If this fact is widely publicized, it will discourage others from attempting to access banned
content, even if the technical measures for preventing it are inadequate. This type of publicity
has been seen in China with Jingjing and Chacha,
4 two cartoon police officers who inform
Internet users that they are being monitored and encourage them to report suspected rulebreakers.
Social Techniques
Social mechanisms are often used to discourage users from accessing inappropriate content.
For example, families may place the PC in the living room where the screen is visible to all
present, rather than somewhere more private, as a low-key way of discouraging children
from accessing unsuitable sites. A library may well situate PCs so that their screens are all
visible from the librarian’s desk. An Internet cafe ´ may have a CCTV surveillance camera. There
might be a local law requiring such cameras, and also requiring that users register with
government-issue photo ID. There is a spectrum of available control, ranging from what
many would find sensible to what many would find objectionable.
Comparison of Mechanisms
Each mechanism has different properties of who can deploy systems based around them,
what the cost will be, and how effective the filtering is. In this section we compare these
properties.
Positioning of System and Scope of Blocking
No single entity has absolute control of the entire Internet, so those who wish to deploy filtering systems are limited in where they can deploy the required hardware or software. Likewise
a particular mechanism will block access only to the desired Web site by a particular group of
Internet users.
In-line filtering mechanisms (HTTP proxies, TCP/IP header/content filtering, and hybrid
approaches) may be placed at any point between the user and the Web server, but to be reliable they must be at a choke point—a location that all communication must go through. This
could be near the server to block access to it from all over the world, but this requires access
to the ISP hosting the server (and they could simply disconnect it completely).
More realistically, these mechanisms are deployed near or in the user’s ISP, thereby blocking content from users of its network. For countries with tightly controlled Internet connectivity,
these measures can also be placed at the international gateway(s), which makes circumvention more difficult and avoids ISPs being required to take any special action. The positioning
of surveillance mechanisms share the same requirements.
DNS tampering is more limited, in that it must be placed at the recursive resolver used
by users and is normally within their ISP. The actual list of blocked sites could, however, be
Tools and Technology of Internet Filtering
65
content, even if the technical measures for preventing it are inadequate. This type of publicity
has been seen in China with Jingjing and Chacha,
4 two cartoon police officers who inform
Internet users that they are being monitored and encourage them to report suspected rulebreakers.
Social Techniques
Social mechanisms are often used to discourage users from accessing inappropriate content.
For example, families may place the PC in the living room where the screen is visible to all
present, rather than somewhere more private, as a low-key way of discouraging children
from accessing unsuitable sites. A library may well situate PCs so that their screens are all
visible from the librarian’s desk. An Internet cafe ´ may have a CCTV surveillance camera. There
might be a local law requiring such cameras, and also requiring that users register with
government-issue photo ID. There is a spectrum of available control, ranging from what
many would find sensible to what many would find objectionable.
Comparison of Mechanisms
Each mechanism has different properties of who can deploy systems based around them,
what the cost will be, and how effective the filtering is. In this section we compare these
properties.
Positioning of System and Scope of Blocking
No single entity has absolute control of the entire Internet, so those who wish to deploy filtering systems are limited in where they can deploy the required hardware or software. Likewise
a particular mechanism will block access only to the desired Web site by a particular group of
Internet users.
In-line filtering mechanisms (HTTP proxies, TCP/IP header/content filtering, and hybrid
approaches) may be placed at any point between the user and the Web server, but to be reliable they must be at a choke point—a location that all communication must go through. This
could be near the server to block access to it from all over the world, but this requires access
to the ISP hosting the server (and they could simply disconnect it completely).
More realistically, these mechanisms are deployed near or in the user’s ISP, thereby blocking content from users of its network. For countries with tightly controlled Internet connectivity,
these measures can also be placed at the international gateway(s), which makes circumvention more difficult and avoids ISPs being required to take any special action. The positioning
of surveillance mechanisms share the same requirements.
DNS tampering is more limited, in that it must be placed at the recursive resolver used
by users and is normally within their ISP. The actual list of blocked sites could, however, be
Tools and Technology of Internet Filtering
65
