[00:00.000 --> 00:06.460] This is the first router when you hit in China. [00:09.550 --> 00:15.410] Okay, and from there we can do lots of testings. [00:16.190 --> 00:25.110] And so if you can get a computer in China, you can test different kind of packages. [00:25.530 --> 00:28.930] So I tried to test TCP, UDP, different parts. [00:28.930 --> 00:36.710] And also I tried if the connection, if it's bidirectional or just one direction. [00:37.030 --> 00:43.750] I mean, if for this blocked IP, can I still send package to China but cannot get package back? [00:44.010 --> 00:49.330] Or can China send package to me but I cannot send any reply? [00:49.890 --> 00:57.050] And what I found is no package can go through in either directions. [00:57.050 --> 01:04.610] And the second feature is there are lots of IPs got blocked. [01:05.390 --> 01:19.370] I estimate that we at simultaneously, there are something like thousand level IPs blocked related to our network. [01:19.370 --> 01:29.130] And besides those, there are still many IPs for like voanews.com, voa.gov or human rights in China website. [01:29.670 --> 01:32.370] Those IPs, they are always blocked. [01:32.570 --> 01:38.730] But since we keep switching to new IPs, so they kind of have to run after us. [01:38.730 --> 01:42.570] So that's a certain number of IPs. [01:42.730 --> 01:53.010] And the third feature is that they have to block those traffic out of a huge number of bandwidths. [01:53.010 --> 01:57.050] And by the end of last year, the bandwidth is 18 gigabytes per second. [01:57.250 --> 01:57.810] And they are growing. [01:58.790 --> 02:00.770] They are doubling every six months. [02:00.890 --> 02:05.730] So now it's probably 36 gigabytes per second. [02:06.050 --> 02:07.050] That's in total. [02:07.330 --> 02:17.810] And as we see in the previous page, they are blocking as the first router you enter China. [02:17.810 --> 02:20.970] There are only a couple of such routers. [02:21.250 --> 02:28.370] So that's lots of bandwidths for each of those routers. [02:28.650 --> 02:32.270] So the question is, who are doing this? [02:32.350 --> 02:33.790] I mean, who is the vendor? [02:35.450 --> 02:41.010] And what they did and how we can disable it? [02:41.570 --> 02:46.950] There are books written by Ethan Guttman called Losing New China. [02:46.950 --> 02:47.910] I think that's the title. [02:48.190 --> 02:51.030] And he talked with someone in Cisco. [02:51.290 --> 03:03.850] And he said Cisco actually customized their router for China specifically for the purpose of censoring the Internet traffic. [03:04.450 --> 03:06.530] I mean, the way China needs. [03:14.240 --> 03:17.120] So that's IP level blocking. [03:18.620 --> 03:24.680] For that, what I think is probably they do it like the Cisco router. [03:24.920 --> 03:26.180] They have the access list. [03:26.360 --> 03:27.940] You can use this kind of technology. [03:27.940 --> 03:34.200] Just look at the layer three, the IP address. [03:34.200 --> 03:39.140] So that can be very high performance, can handle lots of traffic. [03:39.960 --> 03:46.660] But for TCP or UDP, that doesn't require more CPU and memory. [03:46.880 --> 03:49.780] So I will explain them separately. [03:49.780 --> 04:04.220] For TCP, it first catch my attention in 2002 when Google first, they got blocked by China. [04:04.520 --> 04:10.080] And then people found it's redirected to some Chinese search engine. [04:10.080 --> 04:18.540] And then after that, what happened is, Chinese can still visit Google, but they cannot search certain keywords. [04:19.080 --> 04:26.640] So what happened is, once you search some kind of forbidden keywords, your connection will get... [04:26.640 --> 04:30.820] You will lost your connection to Google for a while. [04:32.500 --> 04:40.780] So to study this, we started to think it's something related to the URL. [04:40.960 --> 04:43.820] Google used get method. [04:44.040 --> 04:52.460] So the keyword you are searching is appended to Google's URL. [04:52.460 --> 05:00.460] So we tried to query a Chinese website with a string appended. [05:01.020 --> 05:04.780] And then we observed similar phenomena from United States. [05:05.700 --> 05:16.880] So the key is, your offending package needs to go through the boundary between China and the rest of the world. [05:17.860 --> 05:21.000] And then we still try to go further. [05:23.880 --> 