Green Dam
   HOME

TheInfoList



OR:

Green Dam Youth Escort () is
content-control software An Internet filter is software that restricts or controls the content an Internet user is capable to access, especially when utilized to restrict material delivered over the Internet via the Web, Email, or other means. Such restrictions can be appl ...
for Windows developed in the
People's Republic of China China, officially the People's Republic of China (PRC), is a country in East Asia. With population of China, a population exceeding 1.4 billion, it is the list of countries by population (United Nations), second-most populous country after ...
(PRC) which, under a directive from the
Ministry of Industry and Information Technology The Ministry of Industry and Information Technology (MIIT) is the sixth-ranked executive department of the State Council of the People's Republic of China. It is responsible for regulation and development of the postal service, Internet, wireles ...
(MIIT), was to take effect on 1 July 2009, as a mandatory pre-install, or have the setup files on an accompanying compact disc, for all new personal computers sold in
mainland China "Mainland China", also referred to as "the Chinese mainland", is a Geopolitics, geopolitical term defined as the territory under direct administration of the People's Republic of China (PRC) in the aftermath of the Chinese Civil War. In addit ...
, including those imported from abroad. Subsequently, this was changed to be voluntary. End-users, however, are not under a mandate to run the software. As of 30 June 2009, the mandatory pre-installation of the Green Dam software on new computers was delayed to an undetermined date. However, Asian brands
Sony is a Japanese multinational conglomerate (company), conglomerate headquartered at Sony City in Minato, Tokyo, Japan. The Sony Group encompasses various businesses, including Sony Corporation (electronics), Sony Semiconductor Solutions (i ...
, Acer,
Asus ASUSTeK Computer Inc. (, , , ; stylized as ASUSTeK or ASUS) is a Taiwanese Multinational corporation, multinational computer, phone hardware and electronics manufacturer headquartered in Beitou District, Taipei, Taiwan. Its products include deskto ...
,
BenQ BenQ Corporation (; ) is a Taiwanese multinational company that sells and markets technology products, consumer electronics, computing and communications devices under the "BenQ" brand name, which is an acronym of the company slogan "Bringing ...
and
Lenovo Lenovo Group Limited, trading as Lenovo ( , zh, c=联想, p=Liánxiǎng), is a Chinese multinational technology company specializing in designing, manufacturing, and marketing consumer electronics, personal computers, software, servers, conv ...
etc. were shipping the software as was originally ordered. On 14 August 2009,
Li Yizhong Li Yizhong (; born 1945) is a former director of Minister of Industry and Information Technology of the People's Republic of China. Personal life and education Yizhong was born during 1945 in Datong City, Shanxi Province. He graduated Beijing P ...
, minister of industry and information technology, announced that computer manufacturers and retailers were no longer obliged to ship the software with new computers for home or business use, but that schools, internet cafes and other public use computers would still be required to run the software. Devoid of state funding since 2009, the business behind the software was on the verge of collapsing by July 2010. According to ''
Beijing Times The ''Beijing Times'' () is a Chinese newspaper published in Beijing owned by the ''People's Daily''. History ''Beijing Times'' was launched in May 2001. When it started, ''Beijing Times'' had 12% of the Beijing newspaper market and its percent ...
'', the project team under Beijing Dazhang, one of the two companies responsible for development and support of the software, have been disbanded with their office shut down; also in a difficult situation, the team under Zhengzhou Jinhui, the other company, are likely to suffer the same fate at any time. The 20 million users of the software will lose technical support and customer service should the project cease operation.


Functions

Designed to work with
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
operating systems, the software was developed by Zhengzhou Jinhui Computer System Engineering Ltd. (郑州金惠计算机系统工程有限公司 – Jinhui) with input from Beijing Dazheng Human Language Technology Academy Ltd. (北京大正语言知识处理科技有限公司 - Dazheng). The software, commissioned by the Ministry of Industry and Information Technology through open tender worth 41.7 million yuan in May 2008, is at least officially aimed at restricting
online pornography Internet pornography or online pornography is any pornography that is accessible over the Internet; primarily via websites, FTP connections, peer-to-peer file sharing, or Usenet newsgroups. The greater accessibility of the World Wide Web from the ...
; however, it may be used for electronic censorship and surveillance in addition to its stated purpose. Green Dam Youth Escort automatically downloads the latest updates of a list of prohibited sites from an online database, and also collects private user data. Bryan Zhang, the founder of Jinhui, said that users would not be permitted to see the list, but would have the option of unblocking sites and uninstalling the software. Additional search terms can also be blocked at the owner's discretion.


