21 ms·
How the great firewall of China detects and blocks fully encrypted traffic [pdf]
- dylanzhangdev 3y agohttps://news.ycombinator.com/ https://news.ycombinator.com/ need vpn https://hckrnews.com/ https://hckrnews.com/ no need vpn i use vpn write this comment. my vpn 90$/year, pay use usdt. it is good, watch netflix/youtube fast.
- euix 3y agoI always wondered where the talent and technical expertise inside China for manning and refining the GFW comes from and how many people it feeds - it seems at this point like family planning, an agency so big it exists simply to perpetuate and provide livelihood to a host of people. Also how much truth is there to the statement that Cisco helped setup the GFW for China in the 90's?
- metajs 3y agoGFW always been a big issue, first with github, you only can clone repo at ~20kb/s, then apt yum homebrew, some is ultra slow,some just blocked Nowadays, I already put a lot of effort on how to bypass it
- black_13 3y ago[dead]
- Ballas 3y agoSeems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...
- WinstonSmith84 3y agothat's mentioned at the end of Page 17. The author tells it's a short term solution: "This is merely a stopgap measure, as the censor can enable their censorship for UDP." It doesn't seem that there are any (long term) solution to bypass the rules ...
- throwawayadvsec 3y agosteganography?
- Ballas 3y agoHiding the encrypted messages so that it looks like other normal traffic. Like encoding your encrypted message (subtly) in the pixels of an image (like noise).
- reaperman 3y agoIt does seem like this GFW scheme can be tuned to severely degrade the reliability of any unapproved high entropy traffic. However, this single scheme doesn't cover many other types of circumvention traffic, several of which are noted in the beginning of the paper. This scheme primarily applies to "fully encrypted" traffic - not SSL/TLS, etc. So for now, circumvention can live on, but this explains to everyone using fully encrypted protocols exactly why their connections would have been degraded over the past couple years. In the long term, steganography will probably work well as long as users are able to endure much higher costs for traffic (low ratio of true data to apparent data) and as long as the steganographic systems are effective at hiding any statistical fingerprints (very difficult). Protocol mimicry is another strategy, but a paper cited in this work details why successful protocol mimicry is very difficult.[0] Attempts to disguise circumvention traffic as typical traffic is very difficult, because a lot of fingerprinting information can be gleaned from handshakes and headers. The draw of fully encrypted traffic is that it provides very little variation which can be used to fingerprint and classify different types of usages. However, it's also easy to detect and block en masse -- that much is obvious, but this paper does a great job of showing how China does it and inferences can be made from that to provide a view into China's priorities (how much cost they're willing to incur, rates of false positives they feel is acceptable). Overall, China's blocking current appears to be fairly conservative here, with relatively low rates of false positives. In wider context, China is constantly updating their detection schemes, they're quite competent at it, and anything which doesn't match typical traffic is at risk. 0: https://people.cs.umass.edu/~amir/papers/parrot.pdf https://people.cs.umass.edu/~amir/papers/parrot.pdf
- sysstemlord 3y agoI'd go for ssh if I was trying to bypass it. At least legally I can claim that I'm just sshing to my aws server and not be jailed for using vpn.
- yorwba 3y agoTrying to get off the hook on a technicality isn't going to work. Lots of people use VPNs completely in the open without getting jailed, because they're not otherwise of interest, but if you are being targeted, nobody is going to care about your "sshing to aws" excuse. And ssh tunneling web traffic looks quite different from normal ssh usage anyways.
- 6LLvveMx2koXfwn 3y ago> And ssh tunneling web traffic looks quite different from normal ssh usage anyways. Could you explain this further, this seems counter to my understanding of encrypted traffic!
- yorwba 3y agoSSH encryption only hides the content, not how much is being sent and when. When your browser fires off a bunch of requests to load a webpage, the timing is different from running typical commands on a server and receiving the output.
