Great Firewall

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
National Emblem of the People's Republic of China (2).svg
This article is part of a series on the
politics and government of
China
Flag of the People's Republic of China.svg China portal

The Great Firewall of China (GFW; simplified Chinese: 防火长城; traditional Chinese: 防火長城; pinyin: Fánghuǒ Chángchéng) is the combination of legislative actions and technologies enforced by the People's Republic of China to regulate the Internet domestically. Its role in internet censorship in China is to block access to selected foreign websites and to slow down cross-border internet traffic.[1] The effect includes: limiting access to foreign information sources, blocking foreign internet tools (e.g. Google search,[2] Facebook,[3] Twitter,[4] Wikipedia,[5][6] and others) and mobile apps, and requiring foreign companies to adapt to domestic regulations.[7][8]

Besides censorship, the GFW has also influenced the development of China's internal internet economy by nurturing domestic companies[9] and reducing the effectiveness of products from foreign internet companies.[10] The techniques deployed by the Chinese government to maintain control of the Great Firewall can include modifying search results for terms, such as they did following Ai Weiwei’s arrest, and petitioning global conglomerates to remove content, as happened when they petitioned Apple to remove the Quartz business news publication’s app from its Chinese App Store after reporting on the 2019–20 Hong Kong protests.[11][12]

The Great Firewall was formerly operated by the SIIO, as part of the Golden Shield Project. Since 2013, the firewall is technically operated by the Cyberspace Administration of China (CAC), which is the entity in charge of translating the Communist Party of China's will into technical specifications.[13]

As mentioned in the "one country, two systems" principle, China's special administrative regions (SARs) such as Hong Kong and Macau are not affected by the firewall, as SARs have their own governmental and legal systems and therefore enjoy a high degree of autonomy. Nevertheless, the U.S. State Department has reported that the central government authorities have closely monitored Internet use in these regions.[14]

The term Great Firewall of China is a portmanteau of firewall and the Great Wall of China, and was first used in print by Geremie Barmé in 1997.[15][16] The term started its use in Beijing in 1996 by Stephen Guerin of Redfish Group, a Beijing-based web consultancy. 1996 interviews of Guerin by CNN's Andrea Koppel and NPR's Mary Kay Magistad included Guerin discussing China's "reversing the firewall".[17][18]

History[edit]

A favorite saying of Deng Xiaoping’s in the early 1980s, "If you open the window, both fresh air and flies will be blown in", is considered to be the political and ideological basis of the GFW Project.[nb 1] The saying is related to a period of the economic reform of China that became known as the "socialist market economy". Superseding the political ideologies of the Cultural Revolution, the reform led China towards a market economy and opened up the market for foreign investors. Nonetheless, despite the economic freedom, values and political ideas of the Communist Party of China have had to be protected by "swatting flies" of other unwanted ideologies.[19]

The Internet in China arrived in 1994,[20] as the inevitable consequence of and supporting tool for a "socialist market economy". Gradually, while Internet availability has been increasing, the Internet has become a common communication platform and tool for trading information.

The Ministry of Public Security took initial steps to control Internet use in 1997, when it issued comprehensive regulations governing its use. The key sections, Articles 4–6, are:

Individuals are prohibited from using the Internet to: harm national security; disclose state secrets; or injure the interests of the state or society. Users are prohibited from using the Internet to create, replicate, retrieve, or transmit information that incites resistance to the PRC Constitution, laws, or administrative regulations; promoting the overthrow of the government or socialist system; undermining national unification; distorting the truth, spreading rumors, or destroying social order; or providing sexually suggestive material or encouraging gambling, violence, or murder. Users are prohibited from engaging in activities that harm the security of computer information networks and from using networks or changing network resources without prior approval.[21]

In 1998, the Communist Party of China feared that the China Democracy Party (CDP) would breed a powerful new network that the party elites might not be able to control.[22] The CDP was immediately banned, followed by arrests and imprisonment.[23] That same year, the GFW project was started. The first part of the project lasted eight years and was completed in 2006. The second part began in 2006 and ended in 2008. On 6 December 2002, 300 people in charge of the GFW project from 31 provinces and cities throughout China participated in a four-day inaugural "Comprehensive Exhibition on Chinese Information System".[24] At the exhibition, many western high-tech products, including Internet security, video monitoring and human face recognition were purchased. It is estimated that around 30,000–50,000 police were employed in this gigantic project.[citation needed]

Fang Binxing

Fang Binxing is known for his substantial contribution to China's Internet censorship infrastructure, and has been dubbed "Father of China's Great Fire Wall".[25][26][27]

Origins of Chinese Internet law[edit]

China's view of the internet is as "Internet sovereignty": the notion that the Internet inside the country is part of the country's sovereignty and should be governed by the country.[10][28]

While the United States and several other western countries passed laws creating computer crimes beginning in the 1970s, China had no such legislation until 1997. That year, China's sole legislative body, the National People's Congress (NPC) passed CL97, a law that criminalizes "cyber crimes", which it divided into two broad categories: crimes that target computer networks and crimes carried out over computer networks. Behavior illegal under the latter category includes among many things the dissemination of pornographic material and the usurping of "state secrets."[citation needed]

Some Chinese judges were critical of CL97, calling it ineffective and unenforceable. However, the NPC claimed it intentionally left the law "flexible" so that it could be open to future interpretation and development. Given the gaps in the law, the central government of China relies heavily on its administrative body, the State Council, to determine what falls under the definitions, and their determinations are not required to go through the NPC legislative process. As a result, the CPC has ended up relying heavily on state regulation to carry out CL97.[29]