Scope

A notice issued by the Ministry of Industry and Information Technology on 19 May stated that, as of 1 July 2009, manufacturers must ship machines to be sold in China with the software preloaded—either pre-installed or enclosed on a compact disc, and that manufacturers are required to report the number of machines shipped with the software to the government. A separate notice on the ministry's website required schools to install the software on every computer in their purview by the end of May. The ministry shortlisted products from two suppliers, Jinhui and Dazheng. According to the directive, the aim is to "build a healthy and harmonious online environment that does not poison young people's minds".
Qin Gang Qin Gang (born 19 March 1966) is a Chinese former diplomat and politician who served as the 12th Minister of Foreign Affairs (China), Minister of Foreign Affairs from December 2022 to July 2023 and as State councillor, State Councillor from Mar ...
, spokesman for the foreign ministry, said the software would filter out pornography or violence: "The purpose of this is to effectively manage harmful material for the public and prevent it from being spread," adding that " e Chinese government pushes forward the healthy development of the internet. But it lawfully manages the internet". In June 2009, state-run Chinese media announced that the installation of the Green Dam Youth Escort would not be compulsory but an optional package.


Trials

In 2008, under instructions from political leaders, the MIIT implemented a "community-oriented green open Internet filtering software project" with the support of the Central Civilisation Office and the
Ministry of Finance A ministry of finance is a ministry or other government agency in charge of government finance, fiscal policy, and financial regulation. It is headed by a finance minister, an executive or cabinet position . A ministry of finance's portfoli ...
. Its aim was to build a "green, healthy network environment, to protect the healthy growth of young people". Trials commenced in
Zhengzhou Zhengzhou is the capital of Henan, China. Located in northern Henan, it is one of the nine National central city, national central cities in China, and serves as the political, economic, technological, and educational center of the province. Th ...
,
Nanjing Nanjing or Nanking is the capital of Jiangsu, a province in East China. The city, which is located in the southwestern corner of the province, has 11 districts, an administrative area of , and a population of 9,423,400. Situated in the Yang ...
,
Lanzhou Lanzhou is the capital and largest city of Gansu province in northwestern China. Located on the banks of the Yellow River, it is a key regional transportation hub, connecting areas further west by rail to the eastern half of the country. His ...
, and
Xi'an Xi'an is the list of capitals in China, capital of the Chinese province of Shaanxi. A sub-provincial city on the Guanzhong plain, the city is the third-most populous city in Western China after Chongqing and Chengdu, as well as the most populou ...
in October 2008 after the ministry negotiated with the software suppliers and 50 web portals to make the software publicly available without charge, and more than 2,000 installations took place. Trials rolled out to 10 more cities, including
Chengdu Chengdu; Sichuanese dialects, Sichuanese pronunciation: , Standard Chinese pronunciation: ; Chinese postal romanization, previously Romanization of Chinese, romanized as Chengtu. is the capital city of the Chinese province of Sichuan. With a ...
,
Shenyang Shenyang,; ; Mandarin pronunciation: ; formerly known as Fengtian formerly known by its Manchu language, Manchu name Mukden, is a sub-provincial city in China and the list of capitals in China#Province capitals, provincial capital of Liaonin ...
,
Harbin Harbin, ; zh, , s=哈尔滨, t=哈爾濱, p=Hā'ěrbīn; IPA: . is the capital of Heilongjiang, China. It is the largest city of Heilongjiang, as well as being the city with the second-largest urban area, urban population (after Shenyang, Lia ...
, and
Qingdao Qingdao, Mandarin: , (Qingdao Mandarin: t͡ɕʰiŋ˧˩ tɒ˥) is a prefecture-level city in the eastern Shandong Province of China. Located on China's Yellow Sea coast, Qingdao was long an important fortress. In 1897, the city was ceded to G ...
. The ministry claimed that by December 2008, the software had been downloaded more than 100,000 times, and 3 million times since the end of March 2009. Five leading PC vendors in mainland China,
Founder Founder or Founders may refer to: Places *Founders Park, a stadium in South Carolina, formerly known as Carolina Stadium * Founders Park, a waterside park in Islamorada, Florida Arts, entertainment, and media * Founders (''Star Trek''), the ali ...
,
Lenovo Lenovo Group Limited, trading as Lenovo ( , zh, c=联想, p=Liánxiǎng), is a Chinese multinational technology company specializing in designing, manufacturing, and marketing consumer electronics, personal computers, software, servers, conv ...
, Tongfang,
Great Wall The Great Wall of China (, literally "ten thousand Li (unit), ''li'' long wall") is a series of fortifications in China. They were built across the historical northern borders of ancient Chinese states and Imperial China as protection agains ...
and HEDY, also participated in trial installations.


