Internet censorship circumvention
Internet censorship circumvention is the use of various methods and tools to bypass internet censorship.
Various techniques and methods are used to bypass Internet censorship, and have differing ease of use, speed, security, and risks. Some methods, such the use of alternate DNS servers, evade blocking by using an alternate address or address lookup system to access the site. Techniques using website mirrors or archive sites rely on other copies of the site being available at different locations. Additionally, there are solutions that rely on gaining access to an Internet connection that is not subject to filtering, often in a different jurisdiction not subject to the same censorship laws, using technologies such as proxying, Virtual Private Networks, or anonymization networks.
An arms race has developed between censors and developers of circumvention software, resulting in more sophisticated blocking techniques by censors and the development of harder-to-detect tools by researchers. Estimates of adoption of circumvention tools vary substantially and are disputed. Barriers to adoption can include usability issues, difficulty finding reliable and trustworthy information about circumvention, lack of desire to access censored content, and risks from breaking the law.
There are many methods available that may allow the circumvention of Internet filtering, which can widely vary in terms of implementation difficulty, effectiveness, and resistance to detection.
Alternate names and addresses
Some websites may offer the same content at multiple pages or domain names. For example, the English Wikipedia is available at https://en.wikipedia.org/, and there is also a mobile-formatted version at https://en.m.wikipedia.org/.
If DNS resolution is disrupted but the site is not blocked in other ways, it may be possible to access a site directly through its IP address or modifying the host file. Using alternative DNS servers, or public recursive name servers (especially when used through an encrypted DNS client), may bypass DNS-based blocking.
Censors may block specific IP addresses. Depending on how the filtering is implemented, it may be possible to use different forms of the IP address, such as by specifing the address in a different base. For example, the following URLs all access the same site, although not all browsers will recognize all forms: http://184.108.40.206 (dotted decimal), http://3494942722 (decimal), http://0320.0120.0230.02 (dotted octal), http://0xd0509802 (hexadecimal), and http://0xd0.0x50.0x98.0x2 (dotted hexadecimal).
Mirrors, caches, and copies
Cached pages: Some search engines keep copies of previously indexed webpages, or cached pages, which are often hosted by search engines and may not be blocked. For example, Google allows the retrieval of cached pages by entering "cache:some-url" as a search request.
Decentralised Hosting: Content creators may publish to an alternative platform which is willing to host ones content. Highly decentralised file hosting tools such as Freenet are more effective than centrally moderated platforms. Similarly, services which make use of BitTorrent such as ZeroNet are also resilient.
Anonymity Networks: The anonymity Tor Onion and I2P provides leads to more willingness to host content that would otherwise be censored. However the content is still hosted by a single entity which can be controlled.
Federated: Being semi-decentralised, federated platforms such as PeerTube allow for users to find an instance where they are welcomed.
Web proxies: Proxy websites are configured to allow users to load external web pages through the proxy server, permitting the user to load the page as if it is coming from the proxy server and not the (blocked) source. However, depending on how the proxy is configured, a censor may be able to determine the pages loaded and/or determine that the user is using a proxy server.
For example, the mobile Opera Mini browser uses a proxy-based approach employing encryption and compression in order to speed up downloads. This has the side effect of allowing it to circumvent several approaches to Internet censorship. In 2009 this led the government of China to ban all but a special Chinese versions of the browser.
Domain fronting: Circumvention software can implement a technique called domain fronting, where the destination of a connection is hidden by passing the initial requests through a content delivery network or other popular site which censors may be unwilling to block. This technique was used by messaging applications including Signal and Telegram. Tor's meek uses Microsoft's Azure cloud. However large cloud providers such as Amazon Web Services and Google Cloud no longer permit its use. Website owners can use a free account to use a Cloudflare domain for fronting.
SSH tunneling: By establishing an SSH tunnel, a user can forward all their traffic over an encrypted channel, so both outgoing requests for blocked sites and the response from those sites are hidden from the censors, for whom it appears as unreadable SSH traffic.
