7 ms·
Grew up in China (moved to Australia since early 2008) where GFW is in place and getting overwhelmingly powerful, I've been through multiple stages to cross the
by terrywang 9y ago
Grew up in China (moved to Australia since early 2008) where GFW is in place and getting overwhelmingly powerful, I've been through multiple stages to cross the `great wall`, SSH Dynamic Forwarding, PPTP, OpenVPN and now IPsec (strongSwan). The GFW has evolved so much (capable of massive scale MITM attack, DNS spoofing, traffic sniffing etc. you'll be amazed how capable the GFW is - of course courtesy of the team behind it) that it makes increasingly more difficult for people to access the real Internet.
I've ditched PPTP (not safe any more) and shifted to IPsec (IKEv2 + RSA with X509, IKEv1 + PSK + XAUTH) as it is being used by a lot of MNCs - can't killall. The GFW has developed technique to detect OpenVPN well and it is easily blocked so I don't use it at all. Over the past few years many home brewed protocols emerge - e.g. shadowsocks and variants and many others (I've never used any of them).
The best thing to do with VPN is that to understand the basics of the VPN solution of choice, try to install and configure from scratch on VPS and use that as your main protection (encapsulation) while using public Wi-Fi or untrusted network. There's been many good discussions on how to do this on HN.
NOTE: I am maintaining around 10 strongSwan powered IPsec VPN and 2 OpenVPN to help family members and close friends to access the real Internet (have to keep a low-profile though). Funny though, my networking skills evolved with GFW.
- stevenjohns 9y agoI will be traveling to China in a couple of days and was ignorantly hoping my OpenVPN-based VPN would work. Do you recommend that I set up strongSwan?
- terrywang 9y agoTry to change the default port 1194 to something else (e.g. 443) - this may not help as the GFW has the ability to detect OpenVPN specific traffic. If it is only for yourself and traffic is very little, it may survive the period of your stay in China. Nobody I know in mainland runs OpenVPN any more so I cannot really prove that, sigh...
- scott_karana 9y agoThat trick no longer works at all, to my knowledge. The GFW is wise to it. That's why Tor had to implement HTTPS-like fake traffic padding in its obfsproxy modules, which also need to keep evolving...
- ineedtosleep 9y agoI used PIA with relative success. The caveats being: 1. DNS resolution may not work, so you'll need to find a way to resolve the domain name (i.e. hk.privateinternetaccess.com) to IPs for your config. 2. Even if you get an IP it may not work all the time. You will have to keep resolving the domain name for another IP (or maybe just look at all the DNS records?). EDIT: I should mention I used PIA's PPTP (yes, it's discouraged but it worked for my purposes) and L2TP configurations just fine.
- rahimnathwani 9y agoSet up Shadowsocks. (OpenVPN won't work regardless of port and choice of udp/tcp, unless you tunnel it through obfsproxy or similar.)
- whooshee 9y agoJust use Psiphon or ShadowsocksR, you will be fine, don't use a cliche old VPN.
- ymhuang0808 9y agoA few months ago, I went to Shanghai. Before going to China, I setup the Shadownsock on my server. My 4G network is roaming SIM card. I can surf on Google Map over my SIM card without any proxy or VPN. To prevent from sniffing, I always connect to the network via OpenVPN with non default port. In hotel, the Wi-Fi network cannot connect to many sites. Sometimes, I can connect the Internet via OpenVPN, but, Shadowsocks is more stable.
- jbg_ 9y agoAnother option is roaming on a foreign SIM card - this usually bypasses the GFW quite effectively; roaming is effectively a VPN back to the home provider, and there seems to be some whitelist for these roaming tunnels. The providers probably provide surveillance access to the Chinese govt, but you will not have trouble accessing Google and other blocked sites, and any VPN you like should work fine through a roaming SIM. Whether you can find one with reasonable data rates in China is probably the main question. Two that I have used with great success are Kyivstar from Ukraine and China Unicom HK (note it must be HK, not mainland China). Others may be listed at [0]. [0] http://prepaid-data-sim-card.wikia.com/ http://prepaid-data-sim-card.wikia.com/
- L_Rahman 9y agoI can confirm that the foreign SIM card override works from my experience a couple of years ago. My T-Mobile had free international roaming baked in at 2G speeds. Unlike the US however, most foreign carriers in developed Asian nations (China/Korea) don't support 2G fallback, so I had free 3G everywhere. It was pretty much like using the American internet.
