<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://opennet.net" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>All Content Related to Circumvention</title>
 <link>http://opennet.net/topics/circumvention</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Global Voices blogpost: Flickr users vs. The State</title>
 <link>http://opennet.net/blog/2007/02/global-voices-blogpost-flickr-users-vs-the-state</link>
 <description>&lt;p&gt;Blogger and &lt;a href=&quot;http://www.globalvoicesonline.org/&quot;&gt;Global Voices&lt;/a&gt; contributor &lt;a href=&quot;http://www.globalvoicesonline.org/2007/02/14/access-flickr-iran/&quot;&gt;Sami Ben Gharbia chats with Iranian Hamed Saber&lt;/a&gt; about his innovative method for bypassing the ban on &lt;a href=&quot;http://www.flickr.com/&quot;&gt;Flickr.com&lt;/a&gt; -- a popular photo-archive website site blocked in Iran and the UAE.&lt;/p&gt;
</description>
 <comments>http://opennet.net/blog/2007/02/global-voices-blogpost-flickr-users-vs-the-state#comments</comments>
 <category domain="http://opennet.net/topics/circumvention">Circumvention</category>
 <category domain="http://opennet.net/country/iran">Iran</category>
 <category domain="http://opennet.net/regions/mena">Middle East and North Africa (MENA)</category>
 <pubDate>Thu, 15 Feb 2007 16:49:14 -0500</pubDate>
 <dc:creator>nart</dc:creator>
 <guid isPermaLink="false">561 at http://opennet.net</guid>
</item>
<item>
 <title>Psiphon to offer way around Web censorship</title>
 <link>http://opennet.net/blog/2006/11/psiphon-offer-way-around-web-censorship</link>
 <description>&lt;p&gt;On December 1 the University of Toronto&#039;s &lt;a href=&quot;http://www.citizenlab.org/&quot;&gt;Citizen Lab&lt;/a&gt; will release &lt;a href=&quot;http://psiphon.civisec.org/&quot;&gt;psiphon&lt;/a&gt; -- free software that will enable Internet users around the world to circumvent government censorship of the Web.  Read NY Times &lt;a href=&quot;http://www.nytimes.com/2006/11/27/technology/27censorship.html?_r=1&amp;amp;oref=slogin&quot;&gt;article&lt;/a&gt;.&lt;/p&gt;
</description>
 <comments>http://opennet.net/blog/2006/11/psiphon-offer-way-around-web-censorship#comments</comments>
 <category domain="http://opennet.net/topics/circumvention">Circumvention</category>
 <pubDate>Wed, 29 Nov 2006 17:14:24 -0500</pubDate>
 <dc:creator>nart</dc:creator>
 <guid isPermaLink="false">537 at http://opennet.net</guid>
</item>
<item>
 <title>Unintended Risks and Consequences of Circumvention Technologies: The IBB&#039;s  Anonymizer Service in Iran</title>
 <link>http://opennet.net/advisories/001</link>
 <description>&lt;p&gt;Advisory 001&lt;br /&gt;
Last modified: May 5, 2004&lt;/p&gt;
&lt;h2&gt;I. Executive Summary&lt;/h2&gt;
&lt;p&gt;Internet access in Iran is subject to official censorship. Iranian authorities&#039; guidelines for ISPs and users reportedly warn them to avoid all content seen  as being in breach of social and cultural norms.[&lt;a href=&quot;#n1&quot;&gt;1&lt;/a&gt;] In practice, the filtering of Iranian ISPs extends to cover political as well as pornographic web sites.[&lt;a href=&quot;#iran&quot;&gt;2&lt;/a&gt;] In September 2003, the U.S. &lt;a href=&quot;http://www.ibb.gov/&quot;&gt;International  Broadcasting Bureau&lt;/a&gt; (IBB) sponsored the launch of a service through &lt;a href=&quot;http://www.anonymizer.com&quot;&gt;Anonymizer&lt;/a&gt;,  Inc., designed to allow Iranian Internet users to bypass much of Iran&#039;s national  filtering regime. Throughout this report we refer to the service as the &quot;IBB  Anonymizer&quot; to emphasize that it is distinct from the general services offered  to the public by Anonymizer, Inc.[&lt;a href=&quot;#ibb&quot;&gt;3&lt;/a&gt;]&lt;/p&gt;
&lt;p&gt;In December 2003 and April 2004, we ran a series of tests to gauge the accessibility  of sites through the IBB Anonymizer service. We found that many web sites blocked  by Iranian ISPs could be successfully accessed through the IBB Anonymizer service.  However, filters built in to the IBB Anonymizer service, intended to prevent  Iranians from using it to view pornographic sites, also have the unintended  consequence of blocking access to numerous non-pornographic pages and sites.  At fault appears to be the IBB Anonymizer&#039;s unreleased list of automated &quot;trigger&quot;  keywords applied to domain names before any pages are shown to IBB Anonymizer  users. These &quot;trigger&quot; keywords appear to generate a significant number of false-positive  results, resulting in a significant amount of collateral blocking -- &amp;quot;overblocking&amp;quot;  -- of non-pornographic sites. For example, the IBB Anonymizer service blocks  non-pornographic websites dealing with women&#039;s health issues because the keyword  &quot;breast&quot; is within their domain names. Likewise blocked is the anchor page for links to the U.S. Department of State&#039;s overseas missions -- &lt;a href=&quot;http://usembassy.state.gov/&quot;&gt;usembassy.state.gov&lt;/a&gt;  -- because it contains the trigger keyword &quot;ass.&quot; The service also blocks almost  any site containing the word &quot;asian&quot; in the domain. Some of these apparently  unintentionally blocked sites are themselves blocked within Iran, resulting  in a situation where sites are effectively doubly blocked --by Iranian ISPs &lt;i&gt;and&lt;/i&gt;  by the IBB Anonymizer service. &lt;/p&gt;
