2 ms·
OpenVPN was/is meant to "just be https traffic"
by therealx 7y ago
OpenVPN was/is meant to "just be https traffic"
- chopin 7y agoAny source on how it is then distinguishable from https?
- mikeash 7y agoI don’t have a source, but they do traffic analysis to detect VPNs based on usage, not just protocol. For example, ssh is not blocked. However, use ssh -D to proxy web traffic through your connection, and the whole connection will hang in short order.
- js2 7y agoOpenVPN is based on SSL/TLS, which https also uses, but no, it wasn’t designed to look like https traffic. For one thing, OpenVPN uses UDP on port 1194 by default due to technical issues running TCP over TCP. You can switch it to use TCP and run it on port 443, but the underlying VPN traffic usually doesn’t have the same pattern as a typical http connection so it is discernible from https via side-channel attacks. You can try obfuscating the traffic but my guess is that makes it look even less like https. References: - http://sites.inka.de/~W1011/devel/tcp-tcp.html http://sites.inka.de/~W1011/devel/tcp-tcp.html - https://wiki.wireshark.org/OpenVPN https://wiki.wireshark.org/OpenVPN - https://github.com/OpenVPN/openvpn/pull/3 https://github.com/OpenVPN/openvpn/pull/3 - https://community.openvpn.net/openvpn/wiki/TrafficObfuscation https://community.openvpn.net/openvpn/wiki/TrafficObfuscatio... - http://blog.zorinaq.com/my-experience-with-the-great-firewall-of-china/ http://blog.zorinaq.com/my-experience-with-the-great-firewal... - https://news.ycombinator.com/item?id=10905076 https://news.ycombinator.com/item?id=10905076