- praash 3y agoI assume the timing patterns and amounts of data would likely be distinct between SSH and web. "Normal" SSH usage would mostly consist of much lighter packets, such as user keystrokes and terminal screenfuls of text. Typing tiny commands and getting a few kilobytes of output. SSH file transfers happen occasionally, sometimes with a large bulk of data. Active web browsing requires downloading a crapton of files with wildly different sizes and sporadic timings between them. Add normal user interaction, API requests, ad cycles, long video streams that won't max out all bandwidth, all happening at once across multiple tabs. The client also sends much more data with each TLS handshake and all those HTTP headers. This could probably be masked by deliberately filling idle periods with garbage data just to appear as a stable data stream both ways.
- lordnacho 3y agoWhy would they let that happen? Doesn't seem to make any sense to me if it's how you describe it.
- Ballas 3y agoYes, that is why I also found it interesting. As to their motives - I cannot comment.
- Hikikomori 3y agoWent to china some years ago and my pptp vpn blocked after a day. Switched to ssh and after a day it was rate limited to basically nothing, but I could avoid that by switching port every morning.
- blablablub 3y agoWireguard is detected within the first minute of usage and blocked. The ping is a dead giveaway.
- Ballas 3y agoInteresting. I was just going on my limited scan through the linked PDF, which evidently was not thorough enough.
- jongjong 3y agoI was told that SOCKS proxies (which let you tunnel over SSH) are popular in China. It's super easy to setup and you don't need to install anything. You just need to SSH into any Linux EC2 instance outside of your network with ssh -D $port_number $username@$hostname and change a simple setting in your browser to proxy through that node using SOCKS5. It's nice because you still control the remote host (no need to trust some third party VPN) and the traffic is encrypted between your remote host and your local host (where it counts)... Anyone snooping would just think that you're SSHing into your EC2 instance for work purposes and not realize you're using it to browse the net.
- netheril96 3y agoYou were told wrong. If you uses SSH as a proxy, the connection will be slowed down to a crawl very soon. GFW distinguishes this from SSH command typing by looking at the traffic. This has been in place for at least a decade.
- WinstonSmith84 3y agoI was wondering about simply using VPNs, which is not mentioned in the article at all, but checking GFW on Wikipedia, it tells: > The use of VPNs in China can provide individuals access to the international internet, but in China, it can be a potential legal risk. In 2017, the Chinese government declared all unauthorized VPN services to be illegal.[94] An example of the use of this punishment is Vera Zhou, a student at the University of Washington, who, when visiting her Hui parents in Xinjiang, China, used a VPN to access her school homework. She was arrested and sent to a Xinjiang internment camp from October 2017 until March 2018, followed by house arrest after her release. She was not able to return to the US until September 2019.[95][96]
- Arn_Thor 3y agoAnd for those who don’t feel in legal jeopardy many VPNs are still being blocked and reconfigured in an endless arms race between the provider and the GFW
- FaultBit 3y agoA lot of people actually use VPNs in China (since 2010 even), and some of them call it "加速器" which basically means "booster" (for your internet). Some use it for lower latencies when playing foreign games. The issue is that VPN connections get easily blocked. We aren't really worried about legal issues. Except for that one time when police (of a certain district, not everywhere in China) knocked on people's doors to inspect their phones for VPNs during the "white paper protest" I believe.
- mushbino 3y agoSure, but you're ruining the yellow peril narrative we need for our cold war with China.
- seanmcdirmid 3y agoSurely Xinjiang has stricter rules and more aggressive enforcement than the other provinces/regions? They always put a hardliner in as party head.
- jiggywiggy 3y agoYeah already 10-12 years ago was clear. My university vpn only worked for a few days while studying in China. But there is this tiny little vpn software being spread around. Not sure if it's true but I remember it's falun gong teaming up with the CIA. Which at the time was able to go undetected, I think they keep rotating the IPS or something. Was interesting how fast that tool spread "offline" between international students. Also Chinese have it but its less known among them. Not sure if it still works:https://en.m.wikipedia.org/wiki/Freegate https://en.m.wikipedia.org/wiki/Freegate [Edit] Here is an old hn comment saying it doesn't work anymore and other options that are also hard; https://news.ycombinator.com/item?id=10101965 https://news.ycombinator.com/item?id=10101965
- LT_SPA 3y agoNearly the same experience with my campus life.