&lt;p&gt;The IBB and Anonymizer Inc. confirmed in separate e-mail exchanges with ONI  researchers that the circumvention service is explicitly configured to block  pornography.[&lt;a href=&quot;#note&quot;&gt;4&lt;/a&gt;] They explained that this is intended to  conserve available bandwidth and ensure availability of the service to Iranians  who wish to visit non-pornographic sites. Several notable &lt;a href=&quot;#studies&quot;&gt;studies&lt;/a&gt;  have pointed out the difficulty of implementing keyword-based filtering systems  in such a way as to avoid the unintended consequence of &quot;collaterally blocking&quot;  non-pornographic sites. The keyword rules that drive the filters built in to  the IBB Anonymizer service are not publicly known, making independent assessment  of those rules and their implications more difficult. (Staff at Anonymizer,  Inc., have declined to publicly disclose keywords or methods, considering them  to be proprietary to the company.)&lt;/p&gt;
&lt;p&gt;Further, despite IBB Anonymizer assurances that its Iranian users may surf  the Web freely and safely, our testing suggests that the vast majority of its  traffic is exposed to monitoring by Iranian authorities and corresponding local  ISPs. Iranian users may not be aware that their use of the service may identify  them to Iranian government authorities as citizens wishing to view forbidden  content, or as supportive of the ideas found within that content. &lt;/p&gt;
&lt;h4&gt;Examples of filtered web sites&lt;/h4&gt;
&lt;p&gt;The following list contains examples of non-pornographic web sites filtered  on the IBB Anonymizer service, apparently because their domains contain banned  keywords; a lengthier list of apparent overblockages is reproduced further below.  Filtered web sites include those having to do with women&#039;s health issues, the  President of the United States, a variety of NGO&#039;s, and popular hotel, email,  and other commercial services. In addition, it appears that &lt;i&gt;all&lt;/i&gt; domains  registered in Malaysia (.my) and Tuvalu (.tv, popular domain suffix for television-related  material) are blocked. &lt;/p&gt;
&lt;table border=1 cellpadding=2&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;silver&#039;&gt;Banned Keywords&lt;/td&gt;
&lt;td bgcolor=&#039;silver&#039;&gt;Inadvertently Blocked Websites&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;ass&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://usembassy.state.gov&quot;&gt;http://usembassy.state.gov&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.chass.utoronto.ca&quot;&gt;http://www.chass.utoronto.ca&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.grass-roots.org&quot;&gt;http://www.grass-roots.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;breast&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.breastcancer.com&quot;&gt;http://www.breastcancer.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://breastfeed.com&quot;&gt;http://breastfeed.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.breastcancer-answers.com&quot;&gt;http://www.breastcancer-answers.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;bush&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.georgebush.com&quot;&gt;http://www.georgebush.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.georgewbush.com&quot;&gt;http://www.georgewbush.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.bushwatch.com&quot;&gt;http://www.bushwatch.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;gay&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.gay.com&quot;&gt;http://www.gay.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.gaymiddleeast.com&quot;&gt;http://www.gaymiddleeast.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.365gay.com&quot;&gt;http://www.365gay.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;hot&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.hotmail.com&quot;&gt;http://www.hotmail.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.hotels.com&quot;&gt;http://www.hotels.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://hotwired.wired.com&quot;&gt;http://hotwired.wired.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;my&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://my.msn.com&quot;&gt;http://my.msn.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://my.ca.gov&quot;&gt;http://my.ca.gov&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.kln.gov.my&quot;&gt;http://www.kln.gov.my&lt;/a&gt;    * All &lt;a href=&quot;http://www.mynic.net/&quot;&gt;.my&lt;/a&gt; domain suffixes are blocked&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;old&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.arnold-schwarzenegger.com&quot;&gt;http://www.arnold-schwarzenegger.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.arnold.af.mil&quot;&gt;http://www.arnold.af.mil&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.gold.ahrq.gov&quot;&gt;http://www.gold.ahrq.gov&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;pic&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.pic.int&quot;&gt;http://www.pic.int&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.epic.org&quot;&gt;http://www.epic.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.epic.noaa.gov&quot;&gt;http://www.epic.noaa.gov&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;soft&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.microsoft.com&quot;&gt;http://www.microsoft.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.edu-software.com&quot;&gt;http://www.edu-software.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://software.linux.com&quot;&gt;http://software.linux.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;teen&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://teens.drugabuse.gov&quot;&gt;http://teens.drugabuse.gov&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.teenpregnancy.org&quot;&gt;http://www.teenpregnancy.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://parentingteens.about.com&quot;&gt;http://parentingteens.about.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;trans&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.transparency.org&quot;&gt;http://www.transparency.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.trans-health.com&quot;&gt;http://www.trans-health.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.transnational.com&quot;&gt;http://www.transnational.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td rowspan=3 bgcolor=&#039;#eeeeee&#039; align=center&gt;tv&lt;/td&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.tvguide.com&quot;&gt;http://www.tvguide.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.tv.cbc.ca&quot;&gt;http://www.tv.cbc.ca&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td bgcolor=&#039;white&#039;&gt;&lt;a href=&quot;http://www.emmys.tv&quot;&gt;http://www.emmys.tv&lt;/a&gt;    * All &lt;a href=&quot;http://www.tv&quot;&gt;.tv&lt;/a&gt; domain suffixes are blocked&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h2&gt;II. The IBB Anonymizer Service&lt;/h2&gt;