The latter definition of online activities punishable under CL97, or "crimes carried out over computer networks" is used as justification for the Great Firewall and can be cited when the government blocks any ISP, gateway connections, or any access to anything on the internet. The definition also includes using the internet to distribute information considered "harmful to national security," and using the internet to distribute information considered "harmful to public order, social stability, and Chinese morality." The central government relies heavily on its State Council regulators to determine what specific online behavior and speech fall under these definitions.[citation needed]

The reasons behind the Internet censorship in China include:

  • Social Control: The Internet is a means for freedom of speech, and dissemination of campaigns could lead to protests against the government.
  • Sensitive Content: To control information about the government in China.
  • Economic Protectionism: China prefers the use of local companies that are regulated by Chinese regulations, since they have more power over them. E.g. Baidu over Google.[citation needed]

Campaigns and crackdowns[edit]

As part of the Great Firewall, beginning in 2003 China started the Golden Shield Project, a massive surveillance and censoring system, the hardware for which was provided by mostly U.S. companies, including Cisco Systems. The project was completed in 2006 and is now carried out in buildings with machines manned by civilians and supervised by China's national police force, the Public Security Bureau (PSB). The main operating procedures of the gatekeepers at the Golden Shield Project include monitoring domestic websites and email and searching for politically sensitive language and calls to protest. When damaging content is found, local PSB officials can be dispatched to investigate or make arrests. However, by late 2007 the Golden Shield Project proved to operate sporadically at best, as users had long adapted to internet blocking by using proxy servers, among other strategies, to make communications and circumnavigate to blocked content.[30]

Internet cafés, an extremely popular way of getting online in developing countries where fewer people can afford a personal computer, are regulated by the Chinese government and by local Chinese government officials. Minors (in China, those under the age of 18) are not allowed into Internet cafés, although this law is widely ignored and when enforced, has spurred the creation of underground "Black Web Bars" visited by those underage. As of 2008 internet cafés were required to register every customer in a log when they used the internet there; these records may be confiscated by local government officials and the PSB. To illustrate local regulation of internet cafés, in one instance, a government official in the town of Gedong lawfully banned internet cafés from operating in the town because he believed them to be harmful to minors, who frequented them to play online games (including those considered violent) and surf the internet. However, internet cafés in this town simply went underground and most minors were not deterred from visiting them.[31]

In May 2015, China indefinitely blocked access to the Chinese-language Wikipedia.[32] In contrast (as of 2018), the English-language Wikipedia was blocked only rarely and intermittently.[33] China in 2017 discussed plans for its own version of Wikipedia.[34][35] As of May 2019, all language versions of Wikipedia have been blocked by the Chinese government.[36]

Blocking methods[edit]

Active filtering[edit]

One function of the Chinese firewall is to selectively prevent content from being accessed. It is mostly made of Cisco, Huawei and Semptian hardware[37][38] Not all sensitive content get blocked; in 2007 scholar Jedidiah R. Crandall and others argued that the main purpose is not to block 100%, but rather to flag and to warn, in order to encourage self-censorship.[39] An illustrative but incomplete list of tactics includes:

Method Description
IP range ban using black holes The Chinese firewall maintains a list of IP ranges that are automatically dropped (network black-holing).

Because of the complexity to maintain a big, up-to-date banned network list with dynamic IPs, and because this method has proven not to be compatible with services using content delivery networks, it is usually used as last resort and other blocking methods are preferred (such as filtering based on QoS).

DNS spoofing, filtering and redirection One part of the Chinese firewall is made of liar DNS servers and DNS hijackers returning incorrect IP addresses.[40] Studies seems to point out that this censorship is keyword-based.[41]

Contrary to popular belief,[42] foreign DNS resolvers such as Google Public DNS IP address 8.8.8.8 are reported to work correctly inside the country;[43] however, these DNS servers are also subject to hijacking as their connections aren't encrypted: DNS queries do reach the DNS server, but if the request matches a banned keyword, the firewall will inject a fake DNS reply before the legitimate DNS reply arrives.

Typical circumvention methods include modifying the Hosts file, typing the IP address instead of the domain name in a Web browser or using DNS over TLS/HTTPS.

URL filtering using transparent proxies The Chinese firewall is made of transparent proxies filtering web traffic. These proxies scan the requested URI, the "Host" Header and the content of the web page (for HTTP requests) or the Server Name Indication (for HTTPS requests) for target keywords.[citation needed]

Like for DNS filtering, this method is keyword based. Encrypting the Server Name Indication can be used to bypass this method of filtering. It is currently in development by the IETF,[44] and is offered as a setting in Firefox.[45][46]

Quality of service filtering Since 2012, the GFW is able to "learn, filter and block" users based on traffic behavior, using deep packet inspection.[47] This method was originally developed for blocking VPNs and has been extended to become part of the standard filtering system of the GFW. The method works by mirroring all traffic (using a network tap) to a dedicated analytics unit, that will then deliver a score for each destination IP based on how suspicious the connection is. This score is then used to determine a packet loss rate to be implemented by routers of the Chinese firewall, resulting in a slowed connection on the client side. The method aims to slow down traffic to such an extent that the request times out on the client side, thus effectively having succeeded in blocking the service altogether.

