3 ms·
It's not just a VPS with OpenVPN installed, the main reason why I built it was to be able to click a button and migrate the server to a new location/IP address
by reillychase 8y ago
It's not just a VPS with OpenVPN installed, the main reason why I built it was to be able to click a button and migrate the server to a new location/IP address on demand. Since then I also added "Invisibility Mode" which tunnels VPN over HTTPS bypassing restrictive firewalls, and next I am working on adding pi-hole support to it :)
- nickpsecurity 8y ago"which tunnels VPN over HTTPS bypassing restrictive firewalls," That's one of the reasons I recommend HTTPS-based approaches over things like Tor for anonymity. Makes things look like all the bland, harmless traffic out there. Smart move. :)
- wp381640 8y agoTor supports pluggable transports, one of the most popular of which is meek - which makes your traffic look like Google or Azure CDN traffic over HTTPS[0] Also Tor circuits are also just TLS[1] [0] https://trac.torproject.org/projects/tor/wiki/doc/meek https://trac.torproject.org/projects/tor/wiki/doc/meek [1] https://wiki.wireshark.org/Tor https://wiki.wireshark.org/Tor
- nickpsecurity 8y agoThanks for telling me about meek. I'll warn this might not block visibility at least for domestic TLA's. If they record metadata, they can just work backwards from exit nodes or known relays to whoever is connecting to them. That would map out most likely users of Tor. Then, they can apply whatever passive or active attacks they have. Most probably aren't running OpenBSD, HardenedBSD, QubesOS, etc. ;) Still good for the many, many, other threats out there.
- GordonS 8y agoI don't see anything on "Invisibility Mode" on the GhostiFi website - can you explain a bit about this? Does it work with Windows clients?
- CloudNetworking 8y ago> tunnels VPN over HTTPS bypassing restrictive firewalls That is what I do at https://wormhole.network https://wormhole.network But I don't offer internet access through the VPN, it's purely a virtual network to interconnect your machines in a shared LAN space (100.64.0.0/24 for now).