Showing posts with label filtering. Show all posts
Showing posts with label filtering. Show all posts

Saturday, August 31, 2013

What would Turkey like to hide from its citizens?

Internet censorship in Turkey is a prime example of why democracies should not attempt to filter the internet. I've blogged before about the blocking of Richard Dawkin's website by the Turkish authorities so I was fascinated to learn that a full list of sites which have been blocked by Turkey is available. The information has been compiled by EngelliWeb.com which identifies 31,694 sites as having been blocked, roughly doubled from last year. You can also view all blocked sites as a single page.

Highlights of the blocking list? In addition to Kurdish news sites, it includes the entirety of:

Blogger
Blogspot
Dailymotion
Google Groups
Google Sites
Shoutcast
Ustream.tv
Vimeo
Wordpress
YouTube

One important caveat - not everything on the list is currently blocked. Turkey has flipflopped on many of these sites with on again/off again bans at different times for different reasons. Some sites - such as YouTube - have also been unblocked after caving in to Turkish government pressure and agreeing to censor for Turkish users.

More on Turkish blocking from the excellent Reporters Without Borders site. The Guardian has a recent piece on how Turkish internet users are getting around this censorship.

Thursday, October 25, 2012

Internet betting: Irish government seeks to introduce blocking on no evidence and against EU findings

Roulette, originally uploaded by discopalace
There's been surprisingly little coverage of Irish government plans to require blocking of foreign betting websites. The plans, contained in s.26 of the Betting (Amendment) Bill 2012, would allow the District Court to make orders as follows:
in the case of a remote bookmaker or remote bookmaking intermediary, an order that telecommunications service providers and internet service providers in the State shall not permit access to — (i) the internet address of any internet domain that the remote bookmaker or remote betting intermediary concerned uses for the purposes of conducting his business, (ii) a particular facility in such a domain, or (iii) any other order that that court considers appropriate for the purpose of ensuring that any such domain, or any remote bookmaking operation conducted by the remote bookmaker or remote betting intermediary concerned is not accessible to persons in the State.
Leaving aside the technological inexactitude of this provision (what, exactly, is a "facility" in a domain? A sub-domain? A particular directory or path?) this is a remarkably wide provision which should worry Irish internet companies.

The reference to internet "service" providers rather than internet "access" providers appears to be wide enough to cover any service provider which could be used to access a site - which would appear to include providers of VPNs, search engines, DNS providers and others. This wide power is then further supplemented by a power to make "any other order" that [the] court considers "appropriate" to ensure that the domain etc. "is not accessible". This seems to be drafted with a view to ordering that sites should be delisted from search engines but could, potentially, be used against any internet intermediary and could be used to, for example, block access to proxy sites and other tools which might be used to circumvent the blocking.

What justification has the Irish state provided for such a far reaching power? Essentially, none. Online gambling was first considered in detail by government in the 2008 report Regulating Gaming in Ireland which cautioned against blocking systems:
The Committee is of the view that censorship of the Internet in an effort to achieve such ends is frequently self-defeating, is unlikely to achieve the intended results, leads to the diversion of scarce law enforcement resources and frequently has unintended and undesirable consequences.
This conclusion was, essentially, reiterated in the 2010 report Options for Regulating Gambling which contained no independent analysis on this point. These are, to date, the only government documents which address the issue - there has been no regulatory impact assessment published - and it is striking that neither recommends blocking systems.

In much the same way, the European Commission Staff Working Paper on Online Gambling recently came out against blocking systems, stating that:
However, blocking access to websites does not work as an isolated enforcement tool and can be easily circumvented. Moreover, depending on the technology used, website blocking can impact on legitimate businesses. The efficiency of the blocking method furthermore depends on the validity of the list of blocked websites. Keeping the list up-to-date requires significant resources while internet addresses can be changed instantly. Lastly, ISPs are faced with the implementation of the provisions for blocking access to websites, not only implying costs and tying-up of resources but also creating potential liability issues.
Simply put, the case has not been made for this new type of blocking and it would set a worrying precedent if such a far reaching power were to be created.Once ISPs are forced to introduce blocking mechanisms for one purpose, it is only a matter of time before others seek to jump on the bandwagon.

Wednesday, February 01, 2012

Copyright proposals block innovation and free expression

I have an opinion piece in today's Irish Times arguing against current government proposals which would allow internet blocking and more. Here's an excerpt:
As currently drafted, the statutory instrument provides that the High Court may grant an injunction against an internet intermediary who is entirely innocent of any wrongdoing – but does not specify even the most basic details regarding how this power might be exercised.

What type of injunction might be granted? On what criteria? Against what types of intermediary – internet service providers, discussion forums, search engines, social networking sites, video hosting sites? Who will bear the costs of these injunctions? Who will be responsible if, as often happens, an unrelated website is wrongfully blocked?

This lack of detail makes it impossible to predict how this law might be applied, and means that clarification will come only after repeated and expensive trips to the High Court.

