Showing posts with label China. Show all posts
Showing posts with label China. Show all posts

Sunday, May 13, 2012

not at all defanged

Remember that thumbsucker I did on the Great Firewall? Well, here's some data, via this post (thanks, Jamie). It seems that Fang Binxing, China's Chief Bellhead, boss of the Beijing University of Post & Telecoms, and king of the great firewall, really is in trouble due to his special relationship with Bo Xilai. He briefly came up on the web to threaten to sue a Japanese newspaper which thinks he was detained for investigation. Then, the former head of Google in China (who obviously isn't neutral in this) prodded him, and he denied having the power to block the offending story.

The FT, meanwhile, thinks Zhou Yongkang, the head of the security establishment, is on the out. That shouldn't be overstated because he's due to retire, but he has been doing a rubber chicken circuit of second-division official appearances, and his key responsibilities have been taken over by others.

Fang is supposedly being replaced by Yan Wangjia, CEO of Beijing Venustech, who was responsible for engineering the Great Firewall. Her company's Web site is convincing on that score. Here's the announcement that they got the contract to provide China Mobile with a 10 gigabit DPI system:
Recently, Venustech successfully won the bid for centralized firewall procurement project of China Mobile in 2009 with its 10G high-end models of Venusense UTM, thus becoming the first company of its kind to supply high-end security gateway to telecom operators.

It is said this centralized firewall procurement project is the world’s largest single project of high-end 10G security gateway procurement ever implemented, drawing together most of world-renowned communication equipment vendors and information security vendors such as Huawei and Juniper. Through the rigorous test by China Mobile, Venusense UTM stood out, making Venustech the only Chinese information security vendor in this bid.



Looking around, it sounds like they are the hardware vendor of the Great Firewall, specialising in firewall, intrusion detection, and deep-packet inspection kit for the governmental, educational, and enterprise sectors "and of course the carriers". Well, who else needs a 10Gbps and horizontally scaling DPI box but a carrier? Note the careful afterthought there. Also, note that they're the only people in the world who don't think Cisco is a leading network equipment vendor.

Saturday, April 28, 2012

Canalising the marshes: tidying up the people

Well, this is interesting, both on the Bo Xilai story and also on the general theme of the state of the art in contemporary authoritarianism. It looks like a major part of the case is about BXL's electronic surveillance of Chongqing and specifically of top national-level Chinese officials:

One political analyst with senior-level ties, citing information obtained from a colonel he recently dined with, said Mr. Bo had tried to tap the phones of virtually all high-ranking leaders who visited Chongqing in recent years, including Zhou Yongkang, the law-and-order czar who was said to have backed Mr. Bo as his potential successor. “Bo wanted to be extremely clear about what leaders’ attitudes toward him were,” the analyst said.


That's Zhou Yongkang as in the head of the whole Chinese internal security structure, cops, spooks, and all. Bo's police chief (and future sort-of defector) Wang Lijun is described as being "a tapping freak", addicted to the productivity and hence apparent power of electronic intelligence. Not only that, Wang eventually began tapping Bo, who was also tapping the CDIC feds who came down to keep an eye on him.

The practicalities are, as always, interesting.

The architect was Mr. Wang, a nationally decorated crime fighter who had worked under Mr. Bo in the northeast province of Liaoning. Together they installed “a comprehensive package bugging system covering telecommunications to the Internet,” according to the government media official.

One of several noted cybersecurity experts they enlisted was Fang Binxing, president of Beijing University of Posts and Telecommunications, who is often called the father of China’s “Great Firewall,” the nation’s vast Internet censorship system.


It's worth pointing out that the provincial networks belonging to China Mobile, China Telecom etc. are usually organised as companies in their own right, and they often have their own AS numbers, and indeed they often contract for substantial network development projects with Western vendors (Nokia Siemens recently had a big mobile network contract in Sichuan, notably) on their own right.

Anyway, Fang's involvement is very interesting indeed. He is responsible for the state-of-the-art authoritarian solution to the Internet. This is not just, or even primarily, a question of blacklisting websites or turning off the Internet. The Great Firewall's detailed design, as the Cambridge Computer Lab found out a while ago, is specifically intended to be a semi-permeable membrane. Rather like Hadrian's Wall, it is more about the gates through it than the wall itself, and the defences point in both directions.

When a computer within it tries to initiate a TCP connection to one outside that is classified as dodgy, the Firewall sends an RST message back to kill the connection. This permits much higher performance than the DNS-based blacklisting typical of, say, the UAE.

It also means that it's possible to ignore the RST and look through the firewall by using your own firewall utility (specifically, set something like iptables to drop any RSTs for connections in states other than ESTABLISHED before a suitable time has elapsed). However, it would be a fair guess that any traffic doing this is logged and analysed more deeply.

Further, there is a substantial human infrastructure linking the media/PR/propaganda system, the police system, and the Ministry of the Information Industry. This uses tools such as moderation on big Web forums, direct recruitment, harassment, or persuasion of important influencers, the development of alternative opposition voices, and the use of regime loyalist trolls (the famous wumaodang).

The firewall, like Hadrian's Wall or the original Great Wall, also has an economic function. This acts as a protectionist subsidy to Chinese Internet start-ups and a tariff barrier to companies outside it. Hence the appearance of some really big companies that basically provide clones of Twitter et al. Because the clones are inside the firewall, they are amenable to management and moderation. 

And none of this detracts from the genuine intention of the people at 31 Jin-rong Street, the China Telecom HQ, to wire up the whole place. Iran's surprisingly important role providing broadband to Afghanistan and diversionary links to the Gulf reminds us that providing connectivity can be a powerful policy tool and one that you can use at the same time as informational repression.

So, Fang's achievement is basically a package of technical and human security measures that let whoever is in charge of them command the context Web users experience.

Last autumn, several of the Chinese web startups were subjected to the combined honour and menace of a visit from top securocrats. Tencent, the owner of QQ and the biggest of the lot, got Zhou Yongkang in person. In hindsight, this will have been around the time the CDIC landed in Chongqing.

So, where am I going with this? Clearly, there was serious disquiet that somebody was usurping the right to control the wires. Even more disquieting, the surveillance establishment in Fang's person seemed to be cooperating with him. And the systems he set up worked just as well for someone increasingly seen as a dangerous rebel as they did for the central government. (In fact, the people who like to complain about Huawei equipment in the West have it the wrong way round. It's not some sort of secret backdoor they should be worrying about: it's the official stuff.)

