Security vulnerabilities found in China's nationwide installed filter software
cse.umich.edu
cse.umich.edu
What the government cares about is making the quest for information just enough of a nuisance that people generally won’t bother. Most Chinese people, like most Americans, are interested mainly in their own country. All around them is more information about China and things Chinese than they could possibly take in. The newsstands are bulging with papers and countless glossy magazines. The bookstores are big, well stocked, and full of patrons, and so are the public libraries. Video stores, with pirated versions of anything. Lots of TV channels. And of course the Internet, where sites in Chinese and about China constantly proliferate. When this much is available inside the Great Firewall, why go to the expense and bother, or incur the possible risk, of trying to look outside?
The same points arguably hold for the Green Dam.
Edit: I guess I missed the point of the advisory (see comment below). I assumed they were discussing methods of circumventing the system, but after a second (more careful) reading, that's obviously not the biggest concern.
It's really a crappy situation: mandated software that's this broken. Either join a botnet or potentially raise the government's suspicions by uninstalling the software.
The real issue is simply that this new system is not safe for many reasons, without regard to the situation suggested by the parent post.
That's exactly what happened to this guy and he got off: http://news.cnet.com/8301-10784_3-9970660-7.html
I don't doubt that there's a sizable chance of getting convicted anyway, but I really hope it's not "probable".
My imagined dialogue: "We're here to seize your hard drive to see if you are doing anything illegal." "OK." "Damn, it's encrypted, tell us your password." "I refuse to testify against myself." "Uh, you have to." "I forgot the password." "Fuck."
The fishing expedition then ends fairly quickly. (If you really are distributing child porn, though, they will probably get you some other way. This is exactly how the system should work.)
(You might want to have a "honeypot" that can be activated with a certain password so that you don't even have to claim you forgot the password. This could be helpful for avoiding "contempt of court". IMHO, this should not be necessary, but I Am Not The Supreme Court.)
1. Is it mandatory to install such filter software on Linux boxes also? 2. How do they handle the case where the filter software is chroot'ed in a jail, so that the individual is complying with the letter of the law by installing and running the software, but managing to avoid the ill-effects?
I'm not speaking about censorship etc., just plain curious.