A Canadian human rights monitoring group has documented the use of American-made Internet surveillance and censorship technology by more than a dozen governments, some with harsh human rights policies like Syria, China and Saudi Arabia.
Thor Swift for The New York Times
The Citizen Lab Internet research group, based at the Munk School of Global Affairs at the University of Toronto, used computer servers to scan for the distinctive signature of gear made by Blue Coat Systems of Sunnyvale, Calif.
It determined that Egypt, Kuwait, Qatar, Saudi Arabia and the United Arab Republic employed a Blue Coat system that could be used for digital censorship. The group also determined that Bahrain, China, India, Indonesia, Iraq, Kenya, Kuwait, Lebanon, Malaysia, Nigeria, Qatar, Russia, Saudi Arabia, South Korea, Singapore, Thailand, Turkey and Venezuela used equipment that could be used for surveillance and tracking.
The authors said they wanted to alert the public that there was a growing amount of surveillance and content-filtering technology distributed throughout the Internet. The technology is not restricted from export by the State Department, except to countries that are on embargo lists, like Syria, Iran and North Korea.
“Our findings support the need for national and international scrutiny of the country Blue Coat implementations we have identified, and a closer look at the global proliferation of dual-use information and communications technology,” the group noted. “We hope Blue Coat will take this as an opportunity to explain their due diligence process to ensure that their devices are not used in ways that violate human rights.”
A spokesman for Blue Coat Systems said the firm had not seen the final report and was not prepared to comment.
In 2011, several groups, including Telecomix and Citizen Labs, raised concerns that Blue Coat products were being used to find and track opponents of the Syrian government. The company initially denied that its equipment had been sold to Syria, which is subject to United States trade sanctions.
Shortly afterward, Blue Coat reversed itself and acknowledged that the systems were indeed in Syria, but it said that the devices had been shipped to a distributor in Dubai, and said that it thought that they had been destined for the Iraqi Ministry of Communications.
The Citizen Lab research project was led by Morgan Marquis-Boire and Jakub Dalek. Mr. Marquis-Boire, a Google software engineer, has during the last year been involved in a variety of research projects aimed at exposing surveillance tools used by authoritarian regimes. He said that he carefully segregated his work at Google from his human rights research.
Last year, Mr. Marquis-Boire used computer servers to identify the use of an intelligence-oriented surveillance software program, called FinSpy, which was being used by Bahrain to track opposition activists.
On a hunch last month, the researchers used the Shodan search engine, a specialized Internet tool intended to help identify computers and software services that were connected to the Internet. They were able to identify a number of the Blue Coat systems that are used for content filtering and for “deep packet inspection,” a widely used technology for detecting and controlling digital content as it travels through the Internet.
The researchers stressed that they were aware that there were both benign and harmful uses for the Blue Coat products identified as ProxySG, which functions as a Web filter, and a second system, PacketShaper, which can detect about 600 Web applications and can be used to control undesirable Web traffic.
“I’m not trying to completely demonize this technology,” Mr. Marquis-Boire said.
The researchers also noted that the equipment does not directly fall under the dual-use distinction employed by the United States government to control the sale of equipment that has both military and civilian applications, but it can be used for both political and intelligence applications by authoritarian governments.
“Syria is subject to U.S. export sanctions,” said Sarah McKune, a senior researcher at the Citizen Lab. “When it comes to other countries that aren’t subject to U.S. sanctions it’s a more difficult situation. There could still be significant human rights impact.”
The researchers also noted that a large number of American and foreign companies supplied similar gear in what Gartner, the market research firm, described as a $1.02 billion market in a report issued in May 2012.
The researchers said that some American security technology companies, like Websense, had taken strong human rights stands, but had declined to grapple with the issue of the possible misuse of the technology.
This article has been revised to reflect the following correction:
Correction: January 16, 2013
An earlier version of this article misspelled the surname of a senior researcher at the Citizen Lab Internet research group. She is Sarah McKune, not McCune.