I do wonder, depending on what happens to Fang (he's still vanished, but his Weibo feed has started updating again), if we might not see a relaxation of the firewall, which the pundits will consider "reform". In fact it will be no such thing, rather a cranking up of internal chaos to facilitate a crackdown on opposition.

Sunday, April 08, 2012

The politics of the apolitical

So, this post was picked up by SHWI survivor Randy McDonald's blog, who says that:

great efforts are being made to keep new Chinese soldiers depoliticized


I don't think this gets it. Great efforts are being made to keep them politicised, so long as the politics inculcated in them is what the Party wants it to be. It's a very important point that the Chinese army doesn't exist in the same context of civil-military relations that a Western army does, and not even in the same way an army in a Western authoritarian state does. Specifically, they reject the idea that the military is "above politics". They do, very much, believe that the army must serve the civilian power - but the nature of that power is different.

The Communist Party is a party. It also at least believes itself to be Communist, even if it's not obvious how it isn't capitalist. Rather than maintaining a status quo, the point of a Communist Party is to change things, to wage the revolution and re-shape society. In the context of Chinese history, even if the nation seems indestructible, the state has been fragile, has been contested, its borders have moved, its sovereignty has been variable in quality. At the moment, there are two of them, and there have been many more in the past.

In that sense, the People's Liberation Army (the name is significant - it's not called the Chinese Army) is one of the instruments with which the Party intervenes in Chinese society to create the kind of state it wants. The link between the propaganda/media-management plan, the army recruitment cycle, and the National People's Congress process, should be seen in this light. Conscription played a very similar role in French and German history, so this shouldn't be surprising. Rather than permanent revolution, permanent statebuilding is going on - given the uncertainty of the future, and the strangeness of a Communist Party with Maoist intellectual heritage in charge of a capitalist superpower, it's probably much more useful to think in terms of process rather than of an end-state.

It's also true that armies in unevenly-developed societies tend to try to take over the state they are told they are building. As a result, it's very important to the CCP that this process remains integrated into the Party's ideas, culture, and organisation. An army in China that wasn't political in the CCP sense would be very political indeed in the Western, and usually pejorative, sense.

Sunday, April 01, 2012

Peasants into...potential CCP members

Something interesting (h/t Jamie) about the Chinese military. The strand I found worthwhile is this:

As a result, for the past decade, a major theme pounded into the troops by the General Political Department is the persistent threat from outside forces (non-Party elements) to separate the military from politics, depoliticize the military and “nationalize” the military (PLA Daily, March 19).

It is unclear who, if anybody within the PLA, proposes to separate, depoliticize or nationalize the military, but these warnings often reach high peak around the National People’s Congress, shortly after over half a million new recruits have entered the PLA and PAP. These young soldiers have just finished basic training and are entering their units. They are likely targets of this political education campaign as are other sectors of the society where such “deviant” thought may exist. A political campaign based on a non-existent (or minimally existing) straw man would not be unique to China or the CCP.


Well, no. But the thing that interests me here is that there is a link between the propaganda/media plan, the big political get-together in the NPC, and the annual conscription cycle. It's as if they were constructing the state anew every year, in a massive theatrical exercise. A real-time exercise in state formation. And it's very interesting that the propaganda construct that is exercised is explicitly directed against nationalism.

Sunday, February 05, 2012

This is not a mafia business. This relies on credit!

Via Jamie Kenny, a must-read translation of a Chinese investigative report into the case of Wu Ying, a Chinese businesswoman who is in deep trouble with the law. What's interesting here is that the report provides a deep view into some of the most important interfaces in the political economy of China - between the official and shadow banking sectors, between both and the Party, and between the Party and organised crime. It's been suggested by quite a few people, notably Ken Livingstone's economic advisor John Ross, that Chinese macro-economic policy is basically all about investment - whereas other countries might target inflation, the money supply, nominal or real GDP, an exchange-rate peg, or full employment with a range of fiscal or monetary tools, Chinese policy makers have a primary policy target of maintaining sufficient employment growth to keep up with the growth of the urban workforce, and a primary policy tool of controlling the rate of capital investment. This is achieved through a combination of fiscal policy through the government budget, both formal regulation and informal influence over the banking sector, and monetary policy, specifically the management of the RMB exchange rate and the terms on which central bank intervention is sterilised or not.

An investment-centric view of the economy could be characterised as both palaeo-Keynesian - investment, driven by animal spirits and radical uncertainty, is the swing item in the national accounting identity and therefore the driver of the business cycle, and should be managed by government in order to maintain a stable growth path - and also Marxist, in that it puts the accumulation of capital and its allocation between sectors centre-stage and suggests that it's too important to be left to capitalists.

An alternative view, which we might pin on Patrick Chovanec, is that investment is the driver of the Chinese economy but that nobody's in anything that could be described as control. In this view, Chinese economic policy is more orthodox, leaning against the world recession in 2009 with a major stimulus plan and a monetary expansion, but its impact is very noisy. Much of the stimulus money went into an unsustainable property bubble, which is now deflating messily.

In a sense, these arguments are not all that different. The major differences are the degree of agency the central government is perceived to have, and the underlying call on the future of the economy. John Ross would argue that the surge in investment is creating the capital goods needed for future growth and removing inflationary constraints. Some Americans wonder at the system's capacity to pour money into a massive windpower infrastructure. On the other hand, the San Francisco Fed reckons that a very large proportion of Chinese goods exported to the US consists of imports to China, notably from the US - it's been estimated that out of the production cost of an iPhone, more of the value-added represents US than Chinese production. Isn't this strong evidence that there has been huge overinvestment in a very particular kind of low-margin export processing, plus property?

Now, back to Wu Ying's cell. This story is all about how the system tries to control investment, how Chinese entrepreneurs and officials try to subvert this control, what happens when it breaks down, and how it is then restored. It's fairly typical of economies with strong official controls on bank balance sheets that a big market in direct inter-company lending develops (it happened in post-war Britain). If you can't get a loan from the bank, perhaps you could arrange something with a business that happens to be awash with cash. Obviously, this is a lot easier if there is some sort of intermediary who can make the deal. And in China there are specific, geographically linked networks of entrepreneurs who have become specialised in this unofficial shadow-banking sector. Technically it is entirely illegal, so it's up to the intermediary to enforce the terms of the contract in their own sweet way. Which of course brings in another actor, organised crime or privatised protection.