05:29.640] For TCP-related blocking, one key is, if you want to track the session. [05:30.080 --> 05:32.760] So we want to try the simplest way. [05:32.940 --> 05:37.480] We are thinking maybe they only block based on a single package. [05:37.660 --> 05:38.740] So we try that. [05:40.420 --> 05:50.220] For HTTP traffic, what you have is, you have get, space, and slash, and then your URL. [05:50.600 --> 05:53.560] So there is where the keywords can be found. [05:54.120 --> 05:57.260] So then we try this. [05:57.260 --> 06:04.800] And we find out that, indeed, only a single package with start with ggt, space, slash, and then the keyword. [06:05.280 --> 06:09.400] Then you have got a reset package. [06:09.920 --> 06:22.420] So if you are doing, you are really visiting a website, what happens is, once you send out the get request, your TCP connection will receive a reset package. [06:22.420 --> 06:30.440] With all the source IP, the IP port, and sequence number. [06:30.560 --> 06:31.280] Everything is matched. [06:31.360 --> 06:33.700] So your connection will be teared down. [06:36.700 --> 06:46.820] And moreover, these four parameters, the source port, source IP, destination IP, and destination port, they are on a blacklist. [06:47.300 --> 06:58.820] So from that, if you send out a package without a keyword, I mean a TCP package, still you will get a reset. [06:58.820 --> 07:05.720] So this is why, when people search some forbidden words, and then they cannot connect to Google for a while. [07:08.180 --> 07:17.500] And next thing, I wish I could show you here, but I will only explain to you. [07:18.400 --> 07:27.160] So the next thing we want to figure out is, since it's for any IP, any web server, any IP, you can observe this. [07:27.160 --> 07:32.400] Even there is no computer live behind that IP. [07:33.160 --> 07:36.980] So there is some IP, like, not used in China. [07:37.160 --> 07:43.440] So you send a package, get space, a keyword, and still you will get a reset package back. [07:43.700 --> 07:47.180] So we want to know who is sending this reset package. [07:47.180 --> 07:52.100] So the trick is, like, what happened with trace routes. [07:52.420 --> 07:56.900] So you adjust your TTL, the time to live. [07:57.060 --> 08:06.620] So your package will not reach all the way to the local network of that IP, either dead or alive. [08:06.620 --> 08:23.740] And then, for using the trace route data we just got, we found that this IP in red is, okay, TTL 13 is what you need. [08:24.120 --> 08:32.520] So if you tune your TTL to 12 and send out the keyword package, you won't get anything. [08:32.520 --> 08:36.400] If you turn it to 13, then you will get the reset package. [08:36.880 --> 08:49.040] So everything is going, everything going on about the TCP session hijacking is related to this router in, I mean, somewhere around this router in red. [08:49.040 --> 08:56.940] And so you can see, this is, so the first router is here, when you enter China. [08:57.100 --> 08:58.740] So this is the third router. [08:59.000 --> 09:04.080] But this is kind of pattern we found for this TCP session hijacking. [09:04.400 --> 09:12.360] It's, we scan, like, 1,000 IPs covered everywhere in China. [09:12.360 --> 09:18.980] And so they are mostly at the second or third router when you enter China. [09:19.480 --> 09:45.680] So here, another thing worth mentioning is, if you are sending your forbidden package to a live web server, then it should send you, that live web server should send you a reset because you are, without the TCP hand checking, you directly send it a web request. [09:46.120 --> 09:52.780] But if you are doing this to China with a keyword in it, you will receive two reset packages. [09:53.280 --> 09:57.800] One is from the web server, one is from this kind of engine. [09:57.800 --> 10:05.920] So here, the theory behind it is, it's kind of a sniffing. [10:06.180 --> 10:11.060] So it still allow your package to go through to reach the real web server. [10:11.300 --> 10:16.040] But it will get a copy and then tear down your TCP connections. [10:24.470 --> 10:30.490] So, more about the implication of this TCP session hijacking. [10:34.170 --> 10:38.330] So, here, they only need to look at the URL. [10:40.030 --> 10:46.550] And also, notice that, think about what happened for proxy server. [10:46.770 --> 10:56.490] Since one website is blocked, the