33 ms·
Ask HN: The government of my country blocked VPN access. What should I use?
Indonesia is currently in chaos. Earlier today, the government blocked access to Twitter & Discord knowing news spread mainly through those channels. Usually we can use Cloudflare's WARP to avoid it, but just today they blocked the access as well. What alternative should we use?
- theyknowitsxmas 1y agoOVH VPS-1 and your own configuration.
- scotty79 1y agoMaybe you could buy VPS in another country and set up VPN server yourself?
- sturza 1y agoMullvad
- reisse 1y agoMullvad doesn't really have any modern censorship circumvention options.
- diggan 1y agoTor should be pretty good even for environments where they crack down on VPNs, although it can be a bit slow, at least it works.
- immibis 1y agoThen you will be blocked by Twitter and Discord, which is the same thing.
- diggan 1y agoYeah, sucks, but really should find better places for people to gather regardless, if you're in that sort of environment.
- redserk 1y agoHow is this practical advice in a thread where someone mentions that the clampdown happened without notice? The "shoulda done..." advice isn't useful in the slightest, and I'd argue is malicious with how often it's done simply to satiate a poster's ego.
- lemper 1y agomegavpn, should be around a dollar a month for 5 devices.
- rthnbgrredf 1y agoIn case known VPN providers are blocked you can pick a small VPS from a hoster like Hetzner and setup your own VPN.
- jszymborski 1y agoFolks who are looking to bypass censorship, and those who live in countries where their internet connection is not currently censored who would like to help, can look to https://snowflake.torproject.org/ https://snowflake.torproject.org/
- Aachen 1y agoAren't there local (online or print) newspapers to get news from, as an alternative to Discord? Hope I'm not asking a dumb question
- alluro2 1y agoIn countries where it comes to government blocking/censoring internet traffic, traditional media is cleared of all dissent and fully controlled long before. Last stages of that are happening in my country, Serbia, currently.
- Aachen 1y agoRight, that makes sense. Did some looking up and nonfree press seems to be indeed the case for Indonesia: https://rsf.org/en/country/indonesia https://rsf.org/en/country/indonesia It's a mixed bag apparently, free press is technically legal since 1998 but selective prosecution and harassment of those actually uncovering issues (mainly becomes clear in the last section, "Safety") Tried looking up Serbia next on that website but got a cloudflare block. I'm a robot now...
- wafflemaker 1y agoIt's not a dumb question at all. Level on hn really got down lately if you're getting downvoted. Think about it Aachen. If the government has enough power to censor internet traffic, that what was the first thing it censored? Which media is traditionally known for being censored or just speaking propaganda? That's the classical newspapers. It's not uncommon in authoritarian countries for editors to need state to sign off on the day's paper. And if not that, articles are signed and publishers are known. They will auto-censor to avoid problems. Just like creators on YouTube don't comment on this one country's treatment of civilians to avoid problems.
- reactordev 1y agolocaltunnel.me, some node in the cloud, tunnel…
- jszymborski 1y agoMastodon is not easy for regimes to completely block, and most instances won't block you for using Tor. Mastodon saw a huge migration from Brazil when X was blocked there. https://joinmastodon.org/ https://joinmastodon.org/
- barbazoo 1y agoWouldn't it be easy to block the individual servers, e.g. https://mastodon.social https://mastodon.social?
- evulhotdog 1y agoThere are many instances of Mastodon, and due to its federated nature, you can use any of them to access it, and even host your own.
- Ray20 1y agoWhat's stopping them from just blocking them all and continuing to block new ones?
- evulhotdog 1y agoNothing is stopping them, but like most things in blocking free speech, it’s a game of cat and mouse.
- mayneack 1y agoThe long tail is very long
- beeflet 1y agoIt's not that long. You could probably these servers with an automated process.
- kragen 1y agoSure, but if you have an account on a different server, you can still see things posted on mastodon.social if you have followed someone there.
- defulmere 1y agoSOCKS proxy over SSH?
- pmlnr 1y agoAndroid doesn't come with system wide socks proxy support, and i couldn't find an open source app for it either. Is anyone aware of one? Nonetheless this is a surprisingly simple and bullet proof solution: SSH, that's not vpn boss, i need it for work.
- newlisp 1y agoFor web browsing, Firefox lets you configure socks on android.
- kevindamm 1y agoOutline is an open source shadowsocks client, and you provision your own server to act as the proxy. You can use it against any Shadowsocks server you want, and the protocol makes it look like regular https traffic. https://github.com/Jigsaw-Code/outline-apps https://github.com/Jigsaw-Code/outline-apps Android & iOS & Linux & Mac & Windows their server installer will help set up a proxy for users that aren't familiar with shadowsocks, too
- acuozzo 1y agoGrab a VPS and use SOCKS5 tunneling via SSH.
- Joel_Mckay 1y agoSSH is often targeted by deep packet inspection and protocol binding filters. i.e. One is better off tunneling over https://www.praise-the-glorious-leader.google.com.facebook.com.lol-my-random-regex-is-better-than-cowboy-kneal.localhost https://www.praise-the-glorious-leader.google.com.facebook.c... include SSH traffic protocol auto-swapping on your server (i.e. no way to tell the apparent web page differs between clients), as some corporate networks are infamously invasive. People can do this all day long, and they do... =3
- bitwize 1y agololwut At least it isn't goatse...
- Joel_Mckay 1y agoIt is not a real URI... lol The point was to include something clowns can't filter without incurring collateral costs, and wrapping the ssh protocol in standard web traffic. =3
- chrisweekly 1y agotangent: what is the significance of the "=3" you sign your messages with?
- Joel_Mckay 1y agoDon't worry about it... =3
- deleted 1y ago[deleted]
- deleted 1y ago
- Humorist2290 1y ago- Tor. Pros: Reasonably user friendly and easy to get online, strong anonymity, free. Cons: a common target for censorship, not very fast, exit nodes are basically universally distrusted by websites. - Tailscale with Mullvad exit nodes. Pros: little setup but not more than installing and configuring a program, faster than Got, very versatile. Cons: deep packet inspection can probably identify your traffic is using Mullvad, costs some money. - Your own VPSs with Wireguard/Tailscale. Pros: max control, you control how fast you want it, you can share with people you care about (and are willing to support). Cons: the admin effort isn't huge but requires some skill, cost is flexible but probably 20-30$ per month minimum in hosting.
- msgodel 1y agoIMO most people should have a VPS even if you don't need it for tunneling. Living without having a place to just leave services/files is very hard and often "free" services will hold your data hostage to manipulate your behavior which is annoying on a good day.
- nisegami 1y agoMinimums for a VPS should be closer to $5-10 a month, no?
- Humorist2290 1y agoYeah they can be cheap, but I would definitely recommend having at least 3 for redundancy. If one get shut down or it's IP blacklisted you still hopefully have a backup line to create a replacement.
- shellwizard 1y agoNo, unless you pay month to month. If you wait till BF you can find some really good deals on sites like lowendspirit
- majorchord 1y agoThe cheapest AWS EC2 instance is $3/mo
- 1y ago
- herodoturtle 1y agoOn a related note, does anyone have insight into *why* the Indonesian government is doing this?
- geephroh 1y agohttps://tech.yahoo.com/social-media/articles/indonesia-urges-tiktok-meta-act-120830660.html https://tech.yahoo.com/social-media/articles/indonesia-urges...
- TheChaplain 1y agoThe official word is to counter gambling. Lately the government is not really popular after some decisions that could be interpreted as authoritative, and as citizens have spoken out about it online, causing more voices to join and protests erupting.. So well, my guess is they're trying to control it.
- rickybule 1y agothere is a major protest currently happening due to the legislative body representative just giving themselves a monthly domicile stipend of ~$3300 on top of their salaries (yes, multiple), while the average people earned ~$330 monthly. the information about the protest are not broadcasted on local TVs, so the only spread of information is through social media. i guess since a lot of people went around it using VPN, the gov decided to block it too.
- jofer 1y agoIf it helps, here's some recent coverage: https://www.theguardian.com/world/2025/aug/26/indonesia-protests-austerity-parliament-member-privileges https://www.theguardian.com/world/2025/aug/26/indonesia-prot...
- teekert 1y ago“Some demonstrators on Monday were seen on television footage carrying a flag from the Japanese manga series One Piece, which has become a symbol of protest against government policies in the country.”
- yogorenapan 1y agoWireGuard should still work. Tons of different providers. I trust Mullvad but ProtonVPN has a free tier. If they start blocking WireGuard, check out v2ray and xray-core. If those get blocked... that means somehow they're restricting all HTTPS traffic going out of the country
- Joel_Mckay 1y agoThere are many options, but avoiding the legal consequences may be a grey area: https://www.stunnel.org/index.html https://www.stunnel.org/index.html https://github.com/yarrick/iodine https://github.com/yarrick/iodine https://infocondb.org/con/black-hat/black-hat-usa-2010/psudp-a-passive-approach-to-network-wide-covert-communication https://infocondb.org/con/black-hat/black-hat-usa-2010/psudp... ..and many many more, as networks see reduced throughput as an error to naturally route around. =3
- wdroz 1y agoDNS tunnels with iodine works well, it's easy to setup and work in a lot of place. You can also connect to some random corporate wifi and it's very likely that this will work (not necessary in "direct" mode).
- doix 1y agoI'm currently traveling in Uzbekistan and am surprised that wireguard as a protocol is just blocked. I use wireguard with my own server, because usually governments just block well known VPN providers and a small individual server is fine. It's the first time I've encountered where the entire protocol is just blocked. Worth checking what is blocked and how before deciding which VPN provider to use.
- bryanlarsen 1y agoWe've had success using wireguard over wstunnel in places where wireguard is blocked. https://github.com/erebe/wstunnel https://github.com/erebe/wstunnel
- vehemenz 1y agoThis looks great, thanks.
- bryanlarsen 1y agoI should have mentioned that our use case isn't avoiding government firewalls, it's transiting through broken network environments.
- daveidol 1y agoWow, kinda crazy to think about a government blocking a protocol that just simply lets two computers talk securely over a tunnel.