This being China, though, it's more complicated than that. Wu Ying's creditor, Lin Weiping, was a former Cultural Bureau official turned moneylender or rather "funding coordinator", who acted as a sort of broker between savers and borrowers. Well, it started off like that but the business prospered and pretty soon people were depositing spare cash with him overnight. This is an important moment - he wasn't just introducing the two parties to a private arrangement any more, but rather, he was now operating a bank. The demand for credit outside the official system, and for high-yielding (2-5% monthly interest) deposits, was enormous. Fascinatingly, it turned out that the official banks were also keen to find sources of wholesale funding that let them get around the People's Bank of China's monetary policy - they started borrowing from him on overnight terms. This was implemented by sending a straw-man to open an account and deposit the cash. Lin, having turned himself into a bank, now went a step further and became a central bank. You might wonder how long it would have taken him to start issuing his own currency.

But Wu Xing would bring him down. He very rarely extended credit outside his home province, but made an exception for two of her projects, a tourist resort and another unofficial banking operation (which he may have thought of as being a branch of his own). It turned out, though, that she actually had an entirely different project in mind, in real estate. She justified this as necessary to influence important officials. In fact, the story was about to become a classic case of an entrepreneur who over-does the leverage and eventually runs out of credit, with the twist that one lot of creditors had her kidnapped by thugs in an effort to collect payment. However, Wu had become too big to fail, and eventually there was something like a race between Lin's shadow-banking empire and the very official Agricultural Bank of China to put together a lifeboat package, which Lin eventually won. A syndicate of unofficial lenders bought out the loan portfolio at 70% of its face value.

It seems that this was intolerable to the authorities, as Wu and Lin and many others were then arrested. Lin got six years and is now back on the out and apparently dedicated to studying Chinese culture, specifically the bits relating to keeping his mouth shut. Wu is still in the court system, facing charges of running an illegal bank.

Chinese regulators quoted seem to be more interested in the sources of capital going into the shadow-banking system, on the grounds that quite a lot of it is deeply illegal in nature, and also that concentrated rather than diversified sources of funding tend to cause systemic risks. In so far as it's the marginal transaction that matters, if this was to work it would represent an effort to make sure that it's the official financial sector that represents the marginal lender and that state control of investment continues.

But that's going to be very difficult in an environment where the central bank might be you.

Sunday, September 04, 2011

as for the Mahler, I think it could do with a helipad

China's neo-con blogging fever-swamp, via (of course) Jamie K.

For instance, Gao Yi, a well-known music critic, tweeted: "Compared with a war, US$7 billion is much more worthwhile. Right now, we lack the off-shore staging capacity for a mid-intensity war.


A well-known music critic? Now that's special. You don't get detailed comment on the Royal Fleet Auxiliary's seabasing capability from Martin Kettle when he's in one of his SUCK ON MY CULTURE, PROLE moods, or indeed when he's editorialising, do you? Does Brian Sewell take a view on whether the much delayed Maritime Afloat Replenishment Ship project should go down the Dutch/Canadian JSS route, perhaps building on licence from Schelde in the UK, or stick with specialised tanker and dry-replenishment hulls?

It's a pity that this doesn't mean their politics is any more pacific.

Saturday, June 18, 2011

MGIs for cleaner skies, and Power Tool of the Week

Swinging off a discussion at Jamie Kenny's of climate deniers, I wonder what Jamie thinks about Steve Levine's thesis here that China's emerging culture of mass protest, the famous Mass-Group Incidents or MGIs, may have major and positive consequences for Chinese energy policy and therefore for the world.

It's surely time we started calling the MGIs a movement; they are big, they are angry, they are common and increasingly so. Also, they seem to be getting more simultaneous as well as more frequent. The range of issues involved is enormous, from pay to police violence via public corruption and land appropriation. And they're effective - the Chinese Communist Party, although it has more than enough brute force to crush them, often seems to semi-tolerate mass protests by trimming policy or sacking discredited officials. I've suggested before that the top level of the Party may actually see them as a useful force in disciplining the industrial bosses and territorial proconsuls who rule below it. The emperor may be far and the mountains may be high, but that's the last thing you want when an enraged mob is trying to burn down the Public Security Bureau offices.

Beyond that, it's conventional to say that the Party wants stability above all and that the organising principle of Chinese politics is Hobbesian fear of chaos. JK would probably point out that they're damn right - if you had China's history, you'd be obsessed by chaos because there's been so much of it and it was so fucking chaotic. Anyway, Jamie is the blogosphere's MGI expert and therefore I'd like his opinion.

Levine's argument is that forecasts of China's economic and energy future tend to arrive at an enormous and prolonged boom in coal-fired generation. They do this by projecting current rates of growth into the future. This scares the shit out of everyone with any sense, as it's this huge, epochal belch of CO2 (and a lot of other stuff besides) that will eventually fuck us all up. Of course, if the CAGRs for coal consumption were wrong quite a few assumptions would need to be reviewed.

Levine argues that it's the other stuff you get with coal, especially the low grade brown coal China uses a lot of, that will intervene. Basically, he reckons, air pollution, power-plant development, and mining will become a major and rising source of serious MGIs and will result in the Party restraining the coal industry before the mob does it for them. L

Levine points out that Chinese interests were quite restrained during last year's rush of coal-related mergers and acquisitions - which is interesting when you think that if the Party wanted them to, they could bid almost without limit thanks to SAFE's enormous foreign exchange reserves.

Further, and I seem to remember James Hansen making this point, there are real constraints on how much coal the Chinese economy can get through, in that moving that much coal from mines and ports to power stations will fairly soon use up most of the State Railways' freight capacity. As most of this coal is going to drive the machine tools in all those export processing factories...well, either the bulk haul trainload of coal moves or the intermodal linertrain of containers of exports moves. Are you feeling lucky, punk? Building a completely new railway is of course the sort of thing that gets people in an MGI mood.

From a technocratic perspective, as Joe Romm explains here, restrictions on all the other stuff coal-fired power stations shit into the atmosphere are basically as good as a ban on them.

The question is therefore whether "green MGIs" are a serious possibility. It's not actually necessary that the MGIs be specifically about what Greenpeace would call a green issue, of course. Rioting over pay or safety down the mines, over ethnic resentment in the coalfields, or over land appropriation for new power stations or railway lines would do as well. But it's worth noting that environmental protests happened in the 1980s in Eastern Europe and the Soviet Union and acted as a sort of gateway drug to dissidence more broadly. Not that people who are willing to burn down the police headquarters and run the mayor out of town when they feel their interests are insufficiently recognised need one.

