Internet filter

From The Right Wiki
Revision as of 03:50, 4 November 2024 by imported>Coddlebean (Types of filtering)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

An Internet filter is software that restricts or controls the content an Internet user is capable to access, especially when utilized to restrict material delivered over the Internet via the Web, Email, or other means. Such restrictions can be applied at various levels: a government can attempt to apply them nationwide (see Internet censorship), or they can, for example, be applied by an Internet service provider to its clients, by an employer to its personnel, by a school to its students, by a library to its visitors, by a parent to a child's computer, or by an individual user to their own computers. The motive is often to prevent access to content which the computer's owner(s) or other authorities may consider objectionable. When imposed without the consent of the user, content control can be characterised as a form of internet censorship. Some filter software includes time control functions that empowers parents to set the amount of time that child may spend accessing the Internet or playing games or other computer activities.

Terminology

The term "content control" is used on occasion by CNN,[1] Playboy magazine,[2] the San Francisco Chronicle,[3] and The New York Times.[4] However, several other terms, including "content filtering software", "web content filter", "filtering proxy servers", "secure web gateways", "censorware", "content security and control", "web filtering software", "content-censoring software", and "content-blocking software", are often used. "Nannyware" has also been used in both product marketing and by the media. Industry research company Gartner uses "secure web gateway" (SWG) to describe the market segment.[5] Companies that make products that selectively block Web sites do not refer to these products as censorware, and prefer terms such as "Internet filter" or "URL Filter"; in the specialized case of software specifically designed to allow parents to monitor and restrict the access of their children, "parental control software" is also used. Some products log all sites that a user accesses and rates them based on content type for reporting to an "accountability partner" of the person's choosing, and the term accountability software is used. Internet filters, parental control software, and/or accountability software may also be combined into one product. Those critical of such software, however, use the term "censorware" freely: consider the Censorware Project, for example.[6] The use of the term "censorware" in editorials criticizing makers of such software is widespread and covers many different varieties and applications: Xeni Jardin used the term in a 9 March 2006 editorial in The New York Times, when discussing the use of American-made filtering software to suppress content in China; in the same month a high school student used the term to discuss the deployment of such software in his school district.[7][8] In general, outside of editorial pages as described above, traditional newspapers do not use the term "censorware" in their reporting, preferring instead to use less overtly controversial terms such as "content filter", "content control", or "web filtering"; The New York Times and The Wall Street Journal both appear to follow this practice. On the other hand, Web-based newspapers such as CNET use the term in both editorial and journalistic contexts, for example "Windows Live to Get Censorware."[9]

Types of filtering

Filters can be implemented in many different ways: by software on a personal computer, via network infrastructure such as proxy servers, DNS servers, or firewalls that provide Internet access. No solution provides complete coverage, so most companies deploy a mix of technologies to achieve the proper content control in line with their policies.

Browser based filters

Browser based content filtering solution is the most lightweight solution to do the content filtering, and is implemented via a third party browser extension.

E-mail filters

E-mail filters act on information contained in the mail body, in the mail headers such as sender and subject, and e-mail attachments to classify, accept, or reject messages. Bayesian filters, a type of statistical filter, are commonly used. Both client and server based filters are available.

Client-side filters

This type of filter is installed as software on each computer where filtering is required.[10][11] This filter can typically be managed, disabled or uninstalled by anyone who has administrator-level privileges on the system. A DNS-based client-side filter would be to set up a DNS Sinkhole, such as Pi-Hole.

Content-limited (or filtered) ISPs

Content-limited (or filtered) ISPs are Internet service providers that offer access to only a set portion of Internet content on an opt-in or a mandatory basis. Anyone who subscribes to this type of service is subject to restrictions. The type of filters can be used to implement government,[12] regulatory[13] or parental control over subscribers.

Network-based filtering

This type of filter is implemented at the transport layer as a transparent proxy, or at the application layer as a web proxy.[14] Filtering software may include data loss prevention functionality to filter outbound as well as inbound information. All users are subject to the access policy defined by the institution. The filtering can be customized, so a school district's high school library can have a different filtering profile than the district's junior high school library.

