4 ms·
Is this possible to do, technologically speaking?
by pketh 5y ago
Is this possible to do, technologically speaking?
- bellyfullofbac 5y agoThe Chinese firewall seems to be able to detect VPN packets (not decrypt, just detect them) and drop them, so even trying to connect is annoying. I guess people could use SSL VPN and pretending to be HTTPS, but the detector might be able to detect patterns and realize it's not HTTPS traffic.
- Anunayj 5y agoHard - Impossible. China Already tried to do this in some capacity with deep packet inspection/ Only allowing HTTPs and such. People just circumvent this by just routing data thru HTTPS. Ofcourse you can block IPs of popular VPN providers decreasing accessibility but it'd be impossible to stop it completely. Though this would easily restrict the majority of non-tech savvy individuals while doing nothing Wikipedia [1] documents some methods. [1] https://en.m.wikipedia.org/wiki/Great_Firewall#Blocking_methods https://en.m.wikipedia.org/wiki/Great_Firewall#Blocking_meth...
- rfd4sgmk8u 5y agoYes. DPI (Deep Packet Inspection) can occur on network boundaries and filter out traffic on practically anything you can imagine. Blocking VPN IPSec traffic is easy. Note, it probably requires installing or configuring network bottlenecks for filtering. Getting the topology correct is harder than the actual filtering, which is a standard feature on enterprise and isp networking hardware. State of the Art is the Chinese GFW -- it can do things like: * look for keywords in tcp packets and reset connections * block whole protocols based on attributes (such as encryption parameters), Tor is always playing cat and mouse here and generally blocked * detect if an encrypted ssh session is being used to tunnel traffic, and reset the connection at both sides with a TCP Reset flag. * modify http traffic to send malicious js to browsers to attack other servers