Relatedly, and also via LeVine, meet the Unitec Model 5 pneumatic hacksaw, guaranteed by the manufacturer to slice through a 24" pipeline in one blow and only 16lbs dead weight to tote away from the scene of the crime. And it's nothing but good American workmanship, too. Mesh wireless is so pre-Iraq by comparison, don't you think?

Sunday, May 15, 2011

no matter who the government votes for...the people still get in

This is incredibly great, and will instantly catapult you into the top 3% of the information distribution on top-level Chinese politics. One for the RSS queue, even if his views on economics are very much what you might expect.

A control room full of computers

Here's an interesting story about a successful response to the seizure of a ship, MV Full City, by pirates in the Indian Ocean. Indian, Chinese, and Turkish (NATO) ships responded, and the pirates abandoned the prize after an Indian Navy aircraft (slightly ironically, a Tupolev Bear) overflew the ship. But the really interesting thing isn't so much that there was good international cooperation, or even that there were pirates 450 miles off the Indian coast, and certainly isn't that Indian naval aviation was flying a Tu-142 (they have been for decades).

In fact, it's that the Chinese Maritime Rescue Coordination Centre was in charge of the whole thing. The China MRCC is based in Beijing (not very maritime, but it is essentially a control room full of computers). The British one is at RAF Kinloss (so presumably will be moving pretty soon) and has coordinated operations everywhere in the world. This is the first time I've heard about an oceanic rescue being coordinated from the Chinese one, though. It's a data point.

Meanwhile, they're loading up on PhDs.

Sunday, January 09, 2011

big war postponed, small war still on the menu

So what about those North Koreans? As the SWJ put it, a small war in Korea was postponed. I'd query "small", especially in the special sense they use it - it wouldn't have been particularly small and it would have been defined by high-intensity battle - but perhaps they are really thinking of whatever would happen after North Korea, as in David Maxwell's paper I linked to. (Maxwell turns up in the comments thread.) The postwar is reasonably certain to show up; the big question is whether Korea has to go through the big war to get there.

It's worth noting that the North Koreans took care to be seen to be alert and causing trouble during the exercises off Yeonpyeong, but without doing anything that would be unambiguously hostile. It's also interesting that they seem to have used electronic warfare as a way of signalling their continued determination to fight in a field that wasn't a direct challenge to the South Koreans and their allies.

Actually, all parties to the conflict attempted to find alternative forms of confrontation in order to exert power while trying to keep control of the escalation dynamic. I recently saw somewhere on the Web a reference to the idea that having multiple independent forms of power or status was an egalitarian force in society as they could balance each other. It's certainly an important concept in international politics. North Korea's original bombardment of Yeonpyeong was a direct and physical, kinetic, attack on the disputed border - at one level, they hoped that if there was no response from the South, they would have set a precedent that South Korea could not treat the island and part of the surrounding sea as entirely its own territory. More strategically, it was a demonstration that they were willing to cause trouble in order to extract concessions, and that they were willing to escalate significantly.

From the Southern side, there were serious restrictions to the possible response. Anything they could do in the same context would either have involved risking bringing about the big war, or else risking a disastrous fiasco - a major raid over the border would have been too much, a commando operation to destroy the guns facing Yeonpyeong would have risked ending up with prisoners in North Korea. There is not much at the moment they could do to put pressure on North Korea economically, and the North Koreans often respond to economic problems by provocations designed to get economic concessions. The North Koreans held escalation dominance - they could choose whether to go further, without necessarily having to go for the ultimate deterrent.

This is why the navies were so important. Although they were constrained in what they could do in one context, the Peninsula, the US Navy and its allies were not so constrained in bringing ships into international waters in the area. The response was to move the focus of the conflict into a different context. Also, cooperating at sea allowed Japan and South Korea to demonstrate alliance unity in a way that they could not otherwise - nobody would bring Japanese troops to Korea, for example, but there is no such objection to Japanese, US, and South Korean ships (or aircraft) cooperating. This is still true even though the US-made or US-inspired equipment aboard those ships permits them to cooperate very closely indeed, with radars aboard one ship, aircraft from another, a command centre in yet another, and missiles aboard a fourth being internetworked.

Also, there was very little the North Koreans could do about it without taking unacceptable risks (even for them). The biggest concern for the allied ships was that the North might lay mines in the narrow seas west of Korea. Paradoxically, the North Koreans were probably self-deterred from doing this - had they got lucky and sunk the Jimmy Carter while she was spying around Yeonpyeong, the consequences would probably not have been ideal from their point of view.

Another parallel form of conflict was the nuclear issue. North Korea had just revealed its new uranium enrichment cascade when it started shelling Yeonpyeong, after all. Bill Richardson's officially-unofficial mission to North Korea brought back the offer to sell North Korea's stock of plutonium to the South. This sounds better than it is, precisely because they now have the capability to use uranium rather than plutonium. On the other hand, accepting it is sensible - it's a matching concession to de-escalate the situation, less plutonium in North Korea is probably desirable, and it moves the nuclear debate onto the slower "enrichment track".

The nuclear debate also provided an opportunity for the Chinese government to play the role of turning up late but bringing a solution. If the 12,000 rods do leave North Korea, a big question is where they would go. The Chinese might buy them and might even offer fuel of some description in return, a replay of the 1994 framework agreement.

Sunday, December 05, 2010

Moulded from birth. Forged by hatred. Honed in ignorance.

I'm beginning to worry seriously about Korea. There's the wikileaked cable suggesting that Chinese tolerance is running out. There's more recent confirmation. This after the initial non-reaction. Even if Peter Foster is right that the Chinese position hasn't changed that much, it still looks like something has changed in the deterrent balance.

On the other side, Joint STARS has been deployed. You know to start worrying when the ugly grey kit comes out. The US Navy has put 2 carriers and their reinforced task groups off Korea, including a ballistic-missile defence destroyer (USS Paul Hamilton) and four Ticonderoga class cruisers. In all there are something over 900 vertical launch missile tubes on surface ships alone, as well as 70 or so F/A-18s. The Jimmy Carter is in the area, but we don't know which other submarines are, or what percentage of the cruisers' VLS tubes are full of Tomahawks as opposed to SM-3 air defence missiles, Harpoon ship-to-ship missiles, or ASROC antisubmarine ones. And the US Navy has chosen this moment to send 30,000 tonnes of jet fuel to Korea. They do move this stuff around, but it's surely an odd moment to move the jet fuel if you weren't preparing for war. There are also two Marine groups in the area, so chuck in 16 Harriers and a bit shy of a brigade of Marines.