DNS-based filtering

This type of filtering is implemented at the DNS layer and attempts to prevent lookups for domains that do not fit within a set of policies (either parental control or company rules). Multiple free public DNS services offer filtering options as part of their services. DNS Sinkholes such as Pi-Hole can be also be used for this purpose, though client-side only.[15]

Search-engine filters

Many search engines, such as Google and Bing offer users the option of turning on a safety filter. When this safety filter is activated, it filters out the inappropriate links from all of the search results. If users know the actual URL of a website that features explicit or adult content, they have the ability to access that content without using a search engine. Some providers offer child-oriented versions of their engines that permit only child friendly websites.[16]

Reasons for filtering

The Internet does not intrinsically provide content blocking, and therefore there is much content on the Internet that is considered unsuitable for children, given that much content is given certifications as suitable for adults only, e.g. 18-rated games and movies.

Criticism

Filtering errors

Underblocking

Whenever new information is uploaded to the Internet, filters can under block, or under-censor, content if the parties responsible for maintaining the filters do not update them quickly and accurately, and a blacklisting rather than a whitelisting filtering policy is in place.[17]

Morality and opinion

Many[18] would not be satisfied with government filtering viewpoints on moral or political issues, agreeing that this could become support for propaganda. Many[19] would also find it unacceptable that an ISP, whether by law or by the ISP's own choice, should deploy such software without allowing the users to disable the filtering for their own connections. In the United States, the First Amendment to the United States Constitution has been cited in calls to criminalise forced internet censorship. (See section below)

Legal actions

In 1998, a United States federal district court in Virginia ruled (Loudoun v. Board of Trustees of the Loudoun County Library) that the imposition of mandatory filtering in a public library violates the First Amendment.[20] In 1996 the US Congress passed the Communications Decency Act, banning indecency on the Internet. Civil liberties groups challenged the law under the First Amendment, and in 1997 the Supreme Court ruled in their favor.[21] Part of the civil liberties argument, especially from groups like the Electronic Frontier Foundation,[22] was that parents who wanted to block sites could use their own content-filtering software, making government involvement unnecessary.[23] In the late 1990s, groups such as the Censorware Project began reverse-engineering the content-control software and decrypting the blacklists to determine what kind of sites the software blocked. This led to legal action alleging violation of the "Cyber Patrol" license agreement.[24] They discovered that such tools routinely blocked unobjectionable sites while also failing to block intended targets. The Motion Picture Association successfully obtained a UK ruling enforcing ISPs to use content-control software to prevent copyright infringement by their subscribers.[25]

Religious, anti-religious, and political censorship

Content labeling

Content labeling may be considered another form of content-control software. In 1994, the Internet Content Rating Association (ICRA) — now part of the Family Online Safety Institute — developed a content rating system for online content providers. Using an online questionnaire a webmaster describes the nature of their web content. A small file is generated that contains a condensed, computer readable digest of this description that can then be used by content filtering software to block or allow that site. ICRA labels come in a variety of formats.[26] These include the World Wide Web Consortium's Resource Description Framework (RDF) as well as Platform for Internet Content Selection (PICS) labels used by Microsoft's Internet Explorer Content Advisor.[27] The Voluntary Content Rating (VCR) system was devised by Solid Oak Software for their CYBERsitter filtering software, as an alternative to the PICS system, which some critics deemed too complex. It employs HTML metadata tags embedded within web page documents to specify the type of content contained in the document. Only two levels are specified, mature and adult, making the specification extremely simple.

Use in public libraries

Australia

The Australian Internet Safety Advisory Body has information about "practical advice on Internet safety, parental control and filters for the protection of children, students and families" that also includes public libraries.[28] NetAlert, the software made available free of charge by the Australian government, was allegedly cracked by a 16-year-old student, Tom Wood, less than a week after its release in August 2007. Wood supposedly bypassed the $84 million filter in about half an hour to highlight problems with the government's approach to Internet content filtering.[29] The Australian Government has introduced legislation that requires ISPs to "restrict access to age restricted content (commercial MA15+ content and R18+ content) either hosted in Australia or provided from Australia" that was due to commence from 20 January 2008, known as Cleanfeed.[30] Cleanfeed is a proposed mandatory ISP level content filtration system. It was proposed by the Beazley led Australian Labor Party opposition in a 2006 press release, with the intention of protecting children who were vulnerable due to claimed parental computer illiteracy. It was announced on 31 December 2007 as a policy to be implemented by the Rudd ALP government, and initial tests in Tasmania have produced a 2008 report. Cleanfeed is funded in the current budget, and is moving towards an Expression of Interest for live testing with ISPs in 2008. Public opposition and criticism have emerged, led by the EFA and gaining irregular mainstream media attention, with a majority of Australians reportedly "strongly against" its implementation.[31] Criticisms include its expense, inaccuracy (it will be impossible to ensure only illegal sites are blocked) and the fact that it will be compulsory, which can be seen as an intrusion on free speech rights.[31] Another major criticism point has been that although the filter is claimed to stop certain materials, the underground rings dealing in such materials will not be affected. The filter might also provide a false sense of security for parents, who might supervise children less while using the Internet, achieving the exact opposite effect.[original research?] Cleanfeed is a responsibility of Senator Conroy's portfolio.

