How Governments Block and Censor the Internet, Circumvention and Side Effects

Lecture



Internet censorship (blocking) is the control and suppression of the publication of, or access to, information on the Internet. Internet censorship owes its emergence to the absence of national borders on the Internet. The general problem of Internet censorship can be defined as follows: information that contradicts the laws of a state (the regime of the current government) and is blocked on domestic resources can be published on web servers in other countries.

There are several motives or reasons for Internet filtering: politics and power, social norms and morality, and security concerns. The protection of existing economic interests is an additional motive for Internet filtering. Moreover, the network tools and applications that allow the exchange of information related to these motives are themselves subject to filtering and blocking. And although there are significant differences from country to country, the blocking of websites in the local language is about twice as high as that of websites available only in English or other international languages.

Forms of Internet censorship

Since the Internet is not under the sole control of any one state and its resources are distributed among many commercial organizations, comprehensive Internet censorship is quite difficult, yet entirely feasible. It is carried out through the combined use of the following measures:

  1. Concentrating in the hands of the state the management of network communications, or real levers of influence over the companies that operate the networks crossing the state's borders. This makes it possible to forbid, by decree, users from viewing resources whose content is deemed undesirable.
  2. Making access to Internet resources controlled by companies dependent on those companies' willingness to control the content of the resources, deleting or editing messages that in one way or another fall under the censorship of the country's authorities. As a result, companies that support, for example, a system of online blogs face a choice: either yield to blackmail and censor information, or refuse and lose users. For example, for the Google search engine in China, access to the contents of "cached" pages was blocked through domestic Chinese providers (this cache makes it possible in some cases to get around the ban on viewing certain pages that fall under censorship restrictions), and this continued until Google itself removed cache viewing from the Chinese version of the search results page . Caring about the development of their business, large Internet companies often make deals with governments that practice Internet censorship so as not to lose the market, even coming into conflict with their own officially proclaimed policy of supporting freedom of speech .
  3. Governments can also control the content of some Internet resources through front companies, "non-governmental organizations" or private individuals who censor information under various pretexts.

Censorship on the Internet involves not only the blocking or closing of web resources, but also traffic analysis, the creation of fake opposition web resources, and the application of punitive measures against the authors of publications or the owners of web servers.

According to a report by the public organization Reporters Without Borders, in 2008 1,740 websites were closed or blocked, and 105 bloggers suffered for publishing materials on the Internet, of whom 1 was killed, 59 were arrested and 45 were physically attacked .

Apart from cases of total control over the junction of national networks with the global ones in some countries, such as China, North Korea, Iran and others, it is technically difficult for a single state to overcome the distributed structure of the Internet. The introduction of some measures leads to the emergence of new ways of circumventing the restrictions. Most often, applying censorship on the Internet is more costly than overcoming it. But the enormous resources of states allow them to carry it out in many cases.

"I see no danger to the world as a whole if someone tries to restrict the free spread of information through the Net. It is impossible to control the Internet," believes Bill Gates. "Sooner or later, freedom will win again." .

Methods of blocking Internet resources

In Russia, for example, so-called TSPU (Technical Means of Countering Threats) are used, the very "black boxes" from RKN (Roskomnadzor). They are supposed to be installed at the places marked in red, i.e. at the BRAS output. A BRAS is the device where the subscriber session is actually established and processed. Most subscribers get a "gray" IP address here. Such an address is not routed on the Internet; it must be translated on a NAT (Network Address Translation) server into a "white" IP address. Thus, attacking "gray" addresses from the Internet is difficult (we will not go into technical details; those who are interested can ask or google it), whereas it is much easier to attack the "white" addresses of NAT servers or even of border routers.

How Governments Block and Censor the Internet, Circumvention and Side Effects

There are the following methods of blocking Internet resources and traffic

  • 1. Blocking at the user level (using antivirus software, IP blacklists, a special DNS)

  • 2. Blocking at the level of backbone Internet providers using, for example, DPI (Deep packet inspection) and/or deliberate traffic shaping
  • 3. Blocking at the level of last-mile providers
  • 4. Blocking using a fully autonomous (sovereign) Internet
  • 5. Blocking with traffic analysis
  • 6. Blocking of DNS resources
  • 7. Blocking of IP packets
  • 8. Blocking of pages, users, groups and communities by the web service itself, often owned by a particular government

How Governments Block and Censor the Internet, Circumvention and Side Effects

A group of Indian scientists has published a review of modern Internet blocking methods introduced by government bodies, using their own country as an example. They studied the mechanisms that Internet providers use to restrict access to prohibited information, assessed their accuracy and the possibilities of circumventing such blocks. We present the main points of this work.
In recent years, researchers from various countries have carried out many studies of the blocking methods used in countries considered "not free", for example China or Iran. However, even democratic states such as India have in recent years deployed a large-scale infrastructure for carrying out censorship on the Internet.

In the course of the study, the scientists compiled a list of 1,200 websites potentially blocked in the country. The data was collected from open sources such as Citizen Lab or Herdict. Then Internet access was arranged through the nine most popular Internet providers.

The OONI tool was initially used to determine whether a site was censored and blocked.