Censorship concerns

Professor
Jonathan Zittrain Jonathan L. Zittrain (born December 24, 1969) is an American professor of cyber law, Internet law and the George Bemis Professor of International Law at Harvard Law School. He is also a professor at the Harvard Kennedy School, a professor of co ...
, of Harvard's Berkman Center said: "Once you've got government-mandated software installed on each machine, the software has the keys to the kingdom... While the justification may be pitched as protecting children and mostly concerning pornography, once the architecture is set up it can be used for broader purposes, such as the filtering of political ideas." Colin Maclay, another Harvard academic, said that Green Dam creates a log file of all of the pages that the user tries to access. "At the moment it's unclear whether that is reported back, but it could be." In fact, the current software filter contains about 85% political keywords, and only 15% pornography-related keywords. An analysis of the University of Michigan shows that Green Dam examines text input in different applications for words such as obscenities and other banned words (e.g.,
Falun Gong Falun Gong, also called Falun Dafa, is a new religious movement founded by its leader Li Hongzhi in China in the early 1990s. Falun Gong has its global headquarters in Dragon Springs, a compound in Deerpark, New York, United States, near t ...
). Green Dam utilizes a word list for more complex algorithm processing in its unencrypted file "FalunWord.lib," which contains primarily words related to Falun Gong.


Reception and responses


Computer industry

In June 2009, the
computer industry A computer is a machine that can be programmed to automatically carry out sequences of arithmetic or logical operations (''computation''). Modern digital electronic computers can perform generic sets of operations known as ''programs'', ...
advocacy organization,
Computer and Communications Industry Association The Computer and Communications Industry Association (CCIA) is an international non-profit advocacy organization based in Washington, DC, United States which represents the information and communications technology industries. According to their ...
(CCIA), said the development was "very unfortunate". Ed Black, CCIA president criticised the move as "clearly an escalation of attempts to limit access and the freedom of the internet, ..witheconomic and trade as well as cultural and social ramifications." Black said the Chinese were attempting to "not only control their own citizens' access to the internet but to force everybody into being complicit and participate in a level of censorship". The CCIA was reported to be taking up a test case for American tech companies wishing to present "a united front against censorship" and it called on the
Obama administration Barack Obama's tenure as the 44th president of the United States began with his first inauguration on January 20, 2009, and ended on January 20, 2017. Obama, a Democrat from Illinois, took office following his victory over Republican nomine ...
to intervene with Beijing over the requirement that manufacturers pre-install the software on all new computers. On 8 June,
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
said that appropriate parental control tools were "an important societal consideration". However, " this case, we agree with others in industry and around the world that important issues such as freedom of expression, privacy, system reliability and security need to be properly addressed." An international group of business associations urged the government to scrap the Green Dam directive in a letter to Chinese Premier Wen Jiabao. The letter was signed by the heads of 22 organisations representing international businesses, including the U.S. Chamber of Commerce, the European-American Business Council, the Information Technology Industry Council and other associations from North America, Europe, and Japan. In moves which the ''
San Francisco Chronicle The ''San Francisco Chronicle'' is a newspaper serving primarily the San Francisco Bay Area of Northern California. It was founded in 1865 as ''The Daily Dramatic Chronicle'' by teenage brothers Charles de Young and M. H. de Young, Michael H. ...
'' suggested were politically motivated by the quest for closer ties, Taiwanese manufacturers Acer, Asus, BenQ announced they were already shipping products with Green Dam as originally ordered, joined by Sony and Lenovo.