&lt;p&gt;In response to the recent implementation of Internet content filtering in Iran, the United States, through its federally chartered International Broadcasting  Bureau, contracted with Anonymizer, Inc. to provide what is known as &quot;circumvention  technology&quot; and services to Iranian citizens. &lt;a href=&quot;http://opennetinitiative.net/modules.php?op=modload&amp;amp;name=Archive&amp;amp;file=index&amp;amp;req=listarticles&amp;amp;secid=3&quot;&gt;Circumvention technologies&lt;/a&gt; assist Internet users in bypassing content filtering and surveillance  in areas where such practices exist.&lt;/p&gt;
&lt;p&gt;Anonymizer, Inc.&#039;s flagship public &lt;a href=&quot;http://www.anonymizer.com/anonymizer2004/1.0/&quot;&gt;Anonymizer&lt;/a&gt;  service is often adopted for filtering circumvention purposes. While offered  primarily as a service allowing Internet users to visit web sites without disclosing  any potentially identifying information to those operating the site, the basic  Anonymizer technology can also prove useful to those seeking to circumvent certain  kinds of web filtering. Anonymizer works by serving as an intermediary between  the user and the user&#039;s desired web site -- a so-called &amp;quot;web proxy service.&amp;quot;  By acting as a proxy, only Anonymizer knows a user&#039;s IP address -- the visited  site views the visit as coming from Anonymizer&#039;s servers rather than the user,  and Anonymizer relays what it views on the site back to the requesting user.  Thus, users prevented from accessing Internet content directly on a site can  seek to connect to the Anonymizer service, which retrieves and relays the content  instead. (For this reason, filtering regimes often filter access to Anonymizer  itself.) &lt;/p&gt;
&lt;p&gt;The IBB Anonymizer service is a modified version of the Anonymizer service  offered solely to Iranian Internet users, in conjunction with the Voice of America&#039;s  (VOA) Persian Service and Radio Farda. It appears to be materially &lt;i&gt;less&lt;/i&gt;  secure than the fee-charging Anonymizer services offered to the public at large  -- its &lt;a href=&quot;http://www.anonymizer.com/levels.shtml&quot;&gt;paid encrypted service&lt;/a&gt;  and &lt;a href=&quot;http://anonymizer.com/services/ssh.shtml&quot;&gt;SSH tunneling service&lt;/a&gt;.  Operators of web sites visited by users of the IBB Anonymizer will still see  the visits as coming from Anonymizer&#039;s servers rather than somewhere in Iran,  but the traffic between IBB Anonymizer and its Iranian users is apparently itself  exposed to network monitoring by Iranian ISPs.&lt;/p&gt;
&lt;p&gt;Users that IBB Anonymizer determines to be outside of Iran are unable to access  the service. For those who are found to be within Iran, the service is freely  accessible through several domain names. As soon as the Iranian authorities  block one of the service&#039;s domain names or IP addresses, new locations are announced  to Iranians through Radio Farda and VOA Persian Radio broadcasts. (Some of these  domain names are filtered by some ISPs in Iran and thus inaccessible to users, however even the filtered domains can be accessed by directly entering the IP address.) [&lt;a href=&quot;#ip&quot;&gt;5&lt;/a&gt;] As has been &lt;a href=&quot;http://www.securityfocus.com/news/6807&quot; target=&quot;_new&quot;&gt;reported elsewhere&lt;/a&gt;, pornography filters are present on the IBB Anonymizer service  to prevent Iranians from using the service to retrieve pornographic content. &lt;/p&gt;
&lt;p&gt;After media reports indicating that the IBB had procured the services of Anonymizer  Inc. to develop and deploy circumvention technology for Iranian Internet users,  and that the service was configured with pornography filters, we connected to  the IBB Anonymizer services through remote computers located in Iran and sought  to determine how well the system worked, and what sorts of sites the system  itself filtered. &lt;/p&gt;
&lt;h4&gt;A. How the IBB Anonymizer works&lt;/h4&gt;
&lt;p&gt;1. When accessing the IBB Anonymizer, users are presented with a web form into which URL&#039;s can be entered:&lt;br /&gt;
&lt;a href=&quot;/sites/opennet.net/files/sedayema1.png&quot;&gt;&lt;img src=&quot;/sites/opennet.net/files/sedayema1.png&quot; border=&quot;0&quot; width=”500”&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2. The requested URL is obfuscated within the user&#039;s browser, but not formally encrypted, by converting the ASCII text to hexadecimal using JavaScript.&lt;br /&gt;
In this case, &lt;a href=&quot;http://www.radiofarda.com/&quot; title=&quot;http://www.radiofarda.com/&quot;&gt;http://www.radiofarda.com/&lt;/a&gt; becomes...&lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
687474703a2f2f7777772e726164696f66617264612e636f6d2f