OONI vs. a custom script for detecting blocks


Initially, the researchers intended to use a popular censorship detection tool called OONI. However, it turned out during the experiment that it produces many false positives: manual verification of the results revealed many inaccuracies.

The low quality of censorship detection may be due to OONI's outdated mechanisms. For example, when detecting DNS filtering, the tool compares the IP address of a given host returned by Google DNS (which is considered uncensored) with the IP address assigned to the site by the Internet provider.

If the addresses do not match, OONI signals the presence of a block. However, in the realities of the modern Internet, different IP addresses mean nothing and, for example, may be evidence of the use of CDN networks.

Thus, the researchers had to write their own scripts to detect blocks. Below is an overview of popular ways of blocking content on the Internet and an analysis of their effectiveness in modern conditions.

How blocking is carried out, or what middleboxes are


The analysis showed that in all cases of blocking of various types, it is carried out with the help of embedded network elements. The researchers called them middleboxes: they intercept user traffic, analyze it, and if they detect an attempt to connect to a prohibited site, they insert special packets into the traffic.

To detect middleboxes, the researchers developed their own method, Iterative Network Tracing (INT), which uses the principles of the traceroute utility. Its essence comes down to sending web requests to blocked sites with increasing TTL values in the IP headers.

How Governments Block and Censor the Internet, Circumvention and Side Effects

The middlebox mechanism for intercepting data

DNS blocking


The DNS resolution process is the main step on the path to accessing any website. The URL entered by the user is first resolved into the associated IP address. With DNS blocking, censors always interfere at exactly this step: a controlled resolver returns an incorrect IP address to the user, and as a result the site simply does not open (DNS poisoning).

Another blocking method is the use of DNS injection: in this case a middlebox between the client and the resolver intercepts the DNS request and sends its own response containing an incorrect IP address.

To detect DNS blocking by Internet providers, the researchers used Tor with exit nodes in countries without censorship: if the site opens through it but not through a plain connection via the provider, then blocking is taking place.

After identifying the sites blocked via DNS, the researchers determined the blocking method.

How Governments Block and Censor the Internet, Circumvention and Side Effects

The iterative network tracing method: the client sends special requests (DNS/HTTP GET) containing a blocked site and a constantly increasing TTL

TCP/IP packet filtering


Blocking by filtering on packet headers is considered a popular method of Internet censorship. On the Internet one can find quite a few studies whose authors try to detect precisely this method of blocking sites.

In reality, the problem is that this method is easily confused with ordinary system failures that cause difficulties in the operation of the network and reduce its throughput. Unlike blocking by HTTP, with TCP/IP filtering the user receives no notification that the site they need is blocked: it simply does not open. Validating and separating cases of blocking from ordinary failures and errors in network operation is very difficult.

Nevertheless, the researchers tried to do so. For this they used the handshake procedure. Handshake packets were tunneled through Tor with exit nodes in countries without censorship. For sites with which a connection could be established via Tor, the handshake procedure was repeated five more times in a row with a delay of about two seconds. If every attempt failed, then with a high degree of probability it was a case of deliberate filtering.

As a result, this blocking method was not detected for any of the tested Internet providers.

HTTP filtering


But HTTP filtering was detected for five of the nine providers. This method involves analyzing the contents of HTTP packets. It can be carried out with the help of those same intermediate network elements (middleboxes).

To detect HTTP filtering, the researchers created Tor circuits ending in countries without Internet censorship. Then they compared the content received in response to requests to blocked sites made from inside the country and via Tor.

One of the first tasks was to identify the moment at which the blocking occurs. For example, for some providers, after an HTTP GET request was sent, the response was an HTTP 200 OK with the TCP FIN bit set and a notification about the blocking; it is this that makes the client's browser terminate the connection with the target site. However, after this a packet from the site also arrived. In such cases it was unclear what had triggered the blocking: the client's request or the site's response.

This was determined through a simple manipulation: in the HTTP packet header of the GET request, the Host field was replaced with HOST. That was enough for the blocked site to start opening. This proves that the censors check only the client's requests, not the server's responses.

The methodology and principles of Internet blocking in Russia


First, let us briefly discuss how blocking takes place, in order to understand the full picture.

  • Federal executive authorities or a court decide to ban some information for reasons of their own.
  • They send the information to Roskomnadzor, which necessarily enters a record in the register of prohibited sites.
  • Next come some internal procedures (there are also many of them; a whole lecture could be given), as a result of which Roskomnadzor may decide to block and to add the site to the so-called "unloading", a technical file that is sent to providers.
  • Providers carry out the restriction according to this file.
  • Checking of providers, which for two years has been done automatically.


How Governments Block and Censor the Internet, Circumvention and Side Effects

It is important to understand that traffic is filtered by each provider. That is, not somewhere on cross-border routers or by a state filter, but each provider installs its own filter between the Internet and its subscribers in each of its subnets. In the diagram above, the checking device is next to the subscribers because it poses as a subscriber, and this is important.

Filtering tools


Providers can buy filtered traffic from an upstream provider. But there is a problem here: when buying traffic from an upstream provider, the buying provider cannot determine whether something is a technical problem or a block. It has no tool for this, because it receives already trimmed traffic, and this does not bode well for its business.

Or one can use:

  • special comprehensive commercial solutions;
  • freely distributed open-source solutions (at the moment there is one such project);
  • one's own homemade "kolkhoz" solution.


