Hey Guys,
I just posted this on the Australian broadband forom about this issue and since Ive been largly absent from my own topic I thought this would provide some food for thought
How did we miss this?
Howdy,
As a programmer, I think a huge majority of "IT experts" have missed (I would consider major) issue with the Minister Conroy's Censorship proposals with relation to how easy it would be to reverse-engineer and replicate a near identical copy of the entire blacklist... Heres my perspective of Conroy's proposals based on my experience with writing and working with similar software systems identical to his proposal.
Anyone can easily reverse-engineer Minister Conroy's proposed secret filter after an update to any ISPs regardless of any measure they try take to prevent it, I also believe this will give criminals and child molesters a free government sponsored address-book containing thousands of links to illegal pornography, links to terrorist videos/propaganda, child porn etc... at the expense of the taxpayer and it will be available on every Australian Internet connection across the country considering its mandatory.
The Minister Conroy has said the filters provide "100% accuracy and negligible speed impact (Note: Its this 100% accuracy that makes it incredibly easy to reverse engineer the entire scope of filtering being employed including the filtered addresses) also the $43 billion NBN was never tested at the speeds Minister Conroy himself tells Australians everyday that they will be getting (we'll need new hardware since none currently are compatible, so newly created hardware specifically for the NBN = $80b after R+D.. whats the go here?) " for blocking specific material, also that there will be two blacklists, one is a "Federal state secret" and the other partially-public administered by possibly another government department or organization setup by government?, He has also mentioned the blacklist will be automatic and completely encrypted to prevent its leakage once again.
When these "RC" URLs begin getting filtered (inc two youtube links), What is Conroys reason to keep the list a secret? no one including kids should be able to access these sites after their filtered or be able to bypass the filter... right?
The sane belief is that the decision was made because the Gov don't want kids/adults or criminals having a free government sponsored address-book containing thousands of direct links to illegal material that's regularly(?) updated (if public) on a government website like the ACMA (we've been told even though we will be filtered from viewing any URL on that list even if we tried, we still cant view the list itself, object to anything on the list that shouldn't be on there and the public most probably will not be informed when the legislation changes at a later time (actually happened a few years ago, sorry about that news thing).
Last year some should remember EFF released a tool called Switzerland after widespread illegal filtering by US-ISPs of US customers had taken place:
"The software uses a semi-P2P, server-and-many-clients architecture. Whenever the clients send packets to each other, the server will attempt to determine if any of them were dropped, forged, or modified [.] Switzerland is a much more sophisticated successor to the pcapdiff software that we released last year. It automates many of the things that had to be done by hand with the earlier code.
One advantage this architecture has over other network testing tools is that it can spot arbitrary kinds of packet modifications in any protocol — it doesn't assume that the interference comes in the form of TCP reset packets or web page modifications, and it isn't limited to BitTorrent or any other specific application."
(Info here:
Switzerland Network Testing Tool | Electronic Frontier Foundation, Sourcecode here:
SourceForge.net: Switzerland - Develop)
I used an idea that Phone Phreakers have used for decades called "War Diallng" and I changed the architecture slightly to suit more adequately for more direct tcp/http use than the server just analyzing the traffic between two clients, create a quick "mini-signature" for all web domains without having to download/store the entire page.
Its currently takes 3 ½ days to process a substantial part of the worlds domain index and display analysis of the results (its a crappy spare box) Note: Lists of website domain names can be legally obtained and this should make identification of urls on the blacklist easier because it would negate the need to preform "War Addressing" in two countries.
I plan on optimizing the code over the next year before releasing it publicly in the event the mandatory filtering (pyramid?) scheme is passed by the government since its currently the only way I have let alone others will have of verifying what the government is blocking is legit while keeping them honest (A secret blacklist of banned material setup solely by government is just asking for trouble... It will be abused, dont doubt your politicians wouldn't filter something they shouldn't)
Once the library is a little more mature and optimized by next year, it will only take a few hours and a handful of people inside and out of Australia to reverse engineer Australia's little secret blacklist.
In short, On the first day these mandatory filters are turned on my major concerns are:
a) Instantly allows the secret government blacklist to be reverse-engineered by anyone including criminals, who will get this list then view sites over encrypted connections making it impossible to catch them.
b) Instantly the filters become a target for hackers wanting to DoS the entire Australian public from accessing the internet outside Australia or even in Australia.
It remains to be seen if these (unrealistically) tested filters (that I hear contains multiple CVE exploits from using depreciated FOSS) are capable of detecting/blocking all hackers/ terrorists/ over seas Governments like North Korea or Russia's from being able to modify the filters to suit any of these groups and others nefarious deeds.
c) Instantly the filters become a target for Terrorists and Australia's enemy's wanting to cause a massive communications and stock-market disruption/blackout/crash (could be done by a 17 year old kid half way around the world using just a keyboard).
AFAIK from all the media ive read, Minister Conroy has not planned or even considered the effect these things could have over the entire Australia continent.
I turned 19 in July and over a year before this system is introduced and years afterwords Ill be able to reliably obtain the "secret and encrypted" ACMA blacklists very simply using an application "doing a process of elimination" (War Addressing after War Dialling

) for links accessible outside Australia and ones accessible inside Australia using (semi) distributed computing and recording the links showing consistent blockage by our govt filters.
Simple and 100% effective.
Minister Conroy, I just informed the public how your secret blacklist just doesn't work and how easily it can be reverse-engineered by a mere kid. dont even bother hiding your shame from the Australian public, We see it now.
Have a happy Christmas and new year.
Sincerely
dmex