5 ms·
This article also doesn't touch on the simple technical pains of having to work across the Great Firewall and the effects of it their ability to do business out
by drfritznunkie 10y ago
This article also doesn't touch on the simple technical pains of having to work across the Great Firewall and the effects of it their ability to do business outside of China. Even when you have an excellent partner in China (or vice-versa), so much of the back and forth ends up coming down to issues going across the firewall. Your collaboration tools don't work, so you're split across Slack and WeChat. Github is a disaster in China, and of course, the Googs isn't something you can require anyone in China use. Usual day-to-day stuff is neither simple nor reliable when you have to cross that firewall.
And too boot, it's amazing that Chinese companies are still doing a really poor job of figuring out how to connect well to the outside world. They'll turn to you asking why your API/whatever isn't working for their developers, and then expect that you have some miracle solution to get rid of the 200-400ms of latency (each way!) across the firewall, as well as a cure for the hours of it just dropping all traffic. Perhaps the Party has scared them enough they're not willing to chance employees doing illegal things on the company's connection...
The firewall is a fickle, cantankerous beast that, to me, is really at heart of this matter. Because they want throats to choke for every packet on Chinese soil, they've created this huge barrier that touches everything you might want to do in China or with a Chinese company.
- iliketosleep 10y agototally agree. i'm in china and i can barely have a skype conversation with people abroad - it will randomly cut out or the quality will degrade. i can use google most of the time via VPN, but then there'll be some big political event and even VPN will become intermittent. when my co-founder came to china he couldn't believe how much of a productivity killer the great firewall was. actually, it is quite interesting that the great firewall can totally block most VPN's when the gov. wants it to, but most of the time they choose not to. they just make it enough of a pain for normal people to give up, yet they leave just enough access for those who really need international internet access to get by with VPN (albeit barely).
- eatbitseveryday 10y agoIs there any means to mask packets as being VPN from an observer? I mean, without resorting to complicated scenarios like using SSH tunnels or such.
- yegle 10y agoChina's Internet been an Intranet means GFW don't need to be precise in recognizing traffic flows. A little false positive is fine. Some examples: - Dropping GRE packet so PPTP VPN is not possible - Send TCP RST to both end when a connection to dport=22 generated too much traffic Also from my understanding, it's not that hard to use some basic machine learning techniques to classify the traffic. That's the reason why Tor project developed obfsproxy to obfuscate the traffic flow.
- walrus01 10y agogoogle 'obfsproxy' obfuscation of traffic to make it not look like VPN can be helpful, but traffic flow analysis based on source/origin IPs, timing and kbps/pps can still identify what looks like a VPN.
- heheocoenev 10y agoGFW detects erroneous SSH sessions that contain large data flows. You need to go full protocol obfuscation to untracked destinations.
- drfritznunkie 10y agoI have friends in Shenzhen who regularly walk across the border to connect to HK LTE just to get important work done. And their office has 4? different ISPs, so I know it's a bad day on the firewall when they're working from HK.
- 3pt14159 10y agoIs it illegal to use directional antennas in China? If not, do businesses just get a place with a view to Taipei and route all non-chinese IP requests that way?
- walrus01 10y agothat is way, way too far for any sort of reliable point to point microwave, even with a lot of elevation above MSL on both ends. also the chinese version of the FCC will come along with their partyvan. when you are dealing with a government where non-licensed non-compliant ISP type things will be shut down at OSI layer 1 by armed men with carbines, you have other problems.
- phantom784 10y agoLegality and party vans aside, the concept might work from Shenzhen to Hong Kong.
- dredmorbius 10y agoI'd suggest you run some calculations of mast heights and curvature-of-Earth for various LoS distances. Then consider possible alternatives.
- z2 10y agoNot sure if you were being serious, but along these lines, I stayed in a Shenzhen hotel late last year that strangely provided unfiltered internet. Of course it wasn't advertised as such, but Google worked (redirected to google.com.hk). Given the hotel was right on the border with Hong Kong, one could only speculate how this worked and which option was easier: always-on VPN or antenna :)
- paulsutter 10y agoMy AT&T roaming in China was unfiltered too.
- 10y ago
- superuser2 10y agoOthers on HN have indicated that sufficiently well-connected foreign organizations get their VPNs treated nicely. I think if you are encountering these problems you're just not big enough or haven't paid the right bribes.
- drfritznunkie 10y agoEven when you have control over both endpoints, months of uninterrupted service will be punctuated with weeks of playing hide and seek with the Firewall. BTDT. The problem is when you have a global endpoint that Chinese customers want to access. What do you do then? You either have to figure out how close you can get your services to China and hope and pray they don't whack your traffic one day, or take the bigger risk of deploying your endpoint in China. Either is fraught, but if you want to service that population... And remember, no multicast traffic in China...
- idra 10y agoIt's not about being well-connected. As a company you can actually apply for a state-sanctioned VPN service that would be given the green light and won't be throttled even in the worst of times. If this wasn't the case, how do you think all international companies work in China?
- macspoofing 10y ago>The firewall is a fickle, cantankerous beast that, to me, is really at heart of this matter. The Great Firewall is only one aspect of the problem. Most companies would we willing to host their service within the firewall and deal with it that way. The problem is that running a service within the firewall requires going through the Chinese bureaucracy that is inherently hostile to foreign companies and internet companies.
- jasonjei 10y agoI remember reading this comment awhile back when China shut the door on Uber: "They open the door, allow foreign companies to enter and train locals in the technology and then slam the door when they gain traction." Google executives long suspected China of using local regulations and the GFW to show favoritism to local companies: "[T]he Chinese government against Google seemed less to do with regulations and more like harassment. The sanctions appeared directly tied to how well Google was doing [...] Google executives believed that [...] when [its] market share approached 30%, suddenly bad things would happen. In China, companies need a license to run a website, and it took Google massive effort to secure one. [...] Google’s executives in China realized they were always one step away from another sanction." I think this is exactly what the GFW is for. Train/show local talent a great concept, create/replicate homegrown version, cut off foreign version when homegrown version is ready. At some point, China needs to be concerned if it's pissing off foreign companies. If they want American users, the door has to open both ways.
- system16 10y agoBy the looks of it, it doesn't need to be open both ways at all. Like the article states, Chinese companies like Musical.ly have the chance to access and profit from the US market without US government intervention. US/foreign companies don't have that luxury in China, or they do for just long enough for a local variant to gain traction and then they're booted out. Why the US puts up with this blatant WTO violation is baffling.
- jasonjei 10y ago
- contingencies 10y agodoesn't touch on the simple technical pains of having to work across the Great Firewall Lower bandwidth, higher latency, more packet loss, less reliability. But everything can be achieved. It's not a great problem once you're used to it. Slack and WeChat If you want global, secure, internal chat that works, use XMPP on a VPN. It's pretty trivial to set up. Github is a disaster in China No, it works perfectly. It's not even firewalled. I use it every day, no problems. They'll turn to you asking why your API/whatever isn't working for their developers, and then expect that you have some miracle solution to get rid of the 200-400ms of latency (each way!) across the firewall, as well as a cure for the hours of it just dropping all traffic That's not across the firewall, that's across the Atlantic. A good solution would be placing servers inside of China, or outside but nearby in Hong Kong, Japan or Korea instead of the US. For businesses of any size desiring access to the Chinese market, another POP is not a huge expense. Even for me in the west of China, HK is ~70ms away, Japan is ~100ms.