There is no rocket science there, and the main problems are not at all about writing the program.

There are the following implementation options.
How Governments Block and Censor the Internet, Circumvention and Side Effects

For example, you have a small 100 Gbit channel and you place the filter in-line, in the break of the link.
How Governments Block and Censor the Internet, Circumvention and Side Effects

Some mirror the traffic, but the problem with traffic mirroring is that it works, so to speak, in a race. That is, the filter tries to respond faster than the normal response, so if the filter starts to lag, there are fines (I remind you, 50-100 thousand rubles).
How Governments Block and Censor the Internet, Circumvention and Side Effects

Selective routing is when traffic to IP addresses that may include something from the "unloading" passes through a separate filter.

Unfortunately, there are no exact figures, but judging by indirect signs and tests, this is currently the most common way of filtering traffic.

Selective routing can be supplemented by aggregating the sets of IP addresses to be filtered upward. That is, not just a few addresses are blocked, but an entire /24 network goes to the filter. In addition, large providers, for example MTS, have special security services that deliberately look for risky IP blocks, which also end up being filtered.

Selective routing can also be combined with DNS query filtering.

Existing types of inspections:

  • On-site inspections (mostly by the Ministry of Internal Affairs, the FSB and the prosecutor's office) — they are rare, but they happen.
  • The AS "Revizor" (Inspector) — a favorite automated system that checks all providers.

"Revizor" sits behind the filter and fully pretends to be a subscriber. But the device itself does nothing: it receives tasks and returns answers to a certain control center, i.e. it is a kind of remote shell inside the provider's network. It works very much like RIPE Atlas.

How Governments Block and Censor the Internet, Circumvention and Side Effects

The control center of the automated system is a genuine high-load service, because there are 4 thousand telecom operators, each has more than one network, and the box has to be installed in every network. That is, not at every provider, but in every network of every provider. Accordingly, the control center has certain problems.

Problems of inspection:

  • Does "Revizor" see whether this is a filter of the provider or of the resource? Perhaps one of you found the "Revizor" database and all the sites simply serve a stub page that looks like the provider's stub.
  • The blocking indicator — for all types of blocking (HTTPS, domain, IP address), what is the sign that a resource is blocked? For example, for an IP address you have to scan ports, which is a whole problem in itself.
  • The blocking indicator for other protocols.
  • How do you check a domain by mask? Behind the asterisk there may be different IP addresses and different domains. Can a filter be placed on the whole range? And what should be checked — selectively, or should some hash be generated? I will say right away that such blocking exists in the regulations, but nobody checks it.

The blocking methodology in Belarus

The methodology of shutting down the internet looks schematically as follows. Every country has channels that lead to the outside world. In Belarus, the traffic exchange point was originally controlled by Beltelecom, an operator that is fully transparent to the state. Then the National Traffic Exchange Center (NCOT) appeared, which acts as a special service for controlling the internet. It was NCOT that purchased the hardware and software systems for analyzing transmitted packets, that is, for intercepting traffic and determining its types. Using DPI, access to particular services can be regulated.

In Belarus, the traffic exchange point becomes the bottleneck of the internet. All external channels are not only controlled by the state, but are also limited in bandwidth from the start. This is deliberate, so that traffic can be controlled; in addition, no independent players are allowed to create such traffic exchange points. Anticipating your questions, I will say that in Russia the approach to network construction is fundamentally different: it has the maximum number of traffic exchange points and many channels, and the Belarusian scenario in our country is extremely unlikely. Also, there has not been a single example of the state shutting down the internet because of particular events. During mass rallies, the internet did not work because of load, not because the authorities wanted to shut it down. We see fundamentally different approaches by states.

Since today not only the economy but the state itself depends on the internet, the shutdown in Belarus was not total. The network continued to work for a limited number of clients — law enforcement agencies, government officials and important enterprises. NCOT cut everyone else off from the network, and this was done for everyone using the IPv6 protocol; the transmitted information was also monitored. As a consequence, using VPN clients that had not been added to the blocklist made it possible to get around the imposed restrictions.

Formally, one can say that there was no physical shutdown of the network; the internet was simply severely restricted in its capabilities for most people. That is why technical means made it possible to get around these restrictions and break through to the outside.

You can see how YouTube traffic dropped for the whole of Belarus. It did not fall to zero, meaning there were people who got through to the service, but there were far fewer of them than usual.

How Governments Block and Censor the Internet, Circumvention and Side Effects

Source: transparencyreport.google.com

Roughly the same situation occurred with all the other services; there were no exceptions as such. And here it is important to understand one rule that always and everywhere holds.

With deliberate internet blocking, network connectivity suffers first of all, and transferring large volumes of data becomes almost impossible. As a consequence, for users under blocking, networks and their capabilities degrade. For example, transferring high-resolution video will be difficult, and the download will keep breaking off. Those who block the internet often use packet analysis and cut off sessions in which a noticeable amount of data is transferred; that threshold is set arbitrarily. But messages in messengers, email and similar communications cannot be blocked. The volume of data transferred is too small.

Only a total shutdown of the network can make it stop working, but this is an extreme measure that almost nobody ever takes. Everyone needs the internet, so expect that it will work, one way or another. The question is how to break through to the outside and get around the blocks.