It is believed that the analytics system is using side-channel (such as the handshake headers, and packet sizes) to estimate how suspicious is a connection.[48] It is able to detect traffic protocols (such as SSH tunneling, VPN or Tor protocols), and can measure packets Entropy to detect encrypted-over-encrypted traffic (such as HTTPS over an SSL tunnel).

The sensitivity can be turned up during sensitive political events.

This attack may be resisted by using a pluggable transport in order to mimic 'innocent' traffic, and never connect to 'suspicious' IPs by always having the circumvention software turned on, yet not proxy unblocked content, and the software itself never directly connect to a central server.

Packet forging and TCP reset attacks The Chinese firewall may arbitrarily terminate TCP transmissions, using packet forging. The blocking is performed using a TCP reset attack. This attack does not block TCP requests nor TCP replies, but send a malicious TCP RST packet to the sender, simulating an end-of-connection.

Side channel analysis seems to indicate that TCP Reset are coming from an infrastructure collocated or shared with QoS filtering routers.[49] This infrastructure seems to update the scoring system : if a previous TCP connection is blocked by the filter, future connection attempts from both sides may also be blocked for short period of times (up to few hours).

An efficient circumvention method is to ignore the reset packet sent by the firewall.[50] a patch for FreeBSD has been developed for this purpose.[51]

Man-in-the-middle attacks with TLS The Chinese National Intelligence Law theoretically allows the Chinese government to request and use the root certificate from any Chinese certificate authority,[52] such as CNNIC, to make MITM attacks with valid certificates.

Multiple TLS incidents also happened in the last decade, before the creation of the law:

On 26 January 2013, the GitHub SSL certificate was replaced with a self-signed certificate in China by the GFW.[53]

On 20 October 2014, iCloud SSL certificate was replaced with a self-signed certificate in China.[54] It is believed that the Chinese government discovered a vulnerability on Apple devices and was exploiting it.[55]

On 20 March 2015, Google detected valid certificates for Google signed by CNNIC in Egypt. In response of this event, and after a deeper investigation, CNNIC certificate has been removed by some browsers.[56] Because of the removal being based on proofs and not suspicion, no other Chinese certificate authority has been removed from web browsers, and some have been added since then.[57]

This type of attack can be circumvented by websites implementing Certificate Transparency and OCSP stapling or by using browser extensions.[58]

Active probing[edit]

In addition to previously discussed techniques, the CAC is also using active probing in order to identify and block network services that would help escaping the firewall. Multiple services such as Tor or VPN providers reported receiving unsolicited TCP/IP connections shortly after legitimate use, for the purported purpose of network enumeration of services, in particular TLS/SSL and Tor services, with the aim of facilitating IP blocking. For example, shortly after a VPN request is issued by a legitimate Chinese VPN client and passes outbound though the Great Firewall to a hidden VPN IP, the Great Firewall may detect the activity and issue its own active probe to verify the nature of the previously-unknown VPN IP and, if the probe confirms the IP is part of a blacklisted VPN, blacklist the IP.[59][60] This attack can be circumvented with the Obfs4 protocol, which relies on an out-of-band shared secret.[59][60]

Proxy distribution[edit]

The Great Firewall scrapes the IPs of Tor and VPN servers from the official distribution channels, and enumerates them.[61][62][63][64] The strategy to resist this attack is to limit the quantity of proxy IPs revealed to each user and making it very difficult for users to create more than one identity.[65][66][67][68] Academics have proposed solutions such as Salmon.[69][70][71][72] Dynamic IPs are quite effective to flush out from blacklists. Resilient proxy distribution still remains a major research question.

Effectiveness and impact[edit]

The Great Firewall in China has direct influence on the population's belief and way of thinking.[73]

It is mainly used by the Chinese government to promote and encourage right thinking by censoring dissident ideas. One of the main goals of the Great Chinese firewall is to create an environment where people have the same values. Therefore, the GFW is a political tool using Chinese citizens to promote Chinese Communist Party ideas, such as:

  • Taiwan, Hong Kong and Tibet are part of China.
  • 1989 Tiananmen Square protests should not be considered very important.
  • Prohibition of pornography and obscenity[74]
  • Democracy is not the best system for governing a country. As such pro-democracy groups should be considered as terrorists and Hong Kong protests are supposedly organized by foreign entities.
  • Falun Gong and other anti CCP groups, are "outlawed".

One role of the firewall is to play block access to websites discouraging or criticizing these ideas. Other tools and means include the 50 Cent party, originating in 2004.[75]

Because the social environment of an individual does not necessarily change when moving country, there are multiple reports of Chinese users still promoting these ideas even when they are going abroad and are not under direct influence of the GFW.[76][77] It is largely admitted that the GFW, as well as other means, is playing a non-negligible role in keeping stable, patriotic and CAC-compliant values.