first response is, we can use a proxy server outside China and access that website. [10:56.490 --> 11:11.270] However, for proxy request, what you, the package cross the boundary of China and outside is, get, space, HTTP, column, slash, slash, and the, say, voanews.com. [11:11.550 --> 11:23.250] So, if voanews.com is on the blacklist, no proxy outside China can be used to access voanews.com, because your keyword is here. [11:24.490 --> 11:32.630] So, people say, yeah, maybe China is using proxy hunter to block all the IP of proxies. [11:32.870 --> 11:40.070] I didn't see a need for that with this technology in doing the job. [11:40.570 --> 11:44.410] And then there are all kinds of observation from users. [11:44.410 --> 11:48.090] They say, oh, I cannot get on Google for 20 minutes. [11:49.150 --> 11:53.570] Some people say, oh, my browser will crush something like that. [11:53.670 --> 11:57.250] So, I think that's probably some more like the software problem. [11:57.530 --> 12:01.550] And some people say, if they reboot, they can get back on Google again. [12:01.810 --> 12:08.730] So, my suggestion is probably they, when they reboot, they got a different IP from the ISP. [12:08.730 --> 12:13.770] So, this new IP is not on the blacklist of that router. [12:14.070 --> 12:22.650] But for the actual implementation, I'm not aware of Cisco router can do this kind of thing. [12:23.730 --> 12:28.190] Cisco has IDS product, can do similar things, but that's a separate box. [12:28.330 --> 12:38.890] So, they can just hook up the box besides the router and send a copy of every package to this box. [12:39.890 --> 12:40.430] Okay. [12:40.630 --> 12:41.970] So, that's TCP. [12:42.810 --> 12:45.150] Next is DNS. [12:47.910 --> 12:48.230] Yes. [12:53.450 --> 12:54.230] I'm sorry. [12:54.410 --> 12:55.250] Could you repeat the question? [12:59.630 --> 13:00.270] Yes. [13:00.270 --> 13:02.230] That's what you have to have. [13:02.470 --> 13:15.030] So, either you need to use certain encryption technology like SSL, SSH, and also, we are actually using some specialized encryption. [13:15.390 --> 13:26.290] So, everything looks like HTTP traffic, but the encryption happens inside the application level data. [13:26.570 --> 13:32.810] The reason for this is we wanted to be able to use corporate networks. [13:32.810 --> 13:42.730] many company has an intranet, and all the traffic helps go through their HTTP proxy, and they do not allow anything other than port 80. [13:43.490 --> 13:49.590] So, right now, we have some network in place that people can use. [13:49.770 --> 14:01.390] So, we know how to get around it, but still, this creates some performance issue or stability issue for us. [14:01.790 --> 14:04.290] So, we hope we can disable it. [14:06.850 --> 14:12.350] So, for DNS hijacking, first, it's applied to Google. [14:13.090 --> 14:26.310] And then, at the end of September, there are some news come out that there are some other high-profile websites that got redirected. [14:26.570 --> 14:31.070] So, I look at that and realize that they are doing... [14:32.190 --> 14:39.470] What I observed at that time is for certain domain, like, at that time, voa.gov. [14:40.050 --> 14:42.090] So, for any... [14:42.750 --> 14:46.590] Well, I tried, like, 30 DNS servers in China. [14:46.850 --> 14:51.110] Any of those DNS servers you query voa.gov, you get a bogus IP. [14:53.470 --> 14:54.510] And then... [14:54.510 --> 14:58.090] So, some people in China say, OK, since my ISP... [14:58.090 --> 14:59.430] The ISP... [14:59.950 --> 15:02.310] The DNS server from my ISP is lying. [15:02.470 --> 15:05.330] So, how about using a DNS server in the United States? [15:05.510 --> 15:06.310] So, they tried that. [15:06.490 --> 15:08.690] And still, they get a bogus IP. [15:09.090 --> 15:13.970] And then, some more advanced guys, they tried to sniffer the traffic. [15:14.190 --> 15:15.290] They found two packages. [15:15.830 --> 15:16.470] So, this... [15:17.350 --> 15:21.530] Maybe remind you, the two packages we found before about the TCP. [15:22.290 --> 15:24.330] So, I will run a little bit faster. [15:24.690 --> 15:50.270] So, what happened is, along their network, and maybe accidentally, maybe that's the way they do it, related to the same router, if your DNS query package contains the keyword, like voa.gov, and you hit that router with destination IP to any IP in