Discover Asia


The Butterfly Effect Part II: Inside the Chinese Firewall

This is the second part of my series on thefailure, but foreign networks and servers
Internet in China. I recently returned fromoutside of China blindly blocking larger
a year teaching at a Chinese University.parts of China's networks from connecting.
During my time in China, I had the pleasureThis included one incident that basically
of getting to know the state of the Internetcutoff service from China to most of Europe
in China, both directly and indirectly,and the United States.An often overlooked
through my own use of the Internet and theaspect of our fight against Spam and
classes. In my last article, The Butterflymalicious activity is our own contribution to
Effect Part I: Microsoft, Security, and thecensoring the Internet in China (also by
Developing World, I dealt with the effect ofextension other developing nations). What
pirated software and security and its impactseems to have been missed is how we, as
on development. In this article, I would likesystems administrators and security
to cover my experience of the Chineseprofessionals, also are contributing to the
Firewall from the inside and the way wegreat  firewall  of  China.
contribute to censorship in China.Scanning
Chinese networks the old fashion way with
nmap or similar tools struck me as a bit
impolite and potentially illegal. Being onHere is how it works for those unfamiliar
the other side of the wall, I was not goingwith the process: Millions of unlicensed,
to push my luck too much. However, part of myunsecured, and unpatched Microsoft desktops
teaching duties involved several classes onacross China are turned into zombies networks
research writing and basic computer skills.by the bad guys. Those bot/zombie networks
This gave me access to a very effectiveattack servers with Spam and malicious
network testing tool. Basically, severalactivity outside of China. Systems
hundred average Chinese University students.administrators around the world cutoff
To get an idea of what the average Chinesetraffic to their network by blocking large
experience of the outside Internet world wasblocks of IP addresses in mainland China. The
like, I could simply assign my students toaverage user inside China attempts to connect
retrieve various information from theto websites outside China on those networks
Internet and wait for their reports. Forand fails. This failure to connect, both
example, if a site was not reachable frominside and outside China, is then attributed
inside China, I would be quickly inundated byto the government sensors and the mystic of
emails and questions from panic strickenthe firewall is reinforced. The effect is
students trying to complete their homeworkthat the Chinese firewall, if only in part
assignments.My total number of students wasand inadvertently, is being reinforced by
well over a 1,000 for the length of theWestern democratic countries and companies
school year. I could also add to this all theprotecting their systems from China's
miscellaneous students, staff, and publicinfected computers.Granted, that this is a
seminars where I simply referred them to myvery effective method of protecting networks.
teaching website (hosted outside of China).However, it would seem rather hypocritical of
That would bring the number to something likeus to cheer for Open Source, the free flow of
2,000 people. About 100-200 in any given weekinformation, and criticize the Chinese
where engaged in some sort of InternetGovernments actions; while at the same time,
related project for my classes. My own modestwith a couple dozen key strokes, we restrict
teaching site received a little over 5,000millions of people from accessing information
hits in my time in China. So, through mythey so desperately need to further their
classes at the University and other schoolsdevelopment. Yes, we need to, and should,
in Eastern-Central China, I was able to run acutoff the spam and bot nets from the
sort of ongoing distributed human scan ofInternet; however, it needs to be done with
Internet connectivity in China.My informalmore of a scalpel and less of a
survey  results:howitzer.Overall, the restrictions on the
Internet in China are first and foremost a
Of course there is always a few studentsfunction of networks that are overwhelmed by
that would, for one reason or another, besuch a rapidly growing user base. One
incapable of connecting; however, when a siteestimate puts the NEW Internet users in China
could not be accessed at all, I would see myat over 10,000,000 people a month. Even this
student red flag go up quickly. Normally,is perhaps a low figure. Many of my own
within about 24 hours of giving an assignmentstudents never used the Internet until they
it would be obvious that something was wrong.came to the University. In addition,
thousands of inexperienced systems
administrators struggle to manage computer
systems built and documented for the English
My own Internet connection provided to me byspeaking community. Secondly, the
the University, as far as I could tell,restrictions on the free flow of information
seemed completely unadulterated andare a function of the network security
functioned as it would in any Westernenvironment in China. Millions of compromised
country. This included access to many newscomputers attacking networks inside and
sites in Taiwan and Japan. For example, Ioutside China, and our inevitable security
could access the Gutenberg library, but myresponse to them. Finally, I would list the
students could not. News sites such as BBC,real efforts of the authorities to restrict
and occasionally CNN, were completelyinformation. The reality is, China simply
unaccessible by me or the students. Thedoes not have the computing power and
Google search engine seemed to do someexpertise to effectively regulate all of the
strange things. Both my students and I weretraffic on the Internet. The volume of white
able to download, and watch live, the entirenoise alone insures this fact. The most
U.S. presidential debate on C-span's website.effective control methods the authorities
Later, we were able to download thehave is the simple psychological intimidation
transcripts in both English and Chinese;associated with showing an ID to use a
including the segments where Bush directlycomputer in a public Internet cafe. I might
criticized China. These were the sameremind the reader that using a computer in a
transcripts and video that I later used topublic libraries in the United States also
teach  debate  class  at  the  University.has similar conditions attached.There are
very real controls on the flow of information
in China. What needs to be understood is the
practical reality for millions of Chinese to
On my own Linux computer, I had no problemsaccess information is far less terrible than
connecting to bank websites in New York withwhat it is made out to be in Western Press,
128 bit SSL; or connecting by SSH toat least on a Political level. Increasingly
computers in the United States and SouthChina is becoming more politically open, if
America. I also frequently used Skype tofor no other reason than it is a prerequisite
make encrypted phone calls to friends andfor a market economy to function correctly.
family around the world; Granted, the qualityThis will take time. However, on a technical
of the connection was at times so poor as tolevel, the restrictions are far worse than
be unusable. This I would take to be more anwhat is recognized outside of China. Because,
issue of distance and network quality thanin the final analysis, not being able to
censorship. Bittorent and FTP functionedconnect is as bad as not being allowed to
normally, including Linux sites hosted inconnect. Charles Spencer in the founder and
Taiwan and the United States.The mostof Spencer Global International Consulting
surprising source of censorship inwith members in more than 10 countries in
China:There were several instances where theNorth and South America, Europe, and Asia.
red flag on my human Internet scanner went upSpencer is also editor and Chief designer of
to an unusual high level. Students reportedAll Southern Chile ( a development project of
100% failure. After investigating theSpencer Global International Consulting to
problem, I discovered that it was not apromote the South of Chile in English to the
firewall restriction or China's own networkWorld.



1 A B C D E 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129