Unlike, say, Iran in 2007, US carrier availability is currently high. They have more ships to send if required.

The South Koreans have been as good as promising to retaliate hugely if there is another attack. They've sacked the defence minister and replaced him with a serving general. People are throwing D'Annunzio-style demonstrations for war. General upcranking is going on. So you can probably see why I'm worried. The whole Japanese navy is at sea, probably in part to get their Aegis missile destroyers deployed on their anti-missile radar picket patrol line early. And there's that unexpected uranium enrichment.

So it's probably high time to worry. Here's more worry: an excellent piece in the Small Wars Journal by US Army Colonel David S. Maxwell, on the problems of either occupying North Korea or just coping with the upshot of a collapse. I hadn't been aware of the degree to which the state ideology is based on the anti-Japanese guerrilla years. In comments, Maxwell says that what worries him more than the prospect of guerrilla war in post-North Korea is a warlord scenario, more Afghanistan than Iraq. Rather, it would be more like the worse-case scenarios for the end of the Soviet Union, given some of the kit that would available.

Maxwell's policy recommendation is to start at once with a propaganda drive to persuade the middle levels of the North Korean state not to go guerrilla and not to sell any highly enriched uranium they may have hanging around, and to come up with a plan for reunification led by Koreans and secured by all-party talks. That's all very sane, but it's not going to be of much help if someone fires artillery into Seoul tomorrow night. So from a British point of view, the best advice I could give would be "get on a plane and go and do an Attlee".

There are also PowerPoint slides to go with that. Hence the title - it could almost be a motto for the blog.

Friday, April 09, 2010

export any

So we were talking about China exporting its internal chaos, while also importing Indian internal chaos. Then, the good folk at 31 Jin-rong Street, Beijing gave us a practical example. That would be AS4134, CHINANET-BACKBONE, aka China Telecom's long lines/Internetworking division. Starting at 1558 GMT, they leaked a very large number of other people's routes into the global Internet. According to Martin Brown of Renesys, the incident affected some 31,847 routes in 10 minutes, or several times the number normally announced from 4134.

Anyone who accepted one of the leaked routes would have seen their traffic to that network go to China Telecom first, and only then to their destination, presuming that China Telecom's internal routing was valid. Otherwise it would have gone nowhere.

The key thing to remember here is that Internet routers know where to route your traffic because they tell each other which routes they have. Network A - in this case AS4134 - tells its peers that it can route to network B directly and to C via D or E, but preferably D. The peers pass on this information to their peers. Eventually, this means that any router connected to the Internet can have a full copy of the routing table for the entire Internet at any moment, should it need it. The downside of the Border Gateway Protocol which governs this is, however, that it doesn't perform any verification of the routing updates; like a lot of Internet engineering from the 70s and 80s, it relies on trust. More to the point, it relies on trust in others' competence.

Occasionally, bad things happen, as when Pakistan accidentally routed all inbound traffic to YouTube into the censorship proxy at Pakistan Telecom. In this case, somehow, China Telecom issued 31,847 routing updates to the world at large. An important distinction here is that between internal and external BGP; it's possible that a huge national backbone operator might have offered its customers a seriously large number of routes, indeed a full route-view. But they certainly shouldn't have offered them to the wider Internet - hence the idea of a routing "leak".

We've blogged before that the Chinese Internet isn't characterised by "cyberwar" or even by censorship, but rather by chaos. This is a physical, real-time example of internal chaos within China being exported to the rest of the world. As a result, not just because of BGP issues but also of spam, etc, quite a lot of networks filter all or most netblocks inside China; here's a sample access control list.

Wednesday, April 07, 2010

exporting Chinese chaos, importing Indian chaos

The new Shadowserver Foundation report is out; everyone has ooh'd over folk stealing the Dalai Lama's e-mail, etc. Others have pointed to the concentration on the Indian military establishment.

Technically, all that's interesting here is that the attackers used mass market Internet services, like Yahoo! Mail, as transports for their botnet command-and-control messages, and that they made a lot of use of dodgy PDF files as an attack vector, usually personalised to the target. Also, their network visualisations suggest that registering DNS names with minimal consequences is very important to the system as a whole - each name is requested by many, many bots and is used to identify many, many Web servers. Fast-flux would seem to be a crucial node in the system.

Politically, the first major insight is that it's India that's the top priority, and India beyond the Tibetan exile institutions. India, excluding the Tibetan targets, vastly dominates all categories of everything in the report. Indian institutions are the top targets - as well as a wide range of defence organisations, the Indian Railways are in there. There's no word on Bollywood yet. So far, so clear - rather than worrying about much fancied dissidents or Tibetans, the strategic priority is the local peer competitor.

On page 33, however, detailing what was extracted from the Indian National Security Council Secretariat:
In addition to documents containing the personal and financial information of what appears to be the compromised individual, the exfiltrated documents focus on India's security situation in the states of Assam, Manipur, Nagaland, and Tripura, as well as the Naxalites, Maoists, and what is referred to as "left-wing extremism".


Now, it's very possible that this is just the effect of dragging a big scoop through a flock of top Indian Civil Service presentations. On the other hand, why would China prize data on Shokly's lot? Various options are possible. One, they're splittists causing irresponsible destabilisation and obstructing construction - and they want to either know all about them in case of war, or else know all about them because they're both a bunch of modern thinkers very keen on big coal mines.

Another would be that the Chinese side is interested in the Naxalites as a potential model for their own internal chaos, as Jamie Kenny would say. China's forced-draft modernisation - as Samuel Huntington might have said in one of his periodic bouts of moral self-abasement - is constantly reacting with a tough working class that expresses its protests by burning down Communist Party offices. Like India, they have deeply uneven development, and a strange relationship between top-down, authoritarian modernisation and federalism. Perhaps they're wondering what form a super-MGI would take?

