[HN Gopher] Considered "18+"
___________________________________________________________________
Considered "18+"
Author : elvis70
Score : 329 points
Date : 2022-05-03 13:47 UTC (9 hours ago)
(HTM) web link (daniel.haxx.se)
(TXT) w3m dump (daniel.haxx.se)
| donatj wrote:
| A number of my personal sites end up blocked by corporate
| firewalls. It's slightly infuriating. Even my own company. I got
| in a literal fight with IT needing to justify the _why_ in why I
| needed access to my own website. Like I can live without it, but
| it's nothing but my blog where I rant about tech. The why should
| be _why_ is it blocked to begin with. The default state should
| not be _blocked_.
| dylan604 wrote:
| >I got in a literal fight with IT needing to justify the why in
| why I needed access to my own website.
|
| Legitimately asking, why _do_ you need access to your private
| website on corporate resources during work? Access your private
| stuff on your BYOD.
| kevincox wrote:
| I occasionally link to my blog articles when I am trying to
| make a point. It is often better to reference my well-
| thought-out and composed arguments rather than typing them
| out again on-demand with less thought.
|
| Although that is not a very strong justification.
| gopher_space wrote:
| I'm not looking to work with people who need me to justify
| the info I gather or the tools I use.
|
| The problem isn't what I want to do it's having an
| intermediary in the process who only introduces drag.
| hanoz wrote:
| _> a literal fight with IT_
|
| How did that pan out?
| Someone1234 wrote:
| The word "model" as in "Data Model" or "Mathematical Model" is
| blocked at my work. Why? Because otherwise people might look up
| clothing models or something... This impacts multiple
| programming divisions and has not been lifted even after it was
| raised.
| spogbiper wrote:
| Any exception to the firewall policy requires supporting
| documentation. IT may just be covering their own ass/literally
| doing their job properly when they ask for the justification.
| bragr wrote:
| As a manager, I've noticed people tend to overthink the
| "business justification" field on forms and get themselves
| all worked up that they are being told no because they know
| what to put, but in reality all you normally need to do is
| string together a handful of words that vaguely makes sense
| to the person processing the request so they can check a box.
| unethical_ban wrote:
| Counterpoint: The sole purpose of a business network is to
| execute the requirements of the business. Any extraneous
| activity on the network is at least noise, and at most a direct
| threat to the business. The #1 way in which networks get
| infected is through phishing and employee downloads.
|
| On a corporate network, it can make total sense to block non-
| business sites by default. As someone who used to help manage
| the proxies at a bank, some of the arbitrary decisions annoyed
| me (like blocking gTLDs of all sorts by default) but at the end
| of the day, it was an inconvenience. There were mechanisms to
| request access if needed.
|
| To me, it starts to get more shady with behavioral analytics
| software on terminals that measure your known patterns of
| access and look for aberrations. It becomes intrusive and
| creepy in its move from "passive" filtering to active,
| personalized monitoring.
|
| ---
|
| All that is irrelevant here, because an ISP fucking with my TLS
| connection and throwing up warnings is awful.
| JoeAltmaier wrote:
| BUt some manager's idea of what are business sites, and the
| staff's idea, can be very different.
|
| I don't mean entertainment; I mean suits making decisions
| about what engineering needs etc.
| unethical_ban wrote:
| Yes, it is a bureaucratic pain for IT to request access to
| download a tool for testing, etc. and in many places that
| may be overkill.
|
| Again, prior experience, we had brainstormed the idea of
| denying any executable downloads by frontline workers,
| while permitting it for IT, since frontline workers both
| were less likely to need to download random EXEs, and less
| likely to know how to spot phishing or grayware sites.
| raxxorraxor wrote:
| Default approach of a firewall. When it doubt, block it. But IT
| has really outdone itself and grew to something that could be
| the largest threat to an open internet.
|
| The same could happen to mail, where you can only use
| "certified provider" or you will just be filtered out. Spam and
| phishing are a problem, sure, but recent IT strategies are
| highly questionable in this regard.
| smhenderson wrote:
| _but recent IT strategies are highly questionable in this
| regard._
|
| I think it of as a result of high profile hacks. Either a
| company is hacked once and they go way overboard trying to
| ensure it doesn't happen again. Or, some high profile company
| gets hacked, some C*O's see it, overreact and decide they're
| not going to be next.
| Thiez wrote:
| Incidentally this is also why you see a lot of stuff being
| communicated over https. The other ports are "suspicious".