- roscas 1y agoThat is how you know they haven't got a clue on what they're doing.
- tsimionescu 1y agoOn the contrary, it shows that they know very well what they're doing. Their goal is censorship. If that disrupts connectivity for some niche but valid use cases, so be it. The vast majority of people have never used a WireGuard tunnel, so they are unimpacted. Some corporate use cases that even that government would approve of are disrupted, but they can either lie with that or have a whitelist. Most non-corporate use of this and other similar protocols is not something the government would allow. So, given their nefarious goal, they are doing a great job by blocking WireGuard (and similar protocols, presumably).
- drake99 1y agoIn this scenario, Chinese have very rich experience. you need to use the advance proxy tool like clash ,v2ray, shadowsocks etc.
- mezyt 1y agoshadowsocks was the winner of the state of the art I had to do at work. It address the "long-term statistical analysis will often reveal a VPN connection regardless of obfuscation and masking (and this approach can be cheaper to support than DPI by a stat)" comment.
- QuadmasterXLII 1y agoSomeone should create a vpn protocol that pretends to be a command and control server exfiltrating US corporate secrets from hacked servers. The traffic pattern should be similar, and god forbid Xi blocks the real exfiltrations
- roscas 1y agoBlocking Twitter is a good start, now Facebook, Instagram, Whatsup and TikTok. This is a good start but more should be blocked. Then force ISP to block ads. Not just for Indonesia but all countries. But we still have a lot more to do to fix the web.
- mr90210 1y agoThe issue with that is where do they draw the line. Next thing you know each country becomes North Korea.
- platevoltage 1y agoI can't stand most of these things you want blocked but this is bonkers.
- xyzzzzzzz 1y ago[dead]
- jedisct1 1y agoGet a cheap VPS anywhere, and use DSVPN https://github.com/jedisct1/dsvpn https://github.com/jedisct1/dsvpn Uses TCP and works pretty much anywhere.
- SirMaster 1y agoRemote desktop (RDP/AnyDesk/etc) into a VM hosted somewhere else?
- WarOnPrivacy 1y agoI'm reading posts that indicate (at least some of) the blocking is at the DNS level. https://old-reddit-com.translate.goog/r/WkwkwkLand/comments/1n29vl6/discord_twitter_blocked_post_removed_on_rindonesia/?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wapp https://old-reddit-com.translate.goog/r/WkwkwkLand/comments/... Cloudflare says some issue affecting Jakarta has been resolved. They aren't saying what the issue was. https://www.cloudflarestatus.com/incidents/1chpg2514kq8 https://www.cloudflarestatus.com/incidents/1chpg2514kq8
- rickybule 1y agoWhat I'm worried most are that most people are not even aware of what is DNS and how to change it. I can't imagine those who are caught in the chaos with only their phone and unable to access information that could help them to be safe.
- jhanschoo 1y agoGenerally speaking, the general population that wants to use blocked services will develop enough technical know-how to circumvent it. The biggest risk is that there are bad actors giving malicious advice and to such learners, looking to defraud or otherwise exploit them.
- nomilk 1y agoAustralia and UK might soon go down this path. Something quite depressing is if we (HN crowd) find workarounds, most regular folks won't have the budget/expertise to do so, so citizen journalism will have been successfully muted by government / big media.
- hdgvhicv 1y ago90% of “citizen journalism” is nothing of the sort. Just like “citizen science” researching vaccines.
- RansomStark 1y agoPreach comrade! Those citizen journalists with their primary sources, disgusting. Thats nothing but propaganda. Remember it doesnt matter what the video shows, it only matters who showed it to you.
- Barrin92 1y ago>Remember it doesnt matter what the video shows, it only matters who showed it to you In an age of mass media (where there's a video for anything) or now one step further synthetic media knowing who makes something is much more important than the content, given that what's being shown can be created on demand. Propaganda in the modern world is taking something that actually happened, and then framing it as an authentic piece of information found "on the street", twisting its context. "what's in the video" is now largely pointless, and anyone who isn't gullible will obviously always focus on where the promoter of any material wants to direct the audiences attention to, or what they want to deflect from.
- deleted 1y ago[deleted]
- p_j_w 1y ago> Remember it doesnt matter what the video shows, it only matters who showed it to you. Both matter.
- 1y ago
- Jigsy 1y agoI was wondering something like this but in a different capacity. What with certain countries (they know who they are) and their hatred for encryption, it got me wondering how people would communicate securely if - for example - Signal/WhatsApp/etc. pulled out and the country wound up disconnecting the submarine cables to "keep $MORAL_PANIC_OF_THE_DAY safe." How would people communicate securely and privately in a domestic situation like that?
- RansomStark 1y agoIn person or not at all. At that point you've essentially lost. You either hope another country sees value in spreading you some democracy, or you rise up and hope others join you. Or not and you accept the protection the state is graciously providing to you.
- Jigsy 1y agoSneakerNet or bust, eh? That sucks.
- wsintra2022 1y agoEncrypted hand written notes tied to pigeons
- whyleyc 1y agoI'd recommend using Outline - it's a one click setup that lets you provision your own VPN on a cloud provider (or your own hardware). Since you get to pick where the hardware is located and it is just you (or you and a small group of friends & family) using the VPN, blocking is more difficult. If you don't want the hassle of using your own hardware you can rent a Digital Ocean droplet for <$5 per month. https://getoutline.org/ https://getoutline.org/
- lucasban 1y agoI’ve set this up for friends in fairly heavily censored countries before, it has been working well so far, but as others have said, this is a cat and mouse game
- dongcarl 1y agoGive Obscura a try, we get around internet restrictions by using QUIC as transport, which looks like HTTP/3 and doesn't suffer from TCP-over-TCP meltdown: https://obscura.net/ https://obscura.net/ Technical details: https://obscura.net/blog/bootstrapping-trust/ https://obscura.net/blog/bootstrapping-trust/ Let us know what you think! Disclaimer: I'm the creator of Obscura.
- McNulty2 1y agoIf they're blocking other protocols then likely they're blocking quic also.
- dongcarl 1y agoVery possible, though many of our users are saying that in network environments where WireGuard is blocked they were able to use Obscura.
- tmpfs 1y agoHey, I went to take a look at Obscura and I like the ideas but I can't find the source code. You are making some bold claims but without the source I can't verify those claims. Any plans to open-source it?
- dongcarl 1y agoWe should link it in more places, apologies! Here it is: https://github.com/Sovereign-Engineering/obscuravpn-client https://github.com/Sovereign-Engineering/obscuravpn-client
- deleted 1y ago[deleted]
- tamimio 1y agoLooks good, just one note: btc was never meant for anonymity, if you would add Monero as a payment option that would be great.
- jauntywundrkind 1y agoNations severing peoples connections to the world is awful. I'm so sorry for the chaos in general, and the state doing awful things both. Go on https://lowendbox.com https://lowendbox.com and get a cheap cheap cheap VPS. Use ssh SOCKS proxy in your browser to send web traffic through it. Very unfancy, a 30+ year old solution, but uses such primitive internet basics that it will almost certainly never fail. Builtin to everything but Windows (which afaik doesn't have an ssh client built-in). Tailscale is also super fantastic.
- sertsa 1y agoWindows has had both ssh client/server for years
- int_19h 1y ago> uses such primitive internet basics that it will almost certainly never fail. It already fails in China and Russia. Simply tunneling HTTP through SSH is too easy to detect with DPI. > Windows (which afaik doesn't have an ssh client built-in) It has had both SSH client and SSH server built-in since Win10.
- rurban 1y agoIn this case the blockage will probably just be up for a few days, until the protests calmed down. Other than that: tor
- yupyupyups 1y agoResidential VPNs, but try to find ones that are ran ethically.
- TimCTRL 1y agoI can relate to this because my country has an election soon and I'm sure we wont have internet for 3 - 5 days then.
- guluarte 1y agoSSH tunneling on port 80 could work since it's rarely blocked, rent a cheap vps.
- whalesalad 1y agoSSH SOCKS proxy if you have an SSH host somewhere that is not Indonesia.
- reisse 1y agoYou've come to a wrong place to ask. Most people here (judging by recommendations of own VPN instances, Tor, Tailscale/other Wireguard-based VPNs, and Mullvad) don't have any experience with censorship circumvention. Just look for any VPNs that are advertised specifically for China, Russia, or Iran. These are the cutting edge tech, they may not be so privacy-friendly as Mullvad, but they will certainly work.
- temptemptemp111 1y ago[dead]
- wat10000 1y agoMullvad worked OK in China for me recently. Sometimes I'd have to try a few different endpoints before it worked. Something built specifically to work in those places would probably be better, but it wasn't too much trouble. Not necessarily a recommendation, just sharing one data point.
- Liftyee 1y agoI remember always needing obfuscation enabled in Mullvad, but it would work in the end (as you said, after trying a few endpoints).
- riehwvfbk 1y agoOP: look into VLESS (and similar). And read up on ntc.party (through Google translate). There are certain VPN providers that offer the protocol.
- yogorenapan 1y agoI think REALITY is the newer protocol. I remember VLESS being somewhat more detectable
- taminka 1y agonah, vless is the protocol, reality is a newer obfuscation method that works over vless edit: op, protonvpn has a free tier that works in russia, so likely works everywhere, or if you're comfortable with buying a vps, sshing into it and running some commands, look up x-ray, and use on of their gui panels
- liveoneggs 1y agoAll the various proxy solutions offered are good (although the simplest ones - like squid - haven't been mentioned yet). You can also use a remote desktop or even just ssh -Y me@remote-server "firefox"
- fastnetnet 1y agoTry some of the more niche VPN protocols like IKEv2/IPSec or zinc. SSH over socks is another option or you can run your own proxy server, nobody will ever know... This makes me wonder if you cannot just run OpenVPN on a different port like 443 since it's also TLS based.
- jwong_ 1y agoA proxy service like shadow socks works. There are thousands of providers for $X/month for a decent amount of traffic
- Arubis 1y agoIf you can still get SSH access and can establish an account with a VPS provider with endpoints outside your country of origin, https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand is a little long in the tooth but may still be viable.