China, [15:50.270 --> 15:56.590] if you are doing this from United States, then you will get a response with a bogus IP. [15:57.150 --> 16:06.450] So, this is also something you can test from United States against some IPs, any IP in China. [16:07.110 --> 16:13.770] And you can play with the DTL trick to find out which router is this related to. [16:13.990 --> 16:14.210] Question? [16:14.430 --> 16:20.410] When you get the two DNS packets back, is one of them correct, and one of them has the wrong IP, or do both of them have the wrong IP? [16:21.570 --> 16:33.230] In the case, when you are doing it from China, querying a DNS server in the United States, you have one is correct, the other one is wrong. [16:34.570 --> 16:40.090] And the actual situation is kind of complicated because of the timing issue. [16:40.230 --> 16:50.770] In most cases, the wrong IP package will come back first, so anything like IE will be fooled to use that wrong IP. [16:55.820 --> 17:07.020] So, next I will show a flash that explains the idea I just mentioned kind of in a more visual way. [17:08.620 --> 17:15.760] So, some friends have to make this demonstration in February. [17:16.080 --> 17:29.400] So, if you are in China and querying a DNS server in the United States, and you have to pass the router that somehow has some other things probably carry a black list, so you will get the wrong IP back first. [17:32.020 --> 17:38.400] And if you are outside China and you are querying a DNS server... [17:40.040 --> 17:46.780] Okay, so here it's saying the whole China got hijacked, hijacked the results. [17:47.180 --> 17:50.720] So, if you are in another country, so everything goes fine. [17:50.920 --> 18:01.100] However, I brought this up again this year in February because Verisign is saying that they are going to put a root server in China. [18:01.100 --> 18:11.040] So, if you try to query this root DNS server, you say, oh, I don't know who I can ask about .com. [18:11.180 --> 18:13.920] So, you want to ask this root server. [18:14.220 --> 18:16.460] However, why is it not playing? [18:17.720 --> 18:27.700] If the root server is inside China and you will pass the router again, and you will get the wrong IPs. [18:28.480 --> 18:37.880] So, there are some complications related to the DNS hierarchy and the Unicast IP, all those details. [18:38.460 --> 18:56.260] But still, for countries around China, there is a chance that they are going to be a chance they will pick up that root server and ask about, say, voa.gov, and then got a fake IP. [18:58.140 --> 19:04.240] And so, more about implication of the DNS hijacking thing. [19:04.400 --> 19:06.080] First is overblocking. [19:06.240 --> 19:14.500] And what they do is they are matching with, kind of like, they are matching with wild card. [19:14.860 --> 19:19.960] So, anything that voa.gov will get a fake IP. [19:21.260 --> 19:26.800] Then, so what happened is, like, one of the keywords they have is dweb. [19:27.100 --> 19:32.080] Because the name of our network for Chinese to access block website is called dynoweb. [19:32.620 --> 19:39.760] So, we have some domain contains the stream dword or dtw, some similar stream. [19:39.960 --> 19:48.020] So, when they put dweb onto their blacklist, they will also block www.3dweb.com. [19:49.260 --> 20:00.640] So, if anywhere you're living in the world, if your DNS package happened to cross the boundary between China and outside world, you will get a fake IP. [20:00.880 --> 20:02.400] So, that's overblocking. [20:02.400 --> 20:07.400] So, I did some search about dweb. [20:08.260 --> 20:12.720] So, this keyword will block 2,000 different domains. [20:13.880 --> 20:23.700] And they changed their blacklist and some details for a couple of times since 2002 September. [20:24.100 --> 20:26.880] So, now voa.gov is not blocked. [20:26.880 --> 20:29.460] I mean, the domain name is not hijacked. [20:29.620 --> 20:31.880] But their IP is still blocked. [20:32.680 --> 20:38.880] Now, the keyword lists are mostly related to dynoweb. [20:39.720 --> 20:48.960] Since we used to rely on domain name and keep switching the domain name to different IPs to get around the IP block. [20:49.180 --> 20:56.780] So, now since they are doing the DNS hijacking, so this kind of trick won't be a reliable way. [20:57.740 --> 21:14.680] And, as I just mentioned, if Verisign puts a root server into China, there