3 ms·
Damn, I've read the code. This won't work against an active probe. Censors just use signal domains and non-signal domains to test your proxy. If signal domains
by realducksoft 6y ago
Damn, I've read the code. This won't work against an active probe. Censors just use signal domains and non-signal domains to test your proxy. If signal domains get passed and non-signal domains got denied, you are fucked. Besides, TLS in TLS is highly identifiable by simple packet length dpi. I'd hope there's better plan.
- Diggsey 6y ago> Censors just use signal domains and non-signal domains to test your proxy. If the censor already knows about your proxy they would have no reason to test it... The whole point is that there isn't a central list of proxies for them to easily block.
- deleted 6y ago[deleted]
- pmlnr 6y ago> there isn't YET. I wonder if someone will find a simple way to map these with shodan.
- I_Byte 6y agoThis is the very same problem that Tor faced when Tor bridge use started to pick up in China around the late 2000s / early 2010s. You only needed a single Chinese user to connect to your server for it to be probed by the Chinese censors. Older versions of the obfs Tor bridge protocol could be detected by active probes and thus blocked very much like these Signal proxies. This is a cat and mouse game that Signal could very easily lose should Iran start to care about probing all new active connections that leave Iran.
- lucb1e 6y agoNo but look, they're blocking connections country-wide. Apparently they have government boxes installed on the outside lines. If you're looking at IP headers and deciding to drop or pass based on that, it's trivial to collect the IPs you don't yet know, check if they're running a proxy (Signal, Tor, I2P, whatever), then add them to the block list if they are. If it's trivial to figure out (by doing a nice handshake) whether something is a certain kind of proxy, then the cat-and-mouse game is reduced from finding lots of mice to updating the cat system to test whether passing animals are mice and instantly wiping out the mice population.
- toast0 6y agoTLS 1.3 supports (encrypted) padding bytes for Application Data; which could be used to normalize the packet lengths. Probably not accessibly via normal system TLS libraries though. Although, if only Signal is making nice sized packets, that could be suspicous.
- nirui 6y agoAnd based the log on my hand, probing is really "mainstream" now days. I have a Shadowsocks proxy instance started since Oct 20 last year, and it's been attacked $ docker logs shadowsocks 2>&1| grep "AEAD: repeat salt detected" | wc -l 16468 times total. The last 6 happened less than 10 minutes ago. My expectation is, TLS will be probed even more, because the handshake parameters (the order of CipherSuite for example) itself could leak a lots of info about the client&server. It's not easy to build a protocol that is cryptographically safe all while keep the traffic characterless/innocent. Could be a "World Changing Event" if somebody discovered a way through.