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;a href=&quot;=&quot;/sites/opennet.net/files/sedayema2.png&quot;&gt;&lt;img src=&quot;/sites/opennet.net/files/sedayema2.png&quot; border=&quot;0&quot; width=”500”&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The conversion of ASCII text to hexadecimal might render the submission of  the requested URL to the IBB Anonymizer more subtle -- since URL keyword scanning  by the Iranian authorities, if present, would possibly expect plain text rather  than hexadecimal -- but it would be an easy technical adjustment for anyone  surveilling the exchange to convert hexadecimally encoded URLs back into ASCII.  Thus it&#039;s not clear why URL obfuscation takes place at all.&lt;/p&gt;
&lt;p&gt;3. The request is transported over HTTP, using POST, to a CGI script that processes and redirects the request. &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
POST &lt;a href=&quot;http://sedayema.com/jump.cgi&quot; title=&quot;http://sedayema.com/jump.cgi&quot;&gt;http://sedayema.com/jump.cgi&lt;/a&gt; HTTP/1.1

url=687474703a2f2f7777772e726164696f66617264612e636f6d2f&amp;k=&amp;manual=yes&amp;onclick%3D%27xorValue%28document.menu.url.value%2Cdocument.menu.k.value%29%27=%D8%A7%D8%AC%D8%B1%D8%A7

Location: &lt;a href=&quot;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e726164696f66617264612e636f6d2f&quot; title=&quot;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e726164696f66617264612e636f6d2f&quot;&gt;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e...&lt;/a&gt;
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;After setting some preferences via a cookie, the request is then redirected once&lt;br /&gt;
again.&lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
Location: &lt;a href=&quot;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e726164696f66617264612e636f6d2f&amp;amp;go=go&quot; title=&quot;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e726164696f66617264612e636f6d2f&amp;amp;go=go&quot;&gt;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e72...&lt;/a&gt;
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The requested URL is then &lt;a href=&quot;http://anonymizer.com/docs/faqs/url_encryption.shtml&quot;&gt;encrypted&lt;/a&gt; using the &lt;a href=&quot;http://www.schneier.com/blowfish.html&quot;&gt;Blowfish&lt;/a&gt; algorithm, redirected once again where a GET request is issued for the URL. &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
Location: &lt;a href=&quot;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutmGdOovcmLYzNbqUtINeQ==:&quot; title=&quot;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutmGdOovcmLYzNbqUtINeQ==:&quot;&gt;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutm...&lt;/a&gt;

GET &lt;a href=&quot;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutmGdOovcmLYzNbqUtINeQ==:&quot; title=&quot;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutmGdOovcmLYzNbqUtINeQ==:&quot;&gt;http://anon.user.barandaz.com/cipher:pEtUzcn+vRTQ+kAURpvqhOt4d3DZ/FkLutm...&lt;/a&gt; HTTP/1.1
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The IBB Anonymizer retrieves the requested content and displays it to the user. All links within the requested content are re-written to point through the IBB Anonymizer proxy so that the end-user can browse the Web seamlessly -- a Web page that might link to &lt;a href=&quot;http://www.cnn.com&quot; title=&quot;www.cnn.com&quot;&gt;www.cnn.com&lt;/a&gt; instead will be found by the user to link to a &lt;i&gt;request&lt;/i&gt; for cnn.com &lt;i&gt;through&lt;/i&gt; the IBB Anonymizer system, so that browsing links in displayed pages can continue through the IBB Anonymizer. The use of the well-regarded Blowfish algorithm to &lt;i&gt;encrypt&lt;/i&gt; the user&#039;s requested url in the second round seems puzzling, since the URL is sent &lt;i&gt;encoded &lt;/i&gt;to the IBB Anonymizer service in the first instance. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;/sites/opennet.net/files/sedayema3.png&quot;&gt;&lt;img src=&quot;/sites/opennet.net/files/sedayema3.png&quot; border=&quot;0&quot; width=”500”&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;B. IBB Anonymizer-Filtered Content&lt;/h4&gt;
&lt;p&gt;Our testing shows that the IBB Anonymizer service provides nearly unlimited access to the entire Web, including content filtered by many Iranian ISPs. As previously reported, however, this service is configured to prevent use of its system to obtain sites with sexually-explicit content. In particular, our testing indicates that web hosts with certain keywords in their domain names are unavailable for circumvention. The impermissible keywords generally refer to sexually-explicit English content including the words &quot;ass,&quot; &quot;breast,&quot; &quot;naked,&quot; and &quot;sex,&quot; though some -- such as &amp;quot;my&amp;quot; -- do not. Domain names containing such keywords anywhere within are unavailable through IBB Anonymizer, though if the keyword is found within a directory embedded in the URL (such as &amp;quot;www.name.com/ass&amp;quot;), it does not trigger filtering.&lt;/p&gt;
&lt;p&gt;For example, when a request is issued for &lt;a href=&quot;http://www.playboy.com&quot; title=&quot;http://www.playboy.com&quot;&gt;http://www.playboy.com&lt;/a&gt;, the requested URL is obfuscated by converting the ASCII text to hexadecimal using JavaScript. &lt;a href=&quot;http://www.playboy.com&quot; title=&quot;http://www.playboy.com&quot;&gt;http://www.playboy.com&lt;/a&gt; becomes:&lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
687474703a2f2f7777772e706c6179626f792e636f6d2f
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The requested is transported over HTTP, using POST, to a CGI script that processes the request and redirects the request.&lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
POST &lt;a href=&quot;http://sedayema.com/jump.cgi&quot; title=&quot;http://sedayema.com/jump.cgi&quot;&gt;http://sedayema.com/jump.cgi&lt;/a&gt; HTTP/1.1

