5 ms·
So am I understanding correctly that this is just DNS blocking? Surely this court-ordered blocking can be trivially bypassed by switching your DNS server.
by daxterspeed 8y ago
So am I understanding correctly that this is just DNS blocking? Surely this court-ordered blocking can be trivially bypassed by switching your DNS server.
- stordoff 8y agoDepends on the method used. Virgin Media in the UK intercept HTTP requests (and send resets to HTTPS connections), so even tunneling my DNS traffic over a VPN doesn't help.
- imrehg 8y agoIs Virgin blocking SciHub in the UK? I'm on a Virgin connection, and can use it. Or that technique is just in general for sites that Virgin is blocking? (I wonder if there's a list)
- Deathmax 8y agohttps://www.blocked.org.uk/ https://www.blocked.org.uk/ has a list
- stordoff 8y agoAs far as I can tell, SciHub is not blocked, but try something like yts.am Over HTTP, you get redirected to http://assets.virginmedia.com/site-blocked.html http://assets.virginmedia.com/site-blocked.html Over HTTPS, you get ERR_CONNECTION_RESET (Chrome)
- manquer 8y agoFor dns blocks, DNS over HTTPS should work Firefox supports it, or you could run a local DNS resolver, or use host file for domains that you use and are blocked. Also I am not even sure it is possible to intercept any traffic over VPN without having the keys, so not sure why tunneling over VPN is a problem , DPI and MITM techniques are not even used by the Chinese government for the most part and people can generally VPN out if they want to.
- Ayesh 8y agoOpenVPN runs on HTTPS port, and I suppose it's hard to block without DPI. If the VPN runs on a known port like various other VPN protocols do, it should be trivial to block those connections.
- stordoff 8y agoFor clarity, the HTTPS were in the clear. Only DNS traffic was over the VPN, to ensure I got an untampered DNS result (and I later verified that hosts files do not help either). You can obviously VPN out, I was just curious how the system was implemented (as the typical advice of change your DNS provider does not help).
- larkeith 8y agoIf you already have a VPN, why not just use it for the entirety of your traffic?
- stordoff 8y agoIt was more experimental than anything - I don't particularly want all of my traffic in a VPN. I just temporarily forwarded my DNS resolver box over the VPN.
- mrmanner 8y agoYup. They put out a press release explaining how to do it, and on the PR stunt blocking page they put up for elsevier.com they have instructions as well. But they didn't include a link to the instructions on the court mandated blocking page =(