| Root_Denied wrote:
| Considering the landscape of spam, phishing, and malicious
| actors poking around what's your alternative solution to how
| firewall rules (and category lists generated and maintained
| by companies like Palo Alto) are currently applied? The IT
| side of things has limited tools (and budget) with which to
| control and secure the internal environment.
|
| IMO there's also a failure of government here to both ensure
| an open internet and to come down on people abusing the
| system. A related example might be the phone spam calls
| everyone in the US gets - it's an administrative, legal, and
| regulatory problem, not a technical one.
|
| My context may be a bit skewed though since I'm a sysadmin
| turned cybersecurity and I've seen the large numbers of
| people clicking on the absolute _stupidest_ things. Given the
| "average" computer use that IT has to deal with I'm much more
| sympathetic to their plight.
| coding123 wrote:
| And there's still devs that want the in-office life still..
| donatj wrote:
| We've been working home for 2 years. They want us to run all
| traffic through the VPN that applies the same filtering.
| Please excuse me if I forget to turn it on.
| gopher_space wrote:
| Here's some lag in your process because c-level can't stop
| downloading ringtones.
| nybble41 wrote:
| One would hope you still have separate personal device(s)
| which you can use without connecting through their VPN, in
| addition to the corporate-owned ones used for work. Or do
| they want you to run all your _personal_ traffic through
| the VPN as well?
| Symbiote wrote:
| Even more ridiculous: several small sites run by my team, from
| our own public IP space, have been blocked by the corporate
| firewall.
|
| There has never been anything wrong with them, it's just
| braindead blocking software purchased by incompetent managers.
| nonrandomstring wrote:
| > just braindead blocking software purchased by incompetent
| managers.
|
| Having been that IT person early in my career, responsible
| for networks, firewalls and policies, what you say sounds
| cruel. But I could not agree more. Today there is a tragic
| de-skilling in ICT. When I speak to modern corporate or
| academic IT people I make the best faith assumptions. I
| assume they are like we were in the early 90s and speak to
| them accordingly with technical respect. Then I discover they
| cannot configure a mail or web server, cannot compile a
| program, or even use a package manager... they don't know how
| to read logs or change permissions on a directory.... the
| mind boggles. I've had senior IT people tell me that they're
| "not technical" and it turns out they've arrived on some
| "management track" from an arts-history background.
|
| I'm not knocking arts history, or being "elitist" I hope, but
| this raises serious concerns for me. What is going on in IT?
| Have cloud services, tick-box webmin interfaces and packaged
| solutions led to a brain drain?
|
| One could argue that modern IT people don't need "geeky
| computer skills" any more, because Google and Microsoft have
| solved everything. But that doesn't pan out, because when
| simple things go wrong they cannot fix them (which is their
| job). Right now I am dealing with an international university
| whose impeccable pedigree is bedrock in computing history -
| and their IT people cannot fix a simple email issue, to the
| extent the staff and students have to set up their own
| servers. The fact is, they just don't have control over it
| any longer. I think the entire senior ranks are just marking
| time till they can retire.
| ugjka wrote:
| Yeah "We block 50% more than our competitors" "Good deal!"
| exedore6 wrote:
| Regarding braindead blocking software and incompetent
| managers - all blocking software is braindead and what's
| worse, opaque (good luck finding out why a site is blocked,
| the devs don't care). Us incompetent managers often end up
| purchasing them do tick a check box required by the insurance
| company and/or the government, neither of which care that
| it's all snake oil.
| isaacfrond wrote:
| It is not totally clear from the article, but it appears Vodafone
| blocks a site as 'for 18+' when really it is a case of an
| incorrect certificate. To get round it you need to register with
| Vodafone.
|
| At least google allows me to click away such warnings (while
| warning that doom is imminent).
| sofixa wrote:
| Isn't the certificate "incorrect" only because Vodafone block
| the site and intercept the TLS connection? That's why the
| "incorrect" TLS cert presented mentions Vodafone's "solution"
| for traffic filtering. That's my read of things.
| peppermint_tea wrote:
| same. Just inspected the original cert (not on vodaphone
| here) and the cert is verified by GlobalSign nv-sa
| edent wrote:
| Many years ago, I used to work for Vodafone - and had some
| responsibility for their filtering stuff.
|
| One of the main problems was that, at the time, it was all
| managed by Blue Coat. As they were a US company, many of the
| "violations" that they picked up just weren't considered
| problematic for a UK / EU audience.