Public

Online polls conducted by leading Chinese web portals revealed poor acceptance of the software by
netizen The term ''netizen'' is a portmanteau of the English words ''internet'' and ''citizen'', as in a "citizen of the net" or "net citizen". It describes a person actively involved in online communities or the Internet in general.
s. On
Sina Sina may refer to: Relating to China * Chin (China), or Sina (), old Chinese form of the Sanskrit name Cina () ** Shina (word), or Sina (), archaic Japanese word for China ** Sinae, Latin name for China Places * Sina, Albania, or Sinë, a vi ...
and
Netease NetEase, Inc. () is a Chinese Internet technology company founded by Ding Lei in June 1997. It provides online services with content, community, communications, and commerce. The company develops and operates online PC and mobile games, adverti ...
, over 80% of poll participants said they would not consider or were not interested in using the software; on
Tencent Tencent Holdings Ltd. ( zh, s=腾讯, p=Téngxùn) is a Chinese Multinational corporation, multinational technology Conglomerate (company), conglomerate and holding company headquartered in Shenzhen. It is one of the highest grossing multimed ...
, over 70% of poll participants said it was unnecessary for new computers to be preloaded with filtering software; on
Sohu Sohu, Inc. () is a Chinese Internet company headquartered in the Sohu Internet Plaza in Haidian District, Beijing. Sohu and its subsidiaries offer advertising, a search engine (Sogou.com), on-line multiplayer gaming (ChangYou.com) and other se ...
, over 70% of poll participants said filtering software would not effectively prevent minors from browsing inappropriate websites. A poll conducted by the ''Southern Metropolis Daily'' showed similar results. A report by the
OpenNet Initiative The OpenNet Initiative (ONI) was a joint project whose goal was to monitor and report on internet filtering and surveillance practices by nations. Started in 2002, the project employed a number of technical means, as well as an international netwo ...
project acknowledged the broad global support for measures to help parents limit exposure of their children to harmful online material and published a detailed report on the technical and political flaws of this software and its implications. Internet citizens have created a
manga are comics or graphic novels originating from Japan. Most manga conform to a style developed in Japan in the late 19th century, and the form has a long history in earlier Japanese art. The term is used in Japan to refer to both comics ...
-style
Moe anthropomorphism is a form of anthropomorphism in anime, manga, and games where '' moe'' qualities are given to non-human beings (such as animals, plants, supernatural entities and fantastical creatures), objects, concepts, or phenomena. In addition to ''moe' ...
named 'Green Dam Girl' (; Japanese: ), similar to the
OS-tan OS-tans are ''moe'' anthropomorphic personifications of popular operating systems, originating on the Japanese imageboard Futaba Channel. The designs of the OS-tans, which were created by various amateur Japanese artists, are typically female; ...
s. Many versions exist, but the common features are that she is dressed in green, wears a river crab hat, holding a rabbit (the Green Dam mascot) in hand, and armed with a paintbrush. She also commonly wears an armband with the word ''Discipline'' written on it. On 11 June 2009, a team released a third-party tool aiming to provide users with options to disable the software, change the master password and perform post-uninstallation clean-up (i.e., removing files and registry entries left behind by the uninstaller).


