HTTP 451 explained

In computer networking, HTTP 451 Unavailable For Legal Reasons is a proposed standard error status code of the HTTP protocol to be displayed when the user requests a resource which cannot be served for legal reasons, such as a web page censored by a government. The number 451 is a reference to Ray Bradbury's 1953 dystopian novel Fahrenheit 451, in which books are outlawed.[1] 451 provides more information than HTTP 403, which is often used for the same purpose.[2] This status code is currently a proposed standard in but is not yet formally a part of HTTP, as of .

Examples of situations where an HTTP 451 error code could be displayed include web pages deemed a danger to national security, or web pages deemed to violate copyright, privacy, blasphemy laws, or any other law or court order.

After introduction of the GDPR in the EEA it became common practice for websites located outside the EEA to serve HTTP 451 errors to EEA visitors instead of trying to comply with this new privacy law. For instance, many regional U.S. news sites no longer serve web browsers from the EU.[3] [4] [5]

The RFC is specific that a 451 response does not indicate whether the resource exists but requests for it have been blocked, if the resource has been removed for legal reasons and no longer exists, or even if the resource has never existed, but any discussion of its topic has been legally forbidden (see injunction).[6] Some sites have previously returned HTTP 404 (missing) or similar if they are not legally permitted to disclose that the resource has been removed. It is used in the United Kingdom by some Internet service providers utilising the Internet Watch Foundation blacklist, returning a 404 message or another error message instead of showing a message indicating the site is blocked.[7] [8]

The status code was formally proposed in 2013 by Tim Bray, following earlier informal proposals by Chris Applegate[9] in 2008 and Terence Eden[10] in 2012. It was approved by the IETF on December 18, 2015.[11] It was published as in the Proposed Standard in February 2016.

HTTP 451 was mentioned by the BBC's From Our Own Correspondent programme, as an indication of the effects of sanctions on Sudan and the inability to access Airbnb, the App Store, or other Western web services.[12]

Usage

When an entity intercepts the request and returns status 451, it should include a "Link" HTTP header field whose value is a URI reference identifying itself. The "Link" header field must then have a "rel" parameter whose value is "blocked-by". This is intended to identify the entity implementing the blocking (an ISP, DNS provider, caching system, etc.), not the legal authority mandating the block.[13] At an IETF hackathon, participants used a web crawler to discover that several implementations misunderstood this header and gave the legal authority instead.[14]

Additional uses

The meaning of "a resource which cannot be served for legal reasons" has been interpreted to extend beyond government censorship:

Example

HTTP/1.1 451 Unavailable For Legal ReasonsLink: ; rel="blocked-by"Content-Type: text/html

Unavailable For Legal Reasons

Unavailable For Legal Reasons

This request may not be serviced in the Roman Province of Judea due to the Lex Julia Majestatis, which disallows access to resources hosted on servers deemed to be operated by the People's Front of Judea.

See also

External links

Notes and References

  1. News: Call for Ray Bradbury to be honoured with internet error message. Flood. Alison. 22 June 2012. The Guardian. 22 June 2012.
  2. Web site: HTTP error code 451: "Unavailable For Legal Reasons". Ducklin. Paul. 19 August 2013. Naked Security. Sophos.
  3. News: Matt Burgess. The tyranny of GDPR popups and the websites failing to adapt. WIRED. 2018-08-29. 2018-10-01.
  4. Web site: More than 1,000 U.S. News sites are still unavailable in Europe, two months after GDPR took effect. www.niemanlab.org.
  5. Web site: Major US news sites are still blocking Europeans due to GDPR. Engadget. 27 July 2023.
  6. 7725. An HTTP Status Code to Report Legal Obstacles. February 2016. 3. 451 Unavailable For Legal Reasons. Tim. Bray. Tim Bray.
  7. Web site: If the request is for the blocked content then the proxy server will return a 404 error page to the customer. Cleanfeed. ORG Wiki. Open Rights Group.
  8. Web site: TCP Reset is sent back to the customer instead of content.. How the IWF blacklist stops you seeing the Scorpions' album cover. Technology blog, The Guardian. Charles. Arthur. 8 December 2008.
  9. Web site: There is no HTTP code for censorship. Chris. Applegate. qwghlm.co.uk. 9 December 2008. 23 December 2015. 19 April 2021. https://web.archive.org/web/20210419112431/http://www.qwghlm.co.uk/2008/12/09/there-is-no-http-code-for-censorship/. dead.
  10. Web site: Byrne. Michael. 21 December 2015. The HTTP 451 Error Code for Censorship Is Now an Internet Standard. 2020-07-03. Vice.
  11. Web site: Why 451?. Mark. Nottingham. mnot’s blog. 18 December 2015. 20 December 2015.
  12. From Our Own Correspondent. radio. BBC Radio 4. Sally Hayden. 28 September 2017 . Sally Hayden .
  13. 7725. An HTTP Status Code to Report Legal Obstacles. February 2016. 4. Identifying Blocking Entities. Tim. Bray. Tim Bray.
  14. Web site: RFC Errata Report. Stéphane Bortzmeyer. Stéphane Bortzmeyer. IETF Tools. 11 November 2017. 2018-12-03.