5 ms·
I have been researching VPN protocols that work in China and found that Xray [0] is the most recommended route to escape the GFW. An ideal VPN setup is one wher
by gsa 3y ago
I have been researching VPN protocols that work in China and found that Xray [0] is the most recommended route to escape the GFW. An ideal VPN setup is one where packets appear as normal https traffic. Some VPN setups take it a step further and proxy the traffic through Cloudflare. Setting all this up is nowhere as easy as Wireguard. Coincidentally, I came across this project on Github earlier today which is an obfuscation proxy for Wireguard [1], but I haven't found any information about how well it works.
[0] https://github.com/XTLS/Xray-core https://github.com/XTLS/Xray-core
[1] https://github.com/database64128/swgp-go https://github.com/database64128/swgp-go
- 0xDEF 3y agoI have noticed many new security and privacy oriented projects use Go and even C/C++. Wasn't Rust supposed to be the language that should be used to write all security-critical software? What happened? Are crates like rustls/ring still intentionally sabotaging Rust's cryptographic ecosystem with their "we will always be pre-1.0.0 and never have a stable API" philosophy?
- simfoo 3y agoWhat if "C/C++" is not actually a thing and modern software engineering practices is what actually makes software safe? Writing modern C++ with good test coverage, sanitizers deployed and wrapping critical/unsafe parts into safe interfaces gets you _very_ far.
- pdimitar 3y ago"Just don't write bugs", eh? :P I don't necessarily disagree with you about C/C++ (or even Brainfuck) but some languages have the tendency to push you in the right direction and I've come to appreciate those more with time.
- bluGill 3y agoUnfortunately far too many people writing C++ are not writing modern C++. Most writing C with classes. You can write memory unsafe code in rust, including memory management if you want - you just have to wrap it in unsafe which at least clues others in to watch this area carefully. In C++ you can put unsafe code anywhere. Sometimes unsafe is really needed, rust makes it hard enough to write unsafe code that you will only do that where you must and then jump back to safe code. In C++ you are likely to mix safe and unsafe code all over and that makes audits harder.
- tialaramex 3y agoWishing for something won't make it come true. C++ has had decades to get this to where it needs to be, there's no reason to hope that if we just give them another chance they'll get it right this time when you can instead use a language which got it right.
- yuriizinets 3y agoIf we're talking about Go, the design of this language is perfect for writing a network related stuff, it's pretty easy, safe and stable. Language's stdlib is mature. As far as I know, in case of Rust you have to rely more on external libraries when you're writing network stuff to make development process less verbose and comfortable. Please, correct me if I'm wrong.
- fnordpiglet 3y agoThe std libraries in rust are sufficient for most things, but it’s definitely true there are very rich crates for networking with higher level semantics or specialized abilities (for instance async networking is generally done by bringing in tokio or something similar). In rust this isn’t considered bad, and in a lot of situations like embedded systems you don’t want or can’t use std because (for example) posix semantics aren’t available. Personally I’m not a fan of batteries included languages because they inevitably suffer a Python heat death if standard libraries as the ecosystem improves faster without the baggage standard libraries carry intrinsically. Hence, IMO the fact std provides a highly common and simple layer and external crates provide opinionated ergonomic interfaces is a feature, not a flaw, of rust. The crate ecosystem in rust is exceptionally good.
- coldtea 3y ago>Wasn't Rust supposed to be the language that should be used to write all security-critical software? What happened? What does "supposed" mean in this case? There's no one dictating what language "security-critical" or other software will be written. So, if it was "supposed", it was incorrectly supposed, by people reading some enthusiast posts about Rust and thinking it's adoption is inevitable or that it applies to everybody. In real life, some went with Rust, others chose Go, and others C++, Java, etc. >Are crates like rustls/ring still intentionally sabotaging Rust's cryptographic ecosystem with their "we will always be pre-1.0.0 and never have a stable API" philosophy? That could help, but whether Rust has stable crypto crates or not, wouldn't change the fact that teams and projects will use what they wanna use, which is not necessarily Rust. Just because some enthusiasts went "Rust all the things!" doesn't mean others will follow them.
- plxx7733 3y agoWho would use unsafe Java to write "security-critical" software?
- brabel 3y agoWhat do you mean by "unsafe Java"?? Do you mean Java as a language is somehow unsafe? I beg to disagree - it's one of the most scrutinized platforms you can find and widely used in all sorts of security critical software everywhere.
- plxx7733 3y agoJava has soooo many security vulnerabilities - just browse around a bit...
- coldtea 3y ago"sooo many" is a technical term? "Sooo many" compared to what? Did you scrutinize the equivalent of Java's SDK in Rust + extra crates to get the same functionality? Do you include things like unrelated package bugs, like log4j bugs?