is possibility that people in Taiwan or South Korea or India, maybe they can access some of the blacklisted domain. [21:16.720 --> 21:17.440] Okay. [21:17.800 --> 21:21.180] And then there are some different scenario. [21:21.500 --> 21:25.380] You can take it as your exercise at home. [21:25.380 --> 21:28.960] Because of the complication with the DNS hierarchy. [21:29.280 --> 21:39.000] So, if you query your local ISP's DNS server, it actually has to go around, maybe you query the root server. [21:39.420 --> 21:41.940] And so, it's kind of complicated. [21:42.440 --> 21:50.340] In what kind of situation you will actually finally have a package cross the boundary. [21:50.340 --> 21:54.840] So, there are different combinations I want to go through. [21:58.220 --> 21:58.900] Okay. [21:59.180 --> 22:05.920] So, there are also other kinds of Internet censorship method China use. [22:06.140 --> 22:11.120] And so, the number one is more like the administrative method. [22:11.400 --> 22:15.200] So, they will put pressure on all the business in China. [22:15.200 --> 22:18.060] So, one big example is Yahoo China. [22:18.340 --> 22:27.900] They signed some petition and saying that they were doing self-censorship and remove any illegal content, things like that. [22:28.200 --> 22:32.820] And then, technically, they basically block... [22:32.820 --> 22:35.760] They try to censor everything. [22:42.200 --> 22:43.000] Okay. [22:43.500 --> 22:47.000] So, a quick summary of what I just said. [22:47.560 --> 22:56.600] So, China has developed huge capability to censor their Internet traffic. [22:57.080 --> 22:59.440] And they are putting lots of people there. [23:00.940 --> 23:04.720] The human rights organizations say there are 30,000. [23:04.720 --> 23:09.460] And so, those people are working for government. [23:09.720 --> 23:11.760] So, I guess nobody will work hard. [23:12.000 --> 23:24.160] So, our small group is able to maintain DynWeb and provide service to now tens of thousands daily visitors. [23:27.360 --> 23:36.160] And so, just now, I mentioned the TCP level, the UDP, and IP level. [23:36.380 --> 23:40.660] So, next, I'm going to move on to the other two layers. [23:41.500 --> 23:42.620] Well, wait a minute. [23:42.800 --> 23:45.400] You've got a bullet point on there that says made for free. [23:45.580 --> 23:46.220] Oh, okay. [23:46.580 --> 23:47.500] So, yeah. [23:47.940 --> 23:48.560] That's important. [23:48.780 --> 23:48.960] Do you [23:52.560 --> 23:56.520] have anything other than allocations to back that up? [23:56.520 --> 23:57.220] Or is it... [23:57.220 --> 24:06.900] The reason I ask is there's been Chinese router companies that have stolen Cisco firmware quite blatantly and gotten mailed for doing that. [24:07.220 --> 24:15.580] So, is it maybe possible that it's an adaptation of a pirated Cisco source developed in China, not necessarily Cisco? [24:15.880 --> 24:16.420] Yeah. [24:16.560 --> 24:18.980] I don't have too much information about that. [24:19.300 --> 24:20.780] So, for the... [24:20.780 --> 24:25.700] Technically, I'm studying it as a black box. [24:25.700 --> 24:28.540] And there are various reports. [24:29.040 --> 24:34.740] One is from Ethan Gatman, and the other one is from Greg Walton, the Golden Shale report. [24:34.960 --> 24:38.240] And he's saying that Nortel is doing that. [24:38.560 --> 24:42.480] And also, there are kind of... [24:42.480 --> 24:45.720] Some kind of network security affair in China. [24:45.960 --> 24:52.640] And there you can see lots of vendors trying to sell this kind of product to China. [24:52.640 --> 24:57.000] No, I don't have really specific information for that. [24:57.200 --> 24:57.800] Question? [24:58.860 --> 24:59.300] Yes. [24:59.680 --> 25:08.680] Back about three or four slides ago, there was something about technology where you send more than 20 messages. [25:09.300 --> 25:11.940] Can you flip back a couple of slides? [25:12.240 --> 25:12.840] There it is. [25:12.960 --> 25:17.560] Any communication technology that reach more than 20 people quickly is censored. [25:17.560 --> 25:22.360] Well, if that's true, why are we getting thousands and thousands of spam messages from China? [25:25.280 --> 25:25.760] Because... [25:25.760 --> 25:26.320] Okay, yeah. [25:26.420 --> 25:29.860] That's something I'm going to talk more about later on. [25:30.060 --> 25:40.660] So, the