Virtual private network (VPN): Using a VPN, A user who experiences internet censorship can create a secure connection to a more permissive country, and browse the internet as if they were situated in that country. Some services are offered for a monthly fee; others are ad-supported. According to GlobalWebIndex, over 400 million people use virtual private networks to circumvent censorship or for increased level of privacy.
Tor: More advanced tools such as Tor route encrypted traffic through multiple servers to make the source and destination of traffic less traceable. It can in some cases be used to avoid censorship, especially when configured to use traffic obfuscation techniques.
A censor may be able to detect and block use of circumvention tools through Deep Packet Inspection. There are efforts to make circumvention tools less detectable by randomizing the traffic like Obfs4, attempting to mimic a non-blocked protocol such as Format Transforming Encryption, and Dust2, or tunneling traffic through a whitelisted site by using techniques including domain fronting or Meek. Tor and other circumvention tools have adopted multiple obfuscation techniques that users can use depending on the nature of their connection, which are sometimes called "Pluggable Transports." Torproject presents a list of Pluggable Transports on their site.
A sneakernet is the transfer of electronic information, especially computer files, by physically carrying data on storage media from one place to another. A sneakernet can move data regardless of network restrictions simply by not using the network at all. One example of a widely adopted sneakernet network is El Paquete Semanal in Cuba.
Adoption of circumvention tools
Circumvention tools have seen spikes in adoption in response to high-profile blocking attempts, however, studies measuring adoption of circumvention tools in countries with persistent and widespread censorship report mixed results.
In response to persistent censorship
Measures and estimates of circumvention tool adoption have reported widely divergent results. A 2010 study by Harvard University researchers estimated that very few users use censorship circumvention tools—likely less than 3% of users even in countries that consistently implement widespread censorship. Other studies have reported substantially larger estimates, but have been disputed.
In China, anecdotal reports suggest that adoption of circumvention tools is particularly high in certain communities, such as universities, and a survey by Freedom House found that users generally did not find circumvention tools to be difficult to use. Market research firm GlobalWebIndex has reported that there are over 35 million Twitter users and 63 million Facebook users in China (both services are blocked). However, these estimates have been disputed; Facebook's advertising platform estimates 1 million users in China, and other reports of Twitter adoption estimate 10 million users. Other studies have pointed out that efforts block circumvention tools in China have reduced adoption of those tools; the Tor network previously had over 30,000 users connecting from China but as of 2014 had only approximately 3,000 Chinese users.
In Thailand, internet censorship has existed since 2002, and there is sporadic and inconsistent filtering. In a small-scale survey of 229 Thai internet users, a research group at the University of Washington found that 63% of surveyed users attempted to use circumvention tools, and 90% were successful in using those tools. Users often made on-the-spot decisions about use of circumvention tools based on limited or unreliable information, and had a variety of perceived threats, some more abstract and others more concrete based on personal experiences.
In response to blocking events
In response to the 2014 blocking of Twitter in Turkey, information about alternate DNS servers was widely shared, as using another DNS server such as Google Public DNS allowed users to access Twitter. The day after the block, the total number of posts made in Turkey was up 138%, according to Brandwatch, an internet measurement firm.
After an April 2018 ban on the Telegram messaging app in Iran, web searches for VPN and other circumvention software increased as much as 48x for some search terms, but there was evidence that users were downloading unsafe software. As many as a third of Iranian internet users used the Psiphon tool in the days immediately following the block, and in June 2018 as many as 3.5 million Iranian users continued to use the tool.
Anonymity, risks, and trust
Circumvention and anonymity are different. Circumvention systems are designed to bypass blocking, but they do not usually protect identities. Anonymous systems protect a user's identity. And while they can contribute to circumvention, that is not their primary function. It is important to understand that open public proxy sites do not provide anonymity and can view and record the location of computers making requests as well as the websites accessed.
In many jurisdictions accessing blocked content is a serious crime, particularly content that is considered child pornography, a threat to national security, or an incitement of violence. Thus it is important to understand the circumvention technologies and the protections they do or do not provide and to use only tools that are appropriate in a particular context. Great care must be taken to install, configure, and use circumvention tools properly. Individuals associated with high-profile rights organizations, dissident, protest, or reform groups should take extra precautions to protect their online identities.