Government and manufacturer

A
BBC News BBC News is an operational business division of the British Broadcasting Corporation (BBC) responsible for the gathering and broadcasting of news and current affairs in the UK and around the world. The department is the world's largest broad ...
article reported that critics feared the new software could be used by the government to enhance the existing internet censorship system. Jinhui's general manager, ryanZhang Chenmin, rejected the accusation: "It's a sheer commercial activity, having nothing to do with the government" he said. On 10 June, amidst massive criticism circling within the internet about the software and the MIIT's directive, the
Publicity Department of the Chinese Communist Party The Publicity Department of the Central Committee of the Chinese Communist Party, also known as the Propaganda Department or Central Propaganda Department, is an internal division of the Central Committee of the Chinese Communist Party (CCP) ...
, the agency responsible for censorship, issued an instruction attributed to "central leaders" requiring the Chinese media to stop publishing questioning or critical opinions. Reports in defense of the official stand appeared subsequently, with a commentary by the state-run
Xinhua Xinhua News Agency (English pronunciation: ),J. C. Wells: Longman Pronunciation Dictionary, 3rd ed., for both British and American English or New China News Agency, is the official State media, state news agency of the China, People's Republic ...
news agency saying "support largely stems from end users, opposing opinions primarily come from a minority of media outlets and businesses". The instruction also required online forums to block and remove "offensive speech evolved from the topic" promptly. In response to the "public concern, anger and protest" triggered by the government edict, ''
China Daily ''China Daily'' ( zh, s=中国日报, p=Zhōngguó Rìbào) is an English-language daily newspaper owned by the Central Propaganda Department of the Chinese Communist Party. Overview ''China Daily'' has the widest print circulation of any ...
'' put forward the case for free choice, saying: "Respect for an individual's right to choice is an important indicator of a free society, depriving them of which is gross transgression." On 15 June, an official of the Department of Software Service under the MIIT downplayed the compulsory aspect of the software: "The PC makers only need to save the setup files of the program on the hard drives of the computers, or provide CD-ROMs containing the program with their PC packages" he said. Users will have the final say on whether or not to install the software, he continued, "so it is misleading to say the government compels PC users to use the software ... The government's role is limited to having the software developed and providing it free". Further critical articles appeared in both the state-run ''Peoples' Daily'' and the relatively liberal ''
China Youth Daily The ''China Youth Daily'' ( zh, s=中国青年报, t=, p=) is the official newspaper of the Central Committee of the Communist Youth League of China. It has been the newspaper of the Communist Youth League of China since 1951. It has occasional ...
'', a paper run by the China Youth League of which Chinese President Hu Jintao was a member and a patron. It leads to the belief that support for the MIIT's directive was divided within the Chinese government itself. On the eve of the introduction of the mandatory pre-installation of the Green Dam software on new computers, it was postponed. The MIIT said it would "keep on soliciting opinions to perfect the pre-installation plan." Ministry sources confirmed that the software had been patched, and that the government procurement procedure of the software "had complied with China's Government Procurement Law, which was open, fair, transparent, non-exclusive, ..under strict supervision" and "in line with regulations of the World Trade Organization"


US government

On meeting with officials of the MIIT and the ministry of commerce about Green Dam, American diplomats in China issued a statement:


