitherto low profile Internet Watch Foundation has blacklisted a Wikipedia page. The IWF blacklist - more formally the Child Sexual Abuse Content URL List - is a list of URLs alleged to contain child pornography, which UK ISPs have "voluntarily" agreed to block (that is, they volunteered when the government indicated that if they did not legislation would be introduced compelling them to do so).

This presents all sorts of interesting problems for the law and civil liberties. There is no legislation underpinning the IWF, which is a purely private body. There is no judicial control of its activities, and the process by which it blocks sites is particularly opaque (it does not notify site owners either before or after sites are blocked, nor does it offer a right to be heard). It does claim to offer a right of appeal against blocking, but that is not an appeal to an independent body but to a division of the Metropolitan Police. In short, it has (with government backing) implemented a remarkable system of censorship which departs from almost every traditional understanding of freedom of expression in the UK.

I've been following the development of this system for some time now, and I spoke about some of these issues in this paper at the 2008 BILETA Conference in Glasgow:

Wednesday, February 27, 2008

An overview of ISP Voluntary / Mandatory Filtering

Irene Graham of Electronic Frontiers Australia has compiled an invaluable overview of ISP level filtering systems as part of the EFA campaign against mandatory filtering in Australia. What's most striking about her survey is that unlike much previous work which focused on countries such as China or Saudi Arabia, she looks at the systems put in place in various democracies (including Canada, the United Kingdom and Finland) but still finds the same problems - a lack of democratic legitimacy, opaque systems, overblocking, and indications of function creep.