The Internet Service Providers Association of Ireland (whose members include Google) has opposed the legislation, noting the proposal creates “business uncertainty for those running or considering establishing internet services from Ireland” in a way which may have “drastic consequences” for them: in short, it will act as a deterrent to the next generation of Irish internet businesses which may relocate to warmer legal climes. Significantly, the Department of Enterprise has not produced a Regulatory Impact Assessment of the measure.
Full text

Tuesday, January 24, 2012

Anonymous attacks on Ireland will hurt, not help the case against blocking

My heart sank when I saw this tweet a few minutes ago:
Leave aside, for a moment, the inconvenience and disruption this will cause people trying to make use of government sites, the cost of responding and the controversial question whether denial of service attacks are legitimate as a type of civil disobedience. Quite apart from all these points, the action will do nothing to advance the Anonymous goals.

Until now the Irish campaign against internet blocking proposals has been remarkably effective at getting the issue onto the public and political agenda. With the help of the StopSOPAIreland site, the proposed law has shot from almost no public awareness to national prominence in just a few days, and has seen some Irish politicians genuinely engaging with our concerns. It also is giving many Irish netizens a grounding in political advocacy, something that will help as we confront more of these issues in future.

The Anonymous attacks, if they go ahead, will jeopardise this - making it easier for the music industry to spin critics as criminals, and giving unsympathetic politicians an easy, crowd pleasing reason to ignore the campaign. If the headlines shift from "New law threatens civil liberties" to "Hackers attack Irish government websites" then we will be on the back foot, jeopardising what's been achieved to date.

I don't think Anonymous tend to reconsider their targets once chosen. But if they do, now would be a good time to rethink the Irish attack.

Monday, January 23, 2012

Ireland's SOPA: A FAQ

What's this all about?

Long story short: the Irish government plans, before the end of January, to bring in a law which would allow Irish courts to block access to websites accused of infringing copyright (and possibly do other things as well).

Isn't that a short time for parliament to examine it?

The Irish parliament won't have a chance to debate it before it's passed. The law is to be brought in by a statutory instrument, something which requires only the stroke of a minister's pen.

Who's responsible?

The law is the responsibility of the Department for Jobs, Enterprise and Innovation where the key person is junior minister Sean Sherlock.

What will the law say?

We don't have a final text yet. But the key part is likely to be similar to a previous draft which said:
3. The Act of 2000 is hereby amended by the insertion of the following subsection after subsection (5) of section 40:
(5A)(a) without prejudice to subsections (3) and (4), the owner of the copyright in the work concerned may apply to the High Court for an injunction against a person who provides facilities referred to in subsection (3) where those facilities are being used by one or more third parties to infringe the copyright in that work. 
(b) In considering an application for an injunction under this subsection, the court shall have due regard to the rights of any third party likely to be affected and the court shall make such directions (including, where appropriate, a direction requiring a third party to be put on notice of the application) as the court may deem necessary or appropriate in all the circumstances.
Can we have that in English please?

Certainly. This will give the Irish courts an open-ended power to grant orders against ISPs and other intermediaries who provide facilities which might be used to infringe copyright. This could include hosting providers, social networks, forums, video hosting sites - potentially most online services.

What will these intermediaries be required to do?

We don't know. At a minimum this will probably allow courts to require ISPs to block access to alleged infringing sites (such as The Pirate Bay). Over and above that it becomes impossible to say - the language is so vague it might, for example, allow a court to require an ISP to introduce a three strikes system or to block certain ports. However, once copyright plaintiffs get hold of this power you can expect it to be pushed to its absolute limit.

So who will pay for this?

We don't know. It is possible, under this draft, that the intermediaries will have to pay for both the legal costs of the court application and also the running costs of whatever they are ordered to do - for example, the staff costs of receiving and administering block lists. In that case, expect costs to be passed on to the end user.

Will the sites to be blocked have a right to be heard?

Maybe. The draft language does say that affected third parties might be given notice of applications to block them. On the other hand, in 2009 an Irish High Court judge was happy to allow Eircom to block The Pirate Bay without any notification or chance to be heard which doesn't bode well for the future.

What sort of standard will be used to decide if a site should be blocked?

Your guess is as good as mine - the draft is completely silent on this point.

Isn't this rather vague?

Yes. By failing to provide any real detail, the proposed law leaves the future of the Irish internet essentially in the discretion of Irish judges.

Could this harm Irish industry?

Yes - including the latest push to establish Ireland as a centre for cloud computing. Here's what tech journalist Adrian Weckler had to say:
With their billions of users, YouTube, Facebook and Twitter inherently find some copyright protected material leaked onto their web services. The new law will give music and movie firms the legal footing to get ISPs blocking. That may not go down too well with Google and Facebook, which are two of Dublin's biggest employers. It probably won't sit easily, either, with the IDA, which may have to alter its pitch to large US social media firms who may have been thinking of setting up in Ireland. (That includes Twitter.)
So where's the Regulatory Impact Assessment? Surely we need more detail about the impact this law will have?

Tumbleweed.

Would this vagueness breach the European Convention on Human Rights?

Quite possibly.

If nothing else will it at least stop illegal downloads and protect Bono's pocketbook?