Circumvention sites and tools should be provided and operated by trusted third parties located outside the censoring jurisdiction that do not collect identities and other personal information. Best are trusted family and friends personally known to the circumventor, but when family and friends are not available, sites and tools provided by individuals or organizations that are only known by their reputations or through the recommendations and endorsement of others may need to be used. Commercial circumvention services may provide anonymity while surfing the Internet, but could be compelled by law to make their records and users' personal information available to law enforcement.
There are five general types of Internet censorship circumvention software:
CGI proxies use a script running on a web server to perform the proxying function. A CGI proxy client sends the requested url embedded within the data portion of an HTTP request to the CGI proxy server. The CGI proxy server pulls the ultimate destination information from the data embedded in the HTTP request, sends out its own HTTP request to the ultimate destination, and then returns the result to the proxy client. A CGI proxy tool's security can be trusted as far as the operator of the proxy server can be trusted. CGI proxy tools require no manual configuration of the browser or client software installation, but they do require that the user use an alternative, potentially confusing browser interface within the existing browser.
HTTP proxies send HTTP requests through an intermediate proxying server. A client connecting through an HTTP proxy sends exactly the same HTTP request to the proxy as it would send to the destination server unproxied. The HTTP proxy parses the HTTP request; sends its own HTTP request to the ultimate destination server; and then returns the response back to the proxy client. An HTTP proxy tool's security can be trusted as far as the operator of the proxy server can be trusted. HTTP proxy tools require either manual configuration of the browser or client side software that can configure the browser for the user. Once configured, an HTTP proxy tool allows the user transparently to use his normal browser interface.
Application proxies are similar to HTTP proxies, but support a wider range of online applications.
Peer-to-peer systems store content across a range of participating volunteer servers combined with technical techniques such as re-routing to reduce the amount of trust placed on volunteer servers or on social networks to establish trust relationships between server and client users. Peer-to-peer system can be trusted as far as the operators of the various servers can be trusted or to the extent that the architecture of the peer-to-peer system limits the amount of information available to any single server and the server operators can be trusted not to cooperate to combine the information they hold.
Re-routing systems send requests and responses through a series of proxying servers, encrypting the data again at each proxy, so that a given proxy knows at most either where the data came from or is going to, but not both. This decreases the amount of trust required of the individual proxy hosts.
Below is a list of different Internet censorship circumvention software:
|alkasir||HTTP proxy||Yemeni journalist Walid al-Saqaf||free||www.alkasir.com||Uses 'split-tunneling' to only redirect to proxy servers when blocking is encountered. Is not a general circumvention solution and only allows access to certain blocked websites. In particular it does not allow access to blocked websites that contain pornography, nudity or similar adult content.|
|Anonymizer||HTTP proxy||Anonymizer, Inc.||paid||www.anonymizer.com/||Transparently tunnels traffic through Anonymizer.|
|CGIProxy||HTTP proxy||James Marshall||free||www.jmarshall.com/||Turn a computer into a personal, encrypted proxy server capable of retrieving and displaying web pages to users of the server. CGIProxy is the engine used by many other circumvention systems.|
|Flash proxy||HTTP proxy||Stanford University||free||crypto
||Uses ephemeral browser-based proxy relays to connect to the Tor network.|
|Freegate||HTTP proxy||Dynamic Internet Technology, Inc.||free||www.dit-inc.us||Uses a range of open proxies to access blocked web sites via DIT's DynaWeb anti-censorship network.|
