Comment by usernomdeguerre
6 hours ago
>As we’ve said time and time again: the internet will always route around censorship.
Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.
Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.
Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.
Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.
Have you been to China? It is still super easy to bypass the Great Firewall with VPNs.
8 replies →
My guess is if you are in China they can MITM you with their own root certs.
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
2 replies →
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS
I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".
If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.
So there is a route around censorship, but maybe the public doesn't really care about it.
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
That's the way it was explained to me. Letting the fringe do what they're going to do anyway while inoculating the majority to outside influence is the goal and the difficulty setting is dynamic.
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.
I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
We have a data center in Utah.. And I'm sure some of our customers are storing "adult" material.. Are we now banned?
It's never been true.
The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.
That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP
Having the power of violence behind you makes technical hacks mostly irrelevant.
The internet will always route around censorship in principled western nations.
It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.
I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...
But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.
It seems like Utah could do mostly do this by intercepting all consumer traffic.
Just buy the surveillance equipment from Russia and get it done.
With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?
A VPN/proxy could exist at almost any single address at any given time.
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.
> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.
https://gulfnews.com/world/mena/iran-official-says-starlink-...
There will always be >0 people who find a way around censorship, that's about it. It's not bad AND ineffective, that's a contradiction.
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.
To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.
Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.
And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.