Defects and software issues


Functional defects

Jinhui claimed that Green Dam recognized pornographic images by analyzing skin-coloured regions, complemented by human face recognition. However, according to a ''
Southern Weekly ''Southern Weekly'' () is a Chinese weekly newspaper based in Guangzhou, and is a sister publication of the newspaper '' Nanfang Daily''. From the 1990s to the early 2010s, the newspaper was renowned for its investigative journalism, liberal ...
'' article, the software is incapable of recognizing pictures of nudity featuring black- or red-skinned characters but sensitive enough to images with large patches of yellow that it censors promotional images of the film '' Garfield: A Tail of Two Kitties''. The article also cited an expert saying that the software's misrecognition of "inappropriate contents" in applications including
Microsoft Word Microsoft Word is a word processor program, word processing program developed by Microsoft. It was first released on October 25, 1983, under the name Multi-Tool Word for Xenix systems. Subsequent versions were later written for several other platf ...
can lead it to forcefully close those applications without notifying the user, thus cause data losses. On 21 June 2009, ''
Ming Pao ''Ming Pao'' () is a Chinese-language newspaper published by Media Chinese International in Hong Kong. In the 1990s, ''Ming Pao'' established four overseas branches in North America; each provides independent reporting on local news and coll ...
'' reported that the software detected and censored pictures of Chinese political leaders as pornography. On 11 June 2009, a
BBC News BBC News is an operational business division of the British Broadcasting Corporation (BBC) responsible for the gathering and broadcasting of news and current affairs in the UK and around the world. The department is the world's largest broad ...
article reported that potential faults in the software could lead to a large-scale disaster. The report included comments by Isaac Mao, who said that there were "a series of software flaws", including the unencrypted communications between the software and the company's servers, which could allow hackers access to people's private data or place malicious script on machines on the network to "affect large scale disaster". The software runs only on
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
x86 x86 (also known as 80x86 or the 8086 family) is a family of complex instruction set computer (CISC) instruction set architectures initially developed by Intel, based on the 8086 microprocessor and its 8-bit-external-bus variant, the 8088. Th ...
, so
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
x86-64 x86-64 (also known as x64, x86_64, AMD64, and Intel 64) is a 64-bit extension of the x86 instruction set architecture, instruction set. It was announced in 1999 and first available in the AMD Opteron family in 2003. It introduces two new ope ...
,
Mac OS X macOS, previously OS X and originally Mac OS X, is a Unix, Unix-based operating system developed and marketed by Apple Inc., Apple since 2001. It is the current operating system for Apple's Mac (computer), Mac computers. With ...
,
Linux Linux ( ) is a family of open source Unix-like operating systems based on the Linux kernel, an kernel (operating system), operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically package manager, pac ...
and users of other operating systems are ignored. Even on Microsoft Windows, the software is known to interfere with
Internet Explorer Internet Explorer (formerly Microsoft Internet Explorer and Windows Internet Explorer, commonly abbreviated as IE or MSIE) is a deprecation, retired series of graphical user interface, graphical web browsers developed by Microsoft that were u ...
and
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
, and is incompatible with
Mozilla Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements curren ...
. Also on 11 June 2009, a
Netease NetEase, Inc. () is a Chinese Internet technology company founded by Ding Lei in June 1997. It provides online services with content, community, communications, and commerce. The company develops and operates online PC and mobile games, adverti ...
article reported that the master password of the software could be easily cracked. The software stores the
MD5 The MD5 message-digest algorithm is a widely used hash function producing a 128-bit hash value. MD5 was designed by Ronald Rivest in 1991 to replace an earlier hash function MD4, and was specified in 1992 as Request for Comments, RFC 1321. MD5 ...
checksum A checksum is a small-sized block of data derived from another block of digital data for the purpose of detecting errors that may have been introduced during its transmission or storage. By themselves, checksums are often used to verify dat ...
of the password in a
text file A text file (sometimes spelled textfile; an old alternative name is flat file) is a kind of computer file that is structured as a sequence of lines of electronic text. A text file exists stored as data within a computer file system. In ope ...
disguised as a DLL (C:\Windows\System32\kwpwf.dll), thus the password can be arbitrarily set by changing the contents of the file. This was ridiculed by some
netizen The term ''netizen'' is a portmanteau of the English words ''internet'' and ''citizen'', as in a "citizen of the net" or "net citizen". It describes a person actively involved in online communities or the Internet in general.
s as the software being crackable by "elementary school students". Researchers from
University of Michigan The University of Michigan (U-M, U of M, or Michigan) is a public university, public research university in Ann Arbor, Michigan, United States. Founded in 1817, it is the oldest institution of higher education in the state. The University of Mi ...
found the uninstaller "appears to effectively remove Green Dam from the computer," whereas some sources state that part of the software (e.g. executables loaded on startup) cannot be removed by its own uninstaller, but that most of it (per either blogs or media reports) was removed according to the PRC government's request.