|Freenet||peer-to-peer||Ian Clarke||free||freenetproject.org||A decentralized, distributed data store using contributed bandwidth and storage space of member computers to provide strong anonymity protection.|
(originally Invisible Internet Project)
|re-routing||I2P Project||free||geti2p.net||Uses a pseudonymous overlay network to allow anonymous web browsing, chatting, file transfers, amongst other features.|
|Java Anon Proxy (also known as JAP or JonDonym)||re-routing (fixed)||Jondos GmbH||free or paid||anonymous-proxy-servers.net||Uses the underlying anonymity service AN.ON to allow browsing with revocable pseudonymity. Originally developed as part of a project of the Technische Universität Dresden, the Universität Regensburg, and the Privacy Commissioner of Schleswig-Holstein.|
|Psiphon||CGI proxy||Psiphon, Inc.||free||psiphon.ca||A simple-to-administer, open-source Internet censorship circumvention system in wide-scale use, with a cloud-based infrastructure serving millions.|
|Proxify||HTTP proxy||UpsideOut, Inc.||free or paid||proxify.com/||An encrypted, public, web-based circumvention system. Because the site is public, it is blocked in many countries and by most filtering applications.|
|StupidCensorship||HTTP proxy||Peacefire||free||stupidcensorship.com/||An encrypted, public, web-based circumvention system. Because the site is public, it is blocked in many countries and by most filtering applications. mousematrix.com is a similar site based on the same software.|
|Tor||re-routing (randomized)||The Tor Project||free||www.torproject.org|
|Ultrasurf||HTTP proxy||Ultrareach Internet Corporation||free||www.ultrasurf.us/||Anti-censorship product that allows users in countries with heavy internet censorship to protect their internet privacy and security.|
- Anonymous P2P
- Bypassing content-control filters
- Domain fronting
- Bypassing the Great Firewall of China
- Computer surveillance
- Content-control software
- Electronic Frontier Foundation - an international non-profit digital rights advocacy and legal organization
- Global Internet Freedom Consortium (GIFC) - a consortium of organizations that develop and deploy anti-censorship technologies
- Internet privacy
- Open Technology Fund (OTF) – a U.S. Government funded program created in 2012 at Radio Free Asia to support global Internet freedom technologies
- Proxy list
- Tactical Technology Collective – a non-profit foundation promoting the use of free and open source software for non-governmental organizations, and producers of NGO-in-A-Box
- Callanan, Cormac; Dries-Ziekenheiner, Hein; Escudero-Pascual, Alberto; Guerra, Robert (11 April 2011). "Leaping Over the Firewall: A Review of Censorship Circumvention Tools" (PDF). freedomhouse.org. Retrieved 11 December 2018.
- "How to: Circumvent Online Censorship". Surveillance Self-Defense. 5 August 2014. Retrieved 1 November 2018.
- Everyone's Guide to By-passing Internet Censorship, The Citizen Lab, University of Toronto, September 2007
- New Technologies Battle and Defeat Internet Censorship, Global Internet Freedom Consortium, 20 September 2007
- Dixon, Lucas; Ristenpart, Thomas; Shrimpton, Thomas (14 December 2016). "Network Traffic Obfuscation and Automated Internet Censorship". IEEE Security & Privacy. 14 (6): 43–53. arXiv:1605.04044. doi:10.1109/msp.2016.121. ISSN 1540-7993.
- "2010 Circumvention Tool Usage Report". Berkman Klein Center. Retrieved 15 November 2018.
- "China: The Home to Facebook and Twitter?". GlobalWebIndex Blog. 27 September 2012. Retrieved 13 December 2018.
- Ong, Josh (26 September 2012). "Report: Twitter's Most Active Country Is China (Where It Is Blocked)". The Next Web. Retrieved 11 December 2018.
- Marcello Mari. How Facebook's Tor service could encourage a more open web. The Guardian. Friday 5 December 2014.
- Lee, Linda; Fifield, David; Malkin, Nathan; Iyer, Ganesh; Egelman, Serge; Wagner, David (1 July 2017). "A Usability Evaluation of Tor Launcher". Proceedings on Privacy Enhancing Technologies. 2017 (3): 90–109. doi:10.1515/popets-2017-0030. ISSN 2299-0984.
- Gebhart, Genevieve; Kohno, Tadayoshi (26 April 2017). Internet Censorship in Thailand: User Practices and Potential Threats. 2017 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE. doi:10.1109/eurosp.2017.50. ISBN 9781509057627.