Aside from the social control aspect, the Great Firewall also acts as a form of trade protectionism that has allowed China to grow its own internet giants, such as Tencent, Alibaba, and Baidu.[9][78] China has its own version of many foreign web properties, for example: Tencent Video (YouTube), Tencent Weibo (Twitter), Qzone (Facebook), WeChat (WhatsApp), Ctrip (Orbitz and others), Zhihu (Quora).[79] With nearly one quarter of the global internet population (700 million users), the internet behind the GFW can be considered a "parallel universe" to the Internet that exists outside.[10]

Circumvention[edit]

Methods for bypassing the firewall[edit]

Because the Great Firewall blocks destination IP addresses and domain names and inspects the data being sent or received, a basic censorship circumvention strategy is to use proxy nodes and encrypt the data. Most circumvention tools combine these two mechanisms:[80]

  • Proxy servers outside China can be used, although using just a simple open proxy (HTTP or SOCKS) without also using an encrypted tunnel (such as HTTPS) does little to circumvent the sophisticated censors.[80]
  • Freegate, Ultrasurf, Psiphon, and Lantern are free programs designed and experienced with circumventing the China firewall using multiple open proxies.
  • VPNs (virtual private networks) are one of the most popular tools used by Westerners for bypassing censorship technologies.[81] They use the same basic approaches, proxies and encrypted channels, used by other circumvention tools, but depend on a private host, a virtual host, or an account outside of China, rather than open, free proxies.[80]
  • Tor partially can be used in China.[80][82] Since 2010, almost all bridges at TorProject.org are blocked through proxy distribution. Tor still functions in China using independently published Obfs4 bridges and meek.[83][84][85][86]
  • I2P or garlic routing is useful when properties similar to Tor's anonymity are needed. Due to I2P being much less popular than Tor, it has faced little to no blocking attempts.

Non-proxy circumvention strategies include:

  • Using encrypted DNS may bypass blocking of a few sites including TorProject, and all of GitHub, which may be used to obtain further circumvention.[87] In 2019 Firefox released an update to make it easy to enable DNS over HTTPS.[88] Despite DNS over encryption, the majority of services remains blocked by IP.[89]
  • Ignoring TCP reset packets sent by the GFW. Distinguishing them by the TTL value (time to live), and not routing any further packets to sites that have triggered blocking behavior.[90]
  • There is a popular rumour that using IPv6 bypasses DPI filtering in China.[91][92][93] The academic community is yet to confirm.

Developing circumvention software[edit]

People attempting to develop circumvention software for China should implement the following:

Known blocked methods[edit]

  • OpenVPN protocol is detected and blocked. Connections not using symmetric keys or using "tls-auth" are blocked at handshake, and connections using the new "tls-crypt" option are detected and slowed down (under 56kbit/s) by the QoS filtering system.[citation needed]
  • GRE tunnels and protocols that use GRE (e.g., PPTP) are blocked.[94][unreliable source?]
  • IPSec tunnels and protocols that use it (L2TP) are detected and slowed down (under 56kbit/s) by the QoS filtering system and are sometimes blocked at handshake.[95]
  • TLS, the Great Firewall can identify the difference between legitimate https TLS and other implementations by inspecting the handshake perimeters.[96][97][98][99]

Exporting technology[edit]

Reporters Without Borders suspects that countries such as Cuba, Iran,[100] Vietnam, Zimbabwe and Belarus have obtained surveillance technology from China, although the censorship in these countries is less stringent than in China.[101]

Since at least 2015, Russian Roskomnadzor collaborates with Chinese Great Firewall security officials in implementing its data retention and filtering infrastructure.[102][103][104]

Protest in China[edit]

Despite strict government regulations, some Chinese people continue to protest against their government's attempt to censor the Internet.[citation needed] The more covert protesters set up secure SSH and VPN connections using tools such as UltraSurf. They can also utilize the widely available proxies and virtual private networks to fanqiang (翻墙, "climb over the wall"), or bypass the GFW. Active protest is not absent. Chinese people post their grievances online, and on some occasions, have been successful. In 2003, the death of Sun Zhigang, a young migrant worker, sparked an intense, widespread online response from the Chinese public, despite the risk of the government's punishment. A few months later, Premier Wen Jiabao abolished the Chinese law that led to the death of Sun. Ever since, dissent has regularly created turmoil on the Internet in China.[30] Also in January 2010, when Google announced that it will no longer censor its Web search results in China, even if this means it might have to shut down its Chinese operations altogether, many Chinese people went to the company's Chinese offices to display their grievances and offer gifts, such as flowers, fruits and cigarettes.[105]

Arguments against the GFW[edit]

Critics argue that the GFW is a consequence of China's paranoia of the potential that the Internet has of spreading opposition to their one-party rule.[citation needed] Other arguments given against China are that their method of having a limited Internet impedes freedom of speech and that it holds them down, economically speaking, by discouraging innovation, disapproving communication of important ideas and prohibiting firms the use of certain services that they use. It is also thought to be a detrimental approach for students and professors since they do not have access to resources which promote the sharing of work and ideas for a more comprehensive learning.[citation needed]

Another important argument against the GFW and fear that the critics have is that if other big countries begin following China's approach, the whole purpose of the creation of the Internet could be put in jeopardy. If like-minded countries are successful in imposing the same restrictions on their inhabitants and globalized online companies, then the free global exchange of information could cease to exist.[106]

Reaction of the United States[edit]

The United States Trade Representative's (USTR) "National Trade Estimate Report" in 2016 referred the China's digital Great Firewall: "China's filtering of cross-border Internet traffic has posed a significant burden to foreign suppliers."[107] Claude Barfield, the American Enterprise Institute's expert of International trade, suggested that the U.S. government should bring a case against the Firewall, a huge trade barrier, in the World Trade Organization in January 2017.[108] 8 of the 24 more trafficked websites in China have been blocked by The Great Firewall. This has created a burden to foreign suppliers who rely on these websites to sell their products or services. The lobby's 2016 business climate survey showed 79 percent of its members reported a negative impact on business due to internet censorship.[109]

