5 ms·
I'm wondering if they thought about DoT, DoH and DNSCrypt.
by CAP_NET_ADMIN 2y ago
I'm wondering if they thought about DoT, DoH and DNSCrypt.
- schoen 2y agoI hope not!
- Joel_Mckay 2y agoOr people setting the DNS IP on their routers and phones: Google 8.8.8.8 8.8.4.4 Control D 76.76.2.0 76.76.10.0 Quad9 9.9.9.9 149.112.112.112 OpenDNS Home 208.67.222.222 208.67.220.220 Cloudflare 1.1.1.1 1.0.0.1 AdGuard DNS 94.140.14.14 94.140.15.15 CleanBrowsing 185.228.168.9 185.228.169.9 Alternate DNS 76.76.19.19 76.223.122.150 https://github.com/yarrick/iodine https://github.com/yarrick/iodine =3
- hales 2y agoThis will not work if ISPs redirect DNS queries. Only the methods CAP_NET_ADMIN mentioned will work.
- deleted 2y ago[deleted]
- Joel_Mckay 2y agoDoH APIs at these endpoints: https://dns.google/dns-query https://dns.google/dns-query – RFC 8484 (GET and POST) https://dns.google/resolve https://dns.google/resolve? – JSON API (GET) And tunneling obfuscated traffic is easy... =3
- stingraycharles 2y agoThese are being redirected by the Malaysian government as well.
- Joel_Mckay 2y agoYou do know what happens when people try to MiM SSL traffic correct? Even the UK/China firewall can be tunneled over, but the ramifications for those that do so can be dire. =3
- kelnos 2y agoYes, the connections fail, and most clients will fall back to regular ol' DNS on port 53, which then gets redirected to the government's DNS servers. So far clients have chosen availability instead of fighting this fight.
- Joel_Mckay 2y agoUnless your local router tunnels the DNS traffic via other means. The clients may see slightly higher latency, but for <16 host hotspots it would be negligible. It is quite easy for example, to bonce traffic through a reverse proxy on a Tor tunnel, and start ignoring spoofed drop-connection packets (hence these bypass local DNS, tunnel to a proxy IP to obfuscate Tor traffic detection, and exit someplace new every minute or so.) This is a common method to escape the cellular LTE/G5 network sandbox. Ever played chase the Kl0wN? Some folks are difficult to find for various reasons. Have a nice day, =3
- kijin 2y agoAn easy solution would be for Google to host their DoH endpoints on the same domain(s) as their regular service, so that governments can't block DoH without blocking all of Google or YouTube. Using a dedicated domain like that, they're just begging to be blocked. I wonder if DoH requests can be easily proxied? So if I set up https://www.mydomain.com/dns-query https://www.mydomain.com/dns-query on a U.S.-based cloud server and proxy_pass all requests to Google or Cloudflare, and point my browser at my server, will it work?
- Joel_Mckay 2y agoIodine will obfuscate the traffic using the redirected DNS hijack servers themselves. Perhaps someone will put a configured wifi router image together over Christmas holidays for demonstration purposes... because it is fun to ignore tcp drop DoS too. Tunneling well-obfuscated traffic is easier than most imagine... and IDS technology will fail to detect such things without an OS OSI layer snitch. =3
- kelnos 2y ago> An easy solution would be for Google to host their DoH endpoints on the same domain(s) as their regular service That's not how that works. DoH resolvers need an IP address, not a domain name. Sure, Google could host DoH on www.google.com, www.youtube.com, etc. but most users are not going to be savvy enough to find those IPs and use them. Then again, perhaps users savvy enough to try to use DoH to bypass these blocks would also be fine with this.
- kijin 2y ago> most users are not going to be savvy enough to find those IPs and use them. Very few people configure DoH on their own. It's up to the DoH-enabled client software (mostly browsers) to obtain lists of resolver IPs and keep them up to date. If Cloudflare, for example, really wanted to make their DoH traffic indistinguishable from other HTTPS traffic, they could literally host DoH on any domain or IP under their control and rotate the list every now and then.
- noncoml 2y agothats exactly what the redirection is trying to fight…
- deleted 2y ago[deleted]
- Joel_Mckay 2y agoThey are going to have to ban around 3000 proxies as well to make any impact on users. =3
- schoen 2y ago"Any" impact on users? It sounds like you're working with a model in which most users are conscious that they're very offended or inconvenienced by censorship, and want to research technical means of circumventing it. I wish that were true, but I doubt it's nearly as common as your intuition suggests.
- Joel_Mckay 2y agoMotives are complicated at times, but traditionally despotic movements are always hostile toward sources of truth that contradict official narratives. However, one could be correct in that people may prefer to be ignorant. As YC karma is often negatively impacted by facts. QED =3
- stackghost 2y agoWhy do you keep signing your comments with '=3'?
- Joel_Mckay 2y agoDon't worry about it friend =3
- kelnos 2y ago3000 proxies seems like no big deal for the government to ban. "Any" impact is weird phrasing, though. Only a very small percentage of people will be savvy enough to attempt to circumvent these bans.
- bazzargh 2y agoI'm in the UK; my ISP hijacks dns requests on port 53 so nope, none of that works. They're not alone doing this https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_ISPs https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_... For the most part this is not noticeable; but addresses to a bunch of my _work_ stuff don't resolve on whatever hacky dns replacement they offer, if I'm not on the work vpn. They also block port 853 (so no DoT), and https to well-known dns servers; so you can't use DoH to google, but others may work. If you're on a vpn they never see the traffic, you can also bypass them using a pihole with unbound to proxy dns to a DoH server - as long as they haven't blocked it. Ironically the corporate vpn I use also hijacks dns (but locally only), which bypasses all the ISP issues but makes debugging work DNS problems awkward
- Joel_Mckay 2y agoThe UK government IPs show up on our ban lists often for illegal theft of service, and CVE scans. Have you tried a Bind9 relay with iodine/vpn tunnels for local transparent network traversal across the hostile sandbox? i.e. obfuscate the traffic using the hijacking DNS servers themselves. Just a thought =3
- ekianjo 2y agowhat do you mean they hijack the port 53? this is a local setting on your OS. they cant hijack the DNS call if you set it to something else.
- PhilipRoman 2y agoThey can do anything unless constrained by cryptography. I assume it just means redirecting all port 53 traffic which 99% of time will be DNS regardless of IP.
- inkyoto 2y agoThey absolutely can and some do. The destination UDP port number of a UDP packet traversing the core network of an ISP can be inspected and acted upon as one pleases.
- tsimionescu 2y agoI think most countries that do this also block/redirect the major DoH providers like CloudFlare or Google. Of course, you can always hide your DoH traffic by going to other servers or worse case using an HTTP proxy and avoid that. There are even countries that MITM all HTTPS traffic, and your choices are to install the government MITM root certificates into your trust store, or not use HTTPS.
- kelnos 2y ago> There are even countries that MITM all HTTPS traffic, and your choices are to install the government MITM root certificates into your trust store, or not use HTTPS. Are there? When Kazakhstan announced they were going to do this, all the major browser vendors blocked their CA... so they backed down. What other countries do this and get away with it?
- lemme_tell_ya 2y agoSouth Korea has some requirement like this for banking if I recall correctly https://palant.info/2023/02/06/weakening-tls-protection-south-korean-style/ https://palant.info/2023/02/06/weakening-tls-protection-sout...