Ways of circumventing censorship and blocking

To overcome internet censorship, users rely on accessing blocked resources through other permitted resources. Such resources include: web proxies, proxy servers, anonymous networks, and web services that translate the content of web pages given a page address (for example, Google Translate).

Web proxies

Software installed on a web server which, through a web interface, allows access to the web page addresses entered. The specified web addresses are loaded on behalf of the web server, thereby ensuring anonymity of access for internet users. Using a web proxy does not require any changes to network connection settings, which makes it usable in local networks where internet access is provided through the restrictions of a proxy server. However, almost all proxy and web proxy servers keep visitor access logs, so anonymity is not guaranteed.

Proxy server

A proxy server allows the IP addresses of one subnet to access another, using IP forwarding. In most cases a proxy server is software operating over one of the following protocols: HTTP, HTTPS, Socks 4/5, etc. This software works as an interface on one of the local ports, thereby giving local network users access to its own forwarding system. A proxy server does not always ensure anonymity and may be unavailable from other local networks.

Types of proxy servers:

  • forward proxies;
  • transparent proxies;
  • caching proxies;
  • security proxies;
  • reverse proxies.

A proxy server can be public or private. A public proxy server is available to all users of the proxy server's subnet without an authentication process, while a private proxy server is available only to certain users, most often for specified MAC addresses or after authorization with a login and password.

The Internet Archive

Almost all popular pages turn out to be saved in the Internet Archive. By adding https://web.archive.org/web/*/ to the left of a URL, you can view the saved versions.

Anonymous networks

An anonymous network is a computer network created to provide anonymity on the Internet, using the structure and technologies of the global network. Multilayer encryption and the distributed nature of anonymous networks, by eliminating a single point of failure and a single attack vector, make interception of traffic or even the compromise of some of the network's nodes a non-fatal event. As a rule, connecting to anonymous networks requires installing special software on the user's computer, but in some cases (Psiphon, Veiled) this is not required. The most common examples of such networks are the peer-to-peer Freenet and I2P (Invisible Internet Project), as well as the hybrid TOR (The Onion Router). The main drawbacks of anonymous networks are increased response time, reduced speed and growth in the volume of network traffic.

Online translators

Modern online translators, such as Google Translate, can translate the content of web pages at a specified web address. Since the web address to be translated is loaded onto the translator's web server, the user can obtain the content of a web page that is blocked inside their network. To use this method, access to the online translator's pages is required. A limitation is the impossibility of logging in on the remote web server. This method is suitable only for obtaining blocked text information.

RSS aggregators

Another way of obtaining blocked text information is RSS aggregators. Almost all major media outlets publish RSS news feeds, which can be loaded into an online RSS aggregator (see the List of RSS aggregators). Since a web aggregator loads the specified news feeds onto its own server before displaying them to the user, to get blocked media outlets you need access to this web aggregator and must know the network address of the news feed.

Email

One of the oldest ways of obtaining the content of web pages is internet gateways — "internet by email". To get the content of a blocked page, you send its web address to the email address of such a gateway. In reply, a message containing the requested web page arrives at the return address you specified. Only access to email is needed to use this service. Examples of such services: Web4W3, ERC Web-to-Email and www4mail.

Another well-known way of conducting secret email correspondence is the use of anonymous remailers.

According to the online publication Reuters, the US government is testing and plans to deploy the technology "Feed Over Email" (FOE), which will be used to deliver web content by email to countries with "harsh" internet censorship. Such countries were named as: China, Iran, Myanmar, Tajikistan, Uzbekistan and Vietnam[11].

Traffic tunneling

The method is based on building a tunnel (usually encrypted) between two networks, two computers, or a computer and a network. Tunneling usually takes place at layers 2-4 of TCP/IP. Tunneling at the third or second layer is usually called VPN, and at the 4th — "port forwarding" (usually done using SSH).

Virtual private networks (VPN)

VPN (Virtual Private Network) is a logical network that is created on top of some other network, including the Internet. A VPN provides a secure tunnel established between the user's computer and a special server. When working with a VPN, all traffic is transmitted as encrypted GRE packets, both from the user to the server and back. The server acts as a transparent proxy for all internet protocols. Thus, the IP address issued by the provider is replaced by the address of the VPN service in use. A VPN compares favorably with other ways of achieving anonymity by providing full encryption from the client to the server: when using proxy servers or SOCKS, the user is not insured against packet interception on the way from their provider to the server entrusted with their anonymity, since requests, E-Mail and Instant messaging messages travel unencrypted and all of the user's actions can be recorded in the logs of the local network or the provider. The drawbacks of a VPN are the delay on the first hop, equal to the delay between the user's computer and the VPN server, and reduced speed due to encapsulation and redundant coding. In addition, the VPN encryption algorithm may require an OS upgrade, since many operating systems support by default only 40- and 56-bit encryption, which cannot be considered reliable. Examples of anonymous VPN services include IPREDator[en] (English), Anonymizer[en] (English), LogMeIn (English), Relakks, CyberGhost, FastestVPN, Ivacy, PureVPN, as well as Hamachi[12], Hotspot Shield and dedicated OpenVPN solutions.