According to Stephen Rosen, the GFW is reflective of the Chinese government's fear of civil disobedience or rebellion among the Chinese population against the Chinese Communist Party's rule:

If you want to know what people are worried about look at what they spend their money on. If you’re afraid of burglars you buy a burglar alarm. What are the Chinese spending their money on? We’re told from Chinese figures they’re spending on the People's Armed Police, the internal security force is about as big as they’re spending on the regular military. This whole great firewall of Chinese, this whole massive effort to control the internet, this effort to use modern information technology not to disseminate information, empowering individuals, but to make people think what you want them to think and to monitor their behavior so that you can isolate and suppress them. That’s because this is a regime which is fundamentally afraid of its own people. And it’s fundamentally hostile to them.[110]

See also[edit]

Notes[edit]

  1. ^ Chinese: 打开窗户,新鲜空气和苍蝇就会一起进来。; pinyin: Dǎkāi chuānghù, xīnxiān kōngqì hé cāngying jiù huì yìqǐ jìnlái.
    There are several variants of this saying in Chinese, including "如果你打开窗户换新鲜空气,就得想到苍蝇也会飞进来。" and "打开窗户,新鲜空气进来了,苍蝇也飞进来了。". Their meanings are the same.

References[edit]

  1. ^ Mozur, Paul (13 September 2015). "Baidu and CloudFlare Boost Users Over China's Great Firewall". The New York Times. Archived from the original on 24 January 2019. Retrieved 16 September 2017.
  2. ^ "google.com is blocked in China | GreatFire Analyzer". en.greatfire.org. Archived from the original on 2014-08-05. Retrieved 2020-01-18.
  3. ^ "How China's social media users created a new language to beat censorship on COVID-19". Amnesty International. 6 March 2020. Archived from the original on 3 April 2020. Retrieved 3 April 2020.
  4. ^ "China Blocks Access To Twitter, Facebook After Riots". Washington Post. Archived from the original on 19 September 2010. Retrieved 18 January 2020.
  5. ^ "Wikipedia founder defends decision to encrypt the site in China". The Verge. Archived from the original on 12 June 2018. Retrieved 17 April 2018.
  6. ^ Skipper, Ben (7 December 2015). "China's government has blocked Wikipedia in its entirety again". International Business Times UK. Archived from the original on 3 May 2018. Retrieved 2 May 2018.
  7. ^ Mozur, Paul; Goel, Vindu (5 October 2014). "To Reach China, LinkedIn Plays by Local Rules". The New York Times. Archived from the original on 13 June 2018. Retrieved 4 September 2017.
  8. ^ Branigan, Tania (28 June 2012). "New York Times launches website in Chinese language". The Guardian. Archived from the original on 4 September 2017. Retrieved 4 September 2017.
  9. ^ a b Denyer, Simon (23 May 2016). "China's scary lesson to the world: Censoring the Internet works". The Washington Post. Archived from the original on 6 December 2018. Retrieved 5 September 2017.
  10. ^ a b c Rauhala, Emily (19 July 2016). "America wants to believe China can't innovate. Tech tells a different story". The Washington Post. Archived from the original on 3 September 2017. Retrieved 5 September 2017.
  11. ^ Miller, Chance (2019-10-09). "Apple removes 'Quartz' news app from Chinese App Store". 9to5Mac. Archived from the original on 2019-10-10. Retrieved 2019-10-10.
  12. ^ Statt, Nick (2019-10-09). "Apple removes Quartz news app from the Chinese App Store over Hong Kong coverage". The Verge. Archived from the original on 2019-10-10. Retrieved 2019-10-10.
  13. ^ "How China's Internet Police Control Speech on the Internet". Radio Free Asia. Archived from the original on 11 July 2013. Retrieved 15 August 2018.
  14. ^ "China (includes Tibet, Hong Kong, and Macau) - Hong Kong". U.S. Department of State. Archived from the original on 1 July 2019. Retrieved 29 July 2018.
  15. ^ Lanfranco, Edward (9 September 2005). "The China Yahoo! welcome: You've got Jail!". UPI. Archived from the original on 10 August 2017. Retrieved 9 August 2017.
  16. ^ Barme, Geremie R.; Ye, Sang (6 January 1997). "The Great Firewall of China". Wired. Archived from the original on 1 August 2015. Retrieved 29 December 2015.
  17. ^ Koppel, Andrea (9 February 1996). "China Roadblocks the Internet". CNN. Archived from the original on 6 July 2008. Retrieved 20 April 2019.
  18. ^ Magistad, Mary Kay (14 May 1996). "Internet Cafe". NPR. Archived from the original on 20 April 2019. Retrieved 20 April 2019.
  19. ^ R. MacKinnon "Flatter world and thicker walls? Blogs, censorship and civic discourse in China" Public Choice (2008) 134: p. 31–46, Springer
  20. ^ "中国接入互联网". China News Service. Archived from the original on 19 February 2014. Retrieved 28 August 2013.
  21. ^ "China and the Internet.", International Debates, 15420345, Apr2010, Vol. 8, Issue 4
