
The last days have been marked by the next turn of the peculiar “cyberspace” blocking, will this be a stimulus for government agencies to technically “rewrite” the system of censorship of the Runet?.
The essence of what is happening is described in detail in this post , and it makes no sense to re -describe the events. Roskomnadzor has no adequate ways to counteract the “attack on the DNS on the DNS of the blocked Internet resource”. And so it is not so that Roskomnadzor has to write letters in which regional representatives of the supervisory authority give orphan instructions on the “ban on blocking” of certain IP addresses.
Roskomnadzor drove himself into the current state, which repeatedly, more than once, were warned by telecommunications specialists.
The following occurs administratively:
A kind of managerial loop ...
So what is the problem of the lock mechanism prescribed in the BY Design regulations?
Very simple. The Internet is a dynamic system that is constantly changing and adapting to conditions.
Well, for example, a register of prohibited sites , as an information database, contains the following fields - we give a screenshot:
We are interested in the fields of the domain/url and IP address.
Legally, practically and technically, the logical operand of the conjunction - “Logical and” should be practically and technically between these fields. The resource should be blocked, which has a “and” specified domain/url, “and” specified IP address.
But Roskomnadzor, the court, FSKN, and even the Ministry of Internal Affairs cannot affect the technical characteristics of the conformity of the “universal pointer of the resource” of the IP address. The system, I recall, dynamic-the parameters of the compliance of the URL and IP address are controlled by the domain owner. And this was done completely justified-you never know what can happen to the provider owning the IP address block. It was for this that DNS was invented back in 1987 (thirty years ago, by the way!) In the RFC-1034 .
Is it possible to somehow streamline and centralize the legislative registration of DNS by administrative order? I think no. Because not a single centralized system can be compared with performance with self -service systems, which, in fact, is the DNS system - the domain owner is free to register in Resource Records anything, any reason that will come to the mind of the owner.
And, what is important for the RKN-the entire DNS system is not in the jurisdiction of any state authorities. And even more so - Russian, who have nothing to do with the invention of the Global Network phenomenon.
Therefore, entries in the register according to the logic “and” do not have a practical sense-the owner of a blocked resource immediately “organizes a move” to another IP address and will become again accessible.
Therefore, in the register and the control audience “AS Aptionor”, expansion interpretations of the class are made: “Here we block, here we will not block, but we will still write the fine.” In the telegram channel “ I love the AC“ Examiner ” ” (which, by the way, employees of one of the divisions of the RKN-FSUE RCC are conducted), these practices are very violently discussed-I recommend for study.
At the same time, the expansion of the practice of blocking in the managerial control loop of the “revisor” to the logic “or” leads to very legally (and all the more so technically) insignificant practices of the “prohibition of locks”, as, for example, in the particular letter signed “acting Deputy Head ".
But the technical problems of the registry do not end there. Even more - they are just beginning! And the great problems of the idea of a black list with the current implementation are still ahead.
I see at least two technical problems that will occur in the very near future:
Simple enough: filtering systems are ~~ ordinary ~~ computers that are not very different from the usual ones that each check (I emphasize-everyone!) The user's Internet request on the Internet. If the request is not included in the list, the user is given to OK. If it comes, blocking. It is simple enough, but it requires computing power. That is, each of the billion billion requests must be processed. And it is logical to assume that the longer the list of prohibited resources, the more operations of searching for entry should be done to the appropriate equipment.
That is - the processing time of each request is growing. So far, this is not so noticeable - the thousandths of the microseconds occupies this processing. But if you multiply billions of billions of requests by thousandths of microseconds, then these are already minutes, hours and a day of computational time. And this time will grow.
But for some type of equipment and filtering, the size of the “black list” can be a very serious problem. And even it already became - so the manufacturer of the equipment Allot Communication had such a limit in 60k records. And in the registry there are already 70k+ records.
Perhaps bump limits exist among other manufacturers. It can be 100k, for example. Or even a million. But the limits exist for everyone because of the need to physically grind many, many records of the “Search-Flaps” class.
In a word, locks simply slow down the Internet. And the further, the stronger. 2. Uncontrolled DNS records and the practice of expanding interpretation of locks .
Now the webmaster offended by blocks has been prescribed in the DNS IP address of rather harmless (technically non-significant) Internet resources, such as the RKN itself or the Kremlin.ru website itself.
But something tells me that the consequences can be more catastrophic if more common web resources get into the register. No, this is not "classmates" or VK.
These are purely technical resources on which the vast majority of Internet sites are being built in general. For example - Bootstrap libraries from Twitter. Or open fonts from Google. Or a great many sites on the WordPress engine, which are updated from one source of libraries, can fall under the technical blocking.
What is far to go there - this is the website of the President of Russia, who refers to the harmless Schema.org , which describes data structures:
But no one prevents the “villains” to make “schemes” in the list of IP blocks and thereby violating the correctness of the “main website of the country”.
I am personally sure that very soon we will face this problem practically.
What to do with all this is not clear. More precisely, it is clear, but the RKN, and even more so the State Duma and all the nursing from the “registry”, will not like this proposal. The proposal is simple - to stop engaging in nonsense with locks and finally engage in their direct duties - to catch villains, drug dealers, extremists and other individuals that violate the legislation that they are so happy about.
However, hot heads “for legality and law and order” put forward a new idea - since it is impossible to correctly operate “black lists” - that is, the logical execution of the principle “all that is not prohibited” is allowed, then let's enter the practice of “white lists”. That is, the principle: "Everything is prohibited, except for what is clearly permitted."
This is a technically feasible principle. You can do this. Technically. But let's see how it will be implemented administrative-legal. By analogy with the points above:
Do not you think that then the Internet development process will slow down a little? I think. In addition, this, as they say, will create prerequisites for corruption. ” Well, really - why not get some money for helping the fastest introduction to the “White Register” of a certain resource from a “good person”? Or vice versa. Say, accidentally losing a “statement” from the resource not very good.
Well, or in “Our Internet of our Internet” there will be several hundred sites approved by state bodies (dreams of Milonov and Mizulina), which will lead to a slowdown in the development of the Internet itself, and behind it and economic development in general. For, if there are no new Internet projects, then there is no development-a completely understandable logical chain.
So we live!
Mikhail Klimarev, Zelecom , especially for Roskomvoboda
Read also:
Owners of blocked sites began against Roskomnadzor "Internet Water"
?
Roskomnadzor almost blocked Yandex, VKontakte and himself for Russians
?
Regional telecom operators protest against the "auditor"
?
Bezinterneta League prepared a bill obliging providers to preach Runet
?
Legislative impasse for the purpose of "security of children"