At present this method is not applicable in the networks of some Internet providers. In particular, owing to the exhaustion of the globally routable IPv4 address space, on 7 December 2012 the company MGTS moved some subscribers behind a NAT that does not pass packets of the GRE protocol, which makes it impossible to connect to VPN services based on this protocol[13]. However, there is also VPN over SSL, for example SSTP[en]. It is supported in Windows Vista SP1 and later, by Linux and by a number of equipment, in particular Mikrotik. wiki.mikrotik.com. Retrieved 19 July 2020..

Traffic masking

The transmitted data is altered enough that blocking DPI devices or a filtering proxy do not prevent the exchange of data with the server.

IPv6

Connecting to providers that give an IPv6 address, or using 6to4 technology, can also help, since filtering technologies are mostly designed for IPv4.

Methods of circumventing blocks

There are methods that make it possible to get around censorship. They differ in such respects as

  • difficulty of setup
  • effectiveness in circumventing censorship
  • ability to remain unnoticed while circumventing

Alternative addresses

Censors may block particular domain names using DNS interception or URL filtering. Therefore sites can sometimes be accessible through alternative links that cannot be blocked.

Some websites may offer the same content on several pages or under several domain names. For example, the Russian Wikipedia is available at https://ru.wikipedia.org/ , and its mobile version at https://ru.m.wikipedia.org/.

It is also sometimes possible to access a site directly through its IP address . Using alternative DNS servers can help get around DNS-based blocking.

Censors may block particular IP addresses. Depending on how the filtering is implemented, it may be possible to use the same IP address in a different way.[13] For example, the following URLs lead to the same page (although not all browsers recognize them): http://208.80.152.2 (dotted decimal), http://3494942722 (decimal), http: //0320.0120.0230.02 (dotted octal), http: // 0xd0509802 (hexadecimal) and http: //0xd0.0x50.0x98.0x2 (dotted hexadecimal).

Mirrors, caches and copies

Cached pages. Some search engines keep copies of previously indexed web pages in a cache. They are often stored by the search engine and cannot be blocked. For example, Google allows cached pages to be retrieved by entering "cache: some-url" as the search query.[14]

Mirrors and archive sites. Copies of websites or pages may be available on mirror sites or on archive sites, for example in the Internet Archive.

RSS aggregators, such as Feedly, make it possible to read RSS feeds that are blocked because of censorship.

Proxy servers

Web proxies. Proxy sites are set up so that users can load web pages through a proxy server. That way the page comes from the proxy server rather than from the blocked source. However, depending on how the proxy server is configured, the censor may be able to determine that the page was loaded and that a proxy was used.

For example, the mobile browser Opera Mini uses a proxy server that applies encryption and compression to speed up loading. This has a side effect: such a server can be used to get around censorship. In 2009 this led the Chinese government to ban all versions of the browser except special Chinese ones.[15]

Domain fronting. Software can use domain fronting, in which the destination of a connection is hidden by routing the initial requests through a content delivery network or another popular site.[16] This method was used by messengers including Signal and Telegram, but large cloud providers such as Amazon Web Services and Google Cloud have banned its use.[17]

Tunneling: by setting up an SSH tunnel, a user can forward all their traffic through an encrypted channel, so that both the outgoing requests to blocked sites and the responses from those sites are hidden from censors; only unreadable SSH traffic is visible.[18]

Virtual private network. By using a VPN (virtual private network), a user who wants to get around censorship can create a connection to a more liberal country and browse the Internet as if they were in that country. Some VPNs are offered for a monthly fee; others are funded by advertising. According to GlobalWebIndex, more than 400 million people use virtual private networks to get around censorship or to raise their level of privacy .

Tor: Tor routes encrypted traffic through several servers to make tracking harder. In some cases it can be used to avoid censorship.

How Governments Block and Censor the Internet, Circumvention and Side Effects
Information on how to bypass the blocking of Tor.

Traffic obfuscation

A censor can block the tools that are designed to get around censorship. Attempts are being made to make circumvention tools less noticeable to censors by randomizing traffic, by trying to imitate an unblocked connection, or by tunneling traffic through a whitelisted service using domain fronting. Tor and other circumvention tools use several methods of traffic encryption, which users can choose depending on their connection. These are sometimes called "pluggable transports".[19]

Sneakernet

Sneakernet is the transfer of computer files by physically moving storage media between computers. Sneakernet does not use a network, so it is not subject to censorship.[20] One example of a widespread sneakernet is El Paquete Semanal in Cuba.[21]

Use of circumvention tools

In response to attempts at censorship, the popularity of circumvention tools increases[22][23][24]. However, studies comparing their usage levels in countries that censor the internet show mixed results.

Use in response to constant censorship

Study results vary. In 2010 Harvard University conducted a study which showed that very few users use censorship circumvention tools (probably fewer than 3% of users) even in countries where there is censorship. Other studies reported significantly greater popularity of the tools , but were disputed.