No. Blocking is easily circumvented. But don't take my word for it - here's what UK regulator Ofcom had to say:
For all blocking methods circumvention by site operators and internet users is technically possible and would be relatively straightforward by determined users.
So why is the government pushing this law now?

In a 2010 decision the High Court held that European law required Ireland to introduce blocking into domestic law, and that Ireland was in breach by failing to provide for court ordered blocking.

Doesn't that decision mean that blocking must be introduced?

Maybe. The law in this area is extremely complex, particularly since the European Court of Justice has given an important decision restricting the use of blocking in the meantime. That decision found that filtering would be impermissible if it undermined freedom of expression and blocked lawful communications - something that is inevitable if this proposal is adopted.

From a practical point of view, the European Commission - which monitors implementation of EU law - doesn't seem to think Ireland is in breach and hasn't taken any action against Ireland for failure to introduce blocking. Irish telecoms group ALTO have also put forward a different view arguing that this law is unnecessary.

However, even if we assume that EU law does require some form of blocking then it should not be introduced in a way which
  • short circuits the democratic process and without proper scrutiny by the Irish parliament; and
  • introduces intolerable uncertainty for Irish online businesses and fundamental rights.
What can I do about it?

If you live in Ireland and you want to stop this proposal then you should let Sean Sherlock (email) (twitter @seansherlocktd), the senior minister Richard Bruton (email) and your TDs what you think of it. Phone their offices if you can - one phone call will outweigh 20 emails.

StopSOPAIreland.com has more you can do.

If you live outside Ireland, you might still email Richard Bruton and Sean Sherlock to let them know the effect this will have on Ireland's reputation as a place to set up technology businesses.

One more thing - is it really true that the music industry wants the Irish taxpayer to pay for supposedly lost sales?

Yes. I hope you brought your wallet.

Sunday, January 22, 2012

"Ireland's SOPA" will be vague and open-ended

[23.01.12 Hello Redditors! Here's a FAQ with more information.]

Adrian Weckler has a worrying piece on government proposals for blocking legislation in today's Sunday Business Post (paywalled). I've taken the liberty of extracting some of the highlights:
Is Ireland about to introduce a law that will allow music companies to order Internet service providers to block access to websites? I rang up the Minister of State at the department of Enterprise, Jobs and Innovation, Sean Sherlock, to find out. "The statutory instrument to be introduced is completely different to Sopa [Stop Online Piracy Act] in America" he told me. "We are simply addressing the High Court judgment handed down by Mr Justice Peter Charleton in relation to copyright law... I will introduce this imminently, by the end of January." That's a yes, then ...

The Irish governments new “statutory instrument” threatens to do some of the same things as Sopa, mainly introducing the power to force ISPs to block websites suspected of having copyrighted material on them.

While that means curtains for the Pirate Bay (which few people here will miss), it also leaves open the possibility for a judge to order ISPs to block YouTube, Facebook and Twitter.

Why? Because, with their billions of users, YouTube, Facebook and Twitter inherently find some copyright protected material leaked onto their web services. The new law will give music and movie firms the legal footing to get ISPs blocking. That may not go down too well with Google and Facebook, which are two of Dublin's biggest employers. It probably won't sit easily, either, with the IDA, which may have to alter its pitch to large US social media firms who may have been thinking of setting up in Ireland. (That includes Twitter.)

Given the seismic nature of the proposed change to Irish internet access, surely more detailed primary legislation would be in order here? For example, could there be a limit to enforcement of the injunctions? What defences might be available? Could there be exceptions?  "We will probably need a test case to come before the courts before primary legislation such as that could be considered," said Sherlock. In other words: don't look at us, guv. We may be the government, but this kind of law-making is really a matter for judges. We don't really do that kind of thing ...

Politically, this is a no-win scenario. Even with the government about to open the legal doors for the music and movie companies to start directing ISPs' access policies, the content creation industry is frothing and fuming. Ironically, by taking a leave-it-to-m'lud approach, the government is also now attracting the anger of an increasing tranche of the technology and digital community. It is unusual to alienate both sides of a legislative argument ...

So this really is turning out to be a lose-lose episode for the government. Yet the issue wields vast significance for both sides of the debate (the music industry and the digital technology industry). It could also have profound, long-lasting consequences for Irish industry.
The clear implication from that interview with Sean Sherlock is that the proposed measures will be lacking in any real detail, leaving it entirely up to the judges as to what types of blocking might emerge. (Possibly going beyond web blocking to also target hosting and other services.)

This ambiguity - as well as jeopardising fundamental rights - will create intolerable uncertainty for businesses such as Google who might find themselves at risk of business threatening and unpredictable injunctions and will certainly deter others from setting up in Ireland.

Instead, any action should only take place by primary legislation which the Oireachtas would have a chance to scrutinise and debate. As I said previously in a letter on behalf of Digital Rights Ireland:
It is significant that Charleton J. in EMI v. UPC [2010] IEHC 377 referred to any legislative intervention being properly a matter for the Oireachtas. The Opinion of the Advocate General in Scarlet (Extended) v. SABAM (Case C-70/10) similarly referred to a need for legislation in this area to be "democratically legitimised" (at para. 113).