Security vulnerabilities

On 11 June 2009, Scott Wolchok, Randy Yao, and J. Alex Halderman from the
University of Michigan The University of Michigan (U-M, U of M, or Michigan) is a public university, public research university in Ann Arbor, Michigan, United States. Founded in 1817, it is the oldest institution of higher education in the state. The University of Mi ...
published an analysis of Green Dam Youth Escort. They located various
security vulnerabilities Vulnerabilities are flaws or weaknesses in a system's design, implementation, or management that can be exploited by a malicious actor to compromise its security. Despite a system administrator's best efforts to achieve complete correctness, vir ...
that can allow "malicious sites to steal private data, send spam, or enlist the computer in a
botnet A botnet is a group of Internet-connected devices, each of which runs one or more Internet bot, bots. Botnets can be used to perform distributed denial-of-service attack, distributed denial-of-service (DDoS) attacks, steal data, send Spamming, sp ...
" and "the software makers or others to install malicious code during the update process". They recommended that users uninstall the software immediately for protection. Jinhui's general manager, ryanZhang Chenmin attacked the Wolchok ''et al.'' report as irresponsible action and breach of his company's copyright, and said that Jinhui had been ordered to patch the weaknesses. Wolchok ''et al.'' indicated the existence of buffer overflow vulnerabilities which they ascribed to programming errors. Buffer overflow may occur when the software performs
URL A uniform resource locator (URL), colloquially known as an address on the Web, is a reference to a resource that specifies its location on a computer network and a mechanism for retrieving it. A URL is a specific type of Uniform Resource Identi ...
filtering or updates its blacklist filter files due to the use of fixed-length buffers, and can corrupt the execution stack and potentially allow execution of malicious code. Furthermore, the feature of automatic filter update opens the door to the computer being remotely controlled by the software's makers and possibly third parties who manage to impersonate the update server because the updates are delivered via unencrypted
HTTP HTTP (Hypertext Transfer Protocol) is an application layer protocol in the Internet protocol suite model for distributed, collaborative, hypermedia information systems. HTTP is the foundation of data communication for the World Wide Web, wher ...
. The report included an example page that exploits the buffer overflow vulnerability to crash the software. On 12 June 2009, an exploit that takes advantage of the same defect to practically deploy
shellcode In hacking, a shellcode is a small piece of code used as the payload in the exploitation of a software vulnerability. It is called "shellcode" because it typically starts a command shell from which the attacker can control the compromised ma ...
was published on the website milw0rm.com. The author of the exploit claimed that the exploit is able to bypass the DEP and
ASLR Address space layout randomization (ASLR) is a computer security technique involved in preventing exploitation of memory corruption vulnerabilities. In order to prevent an attacker from reliably redirecting code execution to, for example, a pa ...
protection mechanisms on
Windows Vista Windows Vista is a major release of the Windows NT operating system developed by Microsoft. It was the direct successor to Windows XP, released five years earlier, which was then the longest time span between successive releases of Microsoft W ...
.


Alleged software plagiarism and license violation

In addition to security vulnerabilities, Wolchok, Yao and Halderman also found that a number of blacklist files used by Green Dam Youth Escort were taken from the censorship program
CyberSitter An Internet filter is software that restricts or controls the content an Internet user is capable to access, especially when utilized to restrict material delivered over the Internet via the Web, Email, or other means. Such restrictions can be appl ...
, from
Solid Oak Software Solid is a state of matter where molecules are closely packed and can not slide past each other. Solids resist compression, expansion, or external forces that would alter its shape, with the degree to which they are resisted dependent upon the ...
Inc. The decrypted
configuration file A configuration file, a.k.a. config file, is a computer file, file that stores computer data, data used to configure a software system such as an application software, application, a server (computing), server or an operating system. Some applic ...
references blacklists with download URLs at CyberSitter's website. They also discovered in the software a news bulletin published by CyberSitter in 2004, whose inclusion was conjectured by them to be accidental. A post on the Chinese IT website Solidot published details of the taken files and claimed that the files were outdated. Both the Wolchok ''et al.'' report and a technical analysis released on
WikiLeaks WikiLeaks () is a non-profit media organisation and publisher of leaked documents. It is funded by donations and media partnerships. It has published classified documents and other media provided by anonymous sources. It was founded in 2006 by ...
indicated that software contains code libraries and a configuration file from the BSD-licensed
computer vision Computer vision tasks include methods for image sensor, acquiring, Image processing, processing, Image analysis, analyzing, and understanding digital images, and extraction of high-dimensional data from the real world in order to produce numerical ...
library
OpenCV OpenCV (Open Source Computer Vision Library) is a Library (computing), library of programming functions mainly for Real-time computing, real-time computer vision. Originally developed by Intel, it was later supported by Willow Garage, then Itseez ...
. The WikiLeaks document said the software violated the BSD license.