- JPLeRouzic 3y agoThe algorithm found seems so unintuitive that I wonder if it was not found by the AI. "Allow a connection to continue if the first TCP payload (pkt) sent by the client satisfies any of the following exemptions: Ex1: popcount(pkt) len(pkt) ≤ 3.4 or popcount(pkt) len(pkt) ≥ 4.6. Ex2: The first six (or more) bytes of pkt are [0x20,0x7e]. Ex3: More than 50% of pkt’s bytes are [0x20,0x7e]. Ex4: More than 20 contiguous bytes of pkt are [0x20,0x7e]. Ex5: It matches the protocol fingerprint for TLS or HTTP. Block if none of the above hold."
- vbezhenar 3y agoThis is just some experimentation results, it's not algorithm.
- amrocha 3y agoAn algorithm is just a bunch of rules to follow to perform an operation, so this looks like an algorithm to me.
- netheril96 3y agoYou misunderstood your parent comment. What he/she meant is that the "algorithm" is only a guess from reverse engineering. The actual algorithm deployed at GFW can look significantly different.
- amrocha 3y agoOh yeah, that's definitely not how I read it. Thanks!
- reaperman 3y ago> I wonder if it was not found by the AI. Do you mean "found" by the CCP, or "found" by the researchers? In the case of the CCP it was likely generated through basic statistical analysis, and tuned to minimize side effects and collateral damage below some threshold of acceptability (~0.6% of global traffic unintentionally blocked). In the case of the researchers, the paper details the basic statistical analysis used to discover these rules.
- Renaud 3y agoI remember having to deal with the early GFW about 20 years ago when I was working for a company that had some employees on a site in Shanghai. Every morning, our colleagues in China would open their mail client and it would connect to our server abroad. The first person would usually be OK, but for everyone else, the connection would fail. At the time, almost nothing was known of the GFW and it wasn't as clever as it is now. I found out that the POP connection was quickly blocked after a few minutes, probably triggering some slow firewall rules along the way (it seemed a bit random, so I assumed the firewall setup wasn't unified). Moving to POPS/SMTPS seemed to improve things for a while, but the connection would still be randomly blocked. What worked in the end was to use a bunch of random ports instead of the well known ones to accept POP/SMTP connections on the server, and we never had any issues after that, at least until we changed system a couple of years later.
- dizhn 3y agoWe have a satellite office in Dubai. I know their static IP. When they connect to our imap/smtp server they are coming in from another IP. I never looked into it deeply but assumed their connection is being diverted for inspection. (If true, they would probably not be below performing industrial espionage with the data they are accessing)
- occamrazor 3y agoIs the IMAP/SMTP connection not encrypted?
- proto_lambda 3y ago
- mdhb 3y agoLimited use cases but for moving info in and out of a system like this you should be able to use this https://en.m.wikipedia.org/wiki/Chaffing_and_winnowing https://en.m.wikipedia.org/wiki/Chaffing_and_winnowing
- noman-land 3y agoThis is a really cool idea. Thanks for sharing.
- baybal2 3y agoOn the other hand, this shows GFW authors are more, and more considerate of the collateral damage, which is a surprise. It seems GFW has indeed became good enough to frustrate casual users to trigger uproar when windows update, or AWS ip ranges go belly up, or something. VPN authors should chose the maximum collateral damage strategy to frustrate GFW authors, make China as close as possible to completely cutting off outside internet. No need to completely evade fingerprinting, instead, do the complete opposite, and try to mimic common protocols, and critical applications as much as possible.