- bsimpson 1y ago15 years ago, I was using EC2 at work, and realized it was surprisingly easy to SSH into it in a way where all my traffic went through EC2. I could watch local Netflix when traveling. It was a de facto VPN. Details are not at the top of my mind these years later, but you can probably rig something up yourself that looks like regular web dev shit and not a known commercial VPN. I think there was a preference in Firefox or something.
- hinkley 1y agoI watched a season of Doctor Who that way back when the BBC were being precious about it. But Digital Ocean, so $5.
- mikestorrent 1y agoThe issue these days is that all of the EC2 IP ranges are well known, and are usually not very high-reputation IPs, so a lot of services will block them, or at least aggressively require CAPTCHAs to prevent botting. Source: used to work for a shady SEO company that searched Google 6,000,000 times a day on a huge farm of IPs from every provider we could find
- kccqzy 1y agoTunneling via SSH (ssh -D) is super easy to detect. The government doesn't need any sophisticated analysis to tell SSH connections for tunneling from SSH connections where a human is typing into a terminal. Countries like China have blocked SSH-based tunneling for years. It can also block sessions based on packet sizes: a typical web browsing session involves a short HTTP request and a long HTTP response, during which the receiving end sends TCP ACKs; but if the traffic traffic mimics the above except these "ACKs" are a few dozen bytes larger than a real ACK, it knows you are tunneling over a different protocol. This is how it detects the vast majority of VPNs.
- Nextgrid 1y agoFurthermore, you can always run another VPN on top of that if you don’t trust the outer one with the actual plaintext traffic.
- 05 1y agoNot on mobile - iOS doesn't support nested VPNs, and neither does stock Android.
- ddbb33 1y agoPsiphon works
- vander_elst 1y agoSet up a VM on AWS/azure/gcp/... in the desired cell, install a VPN server and done. Once you have automation in place it takes ~2 minutes to start, you can run it on demand so you can pay per minute.
- mhitza 1y agoUse the Tor browser window in Brave. It's nowhere near as anonymous as the Tor browser, but the built in ad blocking makes browsing via Tor usable. And that's what you and your compatriots are interested in. Prepare to fill in Cloudflare captchas all day, but that's what it takes to have a bit of privacy nowadays.
- ACCount37 1y agoAmneziaWG is a decent option for censorship resistance, and it can be installed as a container on your own server.
- o999 1y agoAmneziaWG clients works just fine with normal Wireguard servers by the way.
- bitbasher 1y agoMake your own VPN using a VPS and something like openvpn. Not every website will allow it, but it should get you access to more than you have now.
- pbiggar 1y agoThere's a new VPN that you might try, built by Boycat. https://www.boycat.io/vpn https://www.boycat.io/vpn Don't know if it will help in this situation as it's designed to be a VPN not controlled by Israel, but it might be worth a try.
- _verandaguy 1y agoHello! I've got experience working on censorship circumvention for a major VPN provider (in the early 2020s). - First things first, you have to get your hands on actual VPN software and configs. Many providers who are aware of VPN censorship and cater to these locales distribute their VPNs through hard-to-block channels and in obfuscated packages. S3 is a popular option but by no means the only one, and some VPN providers partner with local orgs who can figure out the safest and most efficient ways to distribute a VPN package in countries at risk of censorship or undergoing censorship. - Once you've got the software, you should try to use it with an obfuscation layer. Obfs4proxy is a popular tool here, and relies on a pre-shared key to make traffic look like nothing special. IIRC it also hides the VPN handshake. This isn't a perfectly secure model, but it's good enough to defeat most DPI setups. Another option is Shapeshifter, from Operator (https://github.com/OperatorFoundation https://github.com/OperatorFoundation). Or, in general, anything that uses pluggable transports. While it's a niche technology, it's quite useful in your case. In both cases, the VPN provider must provide support for these protocols. - The toughest step long term is not getting caught using a VPN. By its nature, long-term statistical analysis will often reveal a VPN connection regardless of obfuscation and masking (and this approach can be cheaper to support than DPI by a state actor). I don't know the situation on the ground in Indonesia, so I won't speculate about what the best way to avoid this would be, long-term. I will endorse Mullvad as a trustworthy and technically competent VPN provider in this niche (n.b., I do not work for them, nor have I worked for them; they were a competitor to my employer and we always respected their approach to the space).
- azalemeth 1y agoThank you very much for a detailed answer. Might I rudely ask -- as you're knowledgeable in this space, what do you think of Mullvad's DAITA, which specifically aims to defeat traffic analysis by moving to a more pulsed constant bandwidth model?
- _verandaguy 1y agoDAITA was introduced after my time in the industry, but this isn't a new idea (though as far as I know, it's the first time this kind of thing's been commercialized). It's clever. It tries to defeat attacks against one of the tougher parts of VPN connections to reliably obfuscate, and the effort's commendable, but I'll stop short of saying it's a good solution for one big reason: with VPNs and censorship circumvention, the data often speaks for itself. A VPN provider working in this space will often have aggregate (and obviously anonymized, if they're working in good faith) stats about success rates and failure classes encountered from clients connecting to their nodes. Where I worked, we didn't publish this information. I'm not sure where Mullvad stands on this right now. In any case -- some VPN providers deploying new technology like this will partner with the research community (because there's a small, but passionate formal research community in this space!) and publish papers, studies, and other digests of their findings. Keep an eye out for this sort of stuff. UMD's Breakerspace in the US in particular had some extremely clever people working on this stuff when I was involved in the industry.
- deleted 1y ago[deleted]
- princevegeta89 1y agoOP, you can rent a VPS from a reputable and cheap provider within the NA region - OVH, Vultr, Linode etc. are decent. Also check out lowendtalk.com Then, setup Tailscale on the server. You can VPN into it and essentially browse the internet as someone from NA.
- teekert 1y agoFrom some of the comments here I get why you are downvoted. But tbh I would also have gone that route. So are we just inexperienced? I read here indeed that wireguard is very easily blocked. It was at the company I worked for but then I just set port 23 (who uses ftp anyways??). And it worked. But why is this still bad then? Obviously I have 0 real experience with this.
- princevegeta89 1y agoWell, I mean, Tailscale is pretty easy overall. When client apps get blocked, you can literally hook up your router into Tailscale if needed, or you can run a headless version of Tailscale on your home server or the very machine you are on. It should also be possible to use a tunnel to get around the blocking of WireGuard, for example. You can then use it as an exit node if needed. It should work in theory, I have never tried this though. I just speak as a very frequent user of Tailscale with a bunch of nodes that are geographically located in different cities around me.
- teekert 1y agoSure, I know and use it too. But I saw you being downvoted so I responded to that. I think, reading the rest of the thread, your response (as mine would be) does not work as signals 0 experience with actually oppressing regimes. Not?
- TZubiri 1y ago[flagged]
- ddtaylor 1y agoYour first option until you get settled is to use an SSH reverse proxy: ssh -D 9999 user@my.server Then configure your browser to use local port 9999 for your SOCKS5 proxy. This gets you a temporarily usable system and if you can tunnel this way successfully installing some WireGuard or OpenVPN stuff will likely work. EDIT: Thanks it's -D not -R
- ok123456 1y agossh -D 48323 -p 61423 my-vps.big-company.com
- ck2 1y agoJust please be safe and necessarily paranoid One way they tend to "solve" workarounds is making examples of people
- database64128 1y agoYou could use something like https://github.com/database64128/swgp-go https://github.com/database64128/swgp-go to obfuscate WireGuard traffic. Using full-blown VPNs under such environments has the disadvantage of affecting your use of domestic web services. You might want to try something like https://github.com/database64128/shadowsocks-go https://github.com/database64128/shadowsocks-go, which allows you to route traffic based on domain and IP geolocation rules.
- jinnko 1y agoAmneziaVPN has censorship circumvention options and makes it easy to set up a self hosted instance of that's what you prefer, or use their hosted service. https://amnezia.org/ https://amnezia.org/
- afh1 1y agoDepending on the circumstances, maybe ditch the landline local ISP for a satellite connection with a foreign ISP?
- jeffbee 1y agoUse an Actual Private Network? Radio links that you control. Peer with someone who owns a Starlink terminal. Rent instances in GCP's Jakarta datacenter.
- jasonjayr 1y agohttps://en.wikipedia.org/wiki/AMSAT-OSCAR_7#Use_by_Polish_anticommunist_opposition https://en.wikipedia.org/wiki/AMSAT-OSCAR_7#Use_by_Polish_an... <-- "Radio links you control", and is hard to block/detect.
- darkhorn 1y agoPeople in Turkey use https://github.com/ValdikSS/GoodbyeDPI https://github.com/ValdikSS/GoodbyeDPI together with DNS over HTTPS (DoH).
- deleted 1y ago[deleted]
- rieslingspecial 1y agoThis might not be the case for Indonesia currently, but for countries like Russia, China, Iran most of the mentioned solutions will not work. I've had to evade Russian censorship for years now - the censors (Roskomnadzor) use DPI and other means of classifying network traffic, and currently the following things are outright blocked: - Tor - Wireguard and derivatives (incl. Mullvad, Tailscale, ProtonVPN) - OpenVPN - Shadowsocks (incl. Outline) What still works is Xray-core [1] with vless and Reality protocols, whatever those mean. Xray-core is an innovation over v2ray [2]. v2ray might also still work, but I've never tried it. If you have the capacity to run your own VPS, the simplest solution would be to install the 3x-ui [3], which is something like "Xray-core with a simple to use UI in a single package ready-to-use", but you'd also need to setup some basic security measures and a firewall. For those technically inclined, here [4] is a rough ansible playbook to install 3x-ui on a blank Debian machine. Additional configuration will be needed in the UI itself, there is a lot of online tutorials, and I link to one of them in [5] (in Russian, unfortunately). Don't just trust me blindly, please review before running! There are also commercial xray-aware VPN providers, but I wouldn't publicly vouch for any of them. I found it very strange that there is not much info on HN about xray and v2ray, and I also hope it stays this way for most of the people here and not here. However, we live in a weird reality and have to actively engage in such an arms race now. As a side note, if anyone here has quality info about security of the xray-core implementation, I'd be happy to get familiar. I didn't look at the code myself and still am slightly suspicious, but oh well it works :shrug: [1]: https://github.com/XTLS/Xray-core https://github.com/XTLS/Xray-core [2]: https://github.com/v2fly/v2ray-core https://github.com/v2fly/v2ray-core [3]: https://github.com/MHSanaei/3x-ui/ https://github.com/MHSanaei/3x-ui/ [4]: https://pastebin.com/DjFQ8c6Z https://pastebin.com/DjFQ8c6Z [5]: https://habr.com/ru/articles/731608/ https://habr.com/ru/articles/731608/
- akho 1y agoShadowsocks still works. It can be detected through active probing, but blocking it automatically is a bit above their current capabilities. No reason not to use the *rays anyway.
