7 ms·
An unidentifiable mechanism that helps bypass the Great Firewall of China
- netsharc 7y agoThis page has more details than the "executive summary" https://github.com/trojan-gfw/trojan/blob/master/docs/protocol.md https://github.com/trojan-gfw/trojan/blob/master/docs/protoc... As far as I understand it: 1. Client connects to the standard HTTPS port. 2. If it provides a packet with the right (encrypted) password, then the server acts as a SOCKS5 proxy. 3. If it doesn't provide the right password, the server responds like a normal HTTP server over the TLS connection. Seems pretty clever, the hard bit is making sure the passwords don't leak and the firewall starts bombarding suspect servers with requests (brute-forcing passwords). Also if there are timing differences between a genuinely confused HTTP server and a "Trojan" server faking the confusion, they'd figure that out too. Also, things like continuous back-and-forth between the client and a simple webserver would be suspicious, because usually clients send small requests in bursts, get the response, and activity would stop (it doesn't apply to streaming sites, obviously, but there the clients won't be as chatty either). So things like Skype calls might be easily recognized...
- JoachimSchipper 7y agoYes; there is some discussion of attacks in https://github.com/trojan-gfw/trojan/issues/14 https://github.com/trojan-gfw/trojan/issues/14. Personally, I'd be very careful telling people to rely on my software for avoiding the Chinese surveillance - traffic analysis is terrifyingly powerful.
- yorwba 7y agoFor the people currently using random forks of ShadowsocksR they purchased via shady backchannels, an alternative that is less likely to get blocked is probably more important than absolute security guarantees. After all, most users of censorship circumvention tools aren't secretly plotting revolution, they just want to watch YouTube.
- aasasd 7y agoYeah, afaik many DPI tools advertise being able to detect protocols behind TLS/HTTPS or SSH. OTOH if you just wrap HTTP(S) requests to a different server into this, then it probably should look pretty natural.
- kohtatsu 7y agoI think anything looking to serve China should at least avoid hosting on github pages until encrypted SNI is widely available. When someone visits the online documentation at trojan-gfw.github.io, the FQDN is sent plaintext as part of HTTPS. If the data is plainly on github.com (like the wiki), it would at least require an MITM to see what you are reading. Of course an MITM might be likely in China regardless. It's also worth noting the Tor project has done a lot of work in this area: https://2019.www.torproject.org/docs/pluggable-transports.html.en https://2019.www.torproject.org/docs/pluggable-transports.ht...
- thisgoodlife 7y ago> the FQDN is sent plaintext as part of HTTPS. Can you please elaborate on that? domain name is sent after ssl handshake, no? Why is it sent plaintext?
- kohtatsu 7y agoBack in the day there was mostly only 1 website per IP, so when you connected over port 443 for HTTPS, the server would only have the one cert to give you. One day people wanted to serve multiple websites from one IP, so they had browsers tell the server which site they are looking for (Server Name Indication); that way the server would know which SSL cert to send for the handshake. SNI is still plaintext, it's a glaring privacy hole that most people aren't aware of. Encrypted SNI needs to come sooner.
- zzzcpan 7y agoNope, encrypted SNI cannot work against GFW or pretty much any state censorship as the whole idea is bullshit and relies on everyone a) tunneling DNS queries to a centralized party, which itself only operates under the state's mercy, and b) everyone hosting on a single centralized party and c) this party randomizing IP addresses of web sites (none of the CDNs do that, because they want to avoid risking all of their IP ranges being banned by states because of a single website).
- 7y ago
- fnord77 7y agoit took me a few minutes to figure out what "GFW" meant
- marcus_holmes 7y agoI honestly thought Games For Windows
- slantyyz 7y agoI was thinking it was either Games for Windows or Git for Windows, and missed "Great Firewall" on first skim of the Readme.
- IPTN 7y agoFor others - GFW => Great Firewall (of China)
- mapcars 7y agoGlobal Force Wrestling, right? :D
- nostalgk 7y agoUnfortunate name too
- eplanit 7y agoIt used to be a standard of good writing to always expand acronyms at first use. That seems to be gone now as frequently I don't see that in practice much anymore.
- Razengan 7y agoI was about to post the same comment. It's really annoying when someone assumes that everyone will know some uncommon acronyms.
- abc_lisper 7y agoIt is GF who later became a wife ;)
- exabrial 7y agoI don't think it would be very difficult for the Chinese government to demand a compromised root cert authority be installed on every device sold there.
- zhaoweny 7y agoThey certainly can try, but major vendor will resist. Kazakhstan government has tried this method[1]. They sure can try sneaky ways, but any imported laptop connecting to hotel Wi-Fi could reveal it. [1]: https://blog.mozilla.org/security/2019/08/21/protecting-our-users-in-kazakhstan/ https://blog.mozilla.org/security/2019/08/21/protecting-our-...
- gruez 7y ago>They certainly can try, but major vendor will resist It's China. Apple/Microsoft isn't going to resist. Google might not resist because they're already banned there so they've got nothing to lose. Regardless, it doesn't really matter because there's a bunch of homegrown chromium forks that can readily replace Chrome.
- netheril96 7y agoThis software allows you to specify your own CA to verify certificate. The system CA store won't matter in that case.
- m3kw9 7y agoMaybe subscribe to satellite internet
- rvnx 7y ago"unidentifiable mechanism" I'm not sure this is actually true. You can determine that it is a VPN by checking the amount of exchanged packets between interval of time (e.g. if 5 kbps are routinely sent every 30 seconds for 5 minutes this is totally abnormal) Another alternative for the government could be to limit the bandwidth and time of hosts who have a big standard deviation in the amount of the packets per second they transmit. So undetectable I don't think so and I believe smarter people here can find even better ideas. That being said it's a very nice tool, certainly useful in corporate environments as well (except of course, that it'll be suspicious that one single host is exchanging so much data and keeping so long connections)