- ineedtosleep 9y agoI was in China this year and found it surprising that it's as powerful as it is. Consequently, I also found out how powerful not having the entire internet is. The amount of information/sites I wasn't able to access due to it not being accessible at all; or "accessible" but never fully downloadable (i.e. javascript not able to download fully, other assets blocking actual content from being loaded) was staggering. Coupled with the official cable TV service, which is amusingly abbreviated CCTV[1], and other state-controlled media, it's an eye-opening thing to see (more blatant) information control in action. [1] https://en.wikipedia.org/wiki/China_Central_Television https://en.wikipedia.org/wiki/China_Central_Television
- whooshee 9y agoBecause GFW (maybe accidentally) blocked quite a few CDNs, that influenced many other 'not-on-list' sites overseas to download their assets properly.
- forapurpose 9y ago> The amount of information/sites I wasn't able to access due to it not being accessible at all; or "accessible" but never fully downloadable (i.e. javascript not able to download fully, other assets blocking actual content from being loaded) was staggering. Can you read Chinese? I ask because if not, the experience of people who can might be very different. I'm completely against the censorship; I just wonder how effectively they implement it.
- danmaz74 9y agoNot OP, but I suppose that people only reading Chinese in China won't notice this much, because most (all?) of what they find is inside the Great Firewall and thus under control (direct or indirect) of the Chinese government. But that's exactly as intended.
- deleted 9y ago[deleted]
- dvcrn 9y agoI just went to Shanghai, bought a local SIM card and installed any VPN app from the App Store on my phone (I used "HexaTech"). Had no problems at all with it, even with the free tier. I was kind of surprised how easy it was to get through the GFW
- PakG1 9y agoBeing in China now, I can say that just because it works doesn't mean that it's great. I think the government has demonstrated multiple times that they can block and throttle VPN connections at the flick of a switch. If one works, it's because of the government's mercy, not because of some circumvention team's ingenuity. That's my final conclusion. Yes, new methods might break through those times the switch gets turned on to block, but those new methods get blocked eventually too. It's an arms race where one side has near unlimited funding.
- halfelf 9y agoThe most terrible fact about GFW is that it makes people forget they have a chance to access the other part of internet. Most netizens here don't even have a idea to cross it.
- fantispug 9y agoThe amount of censorship varies by province; I wouldn't be surprised if it is easier in Shanghai than in other parts of China.
- forapurpose 9y agoRemember that Chinese people who do it are subject to attracting negative government attention; they face much more risk, even it works.
- yeukhon 9y agoI still believe some of the loopholes are intentional left alone by the government.
- darkmighty 9y agoWith China being such a manufacturing powerhouse, I can imagine loopholes are essential to keep international business and trade in order.
- yeukhon 9y agoIf it is a loophole it is not legitimate. To keep business and trade IN ORDER it would be legal. I think some of the loopholes are “honeypot” just to capture potential intelligence.
- zhte415 9y agoInternational companies can apply for VPN which allows them to legally use one. They need to attest that it will be used for business purposes; this should sensibly part of the negotiation process when investing and establishing a presence.
- PakG1 9y agoI'm not sure about VPNs? As I understand, it's corporate lines to overseas that's allowed. That's what we use, we lease bandwidth on a major submarine cable that goes to California and sign a contract that says we won't be using it to break laws, and Vvv we tell our employees to only use it for work.
- zhte415 9y agoThe data has to get from office to submarine cable, VPN is needed. When logging in from home, I need to select the end-point of the VPN, so I'm pretty sure it is a VPN. This is common with any country - connecting to the corporate network must be via VPN (unless the corporate is crazy and in violation of many laws disclosing customer data).