- nromiun 1y agoUsually when countries block websites they don't block major cloud providers, like AWS and Google Cloud. Because most websites are hosted on them. So you can get a cheap VPS from AWS or GCP (always free VM is available) and host OpenVPN on it.
- ali-aljufairi 1y agovps install tailscale on it use it as exit node
- gwbas1c 1y agoJust curious: Anyone know if things like Starlink are viable?
- akho 1y agoStarlink, by policy, connects you through a ground station in the same country. They wouldn't be allowed to operate otherwise.
- ultim8k 1y agoWhy? Can someone block the sky? (I have 0 satellite knowledge)
- gwbas1c 1y agoIt's not about blocking the sky. Starlink sends the internet connection back down to the ground somewhere in the country you are in. That being said, if I have an American starlink account, and I go to Indonesia, what happens? Does my internet connection go back down through Indonesia or does it go through somewhere else?
- onesociety2022 1y agoStarlink is a legitimate business (ISP) that wants to make money from customers in that country. They will comply with all of the regulations and bans imposed by the government in that country or risk getting banned completely.
- throwpoaster 1y ago[flagged]
- leishman 1y agoI'd recommend Obscura because it uses Wireguard over QUIC and it pretty good at avoiding these blocks. It's also open source.
- o999 1y agoAmneziaWG client worked just fine with normal Wireguard servers in Egypt where official Wireguard clients doesn't, WGTunnel app on android support both protocols. https://github.com/amnezia-vpn/amneziawg-go https://github.com/amnezia-vpn/amneziawg-go https://github.com/wgtunnel/wgtunnel https://github.com/wgtunnel/wgtunnel
- trhway 1y agoHTTPS to you own proxy on a foreign VPS.
- VortexLain 1y agoThe most effective solution is to use X-ray/V2ray with VLESS, or VMESS, or Trojan as a protocol. Another obfuscated solution is Amnezia If you are not ready to set up your own VPN server and need any kind of connection right now, try Psiphon, but it's a proprietary centralized service and it's not the best solution.
- teekert 1y agoWhat is going on if you don’t mind my asking? Our local news does not mention anything. Nor does ddging help? Any sources?
- nograpes 1y agoMassive protests have occurred due to obvious government corruption. In particular the housing allowance for a month for a parliamentarian is now ten times the minimum wage for a month. https://www.theguardian.com/world/2025/aug/26/indonesia-protests-austerity-parliament-member-privileges https://www.theguardian.com/world/2025/aug/26/indonesia-prot... Sorry I don't have a better freely accessible source, maybe someone with more knowledge can fill it in.
- jacobgkau 1y ago> the housing allowance for a month for a parliamentarian is now ten times the minimum wage for a month. I'm almost positive that everyone in the US Congress is making at least ten times the minimum wage in this country. The "housing allowance" being referred to is separate from their normal salary in Indonesia, but still, interesting to imagine how much more seriously people there would take that disparity than in many other countries. This caught my attention more: > Indonesia passed a law in March allowing for the military to assume more civilian posts, while this month the government announced 100 new military battalions that will be trained in agriculture and animal husbandry. In July the government said the military would also start manufacturing pharmaceuticals. They're replacing civilian industry with military, apparently not out of any emergency requirement but just to benefit the military with jobs (and the government with control over those sectors) at the expense of civilian jobs.
- ToValueFunfetti 1y agoThe ratio between Indonesian parliamentary income and the median Indonesian income is ~18x, while the ratio in the US is ~4x. As someone who wants US congressional income to be substantially higher, it's hard for me to be upset at that on its own. There are plenty of other variables at play, though, and a direct comparison of these ones might not be getting at the issue.
- altern8 1y agoTor..?
- deleted 1y ago[deleted]
- swe_dima 1y agoPersonally, I like Amnezia VPN, it has some ways to work around blocks: https://amnezia.org/en https://amnezia.org/en You can very easily self-host it, their installer automatically works on major cloud platforms. Though if Indonesia has blocked VPNs only now, possibly they only block major providers and don't try to detect the VPN protocol itself, which would make self-hosting any VPN possible.
- nine_k 1y agoXRay / XTLS-Reality / VLESS work rather fine, and is said to be very hard to detect, even in China. I followed [1] to set up my own proxy, which works pretty fine. More config examples may be helpful, e.g. [2]. [1]: https://cscot.pages.dev/2023/03/02/Xray-REALITY-tutorial/ https://cscot.pages.dev/2023/03/02/Xray-REALITY-tutorial/ [2]: https://github.com/XTLS/Xray-examples/blob/main/VLESS-TCP-XTLS-Vision-REALITY/REALITY.ENG.md https://github.com/XTLS/Xray-examples/blob/main/VLESS-TCP-XT...
- zeropointsh 1y agoThe great thing about China's Great Firewall is that really good options to circumvent censorship have been around for a while. Was waiting for someone to bring up XRay! Alternatively, here is a great write up of using V2Ray[1]. May be worth OP looking into, as a blogger I found noted[2] is an alternative to a VPN, and may work. [1]: https://www.v2ray.com/en/ https://www.v2ray.com/en/ [2]: https://sequentialread.com/v2ray-caddy-to-access-the-internet-in-china/ https://sequentialread.com/v2ray-caddy-to-access-the-interne...
- taminka 1y agoim curious, isn't ALL of your traffic appearing to be to just one website the most obvious giveaway?
- akho 1y ago*ray clients typically allow configuration of routing. So you can send only blocked stuff through the tunnel; or, in reverse, send some known-working stuff (e. g. local domain) direct. Also works as adblock.
- gck1 1y agoAlso sing-box [1]. I don't use it for its primary use case of censorship circumvention, but rather for some highly complex routing configurations it supports. My use case consists of passing some apps on my Android through interface A (e.g. banking apps through my 5G modem), some apps through US residential proxy (for US banks that don't like me visiting from abroad), and all the rest through VPN. And no root required! It's wild that GFW triggered creation of this and nothing like it existed / exists. [1]: https://github.com/SagerNet/sing-box https://github.com/SagerNet/sing-box
- teaga 1y agoLaunch an EC2 instance in the US region (Ubuntu, open ports 22 and 1194), then connect via SSH and run the OpenVPN install script. Generate the .ovpn profile with the script and download it to your local machine. Finally, import the file into the OpenVPN client and connect to route traffic through the US server.
- wiredpancake 1y agoDoesn't work in China, this is a method for last decades censorship.
- asdefghyk 1y agoshortwave radios would enable you to still get news of major events - not 2 way though
- ryzvonusef 1y agoI live in Pakistan and two years back we had this exact same problem, (election interference) and frankly, you just try to scrape through solutions, but without an answerable government, there is little you can do. We tried things like Proton VPN and Windscribe VPN, as well as enabling MT proxy on Telegram, but soon govts find it easier to just mass ban internet access. Use Netblocks.org to analyse the level of internet blockage and try to react accordingly.
- weregiraffe 1y ago[flagged]
- simmo9000 1y agoRecommendations for any 'good' ones?
- more_corn 1y agoYou could rent a cheapo instance at a cloud provider and tunnel https over ssh. That’s basically undetectable. Long lived ssh connection? Totally normal. Lots of throughput? Also normal. Bursts throughput? Same. Not sure how to do this on mobile. Tailscale might be an option too (they have a free account for individuals and an exit node out of country nearly bypasses your problem) It uses wireguard which might not be blocked and which comes with some plausible deniability. It’s a secure network overlay not a VPN. It just connects my machines, honest officer.
- gudzpoz 1y agoAs someone based in China, it's a bit surprising that techniques used by Chinese people get very few mentions here, while I do think they are quite effective against access blocking, especially after coevolving with GFW for the past decade. While I do hope blocking in Indonesia won't get to GFW level, I will leave this here in case it helps. I found this article [0] summarizing the history of censorship and anti-censorship measures in China, and I think it might be of help to you if the national censorship ever gets worse. As is shown in the article, access blocking in China can be categorized into several kinds: (sorted by severity) 1. DNS poisoning by intercepting DNS traffic. This can be easily mitigated by using a DOT/DOH DNS resolver. 2. Keyword-based HTTP traffic resetting. You are safe as long as you use HTTPS. 3. IP blocking/unencrypted SNI header checking. This will require the use of a VPN/proxy. 4. VPN blocking by recognizing traffic signatures. (VPNs with identifiable signatures include OpenVPN and WireGuard (and Tor and SSH forwards if you count those as VPNs), or basically any VPN that was designed without obfuscation in mind.) This really levels up the blocking: if the government don't block VPN access, then maybe any VPN provider will do; but if they do, you will have a harder time finding providers and configuring things. 5. Many other ways to detect and block obfuscated proxy traffic. It is the worse (that I'm aware of), but it will also cost the government a lot to pull off, so you probably don't need to worry about this. But if you do, maybe check out V2Ray, XRay, Trojan, Hysteria, NaiveProxy and many other obfuscated proxies. But anyways, bypassing techniques always coevolve with the blocking measures. And many suggestions here by non-Indonesian (including mine!) might not be of help. My personal suggestion is to find a local tech community and see what techniques they are using, which could suit you better. [0] https://danglingpointer.fun/posts/GFWHistory https://danglingpointer.fun/posts/GFWHistory
- mxie-ca 1y agoThanks for the link! Is there any good DoT/DoH DNS resolver that works well in China? I know I can build one myself, but forwarding all DNS requests to my home server in NA slows down all connections...