- ixwt 3y agoFrom my understanding, this is what TOR did for some time. They tried to make it look as close as possible to HTTPS.
- cookiengineer 3y agoBut does the paper imply that something like chunked encoding smuggled HTTP requests with an encrypted payload after the second chunk would work? That is, assuming entry nodes are available as e.g. nginx proxies inside the Chinese ASNs and are allowed to operate serving websites to ASNs from foreign countries. I'm mentioning nginx because there were some related bypass vulnerabilities in the past, and one could argue that they just missed updating them.
- blablablub 3y agotried that...done that... blocked The last rule of the GFW is: If you don't know what this traffic is or it looks suspicious, block it.
- NamTaf 3y agoInteresting that it's cracking down on Shadowsocks with obfuscation plugins. SS w/ v2ray was more or less the gold standard when I was going there from 2017 to 2019. Back then, certain times (early June, big government meetings) would see a crackdown on VPNs where, so far as I could tell, they just threw down crude blanket blocks on anything they sorta-kinda knew was a VPN but couldn't procedurally target-block. It would (usually) still connect but be rate-limited to essentially nothingness. I always got the vibe that they sort of informally tolerated VPNs above a certain threshold of sophistication, figuring that they were more interested in blocking the low-hanging fruit that the unwashed masses could easily use, rather than something more sophisticated that only a few techno-nerds could utilise. As other posters have said, they'd know who was doing it and preferred to come knocking with a rubber hose if those people caused too much in the way of issues.
- cynicalsecurity 3y agoCan you bring a Starlink and then just don't really care?
- RocketMan9999 3y agoMaybe you can, but the Chinese "VPN law" used some wording like "unauthorized communication channels" without further definition. They can just call Starlinks "unauthorized" and start confiscating them, just like what they did to the satellite dishes for receiving foreign TV signals.
- hughesjj 3y agoNope. Starlink shuts down over china on the satellite side. Tesla has a huge presence there and they also threatened to shoot the satellites down (which they've done before) if starlink provided internet access there
- reaperman 3y agoTo clarify for readers: China has never shot down someone else's satellite. They've only destroyed one satellite ever and it was their own.
- red-iron-pine 3y agoand creating a ton of space debris in the process. oups
- anovikov 3y agoI wonder what can be done about detecting data hidden within video streams in a steganographic way.
- __sy__ 3y agoI’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when roaming around China, using a vpn to get to that shenzhen gateway. As far as I can recall, that always worked. This led me to believe that most of the vpn traffic analysis (and blocking)was done at the edge of the GFW and not inside of it. Again, this could be outdated by now.
- apatheticonion 3y agoI tried to setup a shadowsocks server to bypass the GFW about 2 weeks ago. Server was hosted on my local network in Australia (with public IP), client was connecting from China (using the server IP). It was blocked immediately and the client could not connect. I had several unknown IPs try to connect prior to the attempted connection. I was stunned at how water tight the GFW is, it's really unfortunate as I would love to work/travel through China but cannot due to needing an active internet connection.
- __sy__ 3y agoYeah pdf of report says that blocking is instant as of 2021. Also completely agree with the need for an active connection to do work. A lot of the software/hacker devs I knew have left China all together in the last 3-4 years. Inability to look up stuff reliably (even on working VPN providers) was one of the reasons cited by a few.
- fundatus 3y agoLast time I went to China (2018) you could simply get a China Unicom Hong Kong SIM card and then use that to roam in mainland China. With that you'd get the Hong Kong censorship level, which is much much less restrictive. No VPN or anything needed apart from the SIM card itself.
- 3y ago
- apatheticonion 3y agoGiven HTTPS traffic is mostly permitted, could one obfuscate VPN traffic over http/3 (which I believe is UDP)?
- netheril96 3y agoIndeed a whole class of GFW bypassing tools are now based on masquerading as HTTPS. Trojan (TCP only), Vision (TCP only), Hysteria (UDP), just for some examples.