Denmark

United Kingdom

{{#section:Web blocking in the United Kingdom|lib}}

United States

The use of Internet filters or content-control software varies widely in public libraries in the United States, since Internet use policies are established by the local library board. Many libraries adopted Internet filters after Congress conditioned the receipt of universal service discounts on the use of Internet filters through the Children's Internet Protection Act (CIPA). Other libraries do not install content control software, believing that acceptable use policies and educational efforts address the issue of children accessing age-inappropriate content while preserving adult users' right to freely access information. Some libraries use Internet filters on computers used by children only. Some libraries that employ content-control software allow the software to be deactivated on a case-by-case basis on application to a librarian; libraries that are subject to CIPA are required to have a policy that allows adults to request that the filter be disabled without having to explain the reason for their request. Many legal scholars believe that a number of legal cases, in particular Reno v. American Civil Liberties Union, established that the use of content-control software in libraries is a violation of the First Amendment.[32] The Children's Internet Protection Act [CIPA] and the June 2003 case United States v. American Library Association found CIPA constitutional as a condition placed on the receipt of federal funding, stating that First Amendment concerns were dispelled by the law's provision that allowed adult library users to have the filtering software disabled, without having to explain the reasons for their request. The plurality decision left open a future "as-applied" Constitutional challenge, however. In November 2006, a lawsuit was filed against the North Central Regional Library District (NCRL) in Washington State for its policy of refusing to disable restrictions upon requests of adult patrons, but CIPA was not challenged in that matter.[33] In May 2010, the Washington State Supreme Court provided an opinion after it was asked to certify a question referred by the United States District Court for the Eastern District of Washington: "Whether a public library, consistent with Article I, § 5 of the Washington Constitution, may filter Internet access for all patrons without disabling Web sites containing constitutionally-protected speech upon the request of an adult library patron." The Washington State Supreme Court ruled that NCRL's internet filtering policy did not violate Article I, Section 5 of the Washington State Constitution. The Court said: "It appears to us that NCRL's filtering policy is reasonable and accords with its mission and these policies and is viewpoint neutral. It appears that no article I, section 5 content-based violation exists in this case. NCRL's essential mission is to promote reading and lifelong learning. As NCRL maintains, it is reasonable to impose restrictions on Internet access in order to maintain an environment that is conducive to study and contemplative thought." The case returned to federal court. In March 2007, Virginia passed a law similar to CIPA that requires public libraries receiving state funds to use content-control software. Like CIPA, the law requires libraries to disable filters for an adult library user when requested to do so by the user.[34]

Bypassing filters

Content filtering in general can "be bypassed entirely by tech-savvy individuals." Blocking content on a device "[will not]…guarantee that users won't eventually be able to find a way around the filter."[35] Content providers may change URLs or IP addresses to circumvent filtering. Individuals with technical expertise may use a different method by employing multiple domains or URLs that direct to a shared IP address where restricted content is present. This strategy doesn't circumvent IP packet filtering, however can evade DNS poisoning and web proxies. Additionally, perpetrators may use mirrored websites that avoid filters.[36] Some software may be bypassed successfully by using alternative protocols such as FTP or telnet or HTTPS, conducting searches in a different language, using a proxy server or a circumventor such as Psiphon. Also cached web pages returned by Google or other searches could bypass some controls as well. Web syndication services may provide alternate paths for content. Some of the more poorly designed programs can be shut down by killing their processes: for example, in Microsoft Windows through the Windows Task Manager, or in Mac OS X using Force Quit or Activity Monitor. Numerous workarounds and counters to workarounds from content-control software creators exist. Google services are often blocked by filters, but these may most often be bypassed by using https:// in place of http:// since content filtering software is not able to interpret content under secure connections (in this case SSL).[needs update] An encrypted VPN can be used as means of bypassing content control software, especially if the content control software is installed on an Internet gateway or firewall. Other ways to bypass a content control filter include translation sites and establishing a remote connection with an uncensored device.[37]

