Considered "18+"
daniel.haxx.se
daniel.haxx.se
One of the main problems was that, at the time, it was all managed by Blue Coat. As they were a US company, many of the "violations" that they picked up just weren't considered problematic for a UK / EU audience.
Similarly, they would use blanked keyword blocking. So sex education resources would frequently get blocked. Although, again, that may have been by puritanical design.
Anything which looked like it might be used to bypass their filters (VPN, proxies, etc) were also blocked.
Ultimately, the customer isn't the user. It is the network who are terrified that Johnny's parent is going to go to the papers screaming about how the evil phone company corrupted their innocent child. That's all it is there for - to protect the network.
> "I had thought that TPB was blocked because of court orders.
> So how come one ISP blocks it, and other doesn't?"
The court order[1] had 6 defined defendants: - BRITISH SKY BROADCASTING LIMITED
- BRITISH TELECOMMUNICATIONS PLC
- EVERYTHING EVERYWHERE LIMITED
- TALKTALK TELECOM GROUP PLC
- TELEFÓNICA UK LIMITED
- VIRGIN MEDIA LIMITED
The court order only affected the listed ISPs (at that time, 94% share of the consumer ISP market). Other ISPs were under no obligation to do the same.[1] http://www.bailii.org/cgi-bin/markup.cgi?doc=/ew/cases/EWHC/...
It's not in the public interest to block TPB. The DA would be suing for the sake of private interests, against the public, and at the public's expense.
You're not kidding. The biggest fear is a parent complaining because a library or school filter fails. People really don't give a damn what a hard problem it is nor do they care that browsers are starting to add counter measures to skip over ISP filtering. Doesn't matter if you don't have control of the laptop, you are still to blame. At this point, I wonder what the next generation of filtering software is going to do.
I had a colleague whose surname, Sextro, was part of his email address. He occasionally had messages blocked by blanket filters like that.
I make a point to mention that my cat’s full name is Robert. I enjoy the reactions: person either looks at me like I’m a moron for thinking this is something worth spending the energy to say out loud, or they really enjoy it. I digress.
It's like if another name for John was Frank. It makes zero sense.
https://www.youtube.com/watch?v=9LMr5XTgeyI (CGP Grey)
(spoiler: he couldn't find out where it came from, and did this video on his research to explain more: https://www.youtube.com/watch?v=qEV9qoup2mQ )
Very likely this is due to both being transliterations from Cyrillic.
Oleksander is Ukranian form of Aleksander.
If someone would pronounce Alek and Olek the same, the chosen transcription of the shortened nickname is pretty much arbitrary.
* Jack
* Dick
* Rock from Roland
* Hank from Henry
* Chuck from Charles
https://en.wikipedia.org/wiki/Dick_Van_Dyke
And a favorite tech blog/news website that is often blocked:
The later (TV-Show) is actually based on the former (twitter feed) but couldn't retain the name in the US. It would probably have been perfectly fine as is in the UK.
I never understand that kind of (often self) censorship where the meaning is intentionally left clear. It could be malicious compliance with keyword-based filters but people do it voluntarily even in places where no such filters exist.
"There are three English football teams that always fall victim to overzealous censorship: Arsenal, Scunthorpe and Manchester Fucking United."
Just out of curiosity: could you provide some examples?
https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin...
Was this in the UK, a UK ISP?
There has never been anything wrong with them, it's just braindead blocking software purchased by incompetent managers.
Having been that IT person early in my career, responsible for networks, firewalls and policies, what you say sounds cruel. But I could not agree more. Today there is a tragic de-skilling in ICT. When I speak to modern corporate or academic IT people I make the best faith assumptions. I assume they are like we were in the early 90s and speak to them accordingly with technical respect. Then I discover they cannot configure a mail or web server, cannot compile a program, or even use a package manager... they don't know how to read logs or change permissions on a directory.... the mind boggles. I've had senior IT people tell me that they're "not technical" and it turns out they've arrived on some "management track" from an arts-history background.