It would be undesirable in any event for a matter dealing with fundamental rights to be disposed of by way of secondary legislation. It is all the more undesirable in this case, however, given the vague and open-ended nature of the powers involved. This is, in effect, a case of delegation heaped on delegation - rather than rules governing blocking and other remedies being made by primary legislation, or even secondary legislation, they are instead effectively being made by delegation to the judiciary.
Although it's the 11th hour, it's not too late for the Irish government to see sense and abandon this proposal. If you agree then you should let Sean Sherlock and your TDs what you think of it.

Saturday, January 21, 2012

The (legal) case against an Irish SOPA

The publicity and success of the anti-SOPA campaign in the US has put internet blocking on the agenda worldwide and Paul Quigley's excellent column in the Journal explains how Ireland is moving towards similar types of blocking - only by the stroke of a Ministerial pen and without any legislation by the Oireachtas. There are any number of reasons to oppose this Irish version of SOPA, and I'll blog about some of them later, but for the moment I want to highlight just one: that it is likely that such a law would be ultra vires the Minister and in breach of the European Convention on Human Rights.

I've previously made this case in a letter on behalf of Digital Rights Ireland in relation to the Department's draft statutory instrument:


In addition, the Irish telecoms group ALTO made similar points in their submission which we supported:
It's now six months since we made those submissions. In the meantime the European Court of Justice handed down its landmark judgment in Sabam v. Scarlet where it held that:
the protection of the fundamental right to property, which includes the rights linked to intellectual property, must be balanced against the protection of other fundamental rights...in the context of measures adopted to protect copyright holders, national authorities and courts must strike a fair balance between the protection of copyright and the protection of the fundamental rights of individuals who are affected by such measures.
Specifically, it held that filtering systems were prone to infringe the right to freedom of expression and held against one such system on the basis that it:
could potentially undermine freedom of information since that system might not distinguish adequately between unlawful content and lawful content, with the result that its introduction could lead to the blocking of lawful communications. Indeed, it is not contested that the reply to the question whether a transmission is lawful also depends on the application of statutory exceptions to copyright which vary from one Member State to another. Moreover, in some Member States certain works fall within the public domain or can be posted online free of charge by the authors concerned.

In light of this judgment the case against blocking is all the stronger, making the Department's proposed law all the shakier. The music industry appears to realise this, which may account for its crude attempt to force the Department's hand by demanding that the taxpayer compensate it for its (supposedly) lost sales. Nevertheless, it's not too late for the Irish government to see sense and abandon this proposal and if you agree then you should let your TDs know what you think of it.

Thursday, January 12, 2012

More on the music industry case against Ireland

Today's Irish Times confirms that the litigation is intended to put pressure on the government in drafting a statutory instrument to allow blocking. Excerpt:
THE IRISH arm of multinational music group EMI has launched a High Court action against the State as part of its bid to stop the illegal downloading of music...

The Government recently pledged to issue an order to allow copyright holders to compel internet service providers (ISPs) to block access to websites that they consider are engaged in piracy. However, EMI Records (Ireland) remains unhappy with what it perceives to be foot-dragging on the part of the Government in tackling this issue. It is concerned that the matter could be delayed again, and that even if a statutory instrument is issued, its contents may not be satisfactory. Chief executive Willie Kavanagh is adamant that the instrument should give companies such as his the right to seek court injunctions against ISPs that allow access to music piracy websites. Mr Kavanagh said yesterday that EMI asked the Government to show them the forthcoming instrument, but it has not yet received it, “leading me to believe it’s unlikely to satisfy the music industry’s requirement for injunctive relief”.
Incidentally, the coverage is misleading in an important aspect - this is a concerted action brought by all the major music companies (including Sony, Universal, Warner and WEA) not merely EMI. It's also disappointing to see a story uncritically repeat the claims of one side to litigation without offering either a response from the other side or an independent perspective.

Previously

Wednesday, January 11, 2012

Music Industry v. Ireland

The long suffering Irish taxpayer will be delighted to learn that the music industry has joined the queue of those seeking a payout and yesterday issued a summons against the State in the High Court for alleged failure to implement aspects of EU copyright law.

The background to this case lies in the October 2010 judgment of Charleton J. in EMI v. UPC where he held that Irish law did not permit an order to be made against an ISP requiring blocking of websites and went on to say that: "In failing to provide legislative provisions for blocking, diverting and interrupting internet [filesharing] Ireland is not yet fully in compliance with its obligations under European law." Immediately after that decision there was some sabre-rattling from the music industry which threatened to sue the State for damages caused by filesharing, on the theory that if blocking laws were in place then filesharing would go away. (Ignoring research such as that from Ofcom which has found that site blocking is easily evaded.)

Since then, however, the music industry appears to have fallen silent on this threat, presumably on the basis that it would get what it wanted through a statutory instrument which would permit blocking. This statutory instrument isn't yet in place but has been promised by mid January 2012, making the timing of this case all the more interesting - on the face of it, the music industry seems to have jumped the gun by bringing an action before that legislation is in place. Curiously, the normally vocal IRMA have nothing on their website and no press release seems to have been put out - perhaps this was intended as a shot across the bow of the State in case the statutory instrument doesn't meet music industry demands? Or perhaps the music industry feels the need to ramp up the pressure in light of the Data Protection Commissioner's ruling against Eircom's three strikes system?