Products and services

Some ISPs offer parental control options. Some offer security software which includes parental controls. Mac OS X v10.4 offers parental controls for several applications (Mail, Finder, iChat, Safari & Dictionary). Microsoft's Windows Vista operating system also includes content-control software. Content filtering technology exists in two major forms: application gateway or packet inspection. For HTTP access the application gateway is called a web-proxy or just a proxy. Such web-proxies can inspect both the initial request and the returned web page using arbitrarily complex rules and will not return any part of the page to the requester until a decision is made. In addition they can make substitutions in whole or for any part of the returned result. Packet inspection filters do not initially interfere with the connection to the server but inspect the data in the connection as it goes past, at some point the filter may decide that the connection is to be filtered and it will then disconnect it by injecting a TCP-Reset or similar faked packet. The two techniques can be used together with the packet filter monitoring a link until it sees an HTTP connection starting to an IP address that has content that needs filtering. The packet filter then redirects the connection to the web-proxy which can perform detailed filtering on the website without having to pass through all unfiltered connections. This combination is quite popular because it can significantly reduce the cost of the system. There are constraints to IP level packet-filtering, as it may result in rendering all web content associated with a particular IP address inaccessible. This may result in the unintentional blocking of legitimate sites that share the same IP address or domain. For instance, university websites commonly employ multiple domains under one IP address. Moreover, IP level packet-filtering can be surpassed by using a distinct IP address for certain content while still being linked to the same domain or server.[38] Gateway-based content control software may be more difficult to bypass than desktop software as the user does not have physical access to the filtering device. However, many of the techniques in the Bypassing filters section still work.