  22. ^ Goldman, Merle Goldman. Gu, Edward X. [2004] (2004). Chinese Intellectuals between State and Market. Routledge publishing. ISBN 0415325978
  23. ^ Goldsmith, Jack L.; Wu, Tim (2006). Who Controls the Internet?: Illusions of a Borderless World. New York: Oxford University Press. p. 91. ISBN 0-19-515266-2.
  24. ^ Website, Adsale Corporate. "Adsale Corporate Website - Adsale Group". www.adsale.com.hk. Archived from the original on 2020-05-02. Retrieved 2020-05-24.
  25. ^ Qiang, Xiao (20 December 2010). "'Father' of China's Great Firewall Shouted Off Own Microblog". China Digital Times (CDT). Archived from the original on 25 December 2019. Retrieved 24 October 2019.
  26. ^ "'Father' of China's Great Firewall Shouted Off Own Microblog – China Real Time Report – WSJ". Wall Street Journal. 20 December 2010. Archived from the original on 19 November 2017. Retrieved 25 December 2010.
  27. ^ "Archived copy" "防火墙之父"北邮校长方滨兴微博遭网民"围攻" (in Chinese). Yunnan Information Times. 23 December 2010. Archived from the original on 21 July 2011. Retrieved 20 May 2011.CS1 maint: archived copy as title (link)
  28. ^ Denyer, Simon (23 May 2016). "China's scary lesson to the world: Censoring the Internet works". Washington Post. Archived from the original on 6 December 2018. Retrieved 2 September 2017.
  29. ^ Keith, Ronald; Lin, Zhiqiu (2006). New Crime in China. Routledge Taylor & Francis Group. pp. 217–225. ISBN 0415314828.
  30. ^ a b August, Oliver (23 October 2007). "The Great Firewall: China's Misguided — and Futile — Attempt to Control What Happens Online". Wired Magazine. Archived from the original on 2 April 2015. Retrieved 1 April 2015.
  31. ^ Cody, Edward (9 February 2007). "Despite a Ban, Chinese Youth Navigate to Internet Cafés". The Washington Post. Archived from the original on 20 December 2014. Retrieved 1 April 2015.
  32. ^ Smith, Charlie (18 June 2015). "We Had Our Arguments, But We Will Miss You Wikipedia". Huffington Post. Archived from the original on 19 June 2015. Retrieved 31 December 2018.
  33. ^ "en.wikipedia.org in China". GreatFire. Archived from the original on 27 April 2019. Retrieved 31 December 2018.
  34. ^ Toor, Amar (4 May 2017). "China is building its own version of Wikipedia". The Verge. Archived from the original on 4 September 2017. Retrieved 4 September 2017.
  35. ^ Watt, Louise (4 May 2017). "China is launching its own Wikipedia – but only the government can contribute to it". The Independent. Archived from the original on 10 December 2018. Retrieved 3 November 2017.
  36. ^ "Search result not found: China bans Wikipedia in all languages". Washington Post. Archived from the original on 7 June 2019. Retrieved 6 June 2019.
  37. ^ Herman, Arthur. "Huawei's (And China's) Dangerous High-Tech Game". Forbes. Archived from the original on 15 May 2019. Retrieved 8 October 2019.
  38. ^ "Cisco, Huawei and Semptian: A Look Behind the Great Firewall of China". C5IS. 15 December 2014. Archived from the original on 14 July 2019. Retrieved 8 October 2019.
  39. ^ Oliver Farnan; Alexander Darer; Joss Wright (2016). "Poisoning the Well". Proceedings of the 2016 ACM on Workshop on Privacy in the Electronic Society - WPES'16. pp. 95–98. doi:10.1145/2994620.2994636. ISBN 9781450345699. S2CID 7275132.
  40. ^ "how to unblock websites in China". pcwizardpro.com. Archived from the original on 27 January 2018. Retrieved 27 January 2018.
  41. ^ "The Great DNS Wall of China - Analysis of the DNS infrastructure" (PDF). Archived (PDF) from the original on 2019-04-03. Retrieved 2019-06-01.
  42. ^ "8.8.8.8 goes pretty well in the Chinese market. (8 being a popular number.) I th... | Hacker News". news.ycombinator.com. Archived from the original on 26 March 2020. Retrieved 31 May 2019.
  43. ^ "r/China - DNS servers in China". reddit. Archived from the original on 29 March 2020. Retrieved 31 May 2019.
  44. ^ "draft-ietf-tls-esni-03 - Encrypted Server Name Indication for TLS 1.3". datatracker.ietf.org. Archived from the original on 6 June 2019. Retrieved 13 June 2019.
  45. ^ "Encrypted SNI Comes to Firefox Nightly". Mozilla Security Blog. Archived from the original on 2020-03-24. Retrieved 2020-02-11.
  46. ^ "Encrypt that SNI: Firefox edition". The Cloudflare Blog. October 18, 2018. Archived from the original on February 14, 2020. Retrieved February 11, 2020.
  47. ^ Arthur, Charles (14 December 2012). "China tightens 'Great Firewall' internet control with new technology". guardian.co.uk. London: The Guardian. Archived from the original on 10 September 2013. Retrieved 8 March 2013.
  48. ^ "My Experience With the Great Firewall of China". blog.zorinaq.com. Archived from the original on 1 July 2016. Retrieved 1 June 2019.[self-published source]