As to the legal basis for the action, the music industry will presumably be relying on the well-known principle in Francovich v. Italy under which damages are possible against a state for failure to transpose a directive if three conditions are met:
first, that the result prescribed by the directive should entail the grant of rights to individuals; secondly, that it should be possible to identify the content of those rights on the basis of the provisions of the directive; and thirdly, that there should be a causal link between the breach of the State's obligation and the loss and damage suffered by the injured parties.
While I'm not aware of any other action of this sort being brought against a country for failure to implement copyright law, the third element would seem to be problematic for the music industry - establishing a causal link between Irish law and filesharing will be difficult, particularly given the evidence from elsewhere that blocking is ineffective.

Sunday, September 18, 2011

Internet blocking in schools: not such a good idea, it turns out

Despite being published in 2010, I somehow managed to miss until now these remarkably sensible research findings from Ofsted on internet blocking in schools:
Restricting pupils’ access to websites may actually impair their judgement, making them more “vulnerable” to paedophiles on-line, said Ofsted. The claims come despite an admission that teachers had problems stopping young people logging on to “inappropriate” websites at school. In a report, Ofsted said there were widespread incidents of pupils accessing social networking websites and instant chat rooms – where they can be targeted with abuse. But inspectors said "locked down" systems that barred access to websites were actually "less effective" in keeping children safe overall.
In a particularly good analogy, Ofsted also points out that:
Children who hold a parent’s hand every time they cross the road are safe. However, unless they are taught to cross the road by themselves, they might not learn to do this independently. A child whose use of the internet is closely monitored at school will not necessarily develop the level of understanding required to use new technologies responsibly in other contexts.
There's a lesson here in relation to internet blocking as applied to adults also.

Daily Telegraph story
Full text of Ofsted report

(h/t Joe McNamee, EDRI)

Wednesday, August 03, 2011

Site Blocking: What the UK Government would prefer you not to see

It's well known that internet blocking is easy to circumvent. Ofcom in today's report "Site Blocking" to reduce online copyright infringement admits as much, saying that:
For all blocking methods circumvention by site operators and internet users is technically possible and would be relatively straightforward by determined users. (p.5)
Despite this, however, one branch of the UK Government still appears determined to keep its head in the sand, and according to that report:
The Department for Culture, Media and Sport has redacted some parts of this document where it refers to techniques that could be used to circumvent website blocks.
Unfortunately, the technical competence of the DCMS appears to be somewhat limited, and the redaction was (ironically?) also easily circumvented, by measures as simple as copy/paste. Needless to say, a department which is unable to censor a single PDF does not exactly inspire confidence when it proposes to introduce blocking for the entire UK internet, and it is just as well that the UK government has today announced plans to abandon the blocking provisions of the Digital Economy Act.

[Updated - 1.15pm]

The full, unredacted version now appears on Scribd. As can be seen from that document, the material which was redacted was all improperly removed. The tactics discussed to circumvent blocking are all well-known, even to a mere lawyer such as myself, and the redactions appear to be motivated more by considerations of security theatre than anything else.Ofcom Site Blocking Report With Redactions Removed

[Previously]

Here are the individual portions of the report which the DCMS attempted to quash. Text in italics was not redacted but appears for context:

pp.28-29
Robustness

Bypassing IP address blocking is technically straightforward for those who have an incentive to do so.
The blocked site operator may:

• change IP address but stay on the same network (i.e. on the same hosting provider);
• move to an entirely new network (to a previously unobserved IP address);
• offer encrypted network services which obscure the true network address/destination such as Virtual Private Networking;26,27 or
• server operators may institute a Fast Flux network (where users run software on behalf of blocked site which hides the true network address of the blocked site).

There are other methods available to site operators. When moving to a new IP address a site operator may register multiple IP addresses for a given site in order to maintain service in the event that some of those individual IP addresses are blocked. This approach has legitimate purposes also.28 Furthermore, by setting a low “Time to Live” (TTL) Domain Name System (DNS) record value, determining the length of time that the IP address for a particular domain (expressed in seconds) remains in remote name server caches, it is easier for a site operator to move IP addresses without end users losing access. Where a low TTL is expressed the ISP DNS name server resolution cache is purged quickly thereby ensuring that newly assigned site IP addresses are retrieved from the authoritative name server and site accessibility is maintained. Figure 13 below shows that the TTL value for "kickasstorrents" is one hour, demonstrating that any changes to IP address to DNS name are refreshed and propagated within ISP DNS servers in just over an hour.

