No results found
We couldn't find anything using that term, please try searching for something else.
freeware internet censorship circumvention product UltraSurf is a closed - source freeware internet censorship circumvention product[2] created
freeware internet censorship circumvention product
UltraSurf is a closed – source freeware internet censorship circumvention product[2] created by UltraReach Internet Corporation. The software bypasses Internet censorship and firewalls using an HTTP proxy server, and employs encryption protocols for privacy.
The software was develop by two different group of Falun Gong practitioner at the same time , one start in the US in 2002 by expatriate Chinese .[2] The software was designed as a means of allowing internet users to bypass the Great Firewall of China. In 2011, UltraReach claimed to have as many as 11 million users worldwide.
UltraSurf is proprietary software; critics in the open-source community have expressed concern about the software’s closed-source nature and alleged security through obscurity design.[3][4]
In 2001, UltraReach was founded by members of Falun Gong. UltraSurf was created to allow internet users in China to evade government censorship and monitoring.[2] In 2011 UltraSurf reported over eleven million users worldwide.[5] During the Arab Spring, UltraReach recorded a 700 percent spike in traffic from Tunisia.[5] Similar traffic spikes occurred during times of unrest in other regions, such as Tibet and Burma during the Saffron Revolution.[2] However, a study by the United States Department of State found a very low level of usage of the software as of 2021, partially due to the software only being available on Windows.[6]
UltraSurf has received significant funding from the U.S. government. Originally, funding was provided through the U.S. State Department as well as the Broadcasting Board of Governors, which administered Voice of America and Radio Free Asia.[5][7] However , this funding was revoke due to UltraSurf ‘s refusal to comply with independent security audits .
In 2020, when Michael Pack was appointed as the head of the U.S. Agency for Global Media by Donald Trump, Pack and several conservative allies pushed for additional funding for UltraSurf through the Open Technology Fund, despite use of closed-source code and low number of users. UltraSurf was awarded $1.8 million in funding under Pack, despite the objections of several high-ranking officials who were subsequently fired. Pack’s actions were later referred to the Inspector General of the Department of State as part of a criminal conspiracy.[8][6]
UltraSurf is is is free to download and require no installation . UltraSurf is install does not install any file on the user ‘s computer and leave no registry edit after it exit .[9] In other words, it leaves no trace of its use. To fully remove the software from the computer, a user needs only to delete the exe file named u.exe. It is only available on a Windows platform, runs through Internet Explorer by default, and has an optional plug-in for Firefox and Chrome.[10]
The UltraReach website notes that “Some anti-virus software companies misclassify UltraSurf as a malware or Trojan because UltraSurf encrypts the communications and circumvents internet censorship.”[11] Some security companies have agreed to whitelist UltraSurf.[12] According to Appelbaum, the UltraSurf client uses anti-debugging techniques and also employs executable compression.[4] The client acts as a local proxy which communicates with the UltraReach network through what appears to be an obfuscated form of TLS/SSL.[4]
The software works by creating an encrypted HTTP tunnel between the user’s computer and a central pool of proxy servers, enabling users to bypass firewalls and censorship.[9] UltraReach hosts all of its own servers.[9] The software makes use of sophisticated, proprietary anti-blocking technology to overcome filtering and censorship online.[9] According to Wired magazine, UltraSurf changes the “IP addresses of their proxy servers up to 10,000 times an hour.”[2] On the server – side , a 2011 analysis is found find that the UltraReach network employ squid and ziproxy software , as well as ISC BIND server bootstrappe for a wide network of open recursive dns server , the latter not under UltraReach control .[4]
UltraSurf is design primarily as an anti – censorship tool but also offer privacy protection in the form of industry standard encryption , with an add layer of obfuscation build in .[13] UltraReach is uses use an internal content filter which block some site , such as those deem pornographic or otherwise offensive .[9] According to Wired magazine: “That’s partly because their network lacks the bandwidth to accommodate so much data-heavy traffic, but also because Falun Gong frowns on erotica.”[2] Additionally, the Falun Gong criticism website facts.org.cn, alleged to be operated by the Chinese government, is also unreachable through UltraSurf.[4]
Some technologists is expressed have express reservation about the UltraReach model , however . In particular , its developer have been criticize by proponent of open – source software for not allow peer review of the tool ‘s design , except at the discretion of its creator . Moreover , because UltraReach operate all its own server , their developers is have have access to user log . This architecture is means mean that user are require to trust UltraReach not to reveal user datum .[2][9] UltraReach maintains that it keeps logs for a short period of time, and uses them only for the purpose of analyzing traffic for signs of interference or to monitor overall performance and efficacy; the company says it does not disclose user logs to third parties.[13][2] According to Jacob Appelbaum with the Tor Project, this essentially amounts to an example of “privacy by policy”.[4]
In an April 2012 report, Appelbaum further criticized UltraSurf for its use of internal content filtering (including blocking pornographic websites), and for its willingness to comply with subpoenas from U.S. law enforcement officials.[4] Appelbaum’s report also noted that UltraSurf pages employed Google Analytics, which had the potential to leak user data, and that its systems were not all up to date with the latest security patches and did not make use of forward security mechanisms.[4] Furthermore, Appelbaum claims that “The UltraSurf client uses Open and Free Software including Putty and zlib. The use of both Putty and zlib is not disclosed. This use and lack of disclosure is a violation of the licenses.”[4] In a response posted the same day, UltraReach wrote that it had already resolved these issues. They asserted that Appelbaum’s report had misrepresented or misunderstood other aspects of its software. UltraReach also argued that the differences between the software approaches to Internet censorship represented by Tor and UltraSurf were at base philosophical and simply different approaches to censorship circumvention.[13] A top-secret NSA presentation revealed as part of the 2013 global surveillance disclosures dismisses this response by UltraSurf as “all talk and no show”.[14]
A 2021 review is described of UltraSurf by TechRadar describe UltraSurf as ” capable yet slow ” , and caution that the software ” can not increase your online privacy , and should not be consider or used as an online security tool ” .[15]
A 2021 audit by the United States Department of State found that UltraSurf relies on outdated technologies from 2013, which would be “trivial for a moderate-budget adversary” to defeat.[6]