China and Global Internet Governance
187
A zero-sum solution to this problem would have required taking root servers away
from the United States and moving them to other countries. Aside from being a nonstarter politically, given U.S. power and the lack of any institutionalized process for
designating and removing root server operators, such a measure had the potential to
create adjustment and compatibility issues. Therefore, leading DNS experts developed
and implemented a technical modifi cation that allowed existing root servers to multiply themselves with “ instances ” elsewhere in the world.
16 This was a positive-sum
solution that used some aspects of the “ anycast ” service to make an authoritative
name-server operator provide access to a single-named server in multiple locations.
China was one of the fi rst countries to set up “ mirrored ” or “ anycasted ” root servers.
There are now instances of three different root servers located in Beijing. And due to
routing agreements among ISPs, it is possible that root-level domain name queries
coming from sources outside China might make use of those root server instances in
China.
What makes this interdependency interesting is that China relies heavily on domain
name blocking to implement the GFW. As a result, its name servers will modify or
tamper with responses to queries about where to fi nd the blocked domains. If someone
lives outside China and, because of network topography, happens to query a root
name server hosted in China, that person ’ s queries will pass through the Great Firewall, potentially subjecting the person to the same censorship imposed on Chinese
citizens. Apparently, China ’ s version of the “ I ” root was not visible to the rest of the
world. In early March 2010, however, it seems to have become visible.
17 As a result,
Chinese censorship “ spilled out ” and affected a number of users outside of China.
Despite some countermeasures taken by the main root server operators, the problem
happened again in June. Like the incident described in the next section, the Chinese
impact on the rest of the world ’ s Internet was almost certainly unintentional.
The BGP “ Hijack ”
U.S. – China Internet relations were infl amed again in November 2010, when the U.S. –
China Economic and Security Review Commission (USCESRC) issued its report to
Congress.
18 Discussing what was probably an unintentional routing-prefi x confi guration error that took place in April, the USCESRC stated that “ a state-owned Chinese
telecommunications fi rm ‘ hijacked ’ massive volumes of Internet traffi c. For about 18
minutes on April 8, 2010, China Telecom advertised erroneous network traffi c routes
that instructed U.S. and other foreign Internet traffi c to travel through Chinese
servers. ”
19
In technical jargon, this is a problem in the border gateway protocol (BGP) routing
protocol, sometimes called “ BGP hijacks ” or more frequently known as “ BGP leaks, ”
in which an ISP announces a route it is not authorized to service and the route
187
A zero-sum solution to this problem would have required taking root servers away
from the United States and moving them to other countries. Aside from being a nonstarter politically, given U.S. power and the lack of any institutionalized process for
designating and removing root server operators, such a measure had the potential to
create adjustment and compatibility issues. Therefore, leading DNS experts developed
and implemented a technical modifi cation that allowed existing root servers to multiply themselves with “ instances ” elsewhere in the world.
16 This was a positive-sum
solution that used some aspects of the “ anycast ” service to make an authoritative
name-server operator provide access to a single-named server in multiple locations.
China was one of the fi rst countries to set up “ mirrored ” or “ anycasted ” root servers.
There are now instances of three different root servers located in Beijing. And due to
routing agreements among ISPs, it is possible that root-level domain name queries
coming from sources outside China might make use of those root server instances in
China.
What makes this interdependency interesting is that China relies heavily on domain
name blocking to implement the GFW. As a result, its name servers will modify or
tamper with responses to queries about where to fi nd the blocked domains. If someone
lives outside China and, because of network topography, happens to query a root
name server hosted in China, that person ’ s queries will pass through the Great Firewall, potentially subjecting the person to the same censorship imposed on Chinese
citizens. Apparently, China ’ s version of the “ I ” root was not visible to the rest of the
world. In early March 2010, however, it seems to have become visible.
17 As a result,
Chinese censorship “ spilled out ” and affected a number of users outside of China.
Despite some countermeasures taken by the main root server operators, the problem
happened again in June. Like the incident described in the next section, the Chinese
impact on the rest of the world ’ s Internet was almost certainly unintentional.
The BGP “ Hijack ”
U.S. – China Internet relations were infl amed again in November 2010, when the U.S. –
China Economic and Security Review Commission (USCESRC) issued its report to
Congress.
18 Discussing what was probably an unintentional routing-prefi x confi guration error that took place in April, the USCESRC stated that “ a state-owned Chinese
telecommunications fi rm ‘ hijacked ’ massive volumes of Internet traffi c. For about 18
minutes on April 8, 2010, China Telecom advertised erroneous network traffi c routes
that instructed U.S. and other foreign Internet traffi c to travel through Chinese
servers. ”
19
In technical jargon, this is a problem in the border gateway protocol (BGP) routing
protocol, sometimes called “ BGP hijacks ” or more frequently known as “ BGP leaks, ”
in which an ISP announces a route it is not authorized to service and the route