I'm not knocking arts history, or being "elitist" I hope, but this raises serious concerns for me. What is going on in IT? Have cloud services, tick-box webmin interfaces and packaged solutions led to a brain drain?
One could argue that modern IT people don't need "geeky computer skills" any more, because Google and Microsoft have solved everything. But that doesn't pan out, because when simple things go wrong they cannot fix them (which is their job). Right now I am dealing with an international university whose impeccable pedigree is bedrock in computing history - and their IT people cannot fix a simple email issue, to the extent the staff and students have to set up their own servers. The fact is, they just don't have control over it any longer. I think the entire senior ranks are just marking time till they can retire.
The same could happen to mail, where you can only use "certified provider" or you will just be filtered out. Spam and phishing are a problem, sure, but recent IT strategies are highly questionable in this regard.
IMO there's also a failure of government here to both ensure an open internet and to come down on people abusing the system. A related example might be the phone spam calls everyone in the US gets - it's an administrative, legal, and regulatory problem, not a technical one.
My context may be a bit skewed though since I'm a sysadmin turned cybersecurity and I've seen the large numbers of people clicking on the absolute stupidest things. Given the "average" computer use that IT has to deal with I'm much more sympathetic to their plight.
I think it of as a result of high profile hacks. Either a company is hacked once and they go way overboard trying to ensure it doesn't happen again. Or, some high profile company gets hacked, some C*O's see it, overreact and decide they're not going to be next.
On a corporate network, it can make total sense to block non-business sites by default. As someone who used to help manage the proxies at a bank, some of the arbitrary decisions annoyed me (like blocking gTLDs of all sorts by default) but at the end of the day, it was an inconvenience. There were mechanisms to request access if needed.
To me, it starts to get more shady with behavioral analytics software on terminals that measure your known patterns of access and look for aberrations. It becomes intrusive and creepy in its move from "passive" filtering to active, personalized monitoring.
---
All that is irrelevant here, because an ISP fucking with my TLS connection and throwing up warnings is awful.
I don't mean entertainment; I mean suits making decisions about what engineering needs etc.
Again, prior experience, we had brainstormed the idea of denying any executable downloads by frontline workers, while permitting it for IT, since frontline workers both were less likely to need to download random EXEs, and less likely to know how to spot phishing or grayware sites.
With how verbose and talkative applications today are it wouldn't be appropriate to route their traffic through the company line anyway.
Of course that decreases the security that deactivating split tunneling offers to a degree, but I think we have to live with that. All this security is ineffective anyway if 99% of attacks come through the inbox. That will never be change and people need to be educated and have to trust IT that they don't blame the user since it can happen to everyone and nobody is on guard to 100%. With decent backups the damage can usually be completely mitigated without a lot of expensive security measures.
Legitimately asking, why do you need access to your private website on corporate resources during work? Access your private stuff on your BYOD.
The problem isn’t what I want to do it’s having an intermediary in the process who only introduces drag.
I 100% understand the frustration of working in a place where lawyers "introduce drag". Lawyer's job isn't to make your job harder/easier, but to protect the company from whatever. Sometimes whatever turns out to be the "well intended" employee. Part of the friction in these situations are very zealous people wanting to do things while they are so scoped in on their task that they are unawares of the larger consequences to the company no matter how well intentioned they may be. As I've become older, I can corrolate that friction with youth. That coefficient of friction becomes smaller with age/experience. It has nothing to do with levels of caring/apathy, but from experiencing the negative affect of "move fast, break things" and being willing to tap the breaks a little bit while changing altitude to see a bigger picture.
Although that is not a very strong justification.
How did that pan out?
Also: polish up your resume and start sending it out.
I've had problems with billing glitches with four utility companies in the UK now and I am starting to suspect that overcharging people and hoping they don't notice is actually a common business strategy in the industry and if they get caught they blame bad IT but really their systems are configured to do this on purpose.
daniel.haxx.se is Daniel Stenberg's blog (famously known as curl maintainer), and would best be displayed with the subdomain as daniel.haxx.se rather than haxx.se, similar to how substacks include the subdomain to make it clear at a glance what the source is.