- trallnag 3y agoCould China implement a MitM proxy for HTTPS traffic like many companies do?
- nikanj 3y agoNo. Companies get around ssl issues by minting their own root CAs and configuring their workstations to trust them. China has no (technical) way of forcing you to trust their root CA
- gruez 3y ago>China has no (technical) way of forcing you to trust their root CA That might be true, but "install our root CA or you can't access websites" would get most people to do it.
- nyolfen 3y agoi recall a chinese guy telling me he got around it on his PC by setting up a streaming webtop on a VPS on a foreign network that he didn't have issues accessing https://docs.linuxserver.io/images/docker-webtop https://docs.linuxserver.io/images/docker-webtop
- ballenf 3y agoWould a steganographic hiding of payloads be possible and usably efficient inside permissible content/protocols? Has it been tried?
- gruez 3y agoThat would require mimicking an existing protocol, and as per the paper that's non-trivial >Houmansadr et al. [39] conclude that mimicking a protocol is fundamentally flawed and suggest that tunneling through allowed protocols be a more censorship-resistant approach. Frolov and Wustrow [35] demonstrate that even when a tunneling approach is used, it still requires effort to perfectly align protocol fingerprints with popular implementations, in order to avoid blocking by protocol fingerprints. For instance, in 2012, China and Ethiopia deployed deep packet inspection to detect Tor traffic by its uncommon ciphersuits [44, 55, 67]. Censorship middlebox vendors have previously identified and blocked meek [29] traffic based on its TLS fingerprint and SNI value [28].
- maldev 3y agoThis paper is nice, but it goes over some finer technical things. So, not about the great wall, but there's projects out there, like this one https://github.com/salesforce/ja3 https://github.com/salesforce/ja3 , which talk about how you can fingerprint fully encrypted traffic(TLS/HTPS). There's a great section in the Readme "How it works" that goes over it. Would be surprising if the great wall doesn't do this, when some open source firewall will.
- supriyo-biswas 3y agoChrome randomizes the ClientHello these days[1], so JA3 is obsolete in that sense. You could still build a fingerprint off of the common advertised TLS parameters, disregarding their order. The linked paper references an incident where the list of ciphersuites were used to detect Tor-obfs connections[2][3]. [1] https://www.fastly.com/blog/a-first-look-at-chromes-tls-clienthello-permutation-in-the-wild https://www.fastly.com/blog/a-first-look-at-chromes-tls-clie... [2] https://gitlab.torproject.org/legacy/trac/-/issues/4744 https://gitlab.torproject.org/legacy/trac/-/issues/4744 [3] https://blog.torproject.org/ethiopia-introduces-deep-packet-inspection https://blog.torproject.org/ethiopia-introduces-deep-packet-...
- deleted 3y ago[deleted]
- H8crilA 3y agoThe exact reverse engineered algorithm of the GFW is on page 4. It looks very reasonable (given what they are trying to achieve with it). The easiest bypass I can think of would be to tunnel your connections via TLS. For example socks server tunneled via SSH which in turn is tuneled via TLS to your gateway. Or perhaps you can somehow get your SSH client to transmit "GET " at the beginning of the connection, have the server ignore those 4 bytes, then proceed as usual.
- EGreg 3y agoThis is what I have a question about. Can China pressure every domestic company to use their certificate authority allowing them to decrypt all TLS traffic, or be blocked? And block all sites outside China?
- H8crilA 3y ago1 - I believe they do it 2 - they obviously do not want to block all traffic, since they can do it any day, but they don't.
- supriyo-biswas 3y agoKazakhstan had attempted a similar move[1], albeit through PSAs rather than convincing device manufacturers to add certificates to end-user devices. [1] https://en.wikipedia.org/wiki/Kazakhstan_man-in-the-middle_attack https://en.wikipedia.org/wiki/Kazakhstan_man-in-the-middle_a...
- nikanj 3y agoIf it’s over https, an outside observer has no way of knowing your stream started with a GET. Unless they’ve tapped ssl certificates, but that would be major news
- H8crilA 3y agoThey are tapped into SSL certificates, those that are generated in China. Plus wherever the Chinese intelligence managed to install their "plugins".
- userbinator 3y agoAs a result of such blocking, I suspect steganographic techniques are only going to become more popular over time.
- DeathArrow 3y agoWhat kind of websites does China block?
- mooxiu 3y agogoogle, facebook, amazon, twitter, github, you name it ...
- osti 3y agoNot sure where you get your info, but github definitely isn't blocked. And there is a amazon.cn, just no one uses that crap.
- mooxiu 3y agoI am Chinese and lived in China until this year if you want to know. For github, the situation is a little complicated, you can read this: https://www.reddit.com/r/China/comments/v8fv0p/why_is_github_so_slow_in_china_recently/ https://www.reddit.com/r/China/comments/v8fv0p/why_is_github.... For Amazon, I mean amazon.com, not amazon.cn. Also amazon.cn's services are declining, almost nothing there.
- seanmcdirmid 3y agoAlso Reddit (ironically Chinese owned).
- cheaprentalyeti 3y agoReddit's owned by the Chinese? I thought they were owned by a US-based conglomerate called Advance Publications, which is the same group that owns Conde Nast.
- seanmcdirmid 3y agoTencent owns $150 million of it (based on its 2019 valuation anyways).
- 3y ago
- GartzenDeHaes 3y ago> 1 security vendor flagged this URL as malicious https://www.virustotal.com/gui/url/f530591ff939e09c1cf8bc5341ed7b333add2e10059a9630039d8ea29d8109c4 https://www.virustotal.com/gui/url/f530591ff939e09c1cf8bc534...
- seanmcdirmid 3y agoI mentioned this a few years ago (maybe 7-8 years ago) on HN when I was told everyone just uses a VPN. Even back then, the cat and mouse game was annoying. You would purchase a VPN (plenty offered), pay a year subscription, and then it would go dark a couple of weeks later (sort of like a membership at a gym that closes down a week after you renew a year subscription). I gave up quickly on outside access, though we had a line out at work so it wasn’t that bad.
- beebmam 3y agoDeeply unethical stuff. Why are Chinese people not currently trying to overthrow this garbage?
- gruez 3y agoThe threat of you and your family members getting sent to a labor camp is a good incentive.
- edvards 3y agoPragmatism, I suppose. The country does well enough economically for people to accept it, not to mention they're used to it all already.
- mrguyorama 3y agoBecause "Everybody does it and gets away with it", as seen in this very comment section, so it doesn't actually put much pressure on the public as far as they are concerned. Also, "it's done for social harmony"; Very few places are as dogmatically hostile towards social good as the US, and are willing to make individual liberty sacrifices so that everyone may be better off. Arguably this is the same rhetoric or philosophy as the "Thin blue line" American cops love. Also, your average chinese person just doesn't care to see english language media that much. They have diverse (to them) opinions and culture on their homegrown social media systems, and don't feel a need to leave the walled garden of Chinese internet much in the same way most westerners do not feel the need to join Russia's social media apps. Also, the CCP "brought millions out of poverty" within living memory. Many people there feel that justifies a hell of a lot of vaguely "bad" actions, or makes it way easier to rationalize things.
- mensetmanusman 3y agoChina doesn't realize how much they are being held back by meaningless investments of time and expertise on this. They spend almost the same %GDP as the US does on the US military as on their internal suppression forces. Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.
- dirtyid 3y agoPRC centralized narrative setting apparatus is more efficient than constant misinformation shitshow on western platforms. Not to mention the entire reason why PRC has domestic info ecosystem is because they were prescient in filtering external content. The system already paid for itself many times over. >They spend almost the same %GDP as the US does on the US military as on their internal suppression forces. It's almost as if PRC doesn't spend that much %GDP on military. The waste is PRC spending as much as US on domestic policing, which is not great considering how militarized US policing is. Meanwhile PRC simply doesn't spend that much on defense <2% vs US ~3.5%, if you include guestimates of shadow budgets, 3% vs 6%.