|
| Similarly, they would use blanked keyword blocking. So sex
| education resources would frequently get blocked. Although,
| again, that may have been by puritanical design.
|
| Anything which looked like it might be used to bypass their
| filters (VPN, proxies, etc) were also blocked.
|
| Ultimately, the customer isn't the user. It is the network who
| are terrified that Johnny's parent is going to go to the papers
| screaming about how the evil phone company corrupted their
| innocent child. That's all it is there for - to protect the
| network.
| j_san wrote:
| > As they were a US company, many of the "violations" that they
| picked up just weren't considered problematic for a UK / EU
| audience.
|
| Just out of curiosity: could you provide some examples?
| LorenPechtel wrote:
| While I can't provide examples a UK company isn't going to
| care about bare breasts.
| ______-_-______ wrote:
| I wonder what the disconnect is that causes people to blame
| Vodafone for content requested over their network, but not
| Royal Mail for the content that arrives in their mailbox, or
| Google/Chrome for the content of webpages, or Dunder Mifflin
| for content printed on paper. Has that ever actually happened,
| or is it just corporate risk aversion?
| pc86 wrote:
| Well there was that quabbity assuence issue with the two
| cartoon characters..
| joosters wrote:
| Oddly enough, vodafone filtering is less restrictive in other
| ways. For instance, they never blocked The Pirate Bay, but I
| just switched ISP from vodafone and my new ISP (Sky) blocks the
| site via some TLS tricks. It's odd because while adult content
| blocks are purely a per-ISP choice (they offer it as a
| service/choice to customers), I had thought that TPB was
| blocked because of court orders. So how come one ISP blocks it,
| and other doesn't?
| manarth wrote:
| > "I had thought that TPB was blocked because of court
| orders. > So how come one ISP blocks it, and other
| doesn't?"
|
| The court order[1] had 6 defined defendants:
| - BRITISH SKY BROADCASTING LIMITED - BRITISH
| TELECOMMUNICATIONS PLC - EVERYTHING EVERYWHERE LIMITED
| - TALKTALK TELECOM GROUP PLC - TELEFONICA UK LIMITED
| - VIRGIN MEDIA LIMITED
|
| The court order only affected the listed ISPs (at that time,
| 94% share of the consumer ISP market). Other ISPs were under
| no obligation to do the same.
|
| [1] http://www.bailii.org/cgi-
| bin/markup.cgi?doc=/ew/cases/EWHC/...
| posterboy wrote:
| No obligation? The DA could sue immediately in the public
| interest, or if not it could be the original plaintiff, and
| then the remaining ISPs would have the opportunity to
| defend their cause themselves.
| nybble41 wrote:
| > The DA could sue immediately in the public interest...
|
| It's not in the public interest to block TPB. The DA
| would be suing for the sake of _private_ interests,
| against the public, and at the public 's expense.
| ArchOversight wrote:
| There's no DA in the UK.
| IfOnlyYouKnew wrote:
| Not criminal law. No DA. (You do get "plaintiff" right,
| so I'm mildly confused)
| doublerabbit wrote:
| If you wish to throw conspiracy in to the mix, data logging
| for govermentental safe-keeping. Sounded like scifi in the
| 00's.
| dmlorenzetti wrote:
| _Similarly, they would use blanked keyword blocking. So sex
| education resources would frequently get blocked._
|
| I had a colleague whose surname, Sextro, was part of his email
| address. He occasionally had messages blocked by blanket
| filters like that.
| _joel wrote:
| Praying for all the people who use the shortened form of
| Richard
| rajangdavis wrote:
| Rich?
| filoleg wrote:
| I believe they were referecing a bit more relevant to the
| discussion short version of "Richard", which is "Dick".
| sedeki wrote:
| Interesting, TIL.
| rmetzler wrote:
| Try again.
| lmc wrote:
| Chard?
| rhdunn wrote:
| Richard is often shortened to Dick, e.g. as in "Tom,
| Dick, and Harry".
| olyjohn wrote:
| I know that Dick is another name for Richard. But Why?
| They don't seem to even be plays off of the same name,
| nor do they sound the same at all.
|
| It's like if another name for John was Frank. It makes
| zero sense.
| bregma wrote:
| Wait until you find out what Peggy, Betty, or Tina are
| short forms of.
| gambiting wrote:
| My wife's name is Aleksandra, but the short version of
| that is Ola. Similarly, Olek is a short for Aleksander.
| Also no idea why.
| melissalobos wrote:
| > Olek is a short for Aleksander.