- miki123211 3y agoGo and Rust are better at different things. Go uses garbage collection, while Rust uses manual memory management with borrow-checking to ensure safety. Both are just as safe, but garbage collection is slower while Rust's manual memory management requires a lot more effort on the part of the developer. In particular, the performance of garbage collection is less predictable, making Go unsuitable for things like audio processing or video games, where you need to reliably deliver data every few milliseconds to avoid crackling audio or weird glitches. In Rust, you can predict exactly when memory will be freed, and if part of your code must always run in a predictable amount of time, this can be done. Go doesn't give you that guarantee. This isn't very important in traditional client-server apps, CLI tools etc, so go is usually fine for those. In addition, Go requires a runtime, which is somewhat heavy. This makes it pretty unsuitable for kernels, software that runs on bare metal, microcontrollers etc. Rust doesn't have that problem. However, Go is usually much faster to write in, as you don't have to worry about managing memory and proving to the borrow checker that you're doing it correctly. The fact that you have Goroutines instead of OS threads also makes it easier to handle lots of concurrent activities, like in a web app that concurrently handles many requests.
- fnordpiglet 3y agoI don’t know what you mean by manual memory management. Memory management in rust is fully automated. The only manual thing is if you want to annotate lifetimes to ensure memory is available past implicit lifetimes, or if the line time of something can’t be automatically derived. Borrow semantics are not manual memory management. You don’t directly control when memory is freed in rust, but because it’s (often) stack based it’s usually pretty obvious memory is freed when the stack is unwound. I feel like you’re confusing rust with c/c++ in this discussion. I don’t find go faster to write in at all. I feel like they’re about the same, but I find go package management to be a mess and prefer cargo. Rust however does require you to be more aware of memory lifetime and ownership, and provides generally better performance in exchange.
- tialaramex 3y ago> Both are just as safe With a single execution context this is true. But, whereas you simply can't write data race bugs in Safe Rust† in Go you can write them and they blow up your safety guarantees. If you race something trivial Go promises (unlike C or C++) that this doesn't immediately set fire to the world, the raced trivial object (say, an integer) is ruined and you must not touch it, but if you stay away from that object your program has clearly defined behaviour. Unfortunately non-trivial objects (say, a slice) are immediately Undefined Behaviour when raced. † This falls out of the mutability rules. A data race is when somebody else modifies something at "the same time" as you're using it, e.g. thread A changes actor to "Steve Buscemi" from "Susan Sarandon" at the same moment thread B is printing the actor out and oops, we write "Susan Sarcemin" or crash or something different happens, who knows. Rust says you can't have multiple aliases and mutability, so this never happens.
- o1y32 3y agoI don't know where you get your information from, but I don't think anyone links specific languages with security oriented projects.
- GoblinSlayer 3y agorust was supposed to write excessive bloatware like servo at 50% quality, that's its killer feature
- Bluecobra 3y agoIf everyone does this wouldn’t that encourage them to try to do carrier grade SSL decryption? I seem to recall that some country is already doing this and to get online you need to trust the state’s CA.
- TheRoque 3y agoI would be interested to know which country this is
- johnbatch 3y agoHere’s an article about Kazakhstan: https://www.f5.com/labs/articles/threat-intelligence/kazakhstan-attempts-to-mitm-itscitizens https://www.f5.com/labs/articles/threat-intelligence/kazakhs...
- 8organicbits 3y agoKazakhstan? That attempt failed. I recently cataloged similar concerns[1]. [1] https://alexsci.com/blog/ca-trust/ https://alexsci.com/blog/ca-trust/
- nirui 3y agoWell, a long time back, there are proxies such as fqrouter, GoAgent and XX-NET which sends plain but loaded HTTP requests as transport. So I guess if a country decides to ban/decrypt TLS, people can just switch to another proxy/protocol. Of course, both fqrouter and GoAgent is long gone by now and should not be used. However, it seems that XX-Net is still been actively developed and (according to their project page on GitHub) is currently give out one million free ChatGPT-3.5 tokens for it's paying user...(I mean like... what??? and why???)
- comprev 3y agoIs it possible to tunnel over SSH through GFW? User connects to server inside GFW, which tunnels outside, and onto the web?
- _lvbh 3y agoYes. I lived in China and that’s how I accessed the internet when my VPN got blocked. They block the port if you connect to it for too long though. Then you will no longer have ssh access to your server without a vpn.
- _lvbh 3y agoX-ray is not the protocol. It’s called Trojan-gfw. X-ray a tool using it. The original (unmaintained) implementation: https://github.com/trojan-gfw/trojan https://github.com/trojan-gfw/trojan