Some even started using multiple X's (i.e. XX, XXX, etc.) to give the impression that their film contained more graphic sexual content than the simple X rating. In some cases, the X ratings were applied by reviewers or film scholars, e.g. William Rotsler, who wrote "The XXX-rating is for Hardcore, the XX-rating is for Softcore, and an X-rating is for comparatively cool films." — https://en.wikipedia.org/wiki/X_rating
That said if they think the domain is a soft hit they should look at content, site age and classification in e.g. bluecoat, etc., which would counter the soft domain indicator. If the site allows comments and doesn’t always successfully moderate or filter out adult bot spam links, that can make even clean content sites get filtered. To be clear, not! aware of any spam at this site, but as a heads up to anyone w/ open commenting, comment engines that allow a website link are often bot-bait.
> It shows that this filter is for this specific host name only, not for the entire haxx.se domain.
That seems to be exactly backwards of the way things should be done if it wasn't mostly security theater.
- Have to consider the domain is a string, not a hierarchy. Too many premier domains have had subdomains with spam, malware, etc., running on some random thing in their namespace, trying to draft on the domain rep.
- Legit traffic + comment forms + web links are a thing spam and adult "se.xx 2nite?" bots target. They seek out the ranked traffic to boost their clicks and good rep to boost their SERPs, so -- perhaps counterintuitive -- scoring traffic + rep as an indicator (to be combined with other indicators of course) is sensible.
Maybe he can change it to daniel.not.haxx.se ?
The opposite happens too - see Elsagate. The newest version of Elsagate material, which I've only seen one person talking about, is weird/inappropriate stories aimed at children but disguised as baking videos - https://youtu.be/HfcKCk6vPCE?t=295
Here's the transcript from a couple, both of which are played over top of those "5-minute craft" style (faked) baking videos:
> > Someone knocked on the front door. I opened it and saw a strange tiny man standing there with a creepy smile on his face and he smells really good.
> > He said "Hi I'm Noah I'm looking for your dad, is he home?"
> > I replied "No he's out there looking for a stupid job."
> > I was about to close the door in his face when he suddenly pushed it back open. I screamed, I thought he was going to hurt me. He took off his glasses and told me to stay calm. He looked a lot less intimidating without his glasses on and his face was softer.
> > I said "okay, come on in"
https://youtu.be/HfcKCk6vPCE?t=436
Or:
> > After one of my live youtube videos one of my viewers sent a message asking if we could meet. It was a bit strange for someone to be so insistent, especially after what my brother was doing so I ignored him at first. Then, a few days later, he messaged me again. He said he knew how to deal with my brother. He believed me. I agreed to meet him but I was nervous. What if it's just a stupid prank, I wondered. I went to the coffee shop he had asked me to go to. I didn't even know his name.
> And in that story he turns out to be a handsome knight in shining armor who rescues her from all her troubled home life problems.
Otherwise ISPs are basically collecting a list of self-identified internet deviants by whatever definition they have. I mean at least make them do a bit of work to process my DNS history to figure that out...
Not to mention the point of the article, that the filtering is often overzealous and captures the weirdest things.
Why 18? why not 21? or 23? What qualifies as explicitly "adult" content? violence perhaps could disqualify most military recruiting sites from my vodaphone. Alcohol? its certainly a moral vice in the UAE but in germany even a fourteen year old can order a bier with their parents. Sex? its a sensitive subject for even the most conservative among us until we touch upon religious texts, which seem to enjoy free reign.
what i wonder most is...what is the altruistic moral source of truth used as litmus by Voda and others? or is it driven largely by a small but vocal minority or is the board pushing this as some sort of nineteenth century neo-victorian purity charge.
More likely than not, this got caught up in a regular job that scans DNS zones for new domains to "filter". It's just a matter of time before this catches anything related to Scunthorpe[0].
It's also worth adding that 18 is typically the age when someone is considered legally accountable for their actions as an adult. We shouldn't be surprised that this age pops up in so many laws because of that, even though it is an arbitrary line in most cases.
Edit: I am not sure if age restriction check is responsibility of sites themselves or service providers according to UK law.