In China, the use of circumvention tools is possibly more widespread at universities.[25][26] However, these data are unconfirmed. A survey conducted by Freedom House showed that users can, as a rule, easily use tools to get around censorship. The research firm GlobalWebIndex reported that in China there are more than 35 million Twitter users and 63 million Facebook users, although both sites are blocked. However, these estimates were disputed;[27] Facebook's advertising platform estimates that there are 1 million users in China. As for Twitter, by some estimates it is used by 10 million people[28]. Other studies indicate that bans on the use of circumvention tools led to a fall in their use. Thus, 30,000 Chinese users used to connect to the Tor network, but as of 2014 there are about 3,000 users from China on Tor.[29]

In Thailand, internet censorship has existed since 2002, and filtering is inconsistent[30]. In a survey of 229 Thai internet users, a research team from the University of Washington found that 63% of respondents had tried to use circumvention tools, and 90% had used these tools successfully. Users often made decisions about using circumvention tools based on limited or unreliable information. They noted that using circumvention tools brings threats, both abstract ones and ones based on personal experience.[11]

In response to the blocking of individual sites

In response to the blocking of Twitter in Turkey in 2014, information about DNS servers spread, since using a different DNS server, such as Google Public DNS, made it possible to use Twitter[31]. The day after the block, the total number of Twitter messages written in Turkey rose by 138% (according to the internet measurement firm Brandwatch).[22]

After the ban on the Telegram application in Iran in April 2018, the number of internet searches related to VPNs and censorship circumvention rose 48-fold for some keywords. However, users sometimes downloaded unsafe programs. A third of Iranian internet users used the Psiphon tool immediately after the block, and in June 2018 up to 3.5 million people were still using it.[23]

Anonymity, risks and trust

Censorship circumvention and anonymity are not the same thing. Circumvention systems are designed to get around blocks, but they do not provide anonymity. Anonymity-related systems protect the user's privacy. And although they can help get around censorship, this is not their main function. Proxy sites do not provide anonymity and can view and record the location of the computers sending requests, as well as the list of websites visited.

The most reliable sites for circumventing censorship are those hosted by trusted third parties who are not connected with the censors and do not collect personal data. The best are the sites of people whom the person knows personally, but often the choice can be made only on the basis of reviews on the Internet. The law may require mandatory disclosure of information to the authorities in case of suspicion.

Censorship circumvention that may lead to breaking the law

In many countries, access to blocked information is a serious crime; in particular, access to child pornography, information threatening national security, and information related to violence may be punishable by law. Therefore, people who want to get around censorship must understand exactly how a given method of protection works, and also understand that the state may hold them liable for circumventing censorship.

Human rights defenders, dissidents, protest or reform groups try to take measures to protect privacy on the Internet, but there is no guarantee that circumventing censorship will not be illegal.

Software for circumventing blocks

There are five main types of software for circumventing internet censorship:

CGI proxies use a script running on a web server to perform the functions of a proxy server. The CGI proxy client sends the requested URL to the CGI proxy server. The CGI proxy server retrieves the site's information, sends its own HTTP request to the final recipient, and then returns the result to the proxy client. For security, trust in the operator of the proxy server is necessary. CGI proxy tools do not require browser configuration or software installation, but an alternative interface must be used inside the existing browser.

HTTP proxies send HTTP requests through an intermediate proxy server. A client connecting through an HTTP proxy sends it exactly the same HTTP request as it would send to the target server without a proxy. The HTTP proxy parses the request; sends its own HTTP request to the target server; and then returns the response to the proxy client. Security is possible if there is trust in the proxy's owner. An HTTP proxy requires software or browser configuration. Once the proxy is configured, you can visit sites without changing the browser interface.

Application proxies are similar to HTTP proxies, but they support a wider range of online applications.[how exactly do they differ?]

Peer-to-peer networks store content on volunteer servers. Re-routing (re-routing) is also used, which increases the reliability of the network. A peer-to-peer system can be trusted because it depends not on a single server but on several, and the amount of content on any given server is limited.

Re-routing systems (re-routing) use several proxy servers at once for protection, so each individual proxy server does not know the full information about a request.

Personal security, smartphone searches, and how to avoid trouble

Unfortunately, we always worry about our own security only at the moment when it is too late to think about it. After all, to ensure your own security you need to take a few simple steps that require little time and minimal effort. But, of course, this involves a certain amount of strain and other user habits that deprive us of our usual comfort. Here everyone must soberly assess their own risks and what this or that situation may threaten them with.

Several people from Minsk reported that young acquaintances of theirs were stopped on the streets and had their smartphones checked, and were forced to show their Telegram and the groups the person is subscribed to. The confidentiality of private correspondence is guaranteed by the law of every country, and such demands are illegal. But you must also realize that when people in uniform with batons loom over you, you will not be quoting laws; the chance of getting hit on the head is at its maximum. And then all that is left is to pray that they do not find something that catches their attention.

When discussing security issues, I often hear the argument that you should not unlock your smartphone, and then no one will be able to get into it. The brave people who reason this way have never faced aggression in the real world, where people under the threat of a beating not only give up their passwords but show everything they have on their phone themselves. You should not consider yourself a hero; it is unnecessary. Just as heroic behavior can lead to health problems.

If you take care of your security in advance, then with a high degree of probability no one will find anything during a quick inspection of your smartphone. Unfortunately, the least protected device today is the iPhone, and this is not even about the possibilities of hacking it, but rather about the fact that by unlocking the device you hand over to strangers everything that is in it.