|
| Very likely this is due to both being transliterations
| from Cyrillic.
| aleksiy123 wrote:
| This is correct.
|
| Oleksander is Ukranian form of Aleksander.
| mod50ack wrote:
| It comes from Middle English rhyming slang. Rick -> Dick;
| Rob -> Bob.
| Beldin wrote:
| Wait till you find out about "Buffy".
|
| https://en.wikipedia.org/wiki/Buffy
| jodrellblank wrote:
| Wait till you find out about "Tiffany"
|
| https://www.youtube.com/watch?v=9LMr5XTgeyI (CGP Grey)
|
| (spoiler: he couldn't find out where it came from, and
| did this video on his research to explain more:
| https://www.youtube.com/watch?v=qEV9qoup2mQ )
| thaumasiotes wrote:
| The standard of counting as "Tiffany" is strange. He's
| not happy with Theophano or Theophania, but he's
| perfectly happy to count (French) Tiphaine, Thifaine,
| Thiephaine, and (English) Tephany as being "obviously"
| the modern name. But the difference between Tephany and
| Theophania is down to the "Th" at the beginning. Why
| agonize over the difference between the very well-
| attested Greek Theophania and modern Tiffany if it's so
| clear that medieval Tephany matches the modern form? It's
| a _better_ match for the Greek form!
| sokoloff wrote:
| Another name for John is Jack, though.
| E4YomzYIN5YEBKe wrote:
| It likely originated in rhyming slang where words that
| rhyme are used as replacement[0]. It isn't the only
| example in nick names. Bill is a nickname for William and
| Bob is a nickname for Robert.
|
| [0] https://en.wikipedia.org/wiki/Rhyming_slang
| smhenderson wrote:
| Did you know people often use Jack as a shorthand for
| John? JFK was often, famously, referred to as Jack
| Kennedy when he was alive...
| cwp wrote:
| And of course he married a woman named Jacqueline.
| gadders wrote:
| See also Prince Harry (Duke of Sussex) who was christened
| Henry.
| sandworm101 wrote:
| The ultimate litmus test for such filtering.
|
| https://en.wikipedia.org/wiki/Dick_Van_Dyke
|
| And a favorite tech blog/news website that is often
| blocked:
|
| https://torrentfreak.com/
| giraffe_lady wrote:
| or literally
| https://en.wikipedia.org/wiki/Scunthorpe_problem
| sandworm101 wrote:
| or.. https://en.wikipedia.org/wiki/Shit_My_Dad_Says
| https://en.wikipedia.org/wiki/$h*!_My_Dad_Says
|
| The later (TV-Show) is actually based on the former
| (twitter feed) but couldn't retain the name in the US. It
| would probably have been perfectly fine as is in the UK.
| hermitdev wrote:
| As a racing fan, Dick Trickle [0] (retired NASCAR driver)
| is also a fun name.
|
| [0] https://en.wikipedia.org/wiki/Dick_Trickle
| anticristi wrote:
| I wonder how such filters work in Sweden. We often see
| advertisement like "Sex gym i stan!". Meaning "Six gyms in
| town!".
| yakshaving_jgt wrote:
| Swedes aren't quite so puritanical, as I think you know. In
| Swedish culture it's apparently funny when small children
| make jokes about bajskorvar.
| _fat_santa wrote:
| Is this filtering an extra feature like parental controls or
| corporate filtering? Or was this just blanket filtering applied
| to all Vodafone customers?
| kalleboo wrote:
| In the UK the filtering is on by default. The customer can
| opt out of the filtering by contacting the ISP and requesting
| to opt out.
|
| https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin.
| ..
| mnd999 wrote:
| My ISP asked my if I wanted filtering when I signed up.
| Amusingly if you say yes it suggests you find a different
| ISP.
| mhandley wrote:
| AAISP? That sounds like the Reverend.
| protomyth wrote:
| _Ultimately, the customer isn 't the user. It is the network
| who are terrified that Johnny's parent is going to go to the
| papers screaming about how the evil phone company corrupted
| their innocent child. That's all it is there for - to protect
| the network._
|
| You're not kidding. The biggest fear is a parent complaining
| because a library or school filter fails. People really don't
| give a damn what a hard problem it is nor do they care that
| browsers are starting to add counter measures to skip over ISP
| filtering. Doesn't matter if you don't have control of the
| laptop, you are still to blame. At this point, I wonder what
| the next generation of filtering software is going to do.
| dylan604 wrote:
| I can see where filtering just takes the standard US
| insurance companies policy of deny, deny, deny.