- Freedom of connection, freedom of expression: the changing legal and regulatory ecology shaping the Internet, Dutton, William H.; Dopatka, Anna; Law, Ginette; Nash, Victoria, Division for Freedom of Expression, Democracy and Peace, United Nations Educational, Scientific and Cultural Organization (UNESCO), Paris, 2011, 103 pp., ISBN 978-92-3-104188-4
- "Circumventing Network Filters Or Internet Censorship Using Simple Methods, VPNs, And Proxies" Archived 14 November 2011 at the Wayback Machine, Not As Cool As It Seems, 16 December 2009, accessed 16 September 2011
- "View web pages cached in Google Search Results - Google Search Help". support.google.com. Retrieved 11 December 2018.
- Steven Millward (22 November 2009). "Opera accused of censorship, betrayal by Chinese users". CNet Asia. Archived from the original on 3 November 2013.
- Fifield, David; Lan, Chang; Hynes, Rod; Wegmann, Percy; Paxson, Vern (1 June 2015). "Blocking-resistant communication through domain fronting". Proceedings on Privacy Enhancing Technologies. 2015 (2): 46–64. doi:10.1515/popets-2015-0009. ISSN 2299-0984.
- Bershidsky, Leonid (3 May 2018). "Russian Censor Gets Help From Amazon and Google". Bloomberg. Retrieved 9 November 2018.
- Hoffman, Chris. "How to Use SSH Tunneling to Access Restricted Servers and Browse Securely". How-To Geek. Retrieved 11 December 2018.
- Shahbar, K.; Zincir-Heywood, A. N. (9 November 2015). Traffic flow analysis of tor pluggable transports. 2015 11th International Conference on Network and Service Management (CNSM). pp. 178–181. doi:10.1109/CNSM.2015.7367356. ISBN 978-3-9018-8277-7.
- Sullivan, Bob (13 April 2006) Military Thumb Drives Expose Larger Problem Archived 6 December 2010 at the Wayback Machine MSNBC Retrieved on 25 January 2007.
- Apr 12, Matt Kwong · CBC News · Posted; April 12, 2016 5:00 AM ET | Last Updated; 2016. "When Cubans want internet content, black-market El Paquete delivers | CBC News". CBC. Retrieved 11 December 2018.
- Edwards, John (21 March 2014). "From Pac-Man to Bird Droppings, Turkey Protests Twitter Ban". WSJ. Retrieved 15 November 2018.
- Kargar, Simin; McManamen, Keith (2018). "Censorship and Collateral Damage: Analyzing the Telegram Ban in Iran". doi:10.2139/ssrn.3244046. ISSN 1556-5068. SSRN 3244046. Cite journal requires
- Al-Saqaf, Walid (2016). "Internet Censorship Circumvention Tools: Escaping the Control of the Syrian Regime". Media and Communication. 4 (1): 39. doi:10.17645/mac.v4i1.357.
- "VPN crackdown a trial by firewall for China's research world". South China Morning Post. Retrieved 15 November 2018.
- Branigan, Tania (18 February 2011). "China's Great Firewall not secure enough, says creator". The Guardian. ISSN 0261-3077. Retrieved 11 December 2018.
- Callanan, Cormac; Dries-Ziekenheiner, Hein; Escudero-Pascual, Alberto; Guerra, Robert (11 April 2011). "Leaping Over the Firewall: A Review of Censorship Circumvention Tools" (PDF). freedomhouse.org. Retrieved 11 December 2018.
- Mari, Marcello (5 December 2014). "How Facebook's Tor service could encourage a more open web". The Guardian. ISSN 0261-3077. Retrieved 13 December 2018.
- "Twitter estimates that it has 10 million users in China". TechCrunch. Retrieved 11 December 2018.
- Crandall, Jedidiah R.; Mueen, Abdullah; Winter, Philipp; Ensafi, Roya (1 April 2015). "Analyzing the Great Firewall of China Over Space and Time". Proceedings on Privacy Enhancing Technologies. 2015 (1): 61–76. doi:10.1515/popets-2015-0005.