On Android there are a few tricks that will let you avoid the attention of those who are quickly trying to find some reason to hurt you. Most Android smartphones support creating second copies of apps; you can set up the same Telegram on a second number, where you should gather all the channels that you read and think might provoke a reaction during an inspection. You hide the icon of the second Telegram somewhere in folders and turn off notifications in the notification shade. This is not the best way to hide information, but it is enough to avoid problems during a quick inspection. You will not pass a thorough check in this case.

Samsung smartphones have a "Secure Folder," which uses the KNOX system. All the contents of this folder are encrypted; this is additional encryption. To get into the folder you need to enter a password (you can use biometrics, but you must disable it! your finger can be pressed to the sensor against your will). The advantage is that the folder can be hidden; it simply will not be in the menu. You turn off notifications from the Secure Folder, and no one will see that it exists on your phone at all. Among other interesting points, an attempt to get into the folder will lead to the contents being locked after several attempts to guess the password.

In my opinion, today the "Secure Folder" is the only way to somehow avoid questions during a search. Unlike the option above, when using KNOX you will be able to withstand even a meticulous examination of your phone.

But all of this needs to be set up in advance, and you need to make sure that you do not perceive information security as a whim. It is what is necessary in critical situations such as the one in Minsk.

Allow me a lyrical digression. I do not believe that people cannot read opposition blogs or channels; they have the right to choose sources of information without censorship, as long as those sources are not prohibited by law. Illegal searches and phone checks all cause bewilderment. Above I described how one can and should deal with this if you believe the threat of such a situation is high.

Fighting state surveillance and restoring internet access

So, a network shutdown is not total, and one can somehow break through to the outside world; the only question is how to do it. Some software has built-in tools for bypassing blocks; for example, Telegram has proven itself excellent, because over a couple of years of fighting blocks in Russia, proxy servers appeared in its settings that allow bypassing one restriction or another. In Belarus many Telegram users broke through to the outside because they gained access via proxies. Interestingly, many proxy servers were blocked quite quickly, but both the Telegram team itself and sympathizers kept setting up new proxies. In the war between the state and Telegram, the messenger won again.

But besides Telegram, there are many programs and services that fall under blocks but that you most likely need for work or communication. What should you do about them? The answer is quite simple: VPN clients, which can be installed on a computer, smartphone, or tablet. The beauty of VPN clients is that they encrypt your traffic and let you become "invisible" to those who try to monitor what you are doing. This is by no means a panacea, since such traffic can also, in theory, be broken into and the data you transmit can be accessed (for example, TOR servers are, as a rule, run by one state or another, which monitor the secrets of those who use them; such a server is an entry point where information is available and can be intercepted). But VPN clients are better than nothing; you can get access to the network at moments when someone shuts it down and pulls the plug.

You need to take care of installing a VPN client before the storm breaks. Perhaps I was lucky, as I constantly travel to China, where access to many foreign services is blocked. So I have several VPN clients; if one does not work, I use another. There are both paid services (no traffic limits, they work better) and free ones. My favorite app is ExpressVPN: many locations around the world, and it easily bypasses various blocks.

But this app cannot be considered perfect. I also fully realize that it may be used to watch me; the only question is who is doing it. This reasoning should always be applied in practice. For example, if you live in Minsk, how important is it to you that you may be watched in America? Most people would consider this threat insignificant.

For the paranoid, I can recommend using VPN services developed by independent groups, which in theory are outside the influence of any particular state. Although, most likely, their independence may turn out to be just as much of a facade. But among these services there is not a single one developed in Belarus, if we tie this to current events.

When the storm broke, the number of VPN client users in Belarus was insignificant. Most clients were either paid or failed to cope with the blocks; Psiphon performed well (its own protocol, a variety of proxies; this app can safely be called a new-generation VPN). Look at the number of connections in Psiphon from Belarus since the blocks began; the graph speaks for itself.

How Governments Block and Censor the Internet, Circumvention and Side Effects

Source: psix.ca

An analogue of Psiphon is Lantern, which is open-source software, but it was created in the USA, and many of its servers are also located in that country. How secure it is remains unclear. I think it makes sense to pay attention to NewNode, an app that promises greater security and works quite well in practice.

In my view, any modern person who worries even a little about their digital security should use a VPN. The only downside is that your smartphone will drain noticeably faster; sometimes energy consumption is almost twice as high. Using a VPN gives you extra chances not only to bypass blocks but also to hide what you do online. It is practically impossible to do this completely; assume that the network is transparent to attackers and even more so to states. The fact that no one has come for you and your friends yet means absolutely nothing.

What to do if there is no internet at all? There is an answer to that too

For those who want to communicate without the internet, there is a simple solution: apps that use Bluetooth or Wi-Fi to create a connection, in which smartphones in such a network act as access points, relaying messages from one recipient to another. A similar app was first used in Hong Kong, and since then many analogues of FireChat have appeared.

For example, you can use the Briar app.

How Governments Block and Censor the Internet, Circumvention and Side EffectsHow Governments Block and Censor the Internet, Circumvention and Side EffectsHow Governments Block and Censor the Internet, Circumvention and Side EffectsHow Governments Block and Censor the Internet, Circumvention and Side EffectsHow Governments Block and Censor the Internet, Circumvention and Side Effects

Or install Bridgefy on your phone.