| diseasedyak wrote:
| I worked for over a decade as a DBA for one of the largest
| private data warehouse companies, and it was hilariously fun to
| get the so-called "naughty word list" for customer suppression
| reasons. I learned so many creative slurs based on where people
| live or were born.
|
| Australians, in particular, have an amazing amount of curse
| words/racial slurs.
| hsbauauvhabzb wrote:
| Automated services need a mandatory human resolution service with
| a legal avenue if the service is substandard.
|
| Looking at you, google.
| EMIRELADERO wrote:
| For once I am happy to live in a third-world country. This
| wouldn't fly here, thanks to the telecommunications law:
|
| ARTICLE 57. - Network neutrality. Prohibitions. Service Providers
| shall not:
|
| a) Block, interfere, discriminate, hinder, degrade or restrict
| the use, sending, reception, offering or access to any content,
| application, service or protocol except by court order or express
| request of the user.
| travisporter wrote:
| I'm glad he was able to resolve this. I get the feeling most
| people wouldn't care, because after all they're not blocking
| instagram/facebook/tiktok.
| gsich wrote:
| Where have you read that? It reads to me that he applied for
| unblocking, but no result as of yet.
| travisporter wrote:
| Sorry you're right I misread that. I can't edit the above
| comment
| isaacfrond wrote:
| He is still blocked. According to:
|
| https://www.blocked.org.uk/site/http://daniel.haxx.se
| joeberon wrote:
| It's because there are too many x's in the name
| jka wrote:
| I'd bet it's because the filtering vendor (Allot) sells a
| simple interface to the customer (Vodafone) that mostly
| consists of allowlist/blocklist entries manually added by
| support agents when someone complains.
|
| There's probably a policy to dictate what content should be
| filtered, but in practice: a ticket is filed to block a site,
| someone looks at the ticket, in all likelihood it is added to
| the blocklist, and then probably ends up there forever until
| complaints are raised.
|
| You could be correct that the presence of multiple x's in the
| URL makes it more likely for support agents to think "yep, this
| is probably sketchy, there's no harm adding it to the
| blocklist" - I doubt it's the original reason though.
| pimlottc wrote:
| Clearly it's a website of sex hacks. Or a saxophone curse, I'm
| not sure...
| gpvos wrote:
| It's Swedish too!
| Minor49er wrote:
| From the article:
|
| > It shows that this filter is for this specific host name
| only, not for the entire haxx.se domain.
| hayd wrote:
| Related "The Conservative Woman" has been blocked by Three:
| https://www.conservativewoman.co.uk/yes-tcw-is-being-censore...
|
| It's sad we're living in times we must exclusively use a VPN.
| freedomben wrote:
| Meta-comment mostly meant for @dang
|
| daniel.haxx.se is Daniel Stenberg's blog (famously known as curl
| maintainer), and would best be displayed with the subdomain as
| daniel.haxx.se rather than haxx.se, similar to how substacks
| include the subdomain to make it clear at a glance what the
| source is.
| gus_massa wrote:
| Send an email to hn@ycombinator.com He usually reply the same
| day. IIRC they only show subdomains for sites that have a lot
| of posts, but it's not a hard rule so he may make an exception.
| mperham wrote:
| It's maddening that there's no audit trail or public record you
| can use to debug "why?".
|
| I had my domain put on a phishing blacklist due to DNS caching.
| During a 30 minute cache window, I decommissioned a server and a
| bad actor picked up the recycled server's IP address. The IP
| reverse lookup showed my domain due to the cache.
| captainbland wrote:
| I'm very much of the opinion that such filtering should be opt-in
| rather than opt-out. Now don't get me wrong, it should be trivial
| for a parent to opt in if they want to but I fundamentally don't
| agree that it should be the default to child-proof the internet.
|
| Otherwise ISPs are basically collecting a list of self-identified
| internet deviants by whatever definition they have. I mean at
| least make them do a bit of work to process my DNS history to
| figure that out...
|
| Not to mention the point of the article, that the filtering is
| often overzealous and captures the weirdest things.
| nimbius wrote:
| im always chuffed and fascinated when tech companies cloister
| themselves in the robes of moral arbiter. Twitter does this now,
| albeit it seems like a cheap excuse to pump user numbers by
| forcing authentication.