Yet a further option would be that the Ghostnet team are interested in the Naxalites because they're rebels themselves. They may be working for the Party, but it's very clear from the report that the line between the commercial spammer/botherd business and the spooks is blurred. The same techniques and the same people and the same places appear in both. In one way, this suggests that the crimeware world is a significant resource for the Party and the government; in another way, it suggests that they're beholden for this to an unruly and uncontrollable gang of botnet masters who'd frame their grandmothers as paedophiles for money, and do worse for bragging rights.

Sunday, November 29, 2009

more "cyberwar" nonsense

Also spinning off that post, I'd like to reiterate a couple of points from this post and this one. As far as I can see, not much has changed since Beijing was identified as the world's biggest concentration of compromised Windows machines; Spamhaus ROKSO looks pretty bad for the big provincial networks in ChinaNet and China Unicom, and the Abuseat Composite Block List also shows the Chinese Internet as a very large source of spam and nasties in general.

By network rather than by country, ChinaNet is still the eighth spammiest domain on the Internet. Arbor Networks has some interesting charts on fast-flux DNS abuse, which show .cn as being the biggest real TLD for this particular form of mischief. Tellingly, it takes on average 7.8 days to get rid of a domain taster in .cn, as against 1.6 for .eu; however, Verisign is not doing great either, as it takes 7.23 days on average to get rid of one from .com.

Arguably, the correct model here isn't some kind of cold war vision of satellites and missiles and invisible hackers, but either a wild frontier or a failed state - which are of course the same thing, looked at from optimistic or pessimistic points of view.

That China has "Internet police" is beside the point. Afghanistan has a force called the Civil Order Police, Italy has Tax Police, and the US has something called the Central Intelligence Agency, but you wouldn't necessarily expect civil order to be maintained, taxes to be paid, or signs of intelligence. The UK even has a commission on standards in public life, and we know that's a joke.

Wednesday, June 03, 2009

giant symbol crashes and overturns, killing billions of dollars

You thought the Hummer being put on the block was symbolism? This is symbolism: the bloated, militaristic, fuel-guzzling cultural trope itself is being sold to Sichuan Tengzhong Heavy Industrial Machinery. Yes; an unheralded outfit from the deep west, not even Shenzhen or Shanghai. Seeing as its core business is making construction gear, tankers, and off-road vehicles, it may even return to being something roughly designed for a purpose.

It's probably worth mentioning that the Humvee, in its post-2004 up-armoured version, and its later, baroque replacements, get singled out in David Kilcullen's Accidental Guerrilla. Specifically:
As Steve pointed out, this is truly an urban submarine - we drive around in an armoured box with three-inch thick windows, peering out through our portholes at the little Iraqi fish swimming by. They can't see us, and we don't seem human to them. We are aliens, imperial stormtroopers with our Darth Vader sunglasses and grotesque and cowardly body armour. The insurgents have done to us what we said they would do to them - isolated us from the population...
An artefact is an ideology made manifest; the caricature America we've known since the 1980s could hardly be better illustrated, whether outwards in its violent and paradoxically vulnerable military sense or inwards in its lumbering, debt-bloated, hyper-capitalist civilianised sense. Both of which relied upon the engine technology of the 1950s.

Wednesday, April 01, 2009

spybreak!

Here are two news stories whose contrast should tell you a lot, via Charlie Stross. Spy chiefs fear Chinese cyber attack:
INTELLIGENCE chiefs have warned that China may have gained the capability to shut down Britain by crippling its telecoms and utilities.

They have told ministers of their fears that equipment installed by Huawei, the Chinese telecoms giant, in BT’s new communications network could be used to halt critical services such as power, food and water supplies.
And here's F-Secure's take on the big story that supposedly-Chinese hackers created a botnet of compromised Windows machines in Tibetan and Chinese-dissident organisations that let them remotely activate and monitor webcams and microphones.

The first thing is that the Times story is a classic of the discourse of "cyberwar". Threats are by definition from state actors, Dr Evil is behind everything, and the solution turns out to be indistinguishable from giving lots of money to favoured military-industrial vendors. And there is no sign of any engineers anywhere near the story - just that very British product, the intelligence-administrative complex, telling itself stories.

But surely there is a risk from Teh Huawei? Well. First of all, what are we trying to protect? "Security" isn't an answer. There are, as far as I can see, essentially three things an attacker could do in the BT core network - crash the whole thing (denial of service), spy on somebody's traffic, or spoof a network entity, to pose as one in order to misroute traffic for some sinister aim. The horrors described in the article are presumably thought to be possible consequences of a massive denial of service attack.

How would they go about attacking it? Well, the whole point here is that they can attack from the public Internet. (If they can attack from within BT, it doesn't matter whose routers we buy...) Physical layer attacks are much less dangerous because you would need to do much more work for every unit of trouble caused - you'd need to physically tap wires and find ways of backhauling the traffic you tapped.

So we're concerned about a breach of Internet security, which implies that the crucial element in our defence will be to prevent malicious traffic getting access to the system's administrative features. For our purposes, a secret backdoor is essentially the same as an administrator interface.

Well, that's good news - this would be absolutely no different if the equipment came from Cisco Systems, Alcatel, Marconi as was, Nokia, ZTE, Motorola, NEC or anyone else, and the security solutions involved are applicable across them all, being essentially good internetworking practice. And 21CN's architecture actually makes an attack from the IP layer rather difficult. It's probably worth opening the Wikipedia page in another tab to follow this bit.

21CN is made up of Multi-Service Access Nodes (MSANs), which replace the old local exchanges, terminate the copper wires from your house, and switch different kinds of traffic into appropriate pipes - steam voice gets converted to VoIP at this point as well, metro-nodes, which are the gateway routers to the core network, core nodes, which are really big MPLS routers, and iNodes, which are voice softswitches and which will control calls, video sessions etc. Huawei's bit is the MSAN, plus some of the optical splitters, repeaters and such.

Importantly, the MSAN isn't an Internet entity; it is a Layer 2 Ethernet device, which talks to the metronode it's connected to. In 21CN, both other ISPs and BT Retail are sold wholesale service in the form of Ethernet links, and the MSAN is responsible for putting the traffic into the right link, but the metronode is the first element to actually route Internet packets. Therefore, even if the Chinese were to secretly control all the MSANs, they would have to create a new Wholesale Broadband Connect Ethernet pipe from each one in order to get the traffic out to the Internet. And to control it, they would have to first of all get in, then break out of the encapsulation to access the MSAN itself.

