4 ms·
Back in the day, XS4ALL, a Dutch internet provider had exactly this feature. They provided ssh access via port 80. It saved me a couple of time while I was trav
by mmzeeman 3y ago
Back in the day, XS4ALL, a Dutch internet provider had exactly this feature. They provided ssh access via port 80. It saved me a couple of time while I was traveling and the only way to get internet access was via hotel WiFi, which blocked everything except port 80. If anybody from XS4ALL is reading this... Thanks!
- pietro72ohboy 3y agoXS4ALL was amazing and it’s a genuine shame that KPN corporate decided to dissolve the brand. But I guess, KPN wouldn’t have been comfortable with XS4ALL’s hacker ethos anyways…
- emmelaich 3y agoFellow xs4all user here, it was fantastic, the real spirit of the early internet. Sort of a redo of the pirate radio ethos of the 60s. https://en.wikipedia.org/wiki/Pirate_radio_in_Europe https://en.wikipedia.org/wiki/Pirate_radio_in_Europe
- rahimnathwani 3y agohad exactly this feature. They provided ssh access via port 80. OP is describing something different: - different port (443, not 80) - different protocol used on that port (https, not ssh)
- narag 3y agoIt seems the same to me: using a port that's open for a commonly used protocol, so http (80) in the 90s, https (443) now. Of course the protocol is different, that's the point!
- rahimnathwani 3y agoIt's not the same at all. OP's port 443 is not 'open' in the same sense that GGP's port 80 was 'open'. In the old days, only the port number mattered. Today, DPI means the protocol matters as well.
- narag 3y agoThe SSL negotiation part happens before any other communication. Once the encrypted connection is established, how do you analize the protocol? Edit: I tested that time ago: https://news.ycombinator.com/item?id=38753897 https://news.ycombinator.com/item?id=38753897 And to save roundtrips: I believe it must be possible to analyze encrypted traffic to find out which protocol is used. But I doubt that the hospital admins are so motivated or sophisticated.
- rahimnathwani 3y ago> The SSL negotiation part happens before any other communication. An SSH server and client do not use SSL/TLS to set up the connection. They use the SSH protocol. As soon as you connect to an SSH server, the server sends an identification string. The identification string always starts with: SSH- It's trivial to detect. In the old days, corporate firewall rules were based solely on port numbers. So you could connect to an outside SSH server running on port 80, even if port 22 was blocked. Nowadays, an SSH server running on any port (80, 443, or any other) can easily be detected and blocked.
- narag 3y agoOK, I believe you, but then, does the trick described in the article work? I ask because if it works, the principle is the same: using a commonly used protocol to circumvent limitations. It used to be easier to do then, it's more involved now. In other words: is it possible to tunnel anything through https?
- rahimnathwani 3y ago> the principle is the same: using a commonly used protocol to circumvent limitations No it's not. The earlier method used only a commonly used port, and did not require the use of a commonly used protocol.
- tedunangst 3y agoThe purpose of using the TLS layer is to prevent the DPI.
- xur17 3y agoI didn't realize they were a full on ISP! I recall using them back in the day as a newsgroup provider.
- nerdbert 3y agoXS4ALL sort of lives on in the form of Freedom - https://freedom.nl/en https://freedom.nl/en
- achillean 3y agoAmong the non-standard ports for SSH, 443 is in the top ports used: https://www.shodan.io/search/facet?query=ssh&facet=port https://www.shodan.io/search/facet?query=ssh&facet=port https://www.shodan.io/search/facet.png?query=ssh&facet=port https://www.shodan.io/search/facet.png?query=ssh&facet=port Port 80 is a lot less common though.