U.S. lawsuit

According to ''The Wall Street Journal'', Solid Oak, which had been apprised of the infringement, announced it would file injunctions on US manufacturers to stop them shipping machines with Green Dam. The report included a response by Jinhui Computer System Engineering Co. denying that they stole anything, quoting Bryan Zhang as saying "That's impossible". Internet lawyer
Jonathan Zittrain Jonathan L. Zittrain (born December 24, 1969) is an American professor of cyber law, Internet law and the George Bemis Professor of International Law at Harvard Law School. He is also a professor at the Harvard Kennedy School, a professor of co ...
said that if the computers are only sold in China it would not be a violation of U.S. copyright and the issue "would have to be resolved in a Chinese court under Chinese law". Solid Oak's Mr Milburn was reported by BBC News as saying that he is not sure legal action will be worth the effort, but would also file a complaint with the
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
's Computer Crime Task Force. Hewlett-Packard and Dell were sent
cease and desist A cease and desist letter is a document sent by one party, often a business, to warn another party that they believe the other party is committing an unlawful act, such as copyright infringement, and that they will take legal action if the oth ...
letters by Solid Oak Software, asking them to respond by 24 June, having determined "without a doubt that Green Dam is indeed pirated, and using 100 percent of our code". In January 2010, Cybersitter filed a $2.2 billion lawsuit against the PRC government and Jinhui Computer System Engineering charging that Green Dam Youth's developers had stolen more than 5,000 lines of code from Cybersitter. In December 2010, a California court denied a motion to have the suit dropped. The motion was filed by
Sony is a Japanese multinational conglomerate (company), conglomerate headquartered at Sony City in Minato, Tokyo, Japan. The Sony Group encompasses various businesses, including Sony Corporation (electronics), Sony Semiconductor Solutions (i ...
, Acer, BenQ and Asustek, who were named as defendants in a list that also includes Chinese PC makers
Lenovo Lenovo Group Limited, trading as Lenovo ( , zh, c=联想, p=Liánxiǎng), is a Chinese multinational technology company specializing in designing, manufacturing, and marketing consumer electronics, personal computers, software, servers, conv ...
and
Haier Haier Group Corporation () is a Chinese multinational home appliances and consumer electronics company headquartered in Qingdao, Shandong. Its Haier Smart Home Company affiliate, of which it owns 35%, designs, develops, manufactures and se ...
.


Reactions of the software's makers

According to an addendum to the Wolchok ''et al.'' report published on 18 June 2009, makers of Green Dam Youth Escort silently patched the software on 13 June, addressing at least the one particular buffer overflow vulnerability showcased in the original report. In spite of the patch, the software nevertheless remained vulnerable to more sophisticated attacks, as demonstrated by a new example attack page included in the addendum, leading the authors to stand by their previous recommendation that users uninstall the software immediately. According to the same addendum, an update was released on 12 June 2009 to reconfigure the software's filtering blacklists files, which modifies one blacklist and disables the rest. However, files taken from CyberSitter continue to be present on the computer even after the update, and are still used in a pre-update version of the software available from its makers' website. Another update was released on 17 June 2009 to include OpenCV's BSD license into the software's help file to address the license violation issue.


Loss of funding

The project was reportedly dead because the ministry refused to continue funding the project. The ''
Beijing Times The ''Beijing Times'' () is a Chinese newspaper published in Beijing owned by the ''People's Daily''. History ''Beijing Times'' was launched in May 2001. When it started, ''Beijing Times'' had 12% of the Beijing newspaper market and its percent ...
'' reported that Beijing Dazheng Human Language Technology Academy had closed the office for the Green Dam project and up to 30 IT engineers were made redundant, and that co-developer Zhengzhou Jinhui Computer System Engineering, would soon run into financial difficulties through lack of funding. However, Dazheng said it had been forced to downsize (and not shut) the Green Dam unit due to financial constraints. Dazheng's general manager said his company received 19.9 million yuan in the first year and had not received payment since, and that its commitment to providing support and updates for the product was costing 7 million yuan annually. Critics said the lack of transparency in the funding cut cast the Ministry in a bad light. In 2010, other commentators, whilst noting no change in the government's policy towards policing the Internet, said the de facto abandonment of the project was an admission of error.


See also

*
Content-control software An Internet filter is software that restricts or controls the content an Internet user is capable to access, especially when utilized to restrict material delivered over the Internet via the Web, Email, or other means. Such restrictions can be appl ...
*
Golden Shield Project The Golden Shield Project (), also named National Public Security Work Informational Project, is the Chinese nationwide network-security fundamental constructional project by the e-government of the People's Republic of China. This project i ...
, also known as the "Great Firewall of China" *
Internet censorship in the People's Republic of China The People's Republic of China (PRC) internet censorship, censors both the publishing and viewing of online material. Many controversial events are censored from news coverage, preventing many Chinese citizens from knowing about the actions of ...
* Wang Junxiu, Chinese internet entrepreneur and opponent of internet censorship


References


External links

{{Censorship in China Content-control software Internet censorship in China Science and technology in the People's Republic of China