And most of the IP layer equipment, including the big routers that link the whole thing to the Internet, is made by Alcatel, Cisco, or Juniper Networks; in fact, 21CN has a fair amount of diversity, which is usually good from a security standpoint. So I would suggest that this is a classic movie plot threat. Like most of them, of course, it taps deep political assumptions and vested interests; there is no evidence of Huawei's equipment being secretly controllable by the Chinese intelligence service whatsoever, but there are a lot of rightwing congressmen who just know it, and they receive contributions of funds from competing vendors with unstartling regularity.

And more to the point, what is the evidence that Huawei is any more likely to be spying on its customers than the alternatives? If the equipment came from Cisco Systems, as some of it does, shouldn't we worry that the Americans have secretly fiddled with it? If from Alcatel, as some of it does, what about the French? (Don't laugh, they're building a Total Info Awareness clone.) The Swedish government wants to run absolutely all Internet traffic on its territory through the facilities of the FRA, its national signals-intelligence agency, so obviously Ericsson (and Juniper, which is an Ericsson division) can be ruled right out.

However, we don't have a single documented case of any of these things happening. In fact, the best documented telco core-network hack, the Vodafone Greece case, involved an Ericsson AXE10 switch and specifically the lawful-interception system, which is really a nonsecret backdoor into the switch for the cops and spooks to listen in. (And the iNodes in 21CN? They're AXE10s. ) So it's quite possible that the security bureaucrats might be the cause of the security threat.

After all, they have Windows PCs in their offices. And they get hacked. By the Chinese. And they *do* have back-door access. Now, no-one knows who was behind the Vodafone Greece case, but we do know who is behind the vast majority of real information security breaches: non-state actors. But for some reason, there is a strange kind of cognitive bias against accepting the reality and agency of non-state actors. Just as a certain kind of government official cannot believe that guerrillas or terrorists can exist without the Dr Evil figure (Iran! Syria! Cuba! Canada!), they can't believe that their computers might get hacked by hackers. I've had to come back to this again and again and again.

The problem is, of course, that it involves believing that the little people have agency, intelligence, and skill. Here's some evidence from F-Secure; the malware used in the Tibetan spying operation is maintained by a group of hackers and is openly on sale (and some people say it's Swedish - didn't I tell you we can't trust those terrible Vikings?). Accepting that is an important political act, and it is absolutely necessary, both for effective security and in general to move beyond fear.

(Update: China Mobile isn't worried and trusts the French. And there is a metal band called Beyond Fear, which is almost as cool as Bruce Schneier.)

Sunday, March 22, 2009

gaseous Goodhart

China's top climate change negotiator wants the Chinese export sector to be excluded from their targets, and "consumers to pay" instead. This is not good news.

For a start, the tactics. It means accepting the principle of letting some special interests off. We know, after all, that there will be the mother of all lobbying wars about this, all wanting their pet interest group to be left out. Therefore it's best to hold a firm line as long as possible, minimising the damage. Also, even if this isn't just special pleading, the output (no CO2 target for much of Chinese industry) is identical to the effects of special pleading. So it's worth treating it as such until proven otherwise.

After all, if it proved to be honest, you can always make a gracious concession later; but you can't take back concessions you made earlier so easily.

Secondly, there is no end to this argument. If they claim a right to export all they like and bill the customer for the CO2, then for this right to be effective, they must also have a right to import capital goods - machine tools, Siemens power stations, that kind of stuff. Wham, half the German engineering sector wants a note from mum too. What about the primary exporters? And come to think of it, if it's the consumer's fault, some of that responsibility must rest with the people who lent them the money...which for the dollar zone was the People's Bank of China, State Administration of Foreign Exchange.

More seriously, it's a really bad idea on the substance. The mechanism of action is something like this - imports containing a lot of embodied CO2 would be taxed and would cost more, so people would buy less carbony ones, and Chinese exporters would stop producing so much CO2. But it's a very long set of tongs; too many moving parts. Unless the energy used in the product is a hell of a lot, the tax component won't be that great compared to the range of prices for that kind of product. The exporter might not notice, or might attribute the drop in sales to something else.

Just taxing fossil fuel at the point of sale, already, has the huge advantage that it falls directly on the user, who has the most control over how much gets used, and it's explicitly and unmistakably down to the fuel.

Further, how many SKUs (Stock-Keeping Units - individual products) does the Chinese export sector produce? It's got to be in the tens of thousands at the least. Under this proposal, each one would have to be carbon-audited accurately and regularly and assessed for taxation on that basis. It is far from clear whether the importing state or the exporting state would do this. Just taxing fossil fuel, already, involves less than a dozen SKUs, which happen to be bulky, smelly, heavy, or black and dusty, and therefore difficult to hide on a big scale.

And every manufacturer would have a fine incentive to lie about the CO2 emissions associated with their product; if you can bring yourself to put melamine in the milk, you can surely lie about your electricity bill. It's the worst Goodhart's Law violation I've seen for a long time.

But here's the really weird bit. Whether the CO2 tax is applied at source as a fuel tax or a cap-and-trade system, on crossing the border like a tariff, or at the point of final sale like VAT, the economic upshot is essentially the same; goods subject to it would cost more than goods not subject to it, and goods subject to it that contained more CO2 would cost more than ones with less.

Either yer man is hoping that the importing states wouldn't bother to impose the tax, or else his argument is actually indistinguishable from the one he's trying to shoot down - that there should be a tariff on goods from states that don't implement a CO2 tax.

Alternatively, he's just talking his book, setting a negotiating marker in a cost-free fashion. In which case, time to pick it up and run it back.

If this leaves you in need of an optimism fix, have a look at this GSFC feature. The "shorter": ozone depletion would have made it unsafe to go out in the sun for as long as five minutes essentially everywhere by 2065, but we, ah, fixed it. (Via German ScienceBlogs; if you speak German there's also a fascinating interview with Paul Crutzen here.)

Sunday, December 21, 2008

business in great waters

Meanwhile, this is good news. As more and more ships from various parts of the world - like China and Iran - arrive in pirate country, somebody's made vaguely sensible arrangements to put them on trial in Kenya, which is what has been done with the ones captured by Northumberland. This is a much better idea than returning them to the tender mercies of Somali rivals, or alternatively to their home base, or any evil nonsense promoted by tiresome Internet hard men. (You know who you are.)