main focus of the Internet censorship is political information, or anything that governments define as political, not really spam. [25:41.440 --> 25:43.280] I mean commercial spam. [25:44.900 --> 25:44.980] Okay. [25:46.780 --> 25:47.140] Question? [25:47.500 --> 25:47.800] If... [25:48.960 --> 25:50.780] Bill, do you want to hold all the questions till the end? [25:50.920 --> 25:51.740] Would that be more convenient? [25:52.720 --> 25:53.380] Okay, yeah. [25:53.620 --> 25:53.940] Thank you. [25:54.180 --> 25:56.480] Okay, so if everybody would just please hold your questions till the end. [25:56.600 --> 25:58.900] We'll get to the presentation and give them a chance to answer afterwards. [26:03.160 --> 26:03.800] Okay. [26:04.480 --> 26:08.820] So, now I'm going to switch to the analogy with metrics. [26:09.280 --> 26:10.120] I think... [26:10.120 --> 26:10.840] Yeah, yeah. [26:10.960 --> 26:11.580] There you... [26:11.580 --> 26:13.780] In the movie, you know, the first thing... [26:14.680 --> 26:16.160] What's this guy's name? [26:16.320 --> 26:16.460] Yeah. [26:16.460 --> 26:20.140] Morphys want to show to Neo is what the reality is. [26:20.460 --> 26:21.240] They show him... [26:21.240 --> 26:22.260] Show him the field. [26:22.520 --> 26:34.380] Only after that, you can have better understanding of what those technologies are doing, and then back to understand better what the illusion is. [26:35.940 --> 26:46.660] So, as a warm up, I will start with media control and try to compare what's going on in China with what's going on here. [26:47.200 --> 26:51.260] For media control, in China it's full control. [26:51.260 --> 26:57.840] So, for all the business, including foreign business trying to enter China markets. [26:57.840 --> 27:03.800] So, they have close control of what can be reported, what cannot be reported. [27:04.180 --> 27:09.280] For Internet, there are specific rules that they cannot have independent reports. [27:09.620 --> 27:13.080] They can only copy from the traditional media. [27:20.740 --> 27:24.300] The technology I talked about is mostly blocking. [27:24.700 --> 27:26.960] So, they want to stop the traffic. [27:27.960 --> 27:34.440] And, in effect, this will tailor the Internet, kind of appear as the way they want. [27:34.440 --> 27:40.840] So, you can only see information saying positive, saying something positively about the government. [27:40.840 --> 27:50.300] And also, in effect, those business in China, they will actively comply to this. [27:51.580 --> 27:54.100] And so, this is kind of self-censorship. [27:57.000 --> 28:00.900] And then, yeah, there is another effect from this blocking. [28:01.820 --> 28:08.360] And so, it's here, you want to put a big picture here, say, our big brother is watching you. [28:08.360 --> 28:11.620] So, someone wants to remind you you are watched. [28:11.840 --> 28:14.440] But in China, they want you to know. [28:15.580 --> 28:19.600] Because they want to create a self-censorship for everybody. [28:20.240 --> 28:25.520] So, like, when you are in, like, email. [28:26.600 --> 28:31.700] So, if you have certain words in your email, and then you realize that your email can go through. [28:31.700 --> 28:32.860] This is a simple example. [28:33.500 --> 28:36.980] So, it's very easy to know the censorship is there. [28:37.160 --> 28:50.080] And also, for the main website, the forum or BBS, they will post there saying that, do not post anything the government doesn't like, something like that. [28:50.160 --> 28:51.360] Otherwise, we will be in trouble. [28:51.360 --> 28:56.650] So, everybody know government is have strong regulation with ISP. [28:57.300 --> 29:04.840] And there are all kinds of ways to block their efforts to communicate the information government like. [29:05.720 --> 29:09.060] And, yeah, they are logging. [29:10.220 --> 29:12.100] Some of the information are logged. [29:12.280 --> 29:15.860] And then, they will try to trace down who is doing that. [29:15.860 --> 29:19.960] And then, those information will be known by others. [29:20.120 --> 29:23.760] So, this will, again, create more self-censorship. [29:28.720 --> 29:34.400] So, let's go more directly to the real world in China. [29:34.700 --> 29:39.640] So, people are arrested for what they are doing on the Internet. [29:39.940 --> 29:41.180] So, from the left to right. [29:41.500 --> 29:44.980] So, this