How Governments Block and Censor the Internet, Circumvention and Side Effects

But you must install these apps in advance, before the network shutdown happens, otherwise you will not be able to communicate with anyone. There are many apps of this kind, and you can find the one you need. Note that you should choose apps that do not require SMS registration; this is a point of vulnerability, and tracing the registration on the operator's side will not be the slightest problem.

Side problems of blocking internet resources and traffic


It might seem that blocks simply exist. We do not like them, but perhaps there is nothing bad about them?

In fact, blocks are a tangle of problems.


Collateral damage is the biggest problem with blocks. The most striking example illustrating this occurred in April 2018, when large blocks of IP addresses of cloud services were blocked, and accordingly many services of government resources, commercial banks, or trade and logistics systems did not work and suffered heavy losses.

Volatility of regulations and practices, which change all the time. A year ago this story would have been completely different, and two years ago it would most likely have contradicted today's. A year from now everything will be different again. Today it is one way, in a month it will be slightly different, and in half a year completely different. You have to keep track of this, but you also have to keep working.

Blocks are hard to diagnose. If a resource was blocked precisely through the registry, that is the simplest case. In the cases we will consider next, it is quite difficult to distinguish a real block from technical problems. A striking example: in October Yandex's DNS was down for about five hours, and in that time many people managed to decide that it was a block by Roskomnadzor. It is indeed hard to determine for certain, and such situations have happened before, so people immediately think of a block.

It is impossible to predict when you will be blocked, or whether you will be blocked at all. You are working calmly, and then suddenly your work is over.

It is completely impossible to calculate the risks, because perhaps some widget on the site that you had already forgotten about will stop working, or perhaps your entire business will be hit. A very good example of the unpredictability of risks is the case of Bitrix24. In March they very quickly moved their services to Amazon. That same month a document leaked online, which may have been fake, listing large Amazon subnets. Nevertheless, Bitrix24 somehow reacted to it and avoided problems in April, when Amazon's services were actually blocked.

I assure you, most of you will not be so lucky! Such documents will not leak into your hands by happy chance. When your business ends, you will find out about it after the fact.

In simple cases it is known why your site was blocked. For example, information was posted on a forum that some court had ruled prohibited, and you did not manage to react in time. But communication with the supervisory authority has unacceptable turnaround times, for example a day. On the internet, in that time you can lose a fifth of your business.

All this leads to a certain sense of hopelessness. One can ironically reflect on, for example, David Komak and the blocking of Lurkmore. But it is quite another matter when it happens to you, as it once happened to me. A client had pointed the IP addresses of my servers at a domain that I did not control: I sit there and the phone simply does not stop ringing. Clients say they are leaving and demand refunds, and I can do nothing! And no one can help me with it. It is truly a feeling of complete hopelessness.

Conclusion


Often specific internet providers do not carry out site blocking themselves but rely in this respect on the providers that manage "neighboring" networks. In the experiment considered, several internet service providers were never observed using blocks of their own, yet the sites blocked in the country could just as well fail to open for their users.

Only one person is responsible for your life and health: you yourself. Many people consider digital security something that can be neglected. But as you can see from the example of Belarus, it is something worth taking care of in advance. And the question is not even that you will lose your usual means of communication or entertainment services. It may be a question of your health or freedom. Take care of yourself and your loved ones, try to be a modern person and pay attention to keeping your information protected: on your smartphone, computer, and other devices. Gadgets are already an integral part of a modern person's life, and their security is a necessity; it is time to think about this and take minimal measures to protect yourself. All the more so since it is not that difficult, and often you need to spend only about ten minutes setting up everything you need.

Unfortunately, the statistics are relentless, and they show that most people do not use VPN clients. Many deny the need to protect their data altogether (in the post-Soviet space there is a rampant spread of viruses, botnets, and other vermin, a consequence of carelessness). Do not be a statistic that demonstrates carelessness toward your own and others' data. Below are a couple of links that will help you protect your data and devices.

See also

  • deniable encryption
  • proxy server
  • VPN
  • DPI
  • Internet
  • Anonymous P2P
  • Content filter
  • Tracking software
  • Cypherpunk
  • Crypto-anarchism
  • Electronic Frontier Foundation
  • Internet privacy
  • Mesh topology
  • Tor
  • Anonymity application
  • Anonymous remailer
  • Anonymous web browsing
  • Comparison of file-sharing applications
  • Dark web
  • Data privacy
  • Internet privacy
  • List of anonymously published works
  • Personally identifiable information
  • Privacy-enhancing technologies and software protection
  • FLAIM
  • I2P
  • I2P-Bote
  • Java Anon Proxy
  • Free Haven Project
  • Tor-ramdisk
  • Secure communication
  • Crypto-anarchism
  • Cypherpunk
  • Digital divide
  • Mesh network
  • Wireless community network
  • [[b11622]]

продолжение следует...

Продолжение:


Часть 1 How Governments Block and Censor the Internet, Circumvention and Side Effects

See also

created: 2020-11-22
updated: 2026-09-29
250



Was this answer useful?
Choose a quick rating so we can improve the next answer for you.
How satisfied are you?


Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Information security, Malicious, and information security"

Terms: Information security, Malicious, and information security