See also

References

  1. "Young, angry … and wired - May 3, 2005". Edition.CNN.com. 3 May 2005. Archived from the original on 8 December 2009. Retrieved 25 October 2009.
  2. Umstead, R. Thomas (20 May 2006). "Playboy Preaches Control". Multichannel News. Archived from the original on 22 September 2013. Retrieved 25 June 2013.
  3. Woolls, Daniel (October 25, 2002). "Web sites go blank to protest strict new Internet law". sfgate.com. Associated Press. Archived from the original on 8 July 2003.
  4. Bickerton, Derek (30 November 1997). "Digital Dreams". The New York Times. Retrieved 25 October 2009.
  5. "IT Glossary: Secure Web Gateway". gartner.com. Retrieved 27 March 2012.
  6. "Censorware Project". censorware.net. Archived from the original on 20 June 2015.
  7. "159.54.226.83/apps/pbcs.dll/article?AID=/20060319/COLUMN0203/603190309/1064". Archived from the original on 19 October 2007.
  8. "DMCA 1201 Exemption Transcript, April 11 - Censorware". Sethf.com. 11 April 2003. Retrieved 25 October 2009.
  9. "Windows Live to get censorware - ZDNet.co.uk". news.ZDNet.co.uk. 14 March 2006. Archived from the original on 5 December 2008. Retrieved 25 October 2009.
  10. Client-side filters. National Academy of Sciences. 2003. ISBN 9780309082747. Retrieved 24 June 2013. {{cite book}}: |work= ignored (help)
  11. "Protecting Your Kids with Family Safety". microsoft.com. Retrieved 10 July 2012.
  12. Xu, Xueyang; Mao, Z. Morley; Halderman, J. Alex (5 Jan 2011). "Internet Censorship in China: Where Does the Filtering Occur?" (PDF). Georgia Tech. University of Michigan. Archived from the original (PDF) on 24 March 2012. Retrieved 10 July 2012.
  13. Christopher Williams (3 May 2012). "The Pirate Bay cut off from millions of Virgin Media customers". The Daily Telegraph. Retrieved 8 May 2012.
  14. "Explicit and Transparent Proxy Deployments". websense.com. 2010. Archived from the original on 18 April 2012. Retrieved 30 March 2012.
  15. Fruhlinger, Keith Shaw and Josh (2022-07-13). "What is DNS and how does it work?". Network World. Retrieved 2023-08-22.
  16. Filtering. National Academy of Sciences. 2003. ISBN 9780309082747. Retrieved 22 November 2010. {{cite book}}: |work= ignored (help)
  17. Stark, Philip B. (10 November 2007). "The Effectiveness of Internet Content Filters" (PDF). University of California, Berkeley. Archived (PDF) from the original on 2010-07-15. Retrieved 22 November 2010.
  18. Lui, Spandas (23 March 2010). "Microsoft, Google and Yahoo! speak out in ISP filter consultation". AARNet.com. Retrieved 22 November 2010.
  19. "Google and Yahoo raise doubts over planned net filters". BBC News. 16 February 2010. Retrieved 30 April 2010.
  20. "Mainstream Loudon v. Board of Trustees of the Loudon County Library, 24 F. Supp. 2d 552 (E.D. Va. 1998)". Tomwbell.com. Retrieved 25 October 2009.
  21. "Reno v. American Civil Liberties Union - 521 U.S. 844 (1997)". Justia.com. 26 June 1997.
  22. "Legal Victories". Electronic Frontier Foundation. Retrieved 2019-02-01.
  23. "Children Internet Safety". www.justice.gov. 2015-05-26. Archived from the original on 2019-02-02. Retrieved 2019-02-01.
  24. "Microsystems v Scandinavia Online, Verified Complaint". Electronic Frontier Foundation. United States District Court, District of Massachusetts. 15 March 2000. Archived from the original on 12 February 2009. Retrieved 25 October 2009.
  25. "Sky, Virgin Media Asked to Block Piracy Site Newzbin2". BBC News. 9 November 2011. Retrieved 26 March 2012.
  26. "ICRA: Technical standards used". Family Online Safety Institute. Retrieved 2008-07-04.
  27. "Browse the Web with Internet Explorer 6 and Content Advisor". microsoft.com. March 26, 2003.
  28. "NetAlert: Parents Guide to Internet Safety" (PDF). Australian Communications and Media Authority. 2 August 2007. Archived from the original (PDF) on 19 April 2013. Retrieved 24 June 2013.
  29. "Teenager cracks govt's $84m porn filter". the Sydney Morning Herald. Fairfax Digital. Australian Associated Press (AAP). 25 August 2007. Retrieved 24 June 2013.
  30. "Restricted Access Systems Declaration 2007" (PDF). Australian Communications and Media Authority. 2007. Archived from the original (PDF) on 24 March 2012. Retrieved 24 June 2013.
  31. 31.0 31.1 "Learn - No Clean Feed - Stop Internet Censorship in Australia". Electronic Frontiers Australia. Archived from the original on 7 January 2010. Retrieved 25 October 2009.
  32. Wallace, Jonathan D. (November 9, 1997). "Purchase of blocking software by public libraries is unconstitutional".
  33. "ACLU Suit Seeks Access to Information on Internet for Library Patrons". ACLU of Washington. November 16, 2006. Archived from the original on December 5, 2006.
  34. Sluss, Michael (March 23, 2007). "Kaine signs library bill: The legislation requires public libraries to block obscene material with Internet filters". The Roanoke Times. Archived from the original on February 29, 2012. Retrieved March 24, 2007.
  35. Satterfield, Brian (4 June 2007). "Understanding Content Filtering: An FAQ for Nonprofits". TechSoup.org. Retrieved 24 June 2013.
  36. Varadharajan, Vijay (July 2010). "Internet filtering - Issues and challenges". IEEE Security & Privacy. 8 (4): 62–65. doi:10.1109/msp.2010.131. ISSN 1540-7993.
  37. "Is It Possible To Easily Avoid Internet Filters?". Comodo Cybersecurity. 4 June 2007. Retrieved 2 October 2018.
  38. Varadharajan, Vijay (2010). "Internet filtering - Issues and challenges". IEEE Security & Privacy. 8 (4): 62–65. doi:10.1109/MSP.2010.131. Retrieved 2024-02-02.