4 ms·
And this new way, while less convenient, is arguably superior due to its decentralisation. They’re not just going after one service they’re now going after peop
by 2cb 6y ago
And this new way, while less convenient, is arguably superior due to its decentralisation. They’re not just going after one service they’re now going after people all around the world running these proxies.
Just set one up myself took 15 minutes and that includes setting up a fresh VPS.
Just thinking what the best way to share it is.
- birdyrooster 6y agolol i accidentally rented a decent VPS for 30 days in switzerland and now I have a use case for it whoo
- stonesweep 6y agoI've been mulling this over today, as your ability to get the name/IP of the proxy has to be censorship resistant as well. The best idea I've had so far is using a CNAME response to a very common DNS query which would pass a basic filter, like I'd ask for "mail.mydomain.com" and it would respond with a CNAME pointing to the actual proxy. I have dead domains which I have configured with null records for MX and stuff (so spammers can't abuse them), I could hide the name of my proxies in the MX records a CNAMEs and nobody would be the wiser... The trick is getting the word out on how to do it - like "hey everyone, just ask random domains for "mx.domain.com" and use the 30 level MX" or something which would pass as legit traffic. Maybe...
- 2cb 6y agoUsing innocent sounding CNAMEs on abandoned domains is definitely a smart idea. I’ve definitely got some old domains kicking about, I’ll see how far off they are from expiration and do something similar if they have at least a few months left in them. The proxies themselves can also be hosted at normal sounding domains and subdomains like cdn.technology.memes or whatever. And when you point other domains to them as CNAMEs use equally regular looking subdomains no algorithm would pick up as a proxy like webmail.abandoned.tld.
- stonesweep 6y agoThought following yours, I like the CDN idea - if you add in some dynamic DNS updates with random CNAME results it could also help - ask for cdn.example.com, get node182.example.com and 5 minutes later get a different CNAME result injected from some cron job...
- iudqnolq 6y agoIf your scheme for conveying innocent sounding proxy domains requires it's own innocent sounding domains what have you added?
- stonesweep 6y agoTo my thinking, it creates a chain of "it's really hard to block them all" - as soon as I saw (via the link) that you submit your new proxy to https://signal.tube https://signal.tube I thought "...so the Iranian gov't just has to block any and all access - DNS, HTTP - to that domain" and people can't even see what proxies are out there. So if my friendly domain name is "learned as a Signal proxy" they just block my domain (personally, I'd use two domains to double-blind it). My conceptual idea is that how you get the person the name of the proxy to use has to hide as signal amongst the noise and not get trapped in DNS/domain blocking filters - and if it's keyword blocked by the Great Firewall, you just start asking other random domains for their MX records etc. I believe it's generally referred to as steganography: https://en.wikipedia.org/wiki/Steganography https://en.wikipedia.org/wiki/Steganography
- thw0rted 6y agoRe-read the OP. No connection is actually made to `signal.tube`, it's only a placeholder domain for triggering an Android registered link handler so that it will open in their app.