Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Wikipedia censorship 'easy to evade'

Tom Espiner ZDNet.co.uk

Published: 11 Dec 2008 17:39 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The blocking mechanism used to censor Wikipedia has been described as "fragile" and "easy to evade" by Cambridge University security expert Richard Clayton.

Access to Wikipedia was restricted between 5 and 9 December after child-abuse watchdog the Internet Watch Foundation (IWF) recommended that ISPs block two Wikipedia pages. The pages contain an image of the 1978 Virgin Killer album cover by German rock band the Scorpions, which shows a naked girl.

According to Wikipedia, the UK ISPs which enforce the IWF list include Be, BT, Demon, Eclipse, Orange, PlusNet, Sky Broadband, T-Mobile, TalkTalk, Telefonica O2, Tesco.net, and UK online. However, Clayton said there was "some confusion" as to which operators had blocked access to the Wikipedia page. Virgin Media, Plusnet, and Be Broadband all made statements this week saying they had blocked the site.

VIDEO

Dialogue Box
Dialogue Box 6.8: Top tech trumps

What are likely to be the most important tech stories over the next few months? Rupert and Charles discuss the contenders

View full video+

However, much of the blocking was ineffectual, wrote Clayton in a blog post on Thursday, due to case sensitivity. Whereas the IWF had recommended that a URL ending in 'virgin_killer' be blocked, the two Wikipedia pages that the ISPs attempted to censor were listed as "Virgin_Killer" and "Virgin_killer". At ISPs where the URL matching was case sensitive, the pages were not blocked.

Users could also unintentionally circumvent the blocking mechanism if they used their own DNS server or a remote proxy mechanism, Clayton added. They could then report that they could see the page, further "muddying the waters", Clayton said. Further confusion was caused over whether ISPs showing 404 error pages were blocking the pages deliberately, or whether the error messages were being returned for another reason.

Clayton said ISPs don't block entire websites, but instead pass the traffic to suspect sites through a web proxy. The proxy checks the web request and blocks specific URLs that are on the IWF list.

However, as part of its policy to prevent vandalism on the site, Wikipedia blocks large numbers of requests from limited IP addresses. The use of proxies meant that all Wikipedia visitors using major ISPs appeared to have "one of a handful" of IP addresses, and so were blocked from editing.

Clayton said it is unknown why the IWF chose to block the web page URLs instead of the image URLs. However, future attempts at blocking images would probably be ineffectual, wrote Clayton.

"The bottom line is that these blocking systems are fragile [and] easy to evade (even unintentionally)," wrote Clayton.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
4 out of 4 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters