5 ms·
Looking at the circumvention techniques GoodbyeDPI uses makes me want to cry. Is this really the state of DPI in 2022: changing Host to hoSt, or adding white sp
by rixrax 4y ago
Looking at the circumvention techniques GoodbyeDPI uses makes me want to cry. Is this really the state of DPI in 2022: changing Host to hoSt, or adding white spaces between method and URI actually works?
- progbits 4y agoCensorship companies probably can't hire good talent. I'm actually glad to see this, however it might get patched if this tool becomes too widespread.
- nnx 4y agoOr perhaps some good talent somehow ending up working there made sure the system is full of plausibly deniable holes.
- friendlyHornet 4y agoI would like to believe that; it makes me feel warm and comfortable
- userbinator 4y agoInteresting to see the two meanings of good appear in both your and your parent's comment.
- gjulianm 4y agoIt's not as much about talent but about tradeoffs. I work in traffic monitoring tools (not censorship, just observability tools for infrastructure) there's always the decision of how many edge cases you want to cover vs how fast you want your tool to go. At millions of packets per second, an extra "if" might make a big difference in the throughput you're able to monitor. So maybe it's actually reasonable to ignore the .1% that use "hoSt" instead of "Host" to avoid losing .5% of the packets.
- someguydave 4y agoMore importantly, using “hoSt” is a self-declaration of being an enemy of the censorship regime which is probably dangerous in Russia.
- Avamander 4y agoI suspect it's not even about not being able to, there's very little motivation. I had a brief contact with ZScaler who operates approximately in this area of traffic inspection, they literally have no clue and they don't care. Their service can be hot flaming trash but people will still pay them money because they check some boxes. I'm sure it applies to other companies in the same area as well.
- ValdikSS 4y agoThat was true 3-4 years ago but nowadays they're getting surprisingly good, and that's alarming.
- malf 4y agoDon’t google “request smuggling vuln”; this is the state of all proxies and load balancers. Everyone tests the happy path and calls it a day.
- kazinator 4y agoIf you're spying on people who use plain HTTP, why would you expect them to be clever.
- Ekaros 4y agoIt is harder problem that it sounds. Deep packet inspection needs to happen at some linespeed. More work you do the harder it is to process it all fast enough. You can write stuff for single packets, but when you have lot of connections happening it becomes much harder problem.
- vlovich123 4y agoIsn’t this stuff typically specially built HW? I feel like an ASIC can accelerate this stuff fairly quickly although the volumes/pricing may not warrant building that. Also if you’re matching on host name there’s no reason you even need to keep up with line rate. All you need is to do is keep up with the connection establishment rate and you can always do the processing in the background and just issue a TCP reset after the fact.
- vbezhenar 4y agoCan you update ASICs with new firmware?
- mytailorisrich 4y agoNo but I suspect many hardware products use FPGAs, which can be updated as you would firmware, and indeed are often updated during firmware updates.
- guardiangod 4y agoYour suspicion is wrong. Sorry.
- mytailorisrich 4y agoI actually work in the field (networking) and FPGAs are very common in professional telecommunication equipments, hence my suspicion/guess that DPI are the same, especially since I'm also guessing that this is the sort of thing that may be updated often. So I think my 'suspicion' is at least as good as yours.
- userbinator 4y agoI suspect it is also due to the scale at which DPI is used; every additional bit of complexity quickly adds up to increase the amount of processing power required.
- cmgbhm 4y agoYou can get really far with cheap techniques when your goal is to dissuade. The bigger concern I’d have is statistical analysis of top offender. Every OSI layer offers more bypass techniques and is the halting problem where your goal is to get value without making everything break when a new browser comes out. You can’t cover all options as a 3rd party and get it perfect. The higher up application layer, the easier it is to bypass. The more you try to classify without impact (dpi,ids,waf,spam,av), the easier bypasses are. The domains that get effective like spam have quicker feedback loops. Network middle boxes have the slowest response cycle where they are explicitly called out in RFCs <script> In a url might get blocked but <script >… bc it’s string matching and not layer aware.
- fafefifofu 4y ago
- pelasaco 4y agomost the engines out there weren't made for security but performance. It's disturbing and relaxing at the same time to see how easy it is to bypass them. Something that works 100% is to multiplex a channel, changing it protocols after some packages. You do the SSL handshake, than after some amount of time, you switch it to SSH, I think something like that https://github.com/yrutschle/sslh https://github.com/yrutschle/sslh (couldn't find the real repository that I used, but that one looks similar) could be used after the detection to bypass filters
- ValdikSS 4y agoNo, unfortunately almost no of these naive methods longer works. However the protocol spoofing ("fake packet" in GoodbyeDPI) with Auto-TTL is pretty effective on most ISPs of Russia, Korea, Indonesia, Turkey.