url=687474703a2f2f7777772e706c6179626f792e636f6d2f&amp;k=&amp;manual=yes&amp;onclick%3D%27xorValue%28document.menu.url.value%2Cdocument.menu.k.value%29%27=%D8%A7%D8%AC%D8%B1%D8%A7

Location: &lt;a href=&quot;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e706c6179626f792e636f6d2f&quot; title=&quot;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e706c6179626f792e636f6d2f&quot;&gt;http://anon.barandaz.com/cgi-bin/redirect.cgi?url=687474703a2f2f7777772e...&lt;/a&gt;
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;After setting some preferences via a cookie, the request is then redirected once again. &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
Location: &lt;a href=&quot;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e706c6179626f792e636f6d2f&amp;amp;go=go&quot; title=&quot;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e706c6179626f792e636f6d2f&amp;amp;go=go&quot;&gt;http://util.barandaz.com/cgi-bin/action.cgi?url=687474703a2f2f7777772e70...&lt;/a&gt;
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The requested URL is then encrypted using the Blowfish algorithm, redirected once again where a GET request is issued for the URL. &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
Location: &lt;a href=&quot;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGWPI+teMBZKGyCaP5unuQ==:&quot; title=&quot;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGWPI+teMBZKGyCaP5unuQ==:&quot;&gt;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGW...&lt;/a&gt;

GET &lt;a href=&quot;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGWPI+teMBZKGyCaP5unuQ==:&quot; title=&quot;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGWPI+teMBZKGyCaP5unuQ==:&quot;&gt;http://anon.user.barandaz.com/cipher:B3EoSzC2Kmgvv2R2Z3JtFx/aI9nzBi2IEGW...&lt;/a&gt; HTTP/1.1
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Instead of retrieving the requested content and displaying it to the user, the request is redirected to a block page of some sort, but the block page itself appears to be unavailable: &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
HTTP/1.1 302 Moved Temporarily
Location: &lt;a href=&quot;https://ssl.kuaidiannao.com/blockpage.html&quot; title=&quot;https://ssl.kuaidiannao.com/blockpage.html&quot;&gt;https://ssl.kuaidiannao.com/blockpage.html&lt;/a&gt;
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;a href=&quot;/sites/opennet.net/files/sedayema-playboy.png&quot;&gt;&lt;img src=&quot;/sites/opennet.net/files/sedayema-playboy.png&quot; border=&quot;0&quot; width=”500”&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The site to which users are redirected when accessing banned content (ssl.kuaidiannao.com) was not accessible.&lt;/p&gt;
&lt;p&gt;In the case above, &amp;quot;playboy.com&amp;quot; appears to be blocked because it  contains the word &amp;quot;boy&amp;quot; -- indeed, any domain name containing &amp;quot;boy&amp;quot;  is blocked.&lt;/p&gt;
&lt;p&gt;Due to these rules, many sexually-explicit sites are indeed unavailable. But  other sites are unavailable too, for words like &quot;ass&quot; appear in the host names  of numerous sites not providing sexually-explicit content. For example, usembassy.state.gov  is unavailable due to the presence of the letters &quot;ass&quot; within the server&#039;s  host name, and sussex.police.uk is unavailable for the same reason. In addition, the words &quot;my&quot; and &quot;tv&quot;, which are also domain suffixes, are filtered by IBB  Anonymizer. As a consequence, all web hosts registered within the domain name systems of Malaysia and Tuvalu are unavailable. Such content can still be accessed by directly entering the IP address of a particular domain, thus bypassing the  domain name keyword filtering, but many Internet users do not have the technical  ability to determine the IP address of a blocked domain name.&lt;/p&gt;
&lt;p&gt;Manual testing revealed that when specific substrings or groups of letters (usually with pornographic connotations) that appear within standard words, were found within a domain name, that web host was inaccessible through the  IBB Anonymizer service. Along with manually chosen words (such as &amp;quot;playboy&amp;quot;  from &amp;quot;boy&amp;quot;), we used Princeton&#039;s &lt;a href=&quot;http://www.cogsci.princeton.edu/%7Ewn/&quot;&gt;WordNet  lexical database&lt;/a&gt; to generate a set of larger words containing apparently-banned  substrings. Each of these words was then used as search terms in a standard &lt;a href=&quot;http://www.google.com&quot;&gt;Google&lt;/a&gt; search to generate lists of non-pornographic URLs. We ran each search with Google&#039;s &lt;a href=&quot;http://www.google.com/help/operators.html#allinurl&quot;&gt;inurl:  modifier&lt;/a&gt; to generate a list of highly ranked domain names with the specified keyword in the domain as well as any directory or filenames within the URLs.  Finally, we scrubbed the Google results to include only domains that contain the relevant keyword, as the IBB Anonymizer does not filter URL paths beyond the domain name that contain the banned keywords. &lt;/p&gt;
&lt;p&gt;When we ran the Google searches we asked for Google&#039;s &amp;quot;&lt;a href=&quot;http://www.google.com/safesearch_help.html&quot;&gt;safe  search&lt;/a&gt;&amp;quot; to be on, thus generating search results that were not deemed  by Google&#039;s automated system to be pornographic. Of course, Google is not 100% effective in screening out all pornographic content, and so some of the results  below contain pornographic web sites. &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; &lt;a href=&quot;/advisories/001/words&quot;&gt;List of blacklisted keywords&lt;/a&gt;  Each of the domains was accessed through five remote computers located in   Iran and through IBB Anonymizer. The results show that domains with these   substrings are being blocked with IBB Anonymizer.