I'm not sure whether to be pleased, or worried that China and Iran are apparently cooperating in an exercise designed to be more law-abiding than some British courts, and far more so than whole swaths of the US defence establishment. This is incredibly important; I keep saying that a primary reason for the success of some Islamist movements is that they offer some form of legal order, rather than Franz Neumann's Behemoth.

After all, dogs have an innate appreciation of justice, so we should surely accept that it matters for human beings too. As a modest proposal, now the EU has taken over the lead in combating piracy in the Gulf of Aden, could we perhaps give the naval task force a further mission - to compel EU-flag fishing vessels to respect the Somali EEZ? (We wouldn't have legal authority to stop anyone else without a UN resolution, but it's a start.) I agree they have plenty on their plate, which is why I'm going to make a second modest proposal.

Rather than frigates, EU states participating in this could instead deploy some of their sizeable fleet of amphibious assault ships, with a deckload of helicopters, a dock of small craft, and a tankdeck containing a mix of marines for boarding parties, and medics, engineers etc to support the UN's aid activities.

Sunday, September 14, 2008

They have wakened the timeless Things; they have killed their father Time

More China convergence blogging. Declan McCullagh reports on efforts by the US and China to sneak something nasty into the ITU standardisation process, through a committee that doesn't publish its documentation or let anyone else in the room. But the Chinese appear to be the ones leaning forward;
The Chinese author of the document, Huirong Tian, did not respond to repeated interview requests. Neither did Jiayong Chen of China's state-owned ZTE Corporation, the vice chairman of the Q6/17's parent group who suggested in an April 2007 meeting that it address IP traceback.

A second, apparently leaked ITU document offers surveillance and monitoring justifications that seem well-suited to repressive regimes: A political opponent to a government publishes articles putting the government in an unfavorable light. The government, having a law against any opposition, tries to identify the source of the negative articles but the articles having been published via a proxy server, is unable to do so, protecting the anonymity of the author.
Now that's what I call a use case! The standards group in question includes someone from the Chinese ministry of telecoms and an NSA official whose biog appears to be secret, as well as someone from Verisign; who is hilariously quoted as saying that:
"The OSI Internet protocols (IPv5) had the capabilities built-in. The ARPA Internet left them out because the infrastructure was a private DOD infrastructure."
(Trust me, if you know your Internet history, it's hilarious.) The poor darling, still wishing for someone to bring back OSI. And the representatives of the Chinese Communist Party conspiring away with the NSA.

Oh well; it's not as if it's going to work. Viz:
“Since passage of the Patriot Act, many companies based outside of the United States have been reluctant to store client information in the U.S.,” said Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington. “There is an ongoing concern that U.S. intelligence agencies will gather this information without legal process. There is particular sensitivity about access to financial information as well as communications and Internet traffic that goes through U.S. switches.”

But economics also plays a role. Almost all nations see data networks as essential to economic development. “It’s no different than any other infrastructure that a country needs,” said K C Claffy, a research scientist at the Cooperative Association for Internet Data Analysis in San Diego. “You wouldn’t want someone owning your roads either.”
Read the whole damn thing; it's one of the best reported stories on the Internet infrastructure I've ever seen, they spoke to the right people (Renesys, k c claffy, Odlyzko), and the conclusions are interesting to say the least.
The Renesys rankings of Internet connections, an indirect measure of growth, show that the big winners in the last three years have been the Italian Internet provider Tiscali, China Telecom and the Japanese telecommunications operator KDDI.

Firms that have slipped in the rankings have all been American: Verizon, Savvis, AT&T, Qwest, Cogent and AboveNet. “The U.S. telecommunications firms haven’t invested,” said Earl Zmijewski, vice president and general manager for Internet data services at Renesys. “The rest of the world has caught up. I don’t see the AT&T’s and Sprints making the investments because they see Internet service as a commodity.”
If the "American Internet" is ending, it's because they don't deserve it any more.

Sunday, April 13, 2008

....here I am!

I have been away, cutting down to only very restricted Internet/computing usage, and living in a district that would make Abu Muq piss his baggy pants. (Walthamstow, he says. You've never been to Bradford, have you?) Which is amusing, because (as in every poor/immigrant 'hood in Europe) every second business is a mobile phone/computer shop. You can pick up a wrap, an Algerian hooker, and an 8GB Nokia N95 in the same queue. But I succeeded in not opening my laptop for a whole seven days, which is a record for me at any time since 2004 at least. This gives rise to a challenge; how quickly can I resynchronise myself with my auxiliary brain? So far I've spent all of today slurping up a week's worth of blogs, to say nothing of the e-mail; the comments, the spam, the news services, and a number of high-activity mailing lists.

And isn't it fucking horrible? I just decided to skip Sadly, No! and a few others; one forgets just how much ideological trench warfare blogging we get through in a week. Anyway, to business. (Speaking of which, there's the work re-sync coming up tomorrow. Thank God I zeroed my inbox before going on holiday. And, yes, I have been reading them; you want to know whether you're going to have to run off the plane and form a defensive perimeter around your job...) I am delighted to see that a hitherto unknown revolutionary political-theatre collective, something similar to the Space Hijackers, successfully staged a demonstration that satirised literally every feature of the Blair/Brown years in one chaotic afternoon of low-level violence, massive traffic disruption, heavy-handed policing, and blanket media coverage.

I refer, of course, to the people who staged the mock Olympic torch relay through London. It was a great idea in itself, but the genius was in the details; who would have thought of including nameless foreign security police beating up thought-criminals while pretending to be Olympic Committee bigwigs? And then, they set about Sebastian Coe, a real Olympic bigwig and one of the most annoying men in the kingdom? And then, who would have imagined a sort of Jim'll Fix It slot in which the ambassador of a vicious dictatorship got to pretend to be a world champion runner with the aid of thousands of cops?

Working Tessa Jowell in there was inspired ("Your Excellency, Auntie Tessa fixed it for you!"), but having the speeches drowned out by a monster sound truck advertising the products of some other country that didn't toast its industrial base by playing dire pseudo-stripper cheesepop at maximum volume right there in Downing Street? Genius. It just says it all - the authoritarianism, the obsession with "events", the utterly whorish foreign policy, the corporate arse-licking, the total absence of anything like taste or class, and the fucking people. Seb Coe. Tessa Jowell. Yes!

Hand that man an Arts Council fellowship. Seriously, it's like a committee of Chris Morris, Mark Thomas, Linda Smith (yes, I know) and Tim Ireland designed the whole thing. They'll never try the real one now, will they?

kostenloser Counter