  49. ^ "Ignoring TCP RST send by the firewall" (PDF). Archived (PDF) from the original on 2019-06-11. Retrieved 2019-06-01.
  50. ^ "zdnetasia.com". zdnetasia.com. Archived from the original on 8 October 2009. Retrieved 13 June 2011.
  51. ^ "FreeBSD patch - ignore TCP RST". Archived from the original on 2008-06-29. Retrieved 2019-06-01.
  52. ^ "Cyber-security Law of the People's Republic of China". www.dezshira.com. Archived from the original on 1 June 2019. Retrieved 1 June 2019.
  53. ^ "GitHub SSL replaced by self-signed certificate in China | Hacker News". News.ycombinator.com. Archived from the original on 5 July 2014. Retrieved 15 June 2013.
  54. ^ "Chinese MITM Attack on iCloud - NETRESEC Blog". Netresec. Archived from the original on 2020-03-29. Retrieved 2019-06-10.
  55. ^ CVE-2014-4449
  56. ^ "TLS certificate blunder revisited – whither China Internet Network Information Center?". nakedsecurity.sophos.com. 2015-04-14. Archived from the original on 21 October 2018. Retrieved 18 October 2018.
  57. ^ "1128392 - Add GDCA Root Certificate". bugzilla.mozilla.org. Archived from the original on 24 March 2020. Retrieved 1 June 2019.
  58. ^ "Certificate Patrol - a psyced Firefox/Mozilla add-on". patrol.psyced.org. Archived from the original on 13 June 2019. Retrieved 7 July 2019.
  59. ^ a b Wilde, Tim (7 January 2012). "Knock Knock Knockin' on Bridges' Doors". Tor Project. Archived from the original on 13 January 2012. Retrieved 3 May 2018.
  60. ^ a b "Learning more about the GFW's active probing system | Tor Blog". blog.torproject.org. Archived from the original on 8 October 2019. Retrieved 8 October 2019.
  61. ^ "28c3: How governments have tried to block Tor". YouTube. 2011-12-28. Archived from the original on 2020-03-29. Retrieved 2020-02-17.
  62. ^ "Roger Dingledine - The Tor Censorship Arms Race The Next Chapter - DEF CON 27 Conference". YouTube. 2019-11-15. Archived from the original on 2020-03-29. Retrieved 2020-02-17.
  63. ^ "#32117 (Understand and document BridgeDB bot scraping attempts) – Tor Bug Tracker & Wiki". trac.torproject.org. Archived from the original on 2020-03-27. Retrieved 2020-01-21.
  64. ^ "Jinyang Li - Censorship Circumvention via Kaleidoscope". YouTube. Archived from the original on 2020-05-23. Retrieved 2020-05-24.
  65. ^ "Tor Games" (PDF). people.cs.umass.edu. Archived (PDF) from the original on 2020-02-17. Retrieved 2020-02-17.
  66. ^ "Data" (PDF). www-users.cs.umn.edu. Archived (PDF) from the original on 2019-06-12. Retrieved 2020-02-17.
  67. ^ "r/IAmA - We build Lantern – an app that you can run at home to fight internet censorship around the world. Ask Us Anything!". reddit. Archived from the original on 2020-03-29. Retrieved 2020-01-21.
  68. ^ "Info" (PDF). censorbib.nymity.ch. Archived (PDF) from the original on 2016-03-17. Retrieved 2020-05-24.
  69. ^ "Info" (PDF). censorbib.nymity.ch. Retrieved 2020-05-24.
  70. ^ "Frederick Douglas - Salmon: Robust Proxy Distribution for Censorship Circumvention". YouTube. 2016-10-10. Archived from the original on 2019-02-04. Retrieved 2020-05-24.
  71. ^ https://community.torproject.org/gsoc/salmon-bridge-distribution/
  72. ^ https://github.com/net4people/bbs/issues/33
  73. ^ "Young people in China don't know the internet we do – and they like it that way". The Independent. 5 September 2018. Archived from the original on 17 May 2020. Retrieved 3 April 2020.
  74. ^ Jacobs, Katrien (2012). People's Pornography: Sex and Surveillance on the Chinese Internet. Intellect Books. ISBN 978-1-84150-493-3.
  75. ^ Economy, Elizabeth C. (29 June 2018). "The great firewall of China: Xi Jinping's internet shutdown". The Guardian. Archived from the original on 10 October 2019. Retrieved 26 April 2020.
  76. ^ "Counter-protests against pro-Hong Kong demonstrators may reflect Chinese state influence". Archived from the original on 2019-11-20.
  77. ^ "Top concern: happiness of compatriots - People's Daily Online". en.people.cn. Archived from the original on 2019-10-22. Retrieved 2019-11-03.
  78. ^ Chen, Te-Ping (28 January 2015). "China Owns 'Great Firewall,' Credits Censorship With Tech Success". WSJ. Archived from the original on 21 November 2017. Retrieved 2 September 2017.
  79. ^ Millward, Steven (12 January 2017). "China's answer to Quora now worth a billion bucks". Tech in Asia. Archived from the original on 4 September 2017. Retrieved 4 September 2017.
  80. ^ a b c d "Splinternet Behind the Great Firewall of China: The Fight Against GFW" Archived 2017-09-20 at the Wayback Machine, Daniel Anderson, Queue, Association for Computing Machinery (ACM), Vol. 10, No. 11 (29 November 2012), doi:10.1145/2390756.2405036. Retrieved 11 October 2013.
  81. ^ "Tech in Asia - Connecting Asia's startup ecosystem". www.techinasia.com. Archived from the original on 2020-03-29. Retrieved 2020-01-20.