Figure 13: Kickasstorrents DNS record Time to Live (1 hour) Name TTL Class Record Address
www.kickasstorrents.com. 3600 IN A 95.215.60.37
www.kickasstorrents.com. 3600 IN A 93.114.40.112
www.kickasstorrents.com. 3600 IN A 193.105.134.81
www.kickasstorrents.com. 3600 IN A 95.143.195.138
www.kickasstorrents.com. 3600 IN A 76.76.107.90

26 Ipredator - Surf anonymously with VPN and proxy https://www.ipredator.se/?lang=en
27 UK based VPN services facilitating access to copyright infringed material may be subject to site blocking injunctions. UK VPN operators may institute site blocking at the VPN egress point. NB: we are not aware of any UK based VPN service marketed or positioned for such activity. Such services are likely to be non-UK based.
pp.33-34
DNS blocking robustness

For site operators and end users with a sufficient incentive to engage in circumvention DNS blocking is technically relatively straightforward to bypass:


• the blocked site may offer services such as Virtual Private Networking, which is where encryption and other security measures are deployed to ensure that the data cannot be viewed by third parties (DNS name resolution may occur within the VPN providers network thereby bypassing the ISP based DNS site-blocking);
• the end-user can change their DNS name servers to 3rd party DNS name servers;32,33
• users may use anonymous web proxy or other anonymising services which are not reliant on the ISP DNS servers; or
• name resolution may be performed locally by adding an entry to a hosts file (IP address resolution information can be obtained from websites running a web-enabled equivalent of “nslookup” command).

32 Google Public DNS - http://code.google.com/speed/public-dns/
33 OpenDNS Store > Sign up for OpenDNS Basic: - https://store.opendns.com/get/basic/

For end users who want to bypass blocks there are several options. For instance, there are many legitimate alternative DNS providers to ISP DNS registries. Examples include OpenDNS and Google DNS. We consider the changing of DNS servers to alternative providers to require low technical skills, as the providers offer clear instructions using plain English. For instance, switching to Google DNS requires 11 steps for Windows users and only 8 for those using MAC OS.

With a modest understanding of internet technologies it is possible to access a site by entering the site IP address (if multiple websites are hosted at the same IP address the user will be displayed the default web site or page for that web server/IP address). Site operators can draw attention to online web based and alternative sources of DNS name resolution within emails to their user base or via online forums.

Other channels that site operators could use to widely distribute advice on how best to circumvent DNS blocking could include posting to online forums, Really Simple Syndication (RSS) or updates via micro blogging sites such as Twitter ®. The advice could include changing to unblocked DNS name servers, Virtual Private Networks and proxy services or other anonymising systems. Similarly, site operators may quickly mirror or make copies of a blocked site on new top level or country code domains pointing towards new IP addresses e.g. www.blockedsite.cc; www.blockedsite.ru; www.blockedsite.vn; www.blockedsite.net.
p.38
Techniques that may undermine URL blocking include:

• web site operators providing encrypted access to their web sites via Secure Sockets Layer/ Transport Layer Security i.e. https connectivity https://www.example.com/downloads/pirate.zip;
• a site operator may run a website on a network port other than port 80;
• the site operator changing the IP address and bypassing the network routing announcements;
• a site operator registering a new domain name e.g. www.example.net or www.example.org;
• the blocked site offering services such as Virtual Private Networking;
• the use of anonymous web proxy or other anonymising services;
• the site operator reorganising the site structure if the blocking is conducted against specific URLs; and
• the site operator or end user encoding URLs to bypass blocking.
p.40
Packet inspection blocking robustness

Both shallow and deep packet inspection can be bypassed by site operators using the following means:


• changing the IP address but staying on the same network;
• moving to an entirely new network (to a previously unobserved IP address);
• the site may use network encryption techniques such as Virtual Private Networking to render scrutiny of the IP packet‟s payload or real IP address destination impossible, given the technology available today; or
• the site operator may add or remove site IP addresses from a pool of IP addresses.

End users who wish to circumvent packet inspection may opt to use anonymous web proxies or other anonymsing services.
p.41
As with the deployment of any of the single primary techniques, the hybrid approach is also susceptible to circumvention by the use of anonymising tools such as The Onion Router, VPNs or anonymous proxy services.
p.44 (Column marked "Difficulty of circumvention" originally redacted)


p.45 (Column marked "Difficulty of circumvention" originally redacted)




p.52
Technical Glossary

Anonymous Web Proxy Service that allows users to place web requests via an intermediary server. The proxy server makes the connection on behalf of the user thereby hiding originating IP address and bypassing blocking network techniques.

The Onion Router (ToR) Anonymity network originally developed by the United States Navy. Used in many countries to bypass state censorship.

Friday, July 29, 2011

Newzbin2: Did BT shoot itself in the foot - and will Irish ISPs do the same?

Yesterday's decision in Twentieth Century Fox v. BT (PDF) introduces mandatory web blocking for the first time in the UK and unsurprisingly has already received a great deal of attention (BBC|Guardian|IPKat).

Lilian Edwards has provided a comprehensive legal analysis, while Richard Clayton tackles the technical implications of the judgment, so I won't attempt to duplicate their work. But a separate blog post might be useful on one point which has received less attention - the significance of the fact that BT had already voluntarily adopted a system - Cleanfeed - to block child abuse images.