- genericuser256 1y agoI would recommend Psiphon [1,2] most (all?) of their code is open source and their main goal is to get around censorship blocks. They do have some crypto side projects but the main product is very solid. [1] https://psiphon.ca/ https://psiphon.ca/ [2] https://github.com/Psiphon-Inc https://github.com/Psiphon-Inc
- adam-p 1y agoState censorship circumvention is exactly what Psiphon is for! So yes, try it. (Disclaimer: I work there.)
- farceSpherule 1y agoIf you are a journalist or other, contact Team Cymru.
- thinkingtoilet 1y agoPlease consider the potential consequences of circumventing the ban. Do what you do, but above all stay safe!
- deleted 1y ago[deleted]
- pinoy420 1y ago[dead]
- arewethereyeta 1y agoGive Trojan proxy a try. It's supposed to go unnoticed since it works on the https port 443. Something like: https://www.anonymous-proxies.net/products/residential-trojan-proxy/ https://www.anonymous-proxies.net/products/residential-troja... If you get it with a residential IP is even better. Works great in Iran and China and i suspect will wotk great for you too
- fruitworks 1y agoTry looking into tor bridges. You could also buy a VPS and use SSH tunneling to access a tor daemon running on a VPS. Host some sort of web service on the VPS so it looks inconspicuous
- zhengiszen 1y agoUse an ethical one https://www.boycat.io/vpn https://www.boycat.io/vpn
- yannick 1y agodoes this include bali? curious as that would impact the large international population.
- ivape 1y agoSSH tunnel on cheap VPS, a couple.
- puffybuf 1y agoI like mullvad. You can buy a prepaid card off amazon. I figured out how to setup wireguard on various unixes Mac/linux/openbsd
- 38 1y ago[dead]
- cogman10 1y agoIMO, the safest route for an individual with tech competency is to setup a small instance server in the cloud outside your country and use ssh port forwarding and a proxy to get at information you want. For an example of a proxy service https://www.digitalocean.com/community/tutorials/how-to-set-up-squid-proxy-for-private-connections-on-debian-11 https://www.digitalocean.com/community/tutorials/how-to-set-... That will give you a hard to snoop proxy service that should completely circumvent a government blockaid (they likely aren't going to be watching or blocking ssh traffic).
- asqueella 1y agoAdvanced enough censors (who have DPI) do block or slow down ssh, e.g.: https://serverfault.com/questions/1122015/ssh-blockedfor-foreign-vps-ip-not-blocked https://serverfault.com/questions/1122015/ssh-blockedfor-for...
- cogman10 1y agoThat's a pretty strict censorship that basically locks your digital infrastructure into your country.
- tsimionescu 1y agoSomething that is often a benefit from the perspective of these regimes, yes.
- asqueella 1y agoWell, mimicking China's GFW is seemingly the objective of some governments. But they are also able to allow some light (text-based) ssh usage and still prevent proxying.
- Havoc 1y agoI guess that's where the slow down part comes in. I'd imagine you can slow SSH to a snails pace and it'll still work for basic CLI use
- 1y ago
- qwezxcrty 1y agoChinese have developed a significant amount of sophisticated tools countering internet censorship. V2ray as far as I recall is the state-of-the-art. To use them, one need to first rent a (virtual) server somewhere from a foreign cloud provider as long as the payment does not pose a problem. The first step sometimes proves difficult for people in China, but hopefully Indonesia is not at that stage yet. What follows is relatively easy as there are many tutorials for the deployment like: https://guide.v2fly.org/en_US/ https://guide.v2fly.org/en_US/
- mrbluecoat 1y agoAgreed, the best tools for circumventing The Great Firewall of China are from Chinese developers. https://github.com/txthinking/brook https://github.com/txthinking/brook comes to mind..
- deleted 1y ago[deleted]
- pshirshov 1y agoYou should use a jet. Actually that's a Russian joke.
- Gud 1y agoTry a ssh socks5 proxy to a cheap vps. It worked well for me in UAE when other solutions didn’t
- stealthlogic 1y ago[dead]
- thewanderer1983 1y agoGo here. https://github.com/net4people/bbs/issues https://github.com/net4people/bbs/issues Very helpful community.
- tonymet 1y agotry Bright Data / luminati and the traffic is http to the proxy as well.
- joshryandavis 1y agoI lived in China for a while and there were several waves of VPN blocks. Also very few VPN services even try to actively support VPN-blocking nations anymore. Any commercial offering will be blocked eventually. What I settled on for decent reliability and speeds was a free-tier EC2 hosted in an international region. I then setup a SOCKS5 server and connected my devices to it. You mentioned Cloudflare so whatever their VM service is might also work. It's very low profile as it's just your traffic and the state can't easily differentiate your host from the millions of others in that cloud region. LPT for surviving the unfree internet: GitHub won't be blocked and you'll find all the resources and downloads you need for this method and others posted by Chinese engineers. Edit: If you're worried about being too identifiable because of your static IP, well it's just a computer, you can use a VPN on there too if you want to!
- la_mezcla 1y agoOut of all VPS providers out there, why did you chose one of the most, if not the most, expensive ones - AWS, EC2?
- wulfstan 1y agoWhen I worked in China (not for long periods but frequently enough that the Great Firewall became an irritant) I hosted an OpenVPN server on port 443 and/or port 22 of a server I owned. That worked sufficiently well most of the time.
- ykl 1y agoThis doesn't work anymore; the GFW no longer detects VPN connections by port but instead by performing deep packet inspection to characterize the type of traffic going over every connection. Using this technique in combination with some advanced ML systems, they're able to detect any encrypted VPN connection and cut it off; it's basically not possible to run any kind of outbound VPN connection (even to private servers) from inside of China anymore, and it's usually not even possible to _tunnel_ a VPN connection through some other protocol because the GFW now detects that too. Stepping back and looking at it from a purely technical perspective, it's actually insanely impressive. Here's a USENIX paper from a few years ago on how it is done: https://gfw.report/publications/usenixsecurity23/en/ https://gfw.report/publications/usenixsecurity23/en/
- jay-418 1y agoCensorship circumvention tools specialize in this, and are extensively used in China, Iran, and Russia. I work on Lantern, and we're not seeing any significant interruptions to connections in Indonesia at the moment. https://lantern.io/download https://lantern.io/download Hope it helps!
- moralestapia 1y agoCan you SSH outside the country? If so, then you have a VPN.
- mulchpower 1y agoURnetwork works where many don't http://ur.io http://ur.io . It used a grab bag of techniques, open source
- asqueella 1y agoThe site is awful, and I couldn't find the technical description easily. I assume it runs an exit node for other people's traffic?
- deleted 1y ago[deleted]
- mynameis777 1y agoHey there – greetings from one of the most heavily censored regions in the world. I once considered using an Indonesian VPS to bypass my country's censorship. However, the Indonesian VPS provider actually refused my direct connection request from my country. I was quite frustrated at the time, wondering why they refused me. But now I understand – it turns out these two countries are in cahoots. Emmm, if you want to break through the censorship, you can start here: https://github.com/free-nodes/v2rayfree https://github.com/free-nodes/v2rayfree It provides many free proxy nodes that are almost unusable in my country, but might work in Indonesia (although you may need a lot of patience to test which ones actually work). A good proxy software is Clash.Meta for Linux (you’ll need to install Linux on Windows using VMware, then set up Clash.Meta). You can start by installing the Windows version of the proxy client software (V2rayN) for a simple way to bypass censorship, but it's not a long-term solution. A special reminder: these free nodes are not secure (they could very well be "honeypot" lines, but if you're not from my country, the police should have no way of dealing with you). You need to quickly set up your own route by purchasing a U.S. VPS and setting up your own proxy nodes. Lastly, I recommend a good teacher: ChatGPT. It will solve all the problems you encounter on Linux. Also, use the Chrome browser with translation. Good luck!
- yegor 1y agoFull disclosure, I run a commercial VPN service (Windscribe). There are 2 paths you can take here: 1. Roll your own VPN server on a VPS at a less common cloud provider and use it. If you're tech savvy and know what you're doing, you can get this going in <1hr. Be mindful of the downsides of being the sole user of your custom VPN server you pay for: cloud providers log all TCP flows and traffic correlation is trivial. You do something "bad", your gov subpoenas the provider who hands over your personal info. If you used fake info, your TCP flows are still there, which means your ISP's IP is logged, and deanonymizing you after that is a piece of cake (no court order needed in many countries). 2. Get a paid commercial VPN service that values your privacy, has a diverse network of endpoints and protocols. Do not use any random free VPN apps from the Play/App stores, as they're either Chinese honeypots (https://www.bitdefender.com/en-us/blog/hotforsecurity/china-linked-vpns-still-offered-in-apple-and-google-stores-report-warns https://www.bitdefender.com/en-us/blog/hotforsecurity/china-...) or total scams (https://www.tomsguide.com/computing/vpns/this-shady-vpn-has-seemingly-been-caught-stealing-from-windscribe https://www.tomsguide.com/computing/vpns/this-shady-vpn-has-...). Do not go with a VPN service that is "mainstream" (advertised by a Youtuber) or one that has an affiliate program. Doing/having both of these things essentially requires a provider to resort so dishonest billing practices where your subscription renews at 2-5x of the original price. This is because VPNs that advertise or run affiliate programs don't make a profit on the initial purchase for that amazing deal thats 27 months with 4 months free or whatever the random numbers are, they pay all of this to an affiliate, sometimes more. Since commercial VPNs are not charities, they need ROI and that comes only when someone rebills. Since many people cancel their subscriptions immediately after purchase (to avoid the thing that follows) the rebill price is usually significantly more than the initial "amazing deal". This is why both Nord and Express have multiple class action lawsuits for dishonest billing practices - they have to do it, to get their bag (back). It's a race to the bottom of who can offer the most $ to affiliates, and shaft their customers as the inevitable result. Billing quirks aside, a VPN you choose should offer multiple VPN protocols, and obfuscation techniques. There is no 1 magic protocol that just works everywhere, as every country does censorship differently, using different tools. - Some do basic DNS filtering, in which case you don't need a VPN at all, just use an encrypted DNS protocol like DOH, from any provider (Cloudflare, Google, Control D[I also run this company], NextDNS, Adguard DNS) - Then there is SNI filtering, where changing your DNS provider won't have any effect and you will have to use a VPN or a secure proxy (HTTPS forward proxy, or something fancier like shadowsocks or v2ray). - Finally there is full protocol aware DPI that can be implemented with various degrees of aggressiveness that will perform all kinds of unholy traffic inspection on all TCP and UDP flows, for some or all IP subnets. For this last type, having a variety of protocols and endpoints you can connect to is what's gonna define your chance of success to bypass restrictions. Beyond variety of protocols, some VPN providers (like Windscribe, and Mullvad) will mess with packets in order to bypass DPI engines, which works with variable degree of success and is very region/ISP specific. You can learn about some of these concepts in this very handy project: https://github.com/ValdikSS/GoodbyeDPI https://github.com/ValdikSS/GoodbyeDPI (we borrow some concepts from here, and have a few of our own). Soooo... what are good VPNs that don't do shady stuff, keeps your privacy in mind, have a reasonably sized server footprint and have features that go beyond basic traffic proxying? There is IVPN, Mullvad, and maybe even Windscribe. All are audited, have open source clients and in case of Windscribe, also court proven to keep no logs (ask me about that 1 time I got criminally charged in Greece for actions of a Windscribe user). If you have any questions, I'd be happy to answer them.