|
| Why 18? why not 21? or 23? What qualifies as explicitly "adult"
| content? violence perhaps could disqualify most military
| recruiting sites from my vodaphone. Alcohol? its certainly a
| moral vice in the UAE but in germany even a fourteen year old can
| order a bier with their parents. Sex? its a sensitive subject for
| even the most conservative among us until we touch upon religious
| texts, which seem to enjoy free reign.
|
| what i wonder most is...what is the altruistic moral source of
| truth used as litmus by Voda and others? or is it driven largely
| by a small but vocal minority or is the board pushing this as
| some sort of nineteenth century neo-victorian purity charge.
| HL33tibCe7 wrote:
| Parents want parental controls on their children's devices, and
| that becomes part of their decision on which provider to choose
| for their children's phone contracts. Vodafone is reacting to
| market desire for an optional feature, there isn't some evil
| spooky ulterior motive at play.
| Reubensson wrote:
| I thought these restrictions were set by UK goverment, not by
| individual operators.
|
| Edit: I am not sure if age restriction check is responsibility
| of sites themselves or service providers according to UK law.
| 0daystock wrote:
| The people responsible for making and distributing this type of
| software and filters for it are mediocre minds, it's as simple
| as that. It gives them (usually an overzealous IT person) power
| and thus identity over smarter engineers, turning it a sadistic
| spectacle sport for them. The only answer is to remove their
| power by using end-to-end encryption with programs like Tor and
| simply laugh at their pathetic antics.
| imglorp wrote:
| > pump user numbers by forcing authentication
|
| Pump, how? Wouldn't forcing ID tank the numbers when all the
| bots are excluded?
| advisedwang wrote:
| It makes users who previously accessed a site anonymously
| create accounts or leave. For some sites, the increase in
| users signed-in may be worth the loss of other users (and
| bots).
| steventhedev wrote:
| These content filtering schemes are usually legally mandated,
| and the age of 18 is set by law.
|
| More likely than not, this got caught up in a regular job that
| scans DNS zones for new domains to "filter". It's just a matter
| of time before this catches anything related to Scunthorpe[0].
|
| [0]: https://en.m.wikipedia.org/wiki/Scunthorpe_problem
| II2II wrote:
| > These content filtering schemes are usually legally
| mandated, and the age of 18 is set by law.
|
| It's also worth adding that 18 is typically the age when
| someone is considered legally accountable for their actions
| as an adult. We shouldn't be surprised that this age pops up
| in so many laws because of that, even though it is an
| arbitrary line in most cases.
| jjjensen90 wrote:
| The odd thing is that in most countries the age of consent
| is below (sometimes significantly below) 18. So we've got
| strange mixed signals.
| willyt wrote:
| Vodafone is a mess. I bought a 24Gb pre-paid sim which was
| supposed to last 2 years but they 'lost' my plan after 6months
| and 2Gb of data use. Spent an hour on chat with them telling me
| that no such plan had ever existed until I told them I had all
| the receipts and evidence of how much data I had used and
| threatened to take them to the small claims court with expenses
| at PS60/hr for my time. They capitulated quickly after that and
| restored it, then 'lost' my plan again the next month.
|
| I've had problems with billing glitches with four utility
| companies in the UK now and I am starting to suspect that
| overcharging people and hoping they don't notice is actually a
| common business strategy in the industry and if they get caught
| they blame bad IT but really their systems are configured to do
| this on purpose.
| ectopod wrote:
| I think it's semi deliberate. They put systems in place to
| catch errors that cost them money but they don't go looking for
| errors that cost their customers. The result is inevitable but
| there is enough plausible deniability to avoid any serious
| consequences for the company.
| astura wrote:
| _Sigh_ Automatic classification of material as "adult" has
| always sucked. I remember watching a news report where schools
| filters had classified webpages referencing the current Super
| Bowl (Super Bowl XXX) as adult content due to XXX typically being
| associated with adult material.
|
| The opposite happens too - see Elsagate. The newest version of
| Elsagate material, which I've only seen one person talking about,
| is weird/inappropriate stories aimed at children but disguised as
| baking videos - https://youtu.be/HfcKCk6vPCE?t=295
| gregmac wrote:
| Yikes, this is so much worse than merely _weird_ , though it
| definitely is that.
|
| Here's the transcript from a couple, both of which are played
| over top of those "5-minute craft" style (faked) baking videos:
|
| > > Someone knocked on the front door. I opened it and saw a
| strange tiny man standing there with a creepy smile on his face
| and he smells really good.
|
| > > He said "Hi I'm Noah I'm looking for your dad, is he home?"
|
| > > I replied "No he's out there looking for a stupid job."