- Access contested : security, identity, and resistance in Asian cyberspace information revolution and global politics. Deibert, Ronald. Cambridge, MA: MIT Press. 2012. p. 85. ISBN 9780262298919. OCLC 773034864.CS1 maint: others (link)
- "Turkish citizens use Google to fight Twitter ban". The Verge. Retrieved 15 November 2018.
- "About alkasir" Archived 10 September 2011 at the Wayback Machine, alkasir.com, accessed 16 September 2011
- www.anonymizer.com/, Anonymizer, Inc., accessed 16 September 2011
- CGIProxy", James Marshall, accessed 17 September 2011
- "Flash proxies", Applied Crypto Group in the Computer Science Department at Stanford University, accessed 21 March 2013
- "About D.I.T." Archived 26 September 2011 at the Wayback Machine, Dynamic Internet Technology, accessed 16 September 2011
- "What is Freenet?" Archived 16 September 2011 at the Wayback Machine, The Freenet Project, accessed 16 September 2011
- "I2P Anonymous Network", I2P Project, accessed 16 September 2011
- "Revocable Anonymity" Archived 25 September 2011 at the Wayback Machine, Stefan Köpsell, Rolf Wendolsky, Hannes Federrath, in Proc. Emerging Trends in Information and Communication Security: International Conference, Günter Müller (Ed.), ETRICS 2006, Freiburg, Germany, 6–9 June 2006, LNCS 3995, Springer-Verlag, Heidelberg 2006, pp.206-220
- "About Psiphon", Psiphon, Inc., 4 April 2011
- "Psiphon Content Delivery Software", Launchpad, accessed 16 September 2011
- "About Proxify", UpsideOut, Inc., accessed 17 September 2011
- About StupidCensorship.com, Peacefire, accessed 17 September 2011
- "Tor: Overview" Archived 6 June 2015 at the Wayback Machine, The Tor Project, Inc., accessed 16 September 2011
- "About UltraReach", Ultrareach Internet Corp., accessed 16 September 2011
|Wikimedia Commons has media related to Internet censorship.|
- Casting A Wider Net: Lessons Learned in Delivering BBC Content on the Censored Internet, Ronald Deibert, Canada Centre for Global Security Studies and Citizen Lab, Munk School of Global Affairs, University of Toronto, 11 October 2011
- Censorship Wikia, an anti-censorship site that catalogs past and present censored works, using verifiable sources, and a forum to discuss organizing against and circumventing censorship
- "Circumvention Tool Evaluation: 2011", Hal Roberts, Ethan Zuckerman, and John Palfrey, Berkman Centre for Internet & Society, 18 August 2011
- "Circumvention Tool Usage Report: 2010", Hal Roberts, Ethan Zuckerman, Jillian York, Robert Faris, and John Palfrey, Berkman Centre for Internet & Society, 14 October 2010
- Digital Security and Privacy for Human Rights Defenders[permanent dead link], by Dmitri Vitaliev, Published by Front Line - The International Foundation for the Protection of Human Rights Defenders
- "Digital Tools to Curb Snooping", New York Times, 17 July 2013
- "DNS Nameserver Swapping", Methods and Scripts useful for evading censorship through DNS filtering
- How to Bypass Internet Censorship, also known by the titles: Bypassing Internet Censorship or Circumvention Tools, a FLOSS Manual, 10 March 2011, 240 pp. Translations have been published in Arabic, Burmese, Chinese, Persian, Russian, Spanish, and Vietnamese
- Internet censorship wiki, provides information about different methods of access filtering and ways to bypass them
- "Leaping over the Firewall: A Review of Censorship Circumvention Tools", by Cormac Callanan (Ireland), Hein Dries-Ziekenheiner (Netherlands), Alberto Escudero-Pascual (Sweden), and Robert Guerra (Canada), Freedom House, April 2011
- "Media Freedom Internet Cookbook" by the OSCE Representative on Freedom of the Media, Vienna, 2004
- "Online Survival Kit", We Fight Censorship project of Reporters Without Borders
- "Selected Papers in Anonymity", Free Haven Project, accessed 16 September 2011
- "Ten Things to Look for in a Circumvention Tool", Roger Dingledine, The Tor Project, September 2010