- cabirum 1y agosshuttle. Tunnel your connections inside ssh.
- RajT88 1y agoSomewhat dated read here: https://www.reddit.com/r/Tailscale/comments/16zfag4/traveling_to_china/ https://www.reddit.com/r/Tailscale/comments/16zfag4/travelin... Some good ideas, though. There seems to be OSS alternatives for TailScale control servers which would make it harder to block - I'd go that route. The top recommendation boils down to, "Set up several different methods, and one will always work".
- Beijinger 1y agoUse Astrill - if you can afford. You could try AirVPN, much cheaper, but if Astrill does not work, probably no VPN will. https://expatcircle.com/cms/privacy/vpn-services/ https://expatcircle.com/cms/privacy/vpn-services/ Why is Indonesia in chaos?
- rufus_foreman 1y ago>> Why is Indonesia in chaos? I was wondering that too, looks like https://en.wikipedia.org/wiki/2025_Indonesian_protests https://en.wikipedia.org/wiki/2025_Indonesian_protests.
- lifeisstillgood 1y agoI’m not sure this is the right conversation right now, but is this thread heading towards “how do we make totalitarian governments become liberal democracies?” It’s a nice technical question on how to run a VPN but the ultimate goal is not the best technical solution but the ability to avoid detection by the state. And that’s not a technical problem but an opsec one If someone is participating in online discussions (discord and twitter) to spread local news - then it’s hard to know who is who, and who to trust - and that’s kind of the why Arab spring did not spring “hey wear a red carnation and meet me by the corner” can become a death sentence The answer to opsec is avoid all digital comms - but at this point you are seriously into “regieme change”, or just as Eastern Europe did, keep your heads down for forty years and hope those who leave you economically behind will half bankrupt them selves bringing you back. I think in the end, a thriving middle class with a sufficient amount of land reform, wealth taxes which can over a generation push for liberalisation sounds a good idea. Our job in the very lucky liberal West is to keep what our forefathers won, and then push it further to show why our values are worth the sacrifice in copying
- inkyoto 1y ago> Our job in the very lucky liberal West is to keep what our forefathers won, and then push it further to show why our values are worth the sacrifice in copying It was the liberal West who helped China build the Great Firewall – Cisco, Sun Microsystems, Nortel, Siemens and others. As long as a lucrative commercial opportunity was there, they seized upon it shoving the liberal values up the orifice where the sun does not shine.
- Ylpertnodi 1y ago> Our job in the very lucky liberal West is to keep what our forefathers won, and then push it further to show why our values are worth the sacrifice in copying Would it be possible for you to 'keep what our forefathers won', and then just stay at home?
- mlhpdx 1y agoA question related to the question, for which I apologize: It seems to me that using WireGuard (UDP) in conjunction with something like Raptor Forward Error Correction would be somewhat difficult to block. A client could send to and receive from a wide array of endpoints without ever establishing a session and communicate privately and reliably, is that correct?
- breve 1y agoYou should use people power to work to make Indonesia a more open, democratic society. Yes, it's hard work. Yes, it will take a long time. Yes, you personally may not get very far with your efforts. But if Indonesians don't take responsibility for and work to improve Indonesia then the rest of it doesn't matter.
- protocolture 1y agoPart of that is knowing whats happening inside the country, of which they were previously using tools like discord, which have now been blocked. So the first step to using people power to make Indonesia a more open, democratic society would be to find a way to tunnel out to get and share that information. To that end the OP has created this Ask HN thread.
- breve 1y agoNope. The outside doesn't matter. The problem is on the inside. External websites will never fix the internal problem. There are no technical solutions to what is fundamentally a problem of political culture.
- degamad 1y agoHow do you propose they coordinate the political activities when they can't use external communications sites/tools, and internal sites are actively monitored by an authoritarian government? Step 1 is establishing a secure means of communication.
- protocolture 1y ago>External websites will never fix the internal problem. Except the internal problem is censoring internal information sources. They can only trust external sites to remain neutral. Not to mention that, politically and historically speaking, there are so many examples of revolutionaries needing to go overseas to organize. The Bolshies literally got started in a London pub.
- 1y ago
- nneonneo 1y agoAn expensive but functional option is to enable roaming on a foreign eSIM. Getting an eSIM is relatively easy. Roaming mobile traffic is routed from the country in which the SIM is from, not the country that you're in, meaning that an eSIM from e.g. an American carrier will not be subject to the censorship in your country. I've used this on multiple trips to China over the past decade (including a trip last year). You can find carriers that will charge very low (or even no) roaming rates.
- gck1 1y agoData-only eSIMs (e.g. ones you get from Airalo and apps like that) are not going to cut it though. You need a "full" eSIM that gives you a real number and even then, it's not a guarantee that your traffic will be routed via the country eSIM is from. Tello does route (or rather, exit) via US for example, but it's 2¢/MB. Chinese forums / blogs have a lot of information about this stuff. I usually ask ChatGPT to translate "Research topic re: some form of circumvention and give me forum posts and blog posts about it" to Chinese, then paste that into DeepSeek with search enabled and just let Chrome translate the responses. Does a really good job. At least better than what I can manage with Baidu.
- andunie 1y agoI don't know if these work or not for the specific case mentioned here, but the cheapest eSIMs by a huge margin are from https://silent.link/ https://silent.link/ if anyone is interested. They definitely do work under normal internet circumstances.
- notpushkin 1y agoYou can go way cheaper than that – https://esimdb.com/ https://esimdb.com/ has a good comparison of options. I’m usually paying sub-$1/GB in Southeast Asia currently.
- andunie 1y agoWow, that is crazy. These prices are hard to believe.
- oleksandr_l5 1y agoSSTP or other HTTPS like VPN
- oleksandr_l5 1y ago[dead]
- andrewinardeer 1y agoWeird. I'm in Indonesia and can access VPNs, X and Discord.
- ies7 1y agoI just wake up in Jakarta and there is nothing wrong with X or Discord
- deleted 1y ago[deleted]
- dboreham 1y agoThe closest I've come to this is on an airplane where almost everything was blocked. SSTP to a server I spun up worked well.
- lidder86 1y agosurfshark works also Im on MTM no issues! Same with Biznet
- rd07 1y agoI live in Indonesia, and I don't find any recent news that mention X (formerly Twittwr) and or Discord being blocked by the government. The only relevant news from a quick Google search I can find is about the government threatened to block X due to pornography content in 2024. You can even check for yourself if a domain is blocked by visiting https://trustpositif.komdigi.go.id/ https://trustpositif.komdigi.go.id/. Also for your unability to access the VPN, as far as my experience goes, in the past some providers do block access to VPN. But, I am not experiencing that for at least the last 5 years. So, maybe you can try changing your internet provider and see if you can connect to VPN?
- andunie 1y agoHow can it be that one person living in Indonesia says everything is blocked and the country is in chaos and another, very calmly, is completely unaware and can't even find any news about it? This is so odd. What is the truth?
- atsuzaki 1y agoThe context that was likely left out due to HN rules is, there are mass protests turned violent in the face of police brutality in several cities. The Indonesian government has a history of blocking/throttling internet access in immediate areas of the unrest to limit coverage.
- JCharante 1y agoAh the India strat
- konimex 1y agoIndonesia is a big country with over ten thousand islands and uneven coverage. What is blocked on one ISP might not be enforced on another (e.g. the state-owned ISP might block or use DNS poisoning on several "non-compliant" DNS providers but my current ISP doesn't). Also, in addition to what the sibling commenter (and another commenter regarding Cloudflare outage) said there might be a general overload on the mobile network near the affected areas since there are lots of users and limited bandwidth.
- throwawayffffas 1y agoMaybe TOR? https://www.torproject.org/ https://www.torproject.org/
- neurostimulant 1y agoProbably just an unfortunate timing. Cloudflare is going down in this region [1] at the same time with the protests and unrest caused by the news of a motorcycle taxi driver who got run over by a swat car during a protest [2]. Such coincidence might seems like the government trying to do some damage control by restricting internet access, but I hope that's not what happen here. At the moment, cloudflare status for Jakarta is still "rerouted". [1] https://www.cloudflarestatus.com/incidents/1chpg2514kq8 https://www.cloudflarestatus.com/incidents/1chpg2514kq8 [2] https://www.youtube.com/watch?v=-jONV0mb9nw https://www.youtube.com/watch?v=-jONV0mb9nw
- throwawayffffas 1y agoYou can also setup your own, get a VM in the free world and setup an open VPN server. https://www.digitalocean.com/community/tutorials/how-to-set-up-and-configure-an-openvpn-server-on-ubuntu-20-04 https://www.digitalocean.com/community/tutorials/how-to-set-...