  82. ^ "r/TOR - Does Tor still work in China?". reddit. Archived from the original on 2019-09-04. Retrieved 2019-11-11.
  83. ^ "Conference paper" (PDF). www.usenix.org. Archived (PDF) from the original on 2019-10-28. Retrieved 2020-05-24.
  84. ^ "28c3: How governments have tried to block Tor". YouTube. 2011-12-28. Archived from the original on 2020-05-23. Retrieved 2020-05-24.
  85. ^ https://trac.torproject.org/projects/tor/ticket/29279
  86. ^ https://www.youtube.com/watch?v=g6xEfNHkFKY&feature=youtu.be&t=756 https://www.youtube.com/watch?v=g6xEfNHkFKY&feature=youtu.be&t=3176
  87. ^ "How to Use DNSCrypt to Prevent DNS Spoofing in China | Tips for China". www.tipsforchina.com. Archived from the original on 2020-02-17. Retrieved 2020-02-17.
  88. ^ Deckelmann, Selena. "DNS-over-HTTPS (DoH) Update – Recent Testing Results and Next Steps". Future Releases. Archived from the original on 2020-01-07. Retrieved 2020-01-20.
  89. ^ [1][dead link]
  90. ^ "Ignoring the Great Firewall of China" Archived 2017-09-09 at the Wayback Machine, Richard Clayton, Steven J. Murdoch, and Robert N. M. Watson, PET'06: Proceedings of the 6th international conference on Privacy Enhancing Technologies, Springer-Verlag (2006), pages 20–35, ISBN 3-540-68790-4, doi:10.1007/11957454_2. Retrieved 11 October 2013.
  91. ^ "Defcon 21 - Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine". YouTube. 2013-11-16. Retrieved 2020-05-24.
  92. ^ "32C3 - How the Great Firewall discovers hidden circumvention servers". YouTube. 2016-04-24. Retrieved 2020-05-24.
  93. ^ "My Experience With the Great Firewall of China". blog.zorinaq.com. Archived from the original on 2016-07-01. Retrieved 2019-06-01.
  94. ^ "r/Windscribe - China almost blocked everything pptp l2tp openvpn tunnel...if use private cloud there's still 50% chance get block". reddit. Archived from the original on 2020-03-29. Retrieved 2019-11-11.
  95. ^ "r/networking - About Chinese Great Firewall and IPsec". reddit. Archived from the original on 2020-03-29. Retrieved 2019-11-11.
  96. ^ "Defcon 21 - Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine". YouTube. 2013-11-16. Archived from the original on 2016-07-07. Retrieved 2020-05-24.
  97. ^ "32C3 - How the Great Firewall discovers hidden circumvention servers". YouTube. 2016-04-24. Retrieved 2020-05-24.
  98. ^ "Data" (PDF). tlsfingerprint.io. 2019. Archived (PDF) from the original on 2019-02-27. Retrieved 2020-05-24.
  99. ^ "Anti-Censorship & Transparency - Roger Dingledine". YouTube. Retrieved 2020-05-24.
  100. ^ "Iran To Work With China To Create National Internet System". www.rferl.org. Retrieved 2020-09-30.
  101. ^ "Going online in Cuba: Internet under surveillance" (PDF). Reporters Without Borders. 2006. Archived from the original (PDF) on 3 March 2009.
  102. ^ Soldatov, Andrei; Borogan, Irina (2016-11-29). "Putin brings China's Great Firewall to Russia in cybersecurity pact". The Guardian. ISSN 0261-3077. Retrieved 2017-07-04.
  103. ^ "China: The architect of Putin's firewall". Eurozine. 2017-02-21. Retrieved 2019-12-10.
  104. ^ "Russia's chief internet censor enlists China's know-how". Financial Times. 2016-04-29. Retrieved 2019-12-10.
  105. ^ Ramzy, Austin (13 April 2010). "The Great Firewall: China's Web Users Battle Censorship". Time. Archived from the original on 20 August 2017. Retrieved 2 May 2020.
  106. ^ "The Great Firewall of China". Bloomberg. Archived from the original on 31 March 2018. Retrieved 2 April 2018.
  107. ^ Barfield, Claude (29 April 2016). "China's Internet censorship: A WTO challenge is long overdue". TechPolicyDaily.com. Archived from the original on 30 April 2016. Retrieved 26 January 2017.
  108. ^ Barfield, Claude (25 January 2017). "China bans 8 of the world's top 25 websites? There's still more to the digital trade problem". American Enterprise Institute. Archived from the original on 26 January 2017. Retrieved 26 January 2017.
  109. ^ Martina, Paul (8 April 2016). "U.S. says China internet censorship a burden for businesses". Reuters. Reuters. Archived from the original on 2 April 2018. Retrieved 23 March 2018.
  110. ^ Kristol, Bill (30 November 2018). "Stephen Rosen interview". Conversations With Bill Kristol. Archived from the original on 25 March 2020. Transcript. Retrieved 26 October 2019.

Further reading[edit]

  • Griffiths, James, "The Great Firewall of China: How to Build and Control an Alternative Version of the Internet", Zed Books (May 2019).
  • Nilekani, Nandan, "Data to the People: India's Inclusive Internet", Foreign Affairs, vol. 97, no. 5 (September / October 2018), pp. 19–26.
  • Segal, Adam, "When China Rules the Web: Technology in Service of the State", Foreign Affairs, vol. 97, no. 5 (September / October 2018), pp. 10–14, 16–18.

External links[edit]