The Butterfly Effect Part II: Inside the Chinese Firewall

This is the second part of my series on the InternetChina blindly blocking larger parts of China's networks
in China. I recently returned from a year teaching atfrom connecting. This included one incident that
a Chinese University. During my time in China, I hadbasically cutoff service from China to most of Europe
the pleasure of getting to know the state of theand the United States.An often overlooked aspect of
Internet in China, both directly and indirectly, throughour fight against Spam and malicious activity is our
my own use of the Internet and the classes. In myown contribution to censoring the Internet in China
last article, The Butterfly Effect Part I: Microsoft,(also by extension other developing nations). What
Security, and the Developing World, I dealt with theseems to have been missed is how we, as systems
effect of pirated software and security and itsadministrators and security professionals, also are
impact on development. In this article, I would like tocontributing to the great firewall of China.
cover my experience of the Chinese Firewall from
the inside and the way we contribute to censorship inHere is how it works for those unfamiliar with the
China.Scanning Chinese networks the old fashion wayprocess: Millions of unlicensed, unsecured, and
with nmap or similar tools struck me as a bit impoliteunpatched Microsoft desktops across China are
and potentially illegal. Being on the other side of theturned into zombies networks by the bad guys.
wall, I was not going to push my luck too much.Those bot/zombie networks attack servers with
However, part of my teaching duties involved severalSpam and malicious activity outside of China. Systems
classes on research writing and basic computer skills.administrators around the world cutoff traffic to their
This gave me access to a very effective networknetwork by blocking large blocks of IP addresses in
testing tool. Basically, several hundred averagemainland China. The average user inside China
Chinese University students. To get an idea of whatattempts to connect to websites outside China on
the average Chinese experience of the outsidethose networks and fails. This failure to connect,
Internet world was like, I could simply assign myboth inside and outside China, is then attributed to
students to retrieve various information from thethe government sensors and the mystic of the
Internet and wait for their reports. For example, if afirewall is reinforced. The effect is that the Chinese
site was not reachable from inside China, I would befirewall, if only in part and inadvertently, is being
quickly inundated by emails and questions from panicreinforced by Western democratic countries and
stricken students trying to complete their homeworkcompanies protecting their systems from China's
assignments.My total number of students was wellinfected computers.Granted, that this is a very
over a 1,000 for the length of the school year. Ieffective method of protecting networks. However,
could also add to this all the miscellaneous students,it would seem rather hypocritical of us to cheer for
staff, and public seminars where I simply referredOpen Source, the free flow of information, and
them to my teaching website (hosted outside ofcriticize the Chinese Governments actions; while at
China). That would bring the number to something likethe same time, with a couple dozen key strokes, we
2,000 people. About 100-200 in any given weekrestrict millions of people from accessing information
where engaged in some sort of Internet relatedthey so desperately need to further their
project for my classes. My own modest teaching sitedevelopment. Yes, we need to, and should, cutoff
received a little over 5,000 hits in my time in China.the spam and bot nets from the Internet; however,
So, through my classes at the University and otherit needs to be done with more of a scalpel and less
schools in Eastern-Central China, I was able to run aof a howitzer.Overall, the restrictions on the Internet
sort of ongoing distributed human scan of Internetin China are first and foremost a function of
connectivity in China.My informal survey results:networks that are overwhelmed by such a rapidly
Of course there is always a few students thatgrowing user base. One estimate puts the NEW
would, for one reason or another, be incapable ofInternet users in China at over 10,000,000 people a
connecting; however, when a site could not bemonth. Even this is perhaps a low figure. Many of my
accessed at all, I would see my student red flag goown students never used the Internet until they
up quickly. Normally, within about 24 hours of givingcame to the University. In addition, thousands of
an assignment it would be obvious that somethinginexperienced systems administrators struggle to
was wrong.manage computer systems built and documented for
the English speaking community. Secondly, the
My own Internet connection provided to me by therestrictions on the free flow of information are a
University, as far as I could tell, seemed completelyfunction of the network security environment in
unadulterated and functioned as it would in anyChina. Millions of compromised computers attacking
Western country. This included access to many newsnetworks inside and outside China, and our inevitable
sites in Taiwan and Japan. For example, I couldsecurity response to them. Finally, I would list the real
access the Gutenberg library, but my students couldefforts of the authorities to restrict information. The
not. News sites such as BBC, and occasionally CNN,reality is, China simply does not have the computing
were completely unaccessible by me or the students.power and expertise to effectively regulate all of the
The Google search engine seemed to do sometraffic on the Internet. The volume of white noise
strange things. Both my students and I were able toalone insures this fact. The most effective control
download, and watch live, the entire U.S. presidentialmethods the authorities have is the simple
debate on C-span's website. Later, we were able topsychological intimidation associated with showing an
download the transcripts in both English and Chinese;ID to use a computer in a public Internet cafe. I
including the segments where Bush directly criticizedmight remind the reader that using a computer in a
China. These were the same transcripts and videopublic libraries in the United States also has similar
that I later used to teach debate class at theconditions attached.There are very real controls on
University.the flow of information in China. What needs to be
understood is the practical reality for millions of
On my own Linux computer, I had no problemsChinese to access information is far less terrible than
connecting to bank websites in New York with 128what it is made out to be in Western Press, at least
bit SSL; or connecting by SSH to computers in theon a Political level. Increasingly China is becoming more
United States and South America. I also frequentlypolitically open, if for no other reason than it is a
used Skype to make encrypted phone calls to friendsprerequisite for a market economy to function
and family around the world; Granted, the quality ofcorrectly. This will take time. However, on a technical
the connection was at times so poor as to belevel, the restrictions are far worse than what is
unusable. This I would take to be more an issue ofrecognized outside of China. Because, in the final
distance and network quality than censorship.analysis, not being able to connect is as bad as not
Bittorent and FTP functioned normally, including Linuxbeing allowed to connect. Charles Spencer in the
sites hosted in Taiwan and the United States.Thefounder and of Spencer Global International
most surprising source of censorship in China:ThereConsulting with members in more than 10 countries in
were several instances where the red flag on myNorth and South America, Europe, and Asia. Spencer
human Internet scanner went up to an unusual highis also editor and Chief designer of All Southern Chile
level. Students reported 100% failure. After( a development project of Spencer Global
investigating the problem, I discovered that it wasInternational Consulting to promote the South of
not a firewall restriction or China's own networkChile in English to the World.
failure, but foreign networks and servers outside of