&lt;li&gt; &lt;a href=&quot;/advisories/001/results&quot;&gt;Complete test results&lt;/a&gt; -- a master list,  indexed by banned substring keyword, of all the domains (and corresponding web  sites) we found to be blocked by IBB Anonymizer.  &lt;b&gt;Whitelisted Domains&lt;/b&gt;  While the rules determining the IBB Anonymizer&#039;s web blocks appear quite   simple -- whether or not a domain name contains a certain keyword -- there   appear to be some manually-inserted exceptions. Some specific domains as well   as many domains that contain the .us domain suffix have been placed on a whitelist   - accessible despite containing blacklisted keywords. Examples include: chat.yahoo.com,   chat.lycos.nl, &lt;a href=&quot;http://www.breast--enlargement.us&quot; title=&quot;www.breast--enlargement.us&quot;&gt;www.breast--enlargement.us&lt;/a&gt; and &lt;a href=&quot;http://www.asian-singles.us&quot; title=&quot;www.asian-singles.us&quot;&gt;www.asian-singles.us&lt;/a&gt;.
&lt;li&gt; &lt;a href=&quot;/advisories/001/whitelist&quot;&gt;Whitelisted domains&lt;/a&gt;  &lt;b&gt;&amp;quot;Double Blocked&amp;quot; Sites&lt;/b&gt;  IBB Anonymizer&#039;s filtering may have little effect on Iranian web surfers,   for users can often request the corresponding sites directly through their   Iranian ISPs without using IBB Anonymizer. But Iranian users have no such   option for sites that are blocked both by Iran and by the IBB Anonymizer.   We thus sought to discover a set of such sites.  The results below show sites blocked by both the IBB Anonymizer service and   Iran, to the extent Iranian filtering can be determined.[&lt;a href=&quot;#iran&quot;&gt;2&lt;/a&gt;] Most appear pornographic, with one significant exception - the site for National Iranian Television, &lt;a href=&quot;http://www.nitv.tv&quot; title=&quot;www.nitv.tv&quot;&gt;www.nitv.tv&lt;/a&gt;, a self-described independent 24-hour Persian TV station providing uncensored news, current affairs, political, cultural, educational and entertainment programming productions. The site is mistakenly filtered by IBB Anonymizer because of the keyword &quot;tv&quot; in the domain. Iran presumably censors the site for political reasons.
&lt;li&gt;&lt;a href=&quot;advisories/001/doubleblock&quot;&gt;Sites filtered both by Iran and by IBB Anonymizer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;C. Security and Privacy Implications of the IBB Anonymizer Service&lt;/h4&gt;
&lt;p&gt;The IBB Anonymizer service works in a way that leaves major gaps in users&#039; security and privacy. On the one hand, operators of users&#039; requested web sites cannot distinguish among IBB Anonymizer users, nor readily identify the true location or identity of any IBB Anonymizer user visiting their sites unless the user chooses to fill out a web form or otherwise indicate more about themselves. Like Anonymizer&#039;s main service, IBB Anonymizer provides an increase in privacy   by hiding the users&#039; true identities from web site operators.  However, IBB Anonymizer provides minimal protection against monitoring by   the Iranian users&#039; primary ISPs or the Iranian government. IBB Anonymizer   connections use plain text HTTP, easily monitored via a &quot;packet sniffer&quot; or   other network intermediary device. By analyzing the content of the Web pages being sent from the IBB Anonymizer to individual users in Iran, Iranian ISPs can readily determine what Web sites and pages their users visit -- even if they use IBB Anonymizer. Since the URL is &lt;i&gt;only&lt;/i&gt; converted to hexadecimal it is possible to block, monitor, and/or determine the domain/URL users are requesting through the service (because a hexadecimal string can be blocked as easily as a domain). When the domain/URL is finally encrypted with Blowfish algorithm, the domain/URL is properly protected but the content of the requested web page is not, and can easily be intercepted.&lt;br /&gt;
&lt;a href=&quot;/sites/opennet.net/files/sedayema-radiofarda.png&quot;&gt;&lt;img src=&quot;/sites/opennet.net/files/sedayema-radiofarda.png&quot; border=&quot;0&quot; width=”500”&gt;&lt;/a&gt;&lt;br /&gt;
  * As illustrated above, the content of &lt;a href=&quot;http://www.radiofarda.com&quot; title=&quot;www.radiofarda.com&quot;&gt;www.radiofarda.com&lt;/a&gt; can be easily identified and deciphered by an intermediary even though the user at IP address 192.168.1.2 is connecting through the IBB Anonymizer at 130.94.107.201 to access the Radio Farda web site. &lt;/p&gt;
&lt;p&gt;IBB Anonymizer can therefore leave a user worse off in at least two distinct   respects. First, IBB Anonymizer may tend to call attention to its users who request the IBB Anonymizer site, facilitating easy monitoring of the users and their activities. Second, IBB Anonymizer tends to give users a false sense  of security. The IBB Anonymizer service specifically promises:  &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
With this service you can surf, search and read the Internet anonymously, without the fear of being traced by the government, hackers or other intruders. [Translated from the text at &lt;a href=&quot;http://www.sedayema.com/&quot;&gt;http://www.sedayema.com&lt;/a&gt;]
&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;While Anonymizer does acknowledge the insecurity of the plaintext system on their public service, nowhere is it acknowledged with respect to the IBB Anonymizer service -- a striking omission given the &quot;Anonymizer&quot; title for the service and the fact that users might refrain from using it if they were aware that web page contents could be readily monitored by the authorities. A &quot;premium&quot; version of Anonymizer offered by the company for the worldwide   public offers encrypted communications from start to finish, indicating that   IBB could have contracted with Anonymizer to provide a wholly secure service.  &lt;/p&gt;