- rqs 9y agoVPN and SSH or other public (detectable) protocols are goner for very long time now. I don't understand why you guys still trying to use it. In China, you may need to use one (Or multiple) of following: https://github.com/shadowsocks https://github.com/shadowsocks https://github.com/v2ray https://github.com/v2ray https://github.com/XX-net https://github.com/XX-net https://github.com/ginuerzh/gost https://github.com/ginuerzh/gost And +https://github.com/gfwlist/gfwlist https://github.com/gfwlist/gfwlist for automatic proxy switch. Those applications may require a dedicated server or VPS to run. Once you set it up, it will act like a relay between you and the host you want to access (So that server or VPS must located outside GFW's shadow. And you better set it up and get it well tested before you move to China). If you don't want to setup a server all by yourself, you can use Lantern or Psiphon, but they are considered not safe as you don't have any control once data leaves your machine. I personally use Shadowsocks + my own one made with Golang. Both of them works very good for me. Some people may had problem with Shadowsocks but cause of those problems remain a myth.
- rtpg 9y agoI was in China a couple months ago and ExpressVPN worked fine for me, are they actually using their own custom protocol?
- rqs 9y agoI have no experience with ExpressVPN, so I can't help you with that. But in a vlog I've watched on Youtube, the host of that vlog said "Over the last coupe of days, ALL the VPN is been very difficult to use". So, I guess that includes ExpressVPN. Here is the video if you interested: https://www.youtube.com/watch?v=EuEdYvQmVFg https://www.youtube.com/watch?v=EuEdYvQmVFg (5:20)
- akaa 9y agoIm in china at the moment using expressvpn (been using it for a year by now) and since about two weeks only three server locations work well (Hong Kong, Tokyo, Los Angeles). Some others work off an on. Before that most locations worked and some of them, Taiwan for example, used to be very fast. Its still usable for streaming and surfing but I'm afraid the end is near. I think sometime in the future one will have to go with shadow socks and or similar protocols/solutions but until then expressvpn is quite convenient (mobile client, router with expressvpn client).
- BlackPlot 9y agoI'm in Beijing. After ExpressVPN was down a friend of mine recommended to give a try for NordVPN as Astrill looks like China's government VPN which logs everything. And I was surprised - Nord works significantly and costs just over 3 bucks.
- pavs 9y agoHijacking the top comment to link to something I wrote recently. As someone who owns and works and knows the ins and outs of an ISP and had the 'pleasure' to deal with many 3-word government organization, I can't help but feel that many people think privacy exist in some form and using VPN somehow makes you immune. Please learn to understand double-speak. If the FBI says they are having a hard time cracking smart-phones or some kind of encryption, understand that they actually want you to use that security because they have figured out how to get around it. I may sound like an alarmist, but it isn't intentional - because the government is much much more powerful in terms of resources they can throw at a problem - if they can't crack something they will find a way to intimidate someone to install a backdoor for them while completely denying it in public. This happens ALL the time. Most of us just don't know about it. http://www.slashgeek.net/2017/10/23/online-privacy-doesnt-exist/ http://www.slashgeek.net/2017/10/23/online-privacy-doesnt-ex...
- weavejester 9y ago"Please learn to understand double-speak. If the FBI says they are having a hard time cracking smart-phones or some kind of encryption, understand that they actually want you to use that security because they have figured out how to get around it." Do you have any evidence, or is this just speculation? I can buy that governments have access to zero-day exploits; I don't buy that every form of encryption they complain about has been secretly been broken.
- uoaei 9y agoInfosec 101: if it truly is a problem for you, you don't tell anyone.
- apexalpha 9y agoWhen I was in China for 6 months I just wrapped my OpenVPN in a regular TCP tunnel with stunnel https://www.stunnel.org/index.html https://www.stunnel.org/index.html Was slow, but it worked.
- antihero 9y agoCan you use SSH? If so, can you SSH tunnel? Furthermore, if ExpressVPN is allowed, could you connect to that and inner-tunnel to your own VPN?
- terrywang 9y agoSSH Dynamic forwarding (ssh -D) to do application-level port forwarding and configure browser to use remote host to do DNS lookup was 1 of the earliest techniques to bypass the GFW and was countered by the GFW long time ago. The wall can easily detect non-administrative SSH traffic and block it. So I won't recommend using it, it is not reliable.
- foxthrowaway 9y agoIf your VPN server is used by many users it tends to be detected and blocked by GFW. In case you found managing shadowsocks servers cumbersome, you may want to check out https://foxshadowsocks.com https://foxshadowsocks.com They manage shadowsocks servers for you and allow you to move servers across regions (to get a new IP).