Pump, how? Wouldn't forcing ID tank the numbers when all the bots are excluded?
return all([c in 'haxx.se' for c in ['s', 'e', 'x']])"3. Use your credit card to confirm your age (you won't be charged)."
https://daniel.haxx.se/blog/wp-content/uploads/2022/05/vodaf...
You can though ring the mobile phone provider and tell them to turn off the block - and we can blame our conservative government for pushing this through (and looking to go even further in the future).
Although the way the web works a web request to domain.xy doesn't mean much anyway but people still believe in it.
Also MITM attacks in IT security should be shunned and I believe the users need to be informed about it when they happen. IT could potentially steal banking information. I believe this to be highly illegal in my country and still a data breach even if an employee wasn't allowed to do the transaction because it was private.
In addition to that we need ODoH and NTS as well. It's pretty clear neither countries or ISPs (not to mention attackers) can keep their grubby fingers out of anything unencrypted. MITM should be visible or impossible.
I had my domain put on a phishing blacklist due to DNS caching. During a 30 minute cache window, I decommissioned a server and a bad actor picked up the recycled server's IP address. The IP reverse lookup showed my domain due to the cache.
AFAIK the filtering isn't legally mandated, but something the ISPs decide on together based on a some government memo. In any case it's dead simple to bypass and a very blunt tool. For example, why does Virigin block Reddit, but not Twitter? Both sites feature adult content, in fact so does Google image search.
The silver lining in all this stupidity is perhaps that it creates a more technically talented population. I don't expect most teenagers know or want to know about DNS, but if that's what stands between them and adult content I'm sure they'll learn.
At least google allows me to click away such warnings (while warning that doom is imminent).
Of course a mobile telephony provider is going to be a lot more certain which phone numbers attract the specific premium rate categories to need to be blocked than they are which random domains should be blocked :P.
ARTICLE 57. - Network neutrality. Prohibitions. Service Providers shall not:
a) Block, interfere, discriminate, hinder, degrade or restrict the use, sending, reception, offering or access to any content, application, service or protocol except by court order or express request of the user.
Australians, in particular, have an amazing amount of curse words/racial slurs.
It's sad we're living in times we must exclusively use a VPN.
Not if they intercept all DNS requests, which is not unheard of.
DoH or DoT would prevent that though, which is getting enabled in browsers now - probably why they are now employing other methods of filtering.
2. present custom "valid" certificate
3. ???
4. profit!
... isn't this something that certificate transparency should help solve?
No. CT is meant to help find illegitimate server certificate issuance by participating CAs, but it cannot help the user-agent get past illegitimate server certs.
Besides, the whole point here is to make the user-agent fail to load the page, therefore the network operator's firewall's CA would not participate in CT (nor be a CAB member), and the network operator does not just not mind that the illegitimate server certificate is noticed, they want it noticed.
That's the point though. I'd rather the user-agent tell me that the certificate is invalid. That's as far as it's currently going anyway when a certificate is, for example, self-signed.
> Besides, the whole point here is to make the user-agent fail to load the page,
That's exactly the minimum that should happen, yes. User-agent sees that the certificate isn't correctly issued for the domain and refuses to send the HTTP request (though SNI is already sent...)
> the network operator does not just not mind that the illegitimate server certificate is noticed, they want it noticed.
More than just noticed: the network operator wants the user to inappropriately act on the illegitimate server certificate.
Of course, accepting the phony certificate will immediately leak your cookies to the middlebox, along with giving it permission to read any credentials out of local storage. So as an end user you should not accept it.
Looking at you, google.
There's probably a policy to dictate what content should be filtered, but in practice: a ticket is filed to block a site, someone looks at the ticket, in all likelihood it is added to the blocklist, and then probably ends up there forever until complaints are raised.
You could be correct that the presence of multiple x's in the URL makes it more likely for support agents to think "yep, this is probably sketchy, there's no harm adding it to the blocklist" - I doubt it's the original reason though.
> It shows that this filter is for this specific host name only, not for the entire haxx.se domain.