&lt;blockquote&gt;
&lt;pre&gt;
Requests to load a page anonymously are sent by your web browser to our Anonymizer servers. Unless you are using our SSH Tunneling service, these requests travel over the Internet &quot;in the clear&quot; (as plain text). Thus, it is possible for your ISP, network administrator, 
or other intermediary to easily log the sites that you visit. URL Encryption prevents this invasion of privacy by rendering the URLs of the web sites you visit meaningless to outside observers. [From &lt;a href=&quot;http://anonymizer.com/docs/faqs/url_encryption.shtml&quot;&gt;anonymizer.com&lt;/a&gt;]&lt;/pre&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;h2&gt;III. Conclusion&lt;/h2&gt;
&lt;p&gt;This case study of the IBB Anonymizer service reveals the growing complexity   of censorship and circumvention issues related to the Internet. The very existence   of the service suggests that the United States government has embraced a policy of facilitating freedom of information in the Middle East and elsewhere, and   this is consistent with the &lt;a href=&quot;http://www.voa.gov/index.cfm?sectionTitle=VOA%20Charter&quot;&gt;VOA   charter&lt;/a&gt;. It is curious to find the United States government promoting a tool to circumvent Iranian limits on freedom while imposing crude and, even by its own standards, widely overdrawn limits of its own. On a more general level, the IBB Anonymizer case raises serious issues concerning   the increasingly widespread practice of content filtering on the Internet.  These include the potential inaccuracy of proprietary and other secretive filtering mechanisms along with the unintentional problems these can create for the countries that employ them. There is also the potential risk to users who think they are using an &quot;anonymous&quot; circumvention technology, which can, in fact, be traced and tracked. Overall, the case underscores how controls   can be imposed on the physical and operational levels of the Internet, beneath   the immediately apparent interface levels to which most users are accustomed -- controls that have enormous implications for what can be communicated and   how. &lt;/p&gt;
&lt;p&gt;The technical research for this advisory was led by Nart Villeneuve, Director of Technical Research ONI/Citizen Lab, with the assistance of Michelle Levesque. The authors thank &lt;a href=&quot;http://www.benedelman.org/&quot; target=&quot;_new&quot;&gt;Ben Edelman&lt;/a&gt; for comments and contributions to earlier drafts of this advisory, and &lt;a href=&quot;http://www.hoder.com&quot;&gt;Hossein Derakhshan&lt;/a&gt; for translations of Persian.&lt;/p&gt;
&lt;h2&gt;Notes&lt;/h2&gt;
&lt;p&gt;&lt;a name=&quot;n1&quot;&gt;&lt;/a&gt; [1] See, for example, Babak Rahimi, &amp;quot;&lt;a href=&quot;http://meria.idc.ac.il/journal/2003/issue3/jv7n3a7.html&quot;&gt;Cyberdissent: The Internet in Revolutionary Iran&lt;/a&gt;,&amp;quot; Middle East Review of International Affairs, Vol. 7, No. 3 (Sept. 2003). &lt;/p&gt;
&lt;p&gt;&lt;a name=&quot;iran&quot; /&gt;&lt;/a&gt; [2] Determining what content is blocked in a country as a whole is very complicated; the scope and nature of Iranian filtering -- and the distinct challenges in measuring it -- will be covered in a separate white paper. &lt;/p&gt;
&lt;p&gt;&lt;a name=&quot;ibb&quot; /&gt;&lt;/a&gt; [3] The IBB is a federal agency of the United States which includes the &lt;a href=&quot;http://www.voanews.com/&quot;&gt;Voice of America&lt;/a&gt; and &lt;a href=&quot;http://www.radiofarda.com/&quot;&gt;Radio Farda&lt;/a&gt;, news and information services tailored to reach audiences in worldwide, including countries that impose official censorship. Through an arrangement with Anonymizer, Inc., the IBB has undertaken to offer a service to Internet users in Iran to bypass that country&#039;s Internet content filtering. Throughout this report we refer to the service as &quot;IBB Anonymizer&quot; to emphasize that it is distinct from the regular and commercial services offered by Anonymizer,Inc. &lt;/p&gt;
&lt;p&gt;&lt;a name=&quot;note&quot; /&gt;&lt;/a&gt; [4] The ONI contacted the International Broadcast Bureau (IBB) and Anonymizer to ascertain the motivation for configuring the IBB Anonymizer service with pornographic filters. The response was that the filters are employed because allowing access to pornographic data through the service is not a prudent use of U.S. taxpayer dollars and would create excessive demand on scarce bandwidth, squeezing out users&#039; ability to access non-pornographic sites. Email correspondence with Ken Berman of the IBB on April 7, 2004 and Lance Cottrell of Anonymizer  on April 7 and 14, 2004.&lt;/p&gt;
&lt;p&gt;&lt;a name=&quot;ip&quot; /&gt;&lt;/a&gt; [5] The filtering technology employed by Iranian ISPs could be configured to block web requests by both domain name and IP address. This is the case with some domains such as playboy.com, however, additional domains added to the block list by the Iranian authorities are configured to only block domain names and not IP addresses. Thus, blocked IBB Anonymizer domains are accessible&lt;br /&gt;
by directly entering the IP address.&lt;/p&gt;
&lt;p&gt;&lt;a name=&quot;studies&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;h4&gt;Filtering Studies&lt;/h4&gt;
&lt;p&gt;Sites Blocked by Internet Filtering Programs&lt;br /&gt;