man is webmaster. [29:44.980 --> 29:53.700] So, because he hosts websites and allowing people to say something about democracy or the government corruption. [29:54.300 --> 29:57.040] So, he was arrested. [29:57.300 --> 30:05.840] And this girl in the middle, what she did is, she wrote articles and posted on the Internet. [30:06.700 --> 30:09.600] And those are rather mild articles. [30:09.600 --> 30:12.200] And after a while, he caught attention. [30:12.560 --> 30:20.630] And then, very likely, the ISP gave out her, the ISP gave out her IPs. [30:21.360 --> 30:23.740] And then, the policeman is able to track her down. [30:24.180 --> 30:34.520] So, there are, for this kind of activities, there are, like, maybe hundreds of writers famous on the Internet. [30:34.520 --> 30:39.040] So, many of them got different kinds of harassment or sent to jail. [30:39.360 --> 30:43.060] And the third one is even more low-key. [30:43.500 --> 30:56.000] What she did is, she received information related to Falun Gong through email from some email server outside China. [30:56.000 --> 30:59.820] And she was arrested, just for this. [31:04.320 --> 31:10.620] So, the next step is, so, for those people who got into prison. [31:11.000 --> 31:16.280] So, there are, here, I'm going to show a few pictures. [31:16.620 --> 31:24.540] Those pictures are taken in the model demonstration in Chicago by some Falun Gong. [31:24.540 --> 31:30.820] And so, those are demonstrations about a torch in Chinese prisons. [31:31.180 --> 31:39.220] And a torch is rather common, especially for the so-called conscience crime. [31:39.460 --> 31:43.220] So, you are charged because of what you think. [31:44.160 --> 31:45.900] And so, think about it. [31:45.980 --> 31:50.200] This is different from, you, someone steals something and he got caught. [31:50.200 --> 31:52.560] So, he will say, oh, I didn't do it. [31:52.660 --> 31:54.700] Or he may say, oh, I'm sorry. [31:54.720 --> 31:59.040] So, please do not charge me too much. [31:59.180 --> 32:07.940] But for this kind of so-called crime, people will, many people will insist on, think the way they think is right. [32:07.940 --> 32:19.900] So, the authority will try to, so, this is why there are more cases of torch in, for those kind of so-called crime. [32:20.400 --> 32:25.300] So, yeah, really quickly, I will pick up a few examples. [32:25.740 --> 32:33.800] Yeah, for this one, what happened is the policeman will dig a bamboo stick into a finger. [32:33.800 --> 32:47.380] And so, those two are, people will be holding some confined, small sale for extended time, even weeks. [32:48.420 --> 32:52.220] And so, not too much time. [32:52.340 --> 32:54.080] So, I will move to the next. [32:54.580 --> 32:58.540] So, those are not individual cases. [32:58.540 --> 33:01.080] It happens throughout China. [33:01.580 --> 33:10.800] In, since 1999, there are 1,000 confirmed cases of Falun Gong practitioners. [33:11.160 --> 33:13.440] They died in detention. [33:14.300 --> 33:21.520] And so, those are, think about it, those are some of the torch case resulted in death. [33:21.520 --> 33:25.720] And those are information you can get because of all those censorship. [33:26.360 --> 33:29.160] So, the actual number should just be larger. [33:29.580 --> 33:31.000] And it's nationwide. [33:31.020 --> 33:33.940] And it has been going on up to now. [33:34.800 --> 33:41.280] And also, according to those policemen, it's from the order from higher officials. [33:41.280 --> 33:54.400] And they have some quota, like each month, during all those torches, how many people are allowed to die. [33:55.000 --> 34:03.000] So, some statistics, there are, this is the death distribution across different provinces in China. [34:03.000 --> 34:05.640] So, you can see, it's everywhere. [34:05.960 --> 34:07.620] And those are the numbers. [34:08.560 --> 34:12.600] The death case, you can see, it keeps increasing. [34:14.520 --> 34:15.180] Okay. [34:15.740 --> 34:23.540] So, I will continue on a little bit about my argument about the conscious crime. [34:23.540 --> 34:31.440] So, it's different from, like, some crazy people that just have fun with touching people. [34:31.780 --> 34:33.840] Or they just want to kill people. [34:34.000 --> 34:34.680] This kind of thing. [34:35.000 --> 34:39.700] The goal of the torch or killing is to change people's mind. [34:39.980 --> 