- jasonlingx 1y agoAn alternative is using an eSIM with an “internet breakout” via another country. Esimdb is a good place to start.
- village_kothi 1y agoCan you try both WireGuard and MASQUE? you can do that by using `warp-cli tunnel protocol set MASQUE'. if you want to try WireGuard, `warp-cli tunnel protocol set WireGuard'
- egberts1 1y agoBuy a VSP elsewhere and run Wireguard over IPSec
- seany 1y agoShadowsocks used to be the thing that _really_ worked in CN. Not sure what's current there. AWS ap-southeast-3 should still be up, and isn't in a different partition like CN, govcloud, iso etc. So a VM there and a vpc peer in the US should get you around a lot of stuff.
- wiredpancake 1y agoShadowsocks isn't a viable method in 2025 it seems. Not by itself apparently. Shadowsocks generates high-entropy noise via packet analysis, which typically is easy to spot out as it looks irregular.
- thenthenthen 1y agoUse shadowsocks for the past 2 years in CN works fine. Also Trojan. Not sure what the servers actually run.
- anikom15 1y ago[flagged]
- txrx0000 1y agoUse the open-source SoftEther VPN. It sends your traffic over software-defined Ethernet wrapped in HTTPS. https://en.m.wikipedia.org/wiki/SoftEther_VPN https://en.m.wikipedia.org/wiki/SoftEther_VPN Here's a list of public instances hosted by volunteers: https://www.vpngate.net/en/ https://www.vpngate.net/en/ For anyone reading this who still lives in a somewhat free country and has resources to spare, please consider hosting a public instance or mirroring the VPN Gate site.
- deleted 1y ago[deleted]
- NamTaf 1y agoI work often in China. I somehow haven’t had my WireGuard VPN back to my own home server blocked, yet. It’s pointed to a domain that also hosts some HTTPS web services so that might help. Prior to this, pre-Covid I used to use shadowsocks hosted on a DO droplet. Shadowsocks with obfs, or a newer equivalent (v2ray w/ vmess or vless protocol) and obfs (reality seems to be the current hotness) will probably work within Indonesia given their blocking will be way less sophisticated than China. The difference here is that it’s a proxy, not a VPN, but it makes it a lot easier to obfuscate its true nature than a VPN which stands out because obfuscation isn’t in its design. Hosting on big public VPSs can be double edged. On one hand, blocking DO or AWS is huge collateral. On the other, it’s an obvious VPN endpoint and can help identify the type of traffic as something to block. If you have access to reddit, r/dumbclub (believe it or not) has some relatively current info but it’s pretty poor signal to noise. Scratch around there for some leads though. Note that this stuff is all brittle as hell to set up and I usually have a nightmarish time duct-taping it all together. That’s why I’m overjoyed my WireGuard tunnel has worked whenever I’ve visited for a year now. One other left-field option, depending on your cost appetite, is a roaming SIM. Roaming by design tunnels all data back to your own ISP before routing out so even in China roaming SIMs aren’t blocked. It’s a very handy backup if you need a clear link to ssh into a box to set up the above, for example.
- ryan-ca 1y agoI recommend using tor over snowflake relays to connect. It is meant to be censorship proof.
- jongjong 1y agoEasy, you can just create any generic Linux Amazon EC2 instance (or just about any cloud provider of your choice; in fact, the smaller the provider, the better) and use it as a SOCKS5 proxy via SSH tunnel with -D flag... Then set one of your browsers (e.g. Firefox) to connect via that proxy. Indistinguishable from any other server on the internet.
- Lu2025 1y agoStarlink?
- aaron695 1y ago[dead]
- mensetmanusman 1y agoWestern governments should have entire budgets focused on software to circumvent great firewalls.
- coretx 1y agoGet a VPS, arrange your own IPV6. Setup a tunnel and block all non encrypted traffic.
- andunie 1y agoAbout VPNs I don't know but you could all start using Nostr instead of Twitter and Discord. Also Telegram using MTProto proxies (that you have to host, do not use those free ones out there), if those don't qualify as VPNs.
- ali-aljufairi 1y agoTailscale
- BobbyTables2 1y agoI block Twitter at home… it’s not a huge loss
- reisse 1y agoI also want to add here because a lot of people either mention Tor as a succesful solution, or mention why Tor is not a solution but state completely wrong reasons. And I have a good soapbox to stand once in a while. Number one reason why Tor is dead is Cloudflare. Let me digress here. In my opinion, Cloudflare does a lot more censoring than all state actors combined, because they singlehandedly decide if the IP you use is "trustworthy" or "not", and if they decided it is not, you're cut off from like half of the Internet, and the only thing you can do is to look for another one. I'd really like if their engineers understood what Orwellian mammoth have they created and resign, but for now they're only bragging without the realization. Or at least if any sane antitrust or comms agency shred their business in pieces. And Cloudflare by default makes browsing with Tor unusable. Either you're stuck with endless captchas, or you're banned outright. Number two reason why Tor is dead is all other antifraud protections combined. Try paying with Stripe through Tor. There is quite a big chance you'll get an "unknown error" of sorts on Stripe side. Try to watch Netflix in Tor - exit nodes are banned. Everyone kept shouting "Tor bad, Tor for criminals", and it became a self-fulfilling prophecy. It's really hard to do just browse web normally in Tor, because all "normal" sites consider it bad. The "wrong" sites, however, who expect Tor visitors...
- brightball 1y agoI understand where you are coming from but there’s a flip side to this. Cloudflare obfuscating such a huge segment of origin servers gives a privacy advantage to anyone using a private DNS, since most of the IPs you can be seen connecting to are just…Cloudflare.
- stoicfungi 1y agoTry this, https://github.com/database64128/swgp-go https://github.com/database64128/swgp-go, setup is a bit complicated but it works extremely well.
- notepad0x90 1y agoI've heard of shadowsocks being advertised for such use cases. https://shadowsocks.org/ https://shadowsocks.org/
- keepamovin 1y agoDo you still have access to GitHub? If so you can run BrowserBox in a GitHub action runner exposed via IP or ngrok tunnel. That will give you a browser in a free region. Easy set up via workflow. You’ll need a ngrok API key and a BrowserBox key. Hit us up: sales@dosaygo.com for a short term key at a discount if it works for you. We will offer keys for free to any journalists in censored regions.
- chidg 1y agoHi, not well educated on the details of VPNs and network security so this may be a basic question, but - VPNs are used regularly by corporates to enable secure intranet access to people offsite, etc - surely completely blocking VPNs or detecting and punishing VPN users is severely detrimental to business and not something countries would want to do carte blanche? How does this work?
- Crestwave 1y agoIt's possible that they're only blocking the VPNs hosted outside of the country (and thus bypassing censorship). Of course, that would still impact international remote workers, but it's probably niche enough for the government to offload it as their problem.
- AugSun 1y agohttps://amnezia.org/ https://amnezia.org/
- ParonoidAndroid 1y ago[dead]
- weirdrandomuser 1y ago[dead]
- comonoid 1y agoAn airport.
- jiggawatts 1y agoAs an aside about professional and engineering ethics: If you’ve ever worked in the DPI space and actively participated in the development or installation of state surveillance and censorship products… Shame. Shame. Shame.
- tuananh 1y agoyou can use anything that has a VM. let's say Github codespaces. Launch a new codespace, setup vpn or just squid. Use it. It will not stop working unless your gov. decides to block said service (GitHub) too.
- arihant 1y agoGet a Digitalocean droplet, and host your own Outline instance. Their manager app makes this a 1-click process.
- pabs3 1y agoTry the Tor Browser, and use bridged mode to to make it look like you aren't using Tor. https://www.torproject.org/ https://www.torproject.org/
- 0xbadcafebee 1y agoWireguard or OpenVPN might work, if someone has a server set up, set up your client to connect. If those don't work you can try something like wssocks (https://github.com/genshen/wssocks https://github.com/genshen/wssocks) or wstunnel (https://github.com/erebe/wstunnel https://github.com/erebe/wstunnel). It tunnels connections through WebSockets, so you can make the connection look like a regular HTTPS connection. Another option would just be a regular-old HTTPS proxy (Nginx, Apache2, etc). Set up an HTTPS proxy somewhere on the internet, connect through it, but configure it to return a regular web page if someone tries to make a non-proxy connection through it. Another tool that may help setting up is chisel (https://github.com/jpillora/chisel https://github.com/jpillora/chisel). Those HTTPS ones may work if, when authorities connect to the host, it returns pages that look like some kind of private video server. (Maybe run an actual video server, in addition to the proxy...) Also, try to enforce TLS 1.3 for the HTTPS server. And another option, if all else fails, is to run a straight-up SOCKS proxy over the internet, on a weird port. It might be so obvious they aren't looking for it. To mask your DNS requests with the SOCKS proxy, use something like Tor-DNS (https://github.com/bfix/Tor-DNS https://github.com/bfix/Tor-DNS), or set up a VPN through the SOCKS proxy and use DNS through that route. Another option is DNS-over-HTTPS.
- cheesepaint 1y agoI'm in Indonesia right now as well and my Proton VPN still works. But I would see it as a short-term solution.
- heinternets 1y agoMay I suggest getting a cheap VPS in another country and using SSH to tunnel traffic, or even setup a window manager on the VPS.
- Maro 1y agoGet a cheap VPS for less than $10/mo or a dedicated server for like $25/mo and ssh tunnel into it. You can also use it to be your devserver, run your blog, etc. I've been using french located OVH servers in France for many years, it just works.
- sudahtigabulan 1y agoUse a less-known DoH or DoT provider. They just "blocked" Reddit today, I selected another DoH provider from the menu in my browser settings, and continued.
- chmod775 1y agoMullvad has some anti-censorship features (shadowsocks) that it will automatically use if regular connections fail and works reliably in China as well (and has for the last 2+ years). You could give it a shot.
- OhNoNotAgain_99 1y ago[dead]
- globular-toast 1y agoThe best time to develop meshnets was 15 years ago. The second best time is now. What is actually holding us back here? Almost everyone has powerful radio equipment these days.