&lt;a href=&quot;http://cyber.law.harvard.edu/people/edelman/mul-v-us/&quot;&gt;http://cyber.law.harvard.edu/people/edelman/mul-v-us/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Children&#039;s Internet Protection Act&lt;br /&gt; Study of Technology Protection Measures&lt;br /&gt;
&lt;a href=&quot;http://www.ntia.doc.gov/ntiahome/ntiageneral/cipa2003/CIPAreport08142003.pdf&quot;&gt;http://www.ntia.doc.gov/ntiahome/ntiageneral/cipa2003/CIPAreport08142003.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;See No Evil: How Internet Filters Affect the Search for Online Health Information&lt;br /&gt;
&lt;a href=&quot;http://www.kaisernetwork.org/health_cast/uploaded_files/Internet_Filtering_exec_summ.pdf&quot;&gt;http://www.kaisernetwork.org/health_cast/uploaded_files/Internet_Filtering_exec_summ.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Access Denied: The Impact of Internet Filtering Software on the Lesbian and  Gay Community&lt;br /&gt;
&lt;a href=&quot;http://www.glaad.org/documents/media/AccessDenied2.pdf&quot;&gt;http://www.glaad.org/documents/media/AccessDenied2.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Internet Filters: A Public Policy Report&lt;br /&gt;
&lt;a href=&quot;http://www.fepproject.org/policyreports/filteringreport.pdf&quot;&gt;http://www.fepproject.org/policyreports/filteringreport.pdf&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;Additional resources:&lt;/h4&gt;
&lt;p&gt;&lt;a href=&quot;http://peacefire.org/&quot;&gt;http://peacefire.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://sethf.com/anticensorware/&quot;&gt;http://sethf.com/anticensorware/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://censorware.net/&quot;&gt;http://censorware.net/&lt;/a&gt;  &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://groups.google.com/groups?selm=e614455c.0205121430.67e80a18%40posting.google.com&amp;amp;oe=ISO-8859-1&amp;amp;output=gplain&quot;&gt;Anonymizer free trial blocks pages with &quot;young&quot; or &quot;old&quot; in the URL (??)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;May 12 2002&lt;br /&gt;
By Bennett Haselton (&lt;a href=&quot;http://peacefire.org&quot;&gt;peacefire.org&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;Seth Finkelstein has &lt;a href=&quot;http://sethf.com/infothought/blog/archives/000601.html&quot;&gt;pointed out&lt;/a&gt; that Bennett Haselton had &lt;a href=&quot;http://groups.google.com/groups?selm=e614455c.0205121430.67e80a18%40posting.google.com&amp;amp;oe=ISO-8859-1&amp;amp;output=gplain&quot;&gt;previously discovered&lt;/a&gt; that Anonymizer blocks by keyword and that some domains are whitelisted.&lt;/p&gt;
&lt;h4&gt;Additional Sources:&lt;/h4&gt;
&lt;p&gt;U.S. Sponsors Anti-Censorship Web Service&lt;br /&gt;
By Kevin Poulsen, SecurityFocus Aug 26 2003&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/news/6807&quot;&gt;http://www.securityfocus.com/news/6807&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Anonymizer Makes the Internet a Safer Place for Iranian Citizens&lt;br /&gt;
&lt;a href=&quot;http://www.anonymizer.com/media/releases/030911.html&quot;&gt;http://www.anonymizer.com/media/releases/030911.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Anonymizer URL Encryption FAQ&lt;br /&gt;
&lt;a href=&quot;http://anonymizer.com/docs/faqs/url_encryption.shtml&quot;&gt;http://anonymizer.com/docs/faqs/url_encryption.shtml&lt;/a&gt;&lt;/p&gt;
</description>
 <category domain="http://opennet.net/topics/circumvention">Circumvention</category>
 <category domain="http://opennet.net/country/iran">Iran</category>
 <category domain="http://opennet.net/regions/mena">Middle East and North Africa (MENA)</category>
 <category domain="http://opennet.net/country/usa">United States of America</category>
 <category domain="http://opennet.net/regions/namerica">United States/Canada</category>
 <pubDate>Tue, 04 May 2004 00:00:00 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">873 at http://opennet.net</guid>
</item>
<item>
 <title>Unintended Risks and Consequences of Circumvention Technologies: The IBB&#039;s Anonymizer Service in Iran</title>
 <link>http://opennet.net/blog/2004/05/unintended-risks-and-consequences-circumvention-technologies-the-ibbs-anonymizer-servic</link>
 <description>&lt;p&gt;ONI testing found that filters built in to the IBB Anonymizer service block access to numerous non-pornographic pages and sites. Some of these apparently unintentionally blocked sites are themselves blocked within Iran, resulting in a situation where sites are effectively doubly blocked --by Iranian ISPs and by the IBB Anonymizer service. Further, despite IBB Anonymizer assurances that its Iranian users may surf the Web freely and safely, our testing suggests that the vast majority of its traffic is exposed to monitoring by Iranian authorities and corresponding local ISPs. &lt;a href=&quot;/advisories/001/&quot;&gt;Click Here&lt;/a&gt; to read the full advisory.&lt;/p&gt;
</description>
 <comments>http://opennet.net/blog/2004/05/unintended-risks-and-consequences-circumvention-technologies-the-ibbs-anonymizer-servic#comments</comments>
 <category domain="http://opennet.net/topics/circumvention">Circumvention</category>
 <category domain="http://opennet.net/country/iran">Iran</category>
 <category domain="http://opennet.net/regions/mena">Middle East and North Africa (MENA)</category>
 <category domain="http://opennet.net/country/usa">United States of America</category>
 <pubDate>Mon, 03 May 2004 16:12:00 -0400</pubDate>
 <dc:creator>nart</dc:creator>
 <guid isPermaLink="false">476 at http://opennet.net</guid>
</item>
</channel>
</rss>