In 2004 - when BT initially adopted Cleanfeed - it was even then obvious that there was a risk of function creep and in particular that copyright holders would seek to use the system. In a briefing to LINX at the time (link now broken), however, BT appeared to believe that it was unlikely to be sued and could mitigate this risk by discontinuing the use of Cleanfeed if scope creep became a reality. According to the then Director of Internet Services for BT Retail: "if the pressure to extend the scope of Cleanfeed became too great [BT] would simply cancel the project" and "BT is unlikely to be the defendent of choice for a copyright holder or other party attempting to hold an ISP legally responsible for Internet traffic".

Yesterday's ruling has shown the limits of this reasoning. Once Cleanfeed provided a proof of concept then function creep was inevitable and the idea that BT could unilaterally turn off the blocking system unrealistic. Instead, it painted a target on its back. According to a representative for the movie industry "BT was chosen because it's the largest and already has the technology in place, through its Cleanfeed system, to block the site".

The use of Cleanfeed also prevented BT from asserting two defences that might otherwise have applied - that there was no clear legal basis for imposing a blocking system and that their obligations would be unclear. Instead, according to the High Court:
the order sought by the Studios is clear and precise; it merely requires BT to implement an existing technical solution which BT already employs for a different purpose; implementing that solution is accepted by BT to be technically feasible; the cost is not suggested by BT to be excessive. (para. 177)
In light of this, therefore, it's hard not to conclude that BT shot itself in the foot by adopting a blocking system which could easily be repurposed for the benefit of Hollywood.

"No good deed goes unpunished" - this case proves the truth of this statement, and will undermine other voluntary initiatives to block child pornography by showing how easily those initiatives can be coopted by the movie industry or music industry. There's also a lesson here for Irish ISPs who are coming under police pressure to introduce similar blocking systems. Will they now do so, knowing that these systems will make them a happy hunting ground for the content companies, defamation plaintiffs, and others who may wish to block access to the web in Ireland?

Tuesday, July 19, 2011

The Internet of Elsewhere

I've just finished reading a review copy of Cyrus Farivar's impressive new book The Internet of Elsewhere. Like many books, it traces the development and mass takeup of the internet - unlike most, however, it is not US-centric and instead gives equal space to case studies from four countries: South Korea, Senegal, Estonia and Iran. In doing so, it provides a wealth of detail for many developments (the 2003 Iranian crackdown on bloggers, the Seoul "Dog Poop Girl", the Estonian takeup of wifi) which are often cited but seldom put into their wider social context. The author makes a particular point of describing the factors such as demographics, literacy and cost which have driven the use of the internet in each country - or, in the case of Senegal, have kept much of the population offline. A particular highlight for anyone interested in civil liberties online is the description of Iranian control of the internet, which goes back to early measures in 2000 and describes the various state tactics since then which have resulted in many prominent bloggers being forced to leave the country. The book also succeeds in being an easy read - while it is well researched and sourced it is also journalistic in its tone and describes each country through the stories of individuals. I would recommend this to anyone with an interest in the takeup of the internet and the social changes it prompts.

Monday, April 11, 2011

The curious case of internet filtering in Ireland

[Reblogged from the new website MediaLaws.eu, where I will be contributing updates from Ireland.]

One of the most important developments for freedom of expression online has been the growth of internet filtering systems, which have rapidly been adopted by national governments as the “solution” to various forms of internet wrongdoing. Ireland is no exception to this trend, and last month it was revealed that the Garda Síochána (the national police force) is now attempting to introduce a system whereby ISPs would block access to websites alleged to host child abuse images.

It is somewhat ironic that this news becomes public just as both Germany and the Netherlands have decided to abandon similar systems, having found that they are ineffective as a means of tackling child abuse images. Even leaving aside considerations of effectiveness, however, the proposed Irish system still presents a number of significant concerns.

A fundamental principle under Article 10 of the European Convention on Human Rights is that measures which have the effect of restricting freedom of expression must be “prescribed by law”. In this case, however, the Irish system would not have any legal basis whatsoever, much less any judicial oversight or control. Instead, it would involve the police in telling ISPs what domains to block on a “self-regulatory” basis. Consequently, it would seem on the face of it that the proposed system would violate Article 10. The European Commission recently reached the same conclusion about self-regulatory blocking systems (p.30) as did a government study which was decisive in causing the Dutch blocking system to be abandoned.

A further problem relates to the secret manner in which the government and the police have attempted to introduce this system. There has been no public consultation or debate of any kind regarding blocking – instead, information has only dripped out in response to freedom of information requests and leaks from ISPs. This is particularly worrying given that (as Lessig points out) internet filtering is an inherently opaque process, which is prone to operating in an unaccountable way and to being extended beyond its original purposes. In the Irish context, the secrecy surrounding the introduction of filtering doesn’t bode well for the future.

The nature of the proposed blocking is also worrying. What Irish police have suggested is based on the CIRCAMP model, which attempts to block material by using DNS tampering. In short, the police would notify ISPs to block http://example.com or http://subdomain.example.com and the ISP would then configure their DNS servers to redirect all attempts to visit any material hosted on those (sub)domains. The effect would be massive overblocking, where users would be unable to visit any page hosted on a particular domain, irrespective of whether it had any connection whatsoever with the blocked material. Last February, a similar approach in the United States saw over 84,000 innocent websites being wrongfully blocked, and there is no reason to think that the Irish approach would be any more precise.