- jcarrano 3y agoIt is not the goal of the CCP to advance China as it is to keep themselves in power.
- H8crilA 3y agoI would disagree. The leading organization is much more aligned with the needs of the nation than the likes of Iran or Russia, which probably wouldn't mind bombing the shit out of their own city if it was necessary to stay in power. For example they actually bow to American pressure and try to avoid sanctions or other trade problems. As of today their navy could be completely destroyed with like 30% of the US Navy, so any naval blockade is probably unbreakable for them. Iran's hunta would (and did) just say "whatever" and continued tanking the GDP. Another example - the Chinese intelligence helps domestic industries, even those that are far from the defense business.
- 3y ago
- law_enforcement 3y agoThe comments from people obviously never having been into a restricted country are hilarious. There are a few, most likely shadow approved, VPN providers that work. I refuse to believe they are just smarter than the GFW. I am convinced they are sanctioned and monitored. Which is fine if you never have any beef with the government. Which you never know you do until you do. Stuff like socks5/shadowsocks and wireguard have long been useless. Imagine being in your house, and you want to go out, without anyone seeing you. No matter how well you try, just the attempt itself reveals you are trying - thus you are caught. Same for escaping GFW. A sanctioned VPN or RDP that stays alive without metering, is your best option.
- bilkow 3y agoCan't you use a "sanctioned" VPN to tunnel your connection to a "real" VPN or any wireguard endpoint? They could still be able to find out you're using a VPN, but not monitor your traffic.
- law_enforcement 3y agoYes, you can. But you have to wonder what the sanctioned VPN is doing on/to your machine. There is a lot of trust going into any VPN solution.
- ImPostingOnHN 3y agoare you talking about the VPN endpoint exploiting a 0day vulnerability in the VPN client stack of the OS?
- rfoo 3y agoYour comment is equally hilarious from the point of view of a native who lives in China now. idk if i'm smarter than the GFW but every time I rolled my own censorship-circumvention tool it worked well, even the most lazy way worked. I've never used any VPN provider. And FYI even unchanged WireGuard still works, though there seems to be some offline traffic analysis looking for that, so once a week you'd wake up to your VPN connection broken and had to change ListenPort on the server. The only annoying thing for me is: f- you AWS, egress too damn expensive!
- FredPret 3y agoThis is such an own goal by China. All this useless work done suppressing the human spirit.
- pessimizer 3y ago> All this useless work done suppressing the human spirit. It also becomes an inspiration to others.
- FredPret 3y agoWould-be dictators, or firewall makers?
- red-iron-pine 3y agogoogle
- olodus 3y agoI am a total obfuscation noob. How far does their DPI go? I am guessing Tor and stuff have tried hiding it inside lots of different protocols and file types (I think I read something about that at some point). Is it to the point of hiding it as part of a html doc (like under a specific tag or something). At what point do we move towards having executable Javascript generate the encrypted text which then is decrypted?
- j-a-a-p 3y agoWith Youtube blocked, the Chinese are not being bombarded with VPN advertisements
- kurtoid 3y agoThey say UDP is never blocked, so would Wireguard work?
- password4321 3y agohttps://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wiki/Domain_fronting was a workaround for a while. https://signal.org/blog/looking-back-on-the-front/ https://signal.org/blog/looking-back-on-the-front/ (2018) https://news.ycombinator.com/item?id=16970199 https://news.ycombinator.com/item?id=16970199
- JoeAltmaier 3y agoSo now we have to embed encrypted traffic in innocuous plaintext envelopes? It's like the cold war.
- ck2 3y agoHow long do you figure until the first public execution for using starlink? And yet we can never cut them off because it would be economic suicide.