|
| > > I was about to close the door in his face when he suddenly
| pushed it back open. I screamed, I thought he was going to hurt
| me. He took off his glasses and told me to stay calm. He looked
| a lot less intimidating without his glasses on and his face was
| softer.
|
| > > I said "okay, come on in"
|
| https://youtu.be/HfcKCk6vPCE?t=436
|
| Or:
|
| > > After one of my live youtube videos one of my viewers sent
| a message asking if we could meet. It was a bit strange for
| someone to be so insistent, especially after what my brother
| was doing so I ignored him at first. Then, a few days later, he
| messaged me again. He said he knew how to deal with my brother.
| He believed me. I agreed to meet him but I was nervous. What if
| it's just a stupid prank, I wondered. I went to the coffee shop
| he had asked me to go to. I didn't even know his name.
|
| > And in that story he turns out to be a handsome knight in
| shining armor who rescues her from all her troubled home life
| problems.
|
| https://youtu.be/HfcKCk6vPCE?t=485
| LorenPechtel wrote:
| There is no decent solution to the Scunthorpe problem. It
| doesn't matter how many try, they never succeed.
| vorpalhex wrote:
| The thing that gets me with the elsagate material is that it is
| weird. More weird than offensive. Is this just machine written
| content that has gone a bit nuts?
| hatware wrote:
| I learn a little more about net neutrality every day.
| gorgoiler wrote:
| Good! curl is a dangerous tool that can be used to circumvent
| deep link protections for corporate intellectual property.
| Imagine the kinds of evil that can be done by pirates if they are
| able to construct a URL and then simply fetch it using this so
| called haxx (hacks, aka hackers) tool.
| [deleted]
| K0nserv wrote:
| I have a Virgin Media subscription for my phone and a while back
| I discovered that sometimes Reddit didn't load. It took me a
| while to figure out that it was on 4G and happened because I'd
| been using Virign's DNS servers. This is a similar "adult
| filter", that most UK ISPs implement.
|
| AFAIK the filtering isn't legally mandated, but something the
| ISPs decide on together based on a some government memo. In any
| case it's dead simple to bypass and a very blunt tool. For
| example, why does Virigin block Reddit, but not Twitter? Both
| sites feature adult content, in fact so does Google image search.
|
| The silver lining in all this stupidity is perhaps that it
| creates a more technically talented population. I don't expect
| most teenagers know or want to know about DNS, but if that's what
| stands between them and adult content I'm sure they'll learn.
| fuzzy2 wrote:
| ESNI cannot come fast enough.
| Avamander wrote:
| It's ECH now, Chromium/Google are actively working in it. So
| soon(tm)
|
| In addition to that we need ODoH and NTS as well. It's pretty
| clear neither countries or ISPs (not to mention attackers) can
| keep their grubby fingers out of anything unencrypted. MITM
| should be visible or impossible.
| slowmovintarget wrote:
| Isn't ECH the new new?
| https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-08
| raxxorraxor wrote:
| Yes, we really need that. Glad we have TLS and questionable
| ambitions show that it doesn't even reach deep enough.
|
| Although the way the web works a web request to domain.xy
| doesn't mean much anyway but people still believe in it.
|
| Also MITM attacks in IT security should be shunned and I
| believe the users need to be informed about it when they
| happen. IT could potentially steal banking information. I
| believe this to be highly illegal in my country and still a
| data breach even if an employee wasn't allowed to do the
| transaction because it was private.
| hathym wrote:
| They must have a rule like this one: return
| all([c in 'haxx.se' for c in ['s', 'e', 'x']])
| LeifCarrotson wrote:
| They are to catch those sneaky, morally subversive domains like
| 'xes-spelled-backwards.com'!
| nly wrote:
| Par for the course. It's more or less untenable to surf in the UK
| without a VPN.
| Terretta wrote:
| Can't think what the "ha" would stand for in their analysis, but
| the se and xx can be indicators of adultness when you have a
| naive algo for dealing with bot spam domains for adult-content-
| as-spam:
|
| _Some even started using multiple X 's (i.e. XX, XXX, etc.) to
| give the impression that their film contained more graphic sexual
| content than the simple X rating. In some cases, the X ratings
| were applied by reviewers or film scholars, e.g. William Rotsler,
| who wrote "The XXX-rating is for Hardcore, the XX-rating is for
| Softcore, and an X-rating is for comparatively cool films."_ --
| https://en.wikipedia.org/wiki/X_rating
|
| That said if they think the domain is a soft hit they should look
| at content, site age and classification in e.g. bluecoat, etc.,
| which would counter the soft domain indicator. If the site allows
| comments and doesn't always successfully moderate or filter out
| adult bot spam links, that can make even clean content sites get
| filtered. To be clear, not! aware of any spam at this site, but
| as a heads up to anyone w/ open commenting, comment engines that
| allow a website link are often bot-bait.