Finally, one particularly unusual aspect of the proposals is the way in which police seek to introduce monitoring of users. According to the proposals, where a user attempts to view a blocked domain name, police would “obtain details of other websites visited by the user, along with other technical details, in order that [they] can identify any new websites that require blocking”. This in effect seeks the full browsing history of users – whether or not there has been any attempt on their part to view child pornography! (Bearing in mind that DNS tampering results in massive overblocking, it is quite likely that a user may have their browsing history disclosed due to an attempt to visit http://example.com/innocent_content when the entirety of example.com has been blocked due to a single image or page elsewhere in the site.) This raises fundamental privacy and data protection concerns, particularly given that a user can often be identified by viewing their browsing history (e.g.), and has therefore been referred to the Data Protection Commissioner for investigation.

Given these problems, it must be hoped that these proposals are abandoned. But quite apart from these particular proposals, it is now also time to look at the other systems of internet filtering in Ireland that have developed on an ad hoc basis. In particular, Irish mobile phone companies have been engaged in self-regulatory blocking for some time (1|2), in a manner which often affects innocent users due to crude DNS systems. Similarly, the largest Irish broadband provider Eircom recently settled an action brought by the music industry by (amongst other things) agreeing to block access to The Pirate Bay and “related domain names”. These systems have developed without any real public scrutiny or oversight and it is time to consider the effect which they have on users, whether they are subject to adequate transparency and oversight mechanisms and whether or not they are effective at achieving their goals.

Friday, March 25, 2011

The Internet in Society: Empowering or Censoring Citizens?

This video by RSA Animate is a superb visualisation of Evgeny Morozov's recent book The Net Delusion on cyber-utopianism and the impact of the internet on fundamental freedoms. While I don't agree with his overall conclusions, his cyber-realist argument is certainly a welcome corrective to a media tendency to believe in technological determinism and the inevitable spread of freedom via Facebook. His pessimistic views on the crowd-sourcing of surveillance and censorship are particularly insightful and present an interesting challenge for advocates of free speech online.

Saturday, January 22, 2011

Finance Bill taxes internet betting sites - will this lead to blocking of offshore sites?

In my last post I looked at the possible implications of the Finance Bill for Irish computer crime and data protection laws. I missed, however, another important aspect of the Bill, which is that it will extend betting duty to internet betting sites. (In my defence, I didn't read all 223 pages of the Bill and don't plan to do so any time soon. The relevant provision is s.46, at p.186.)

According to the Taoiseach, this extension of duty will be matched by a new requirement that offshore providers obtain a licence to offer their services in Ireland:
The Government will introduce legislation to ensure that overseas betting providers comply with a licensing regime that will permit them to sell their products into our jurisdiction.
So what happens if the offshore providers decide not to play ball? It might not be a coincidence that the Department of Justice has been considering the introduction of internet filtering for some time now - and officials in the Department's Gaming Control section have been taking part in this discussion (PDF released under FOI - see item 49). I can't help but suspect that there will be calls for ISPs to block access to offshore sites which don't pay this new tax - and there have been some European developments in this direction already.

Watch this space.

Monday, October 11, 2010

EMI v. UPC - Full judgment now available

It's been a busy few days for copyright law in Ireland. First the important decision in Koger v. HWM, and now the landmark decision in EMI v. UPC (RTÉ | Irish Times), which derailed music industry plans to compel ISPs to introduce "three strikes" in Ireland.

I'm still digesting the 82 pages of the judgment, but in the meantime here's the full text for your delectation:

EMI v. UPC                                                            

Wednesday, July 14, 2010

Access controlled


The new book Access Controlled from the OpenNet Initiative is now available for free download to read free online. The sequel to the superb Access Denied, it describes a system of state control of the internet which is developing rapidly - from the relatively crude first generation of controls based on filtering and blocking towards a more sophisticated next-generation system which adds features such as built-in surveillance, control of users by contractual terms of use, and authority delegated to private bodies to oversee the net. As the introduction puts it:
States no longer fear pariah status by openly declaring their intent to regulate and control cyberspace. The convenient rubric of terrorism, child pornography, and cyber security has contributed to a growing expectation that states should enforce order in cyberspace, including policing unwanted content... Internet censorship is becoming a global norm.
As with Access Denied, the book is divided into two parts: opening with analytical chapters examining developments from data retention to the Global Network Initiative and followed by individual country and regional profiles. The latter are extremely useful overviews of the state of play worldwide - for me, however, the real strength of the book lies in the first six chapters in which a strong line up of authors consider international developments. Colin Maclay's chapter Protecting Privacy and Expression Online: Can the Global Network Initiative Embrace the Character of the Net? was a particular highlight, shining a light on a promising but as yet immature and relatively unexamined development.

Strongly recommended.

Saturday, May 01, 2010

For a safer and cleaner internet

I was extremely impressed with this cynical but accurate video about EU internet blocking proposals. Enjoy:



For more, see the Cleanternet website.