3 ms·
You didn’t even need to do that. Just needed an /etc/hosts entry for the domain.
by trollied 1y ago
You didn’t even need to do that. Just needed an /etc/hosts entry for the domain.
- Retr0id 1y agoMy ISP (Virgin Media) does DNS filtering and IP-based blocking and TLS SNI inspection. So you have to use ESNI or domain fronting, which last time I checked my browser could not be easily configured to do.
- grishka 1y agoYou may have some success with DPI bypass tools we've been using in Russia for years now, like GoodbyeDPI and Zapret.
- arp242 1y agoIs that common for all ISPs or just Virgin? When I lived in the UK (already a number of years ago) it was all just DNS-based. Running my own DNS resolver unblocked everything. I don't recall which ISP.
- Retr0id 1y agoI think it's just Virgin doing the SNI stuff, but I wouldn't be surprised if others are doing IP filtering. I'm not sure if anyone's done a good survey of what the different ISPs are doing (it'd be an interesting project).
- doublerabbit 1y agoTalkTalk, Sky, BT & pretty much all domestic mainstream ISPs do DPI down to SNI. They also exercise an IWF proxy so your already MiTM'd. https://www.iwf.org.uk/ https://www.iwf.org.uk/
- _lvbh 1y agoAt this point, what's the difference between the UK and China other than the specific content they block? Some ISPs have even started blocking wireguard here & I've had to resort back to xray/v2ray
- Retr0id 1y agoVery little difference. But blocking wireguard is huge change, which ISPs are doing that?
- _lvbh 1y agoI currently live in student accommodation so not sure what they're using upstream. The university network also drops wireguard connections but only to known providers like Mullvad (assuming obfuscation is off)