| josephcsible wrote:
| I don't think that has anything to do with it, because of this:
|
| > It shows that this filter is for this specific host name
| only, not for the entire haxx.se domain.
| sockmeistr wrote:
| No offence to the other members of haxx, but I suspect
| Daniel's site is the only one that gets enough traffic to be
| considered for filtering.
| LordDragonfang wrote:
| Somehow that seems worse. Don't apply automatic filters to
| sketchy, fly-by-night spam sites that pop up and disappear,
| but _do_ apply purely automatic filters to sites with a
| significant enough amount of legitimate traffic?
|
| That seems to be exactly backwards of the way things
| _should_ be done if it wasn 't mostly security theater.
| [deleted]
| cryptonector wrote:
| Daniel Stenberg is such a haxx.or, I guess.
| inetknght wrote:
| 1. intercept traffic to IP
|
| 2. present custom "valid" certificate
|
| 3. ???
|
| 4. profit!
|
| ... isn't this something that certificate transparency should
| help solve?
| cryptonector wrote:
| > isn't this something that certificate transparency should
| help solve?
|
| No. CT is meant to help _find_ illegitimate server certificate
| issuance by participating CAs, but it cannot help the user-
| agent get _past_ illegitimate server certs.
|
| Besides, the whole point here is to make the user-agent fail to
| load the page, therefore the network operator's firewall's CA
| would not participate in CT (nor be a CAB member), and the
| network operator does not just not mind that the illegitimate
| server certificate is noticed, they _want it noticed_.
| inetknght wrote:
| > _CT is meant to help find illegitimate server certificate
| issuance by participating CAs, but it cannot help the user-
| agent get past illegitimate server certs._
|
| That's the point though. I'd rather the user-agent tell me
| that the certificate is invalid. That's as far as it's
| currently going anyway when a certificate is, for example,
| self-signed.
|
| > _Besides, the whole point here is to make the user-agent
| fail to load the page,_
|
| That's exactly the minimum that _should_ happen, yes. User-
| agent sees that the certificate isn 't correctly issued for
| the domain and refuses to send the HTTP request (though SNI
| is already sent...)
|
| > _the network operator does not just not mind that the
| illegitimate server certificate is noticed, they want it
| noticed._
|
| More than just noticed: the network operator wants the user
| to _inappropriately act_ on the illegitimate server
| certificate.
| sp332 wrote:
| Why would they bother doing a TLS handshake with a phony
| certificate?
| xmodem wrote:
| How else could they let the end user know what's going on? Due
| to pinning, it's either present a phony certificate, or
| completely fail the connection and give the user no indicationo
| why.
|
| Of course, accepting the phony certificate will immediately
| leak your cookies to the middlebox, along with giving it
| permission to read any credentials out of local storage. So as
| an end user you should not accept it.
| JonathonW wrote:
| If you were a school or other institutional user using this
| filtering service (which isn't just marketing to service
| providers like Vodafone), you'd probably have their root CA
| installed so your users see the filter error page instead of
| just an SSL error.
| digitallyfree wrote:
| And if this wasn't bad enough, they want your credit card info to
| unblock the site.
| philjohn wrote:
| UK citizen here - yeah, it's supper annoying. It's to verify
| you're over 18 as that's the age at which you can obtain a
| credit card.
|
| You can though ring the mobile phone provider and tell them to
| turn off the block - and we can blame our conservative
| government for pushing this through (and looking to go even
| further in the future).
| hsbauauvhabzb wrote:
| Citation? I wonder if the card authorities would be pleased to
| hear that.
| digitallyfree wrote:
| There's a screenshot of the block page in the original post.
|
| "3. Use your credit card to confirm your age (you won't be
| charged)."
|
| https://daniel.haxx.se/blog/wp-
| content/uploads/2022/05/vodaf...
| nickdothutton wrote:
| My own blog (Cyber Security related) was also blocked by a couple
| of mobile operators in the UK the last time I checked. The
| internet has been dead for some years now.
___________________________________________________________________
(page generated 2022-05-03 23:01 UTC)