34:44.600] This is an attack on the human spirituality. [34:45.680 --> 34:49.680] And all those things are on the background of the media control. [34:49.680 --> 34:57.240] So, from the beginning, it's hard for people to get to know the real information. [34:57.480 --> 35:01.380] All those cases are covered up in China. [35:01.760 --> 35:11.380] And also, with all the economic opportunities in China. [35:11.660 --> 35:15.780] And so, there are various ways. [35:15.780 --> 35:22.080] So, China is getting collaboration from the business in outside China. [35:22.440 --> 35:24.140] Like, the Yahoo China case. [35:24.920 --> 35:31.600] If you search Yahoo for certain keywords, the result is very different from what you got on Google. [35:31.860 --> 35:41.880] All the information the Chinese government doesn't like, you cannot find it on Yahoo China's search engine. [35:49.920 --> 35:50.560] Okay. [35:51.020 --> 35:58.420] So, I think all those things should come to an end. [35:59.100 --> 36:03.580] First, I think more and more people are being aware of this. [36:03.580 --> 36:15.600] And what I think is important is we want to facilitate the information flow of what's going on in China to here. [36:15.820 --> 36:19.200] And also, let them flow inside China. [36:19.360 --> 36:21.000] So, that's what I'm trying to do. [36:21.320 --> 36:25.680] And also, you can share those information with your friends. [36:25.680 --> 36:30.340] So, last slide summary. [36:30.800 --> 36:35.000] There are severe human rights violations in China. [36:35.520 --> 36:42.800] And China controls the Internet and also all kinds of information channels. [36:44.680 --> 36:50.920] And so, to learn more information, you can followinfo.net. [36:50.920 --> 36:54.220] That's more about the persecution related to Falun Gong. [36:54.480 --> 36:57.300] And hrichina.org. [36:57.300 --> 37:00.080] So, that's the Human Rights in China website. [37:00.700 --> 37:02.280] And 6-4 Memo. [37:02.460 --> 37:07.100] That's about June 4th, Tiananmen Square. [37:09.320 --> 37:15.020] China 21, that's about the persecution related to Christian. [37:15.440 --> 37:18.460] And they have... their website is not very good. [37:18.600 --> 37:20.000] I tried to find a picture there. [37:20.120 --> 37:24.100] I remember I saw it about a torch picture, but I can't find it. [37:24.240 --> 37:27.740] And also, our website, dit-inc.us. [37:27.940 --> 37:31.180] And you can contact me at this email address. [37:32.220 --> 37:32.760] Okay. [37:32.920 --> 37:34.220] So, now we are open to questions. [37:52.510 --> 37:54.390] What do you mean by host file? [37:54.730 --> 37:57.050] You mean locally put on users? [37:57.450 --> 37:57.950] Okay. [37:58.450 --> 37:58.550] Yeah. [37:58.970 --> 38:06.130] So, it's kind of related to more details of our network. [38:06.130 --> 38:15.050] So, you need a way to tell the users in China the IP of our network. [38:15.210 --> 38:16.270] Which is keep changing. [38:16.790 --> 38:18.310] Because China will try to block it. [38:19.710 --> 38:20.830] So, then... [38:21.290 --> 38:25.190] Lots of this question is related to kind of chicken-egg problem. [38:25.490 --> 38:31.950] So, for this host file, you have some hard-coded IP, which will be blocked very soon. [38:31.950 --> 38:39.050] So, still we need to find a channel to deliver updated IP information to users. [38:40.070 --> 38:41.310] Last question. [38:42.410 --> 38:43.250] Okay. [38:43.770 --> 38:47.390] I've had a little bit of experience tunneling outside. [38:53.430 --> 38:58.750] And I was wondering, have you noticed major differences between the mainland and Hong Kong? [38:59.850 --> 39:02.890] Hong Kong, from my observation, is kind of split. [39:02.890 --> 39:07.230] Some of the ISP is not blocked. [39:07.470 --> 39:12.470] And some ISP has all those IP blocking TCP, UDP things. [39:13.290 --> 39:14.630] That's what I've noticed. [39:14.630 --> 39:18.870] In Hong Kong, you can usually get VPN tunnels directly out to the rest of the world. [39:19.110 --> 39:19.370] Yeah. [39:19.470 --> 39:23.950] Actually, there are some people running a T1 line in China. [39:23.950 --> 39:28.390] They just cross the little river in between Hong Kong and mainland. [39:28.730 --> 39:30.050] And then they can get around. [39:30.870 --> 39:31.550] Right on. [39:33.850 --> 39:34.430] Okay. [39:34.570 --> 39:34.950] Thank you.