- worthless-trash 1y agoIsn't there an SSH proxy command as long as you have shell access ?
- Imustaskforhelp 1y agonextdns recently created geo spoofing methods, I may be wrong, I usually am but I am curious as to if these censorship can be fixed by nextdns. I don't know if indonesia is becoming exactly like china/ so a complete crackdown as people are discussing things as if its for china, but I feel like that there are definitely some easier things than hosting your own server or using shadowsocks. Check if proton vpn/mullvad vpn are working once please, they are definitely plug n play and proton even offers a free tier.
- 0xml 1y agoIf VPNs don't work for you, I recommend using an anti-censorship tool with an obfuscation protocol like v2ray which is commonly used in China. https://github.com/v2fly/v2ray-core https://github.com/v2fly/v2ray-core https://github.com/XTLS/Xray-core https://github.com/XTLS/Xray-core https://github.com/net4people/bbs https://github.com/net4people/bbs https://en.wikipedia.org/wiki/Great_Firewall https://en.wikipedia.org/wiki/Great_Firewall
- figassis 1y agoThe thing about fighting against vpn blocks is that if you win, the govt can just turn off the internet. Something like starlink would be ideal in these circumstances, but you'd have to have the receivers in the country before lockdown.
- rkomorn 1y agoAssuming something like Starlink doesn't cooperate with shutting down in the country just like the land-based ISPs would.
- GJim 1y agoThereby entrusting your internet connectivity to the whims of an unhinged lunatic.
- tmarsden 1y agoWell that "unhinged lunatic" has also publicly characterized himself as a "free speech absolutist" so until someone or something better comes along you take what you can get.
- jorisnoo 1y agoWorking from China, i've rented VPS outside of the country and set up tailscale exit nodes - as my private VPN. Speed is not always optimal but it mostly works.
- ghsar 1y agoHello! I use Octohide VPN - it has VLESS protocol that can bypass geo-blocks (in countries like Russia, China). Its fast, the connection to a server takes merely a second and I do not even have an account as there is no registration required. Try it and see whether it helps you.
- ggfugg123 1y ago[dead]
- lubosm 1y agoVPN services are just someone else's computers. Any cloud provider with a low performance virtual machine can become a VPN gateway using Linux distribution of your choice for around $4. OpenVPN or WireGuard are my tools of choice. Professionally, I also use OpenVPN's EasyRSA PKI framework for certificates, but you can just generate your keys using any tutorial out there. "OpenVPN Cookbook" ebook from Packt is my go to source. For performance reasons, WireGuard is better.
- jodosha 1y agoI’m in Indonesia at the moment for vacation. Just checked with NordVPN connected to their server Indonesia #54 (Borneo) and I was able to access twitter.com (via Chrome) and Discord (via app). I’m on iPhone.
- raxxorraxor 1y agoI would rent a server in an outside jurisdiction and use it as proxy. It isn't too hard to setup and you can share it with others too. I believe it would be completely legal as well. As least it should be. That said, you are much less anonymous with that. But you could opt for your server using an additional VPN service to mitigate that.
- rdl 1y agoA one way plane ticket, a rifle, or a drone swarm. (What I’d use if my country blocked VPNs)
- pilingual 1y agoTo where would you fly?
- wildylion 1y agoAs a long-standing supporter of Internet freedoms in Russia, I could advise you to use multiple tools at the same time, to avoid them being blocked. What would probably work UNLESS they roll out pretty sophisticated DPI that could block by signatures and do active probing: 1. AmneziaVPN (https://amneziavpn.org https://amneziavpn.org) - they have the hosted option, or you could run your own on a cheap VPS (preferable). They use Xray/REALITY or a variant of Wireguard with extra padding that confuses DPIs. Should be good enough. 2. Psiphon 3. Lantern 4. Sometimes Tailscale works surprisingly well (even in Russia where they have advanced DPI systems!) Here's a link to several Tor browser mirrors for you so you could download the VPN software itself: https://mirror.freedif.org/TorProject/ https://mirror.freedif.org/TorProject/ https://mirrors.mit.edu/torproject/download/ https://mirrors.mit.edu/torproject/download/ A couple of Tor bridges in case Tor is blocked: webtunnel [2001:db8:9947:43ae:8228:97b7:7bd:2c2e]:443 6E6A3FCB09506A05CC8E0D05C7FEA1F5DA803412 url=https://nx2.nexusocean.link ver=0.0.1 webtunnel [2001:db8:a436:6460:fa7b:318:4e8e:9de3]:443 F76C85011FD8C113AA00960BD9FC7F5B66F726A2 url=https://disobey.net/vM8i19mU4gvHOzRm33DaBNuM ver=0.0.2
- devops000 1y agoIn China uses Rocket Shadow. Alternatively, you could purchase an eSIM, such as Holafy.
- 01jonny01 1y agoHey I run Skipvids.com we receive alot of Indonesia traffic. I think we are still accessible there.
- bdd8f1df777b 1y agoIf you need to bypass censorship, you'll need a tool specifically designed for anti-censorship, rather than any one repurposed for that. Since China has the most advanced network censorship, the Chinese have also invented the most advanced anti-censorship tools. The first generation is shadowsocks. It basically encrypts the traffic from the beginning without any handshakes, so DPI cannot find out its nature. This is very simple and fast and should suffice in most places. The second generation is the Trojan protocol. The lack of a handshake in shadowsocks is also a distinguishing feature that may alert the censor and the censor can decide to block shadowsocks traffic based on suspicions alone. Trojan instead tries to blend in the vast amount of HTTPS traffic over the Internet by pretending to be a normal Web server protected by HTTPS. After Trojan, a plethora of protocol based on TLS camouflaging have been invented. 1. Add padding to avoid the TLS-in-TLS traffic characteristics in the original Trojan protocol. Protocols: XTLS-VLESS-VISION. 2. Use QUIC instead of TCP+TLS for better performance (very visible if your latency to your tunnel server is high). Protocols: Hysteria2 and TUIC. 3. Multiplex multiple proxy sessions in one TCP connection. Protocols: h2mux, smux, yamux. 4. Steal other websites' certificates. Protocols: ShadowTLS, ShadowQUIC, XTLS-REALITY. Oh, and there is masking UDP traffic as ICMP traffic or TCP traffic to bypass ISP's QoS if you are proxying traffic through QUIC. Example: phantun.
- cm2187 1y agoDoes starlink work in China?
- bdd8f1df777b 1y agoNo, it’s illegal to bring starlink devices here, and I heard that Elon Musk chooses to block China from accessing starlink too, to appease the Chinese authorities.
- boxed 1y ago"Appease" is such a loaded word. He's literally not allowed by law to do it. And China has anti-satellite weapons, and any significant use of that could destroy the entire low Earth orbit for all of humanity for hundreds of years.
- paddlesteamer 1y agoYears ago, I created a very basic HTTP proxy using Google Cloud. The idea relies on Google Cloud wouldn't be blocked because the industry in that country probably also needs Google Cloud to function, so the government couldn't touch it. You can see it here: https://github.com/paddlesteamer/gcrproxy https://github.com/paddlesteamer/gcrproxy. I don't know whether it works or not (maybe something has changed; it is very old code), but the idea beneath it remains. And I think it is also applicable to other cloud services, too. Cheaper (even free to some point) than having your own VPS.
- mediumsmart 1y agoThe real problem of course is that no government is going to block twitterredditmetadiscordandwhathaveyou long enough to risk people becoming informed citizens.
- dragonz00011011 1y ago2323
- dragonz00011011 1y ago2121
- dragonz00011011 1y agosadsa das asd asd sa
- dragonz00011011 1y agoaaaaaaaaaaaaaaaaaaaaaaaaaa
- berlinismycity 1y agoLove Indonesia. Spend the last six months on Bali. This VPN thing is a shame!
- fguerraz 1y agoTake the power back?
- antonios 1y agoAs a quick solution before implementing the more sophisticated suggestions in this thread, you can try getting a small cheap VPS from somewhere outside and trafficking all your traffic through it via sshuttle[1]. For example, Vultr (not an endorsement) has some with ~$3/month that should be sufficient for your case. [1] https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle
- grishka 1y agoIt very much depends on how the block is implemented technically. I can only talk about Russia where I'm from — we have quite a lot of success with DPI bypass tools like GoodbyeDPI. If that fails, use VPN protocols specifically designed for censorship circumvention, like VLESS. Better yet, get yourself a VDS in another country and self-host your VPN there.
- yuyu74189w 1y ago[dead]
- notorandit 1y agoI would use SSH dynamic TCP forwarding (-D). Then use "SOCKSv5" proxy configuration in your browsers and in your apps (if that's supported). You can hve remote SSH server listen on different ports and IPv6. Maybe speed and latency will not be the best, but it'd be OK. Simple and easy.
- raugustinus 1y agoThere's https://refraction.network/ https://refraction.network/ but I am not sure how feasible that is at the moment (or at all). I came across it when researching some TLS stuff in golang (programming language).
- arman_nocapro 1y agoSama-sama bro, confirming this from Jakarta. It's a mess. My group chats were blowing up yesterday when WARP and Twitter suddenly went down. Felt like they pulled the plug right when everyone needed info on the protests. Be very careful with random free VPNs being shared around on WhatsApp right now, many could be honeypots. Like others have said, the most reliable long-term fix is rolling your own. I've had a cheap VPS in Singapore for years for moments just like this. The latency is low and it's been rock solid. I'm using v2ray with a simple setup, and it's been working fine because it just looks like normal web traffic to my ISP (Indihome). The guides posted in the top comment are excellent starting points. For my less technical friends, I've been helping them set up ProtonVPN. Their 'Stealth' protocol seems to be holding up for now, but who knows for how long. The hardest part is getting this info to people who aren't tech-savvy. Stay safe out there, everyone. Jaga diri.
- game_the0ry 1y agohttps://www.privacytools.io/privacy-vpn https://www.privacytools.io/privacy-vpn
- huksley 1y agoShadowsocks over websockets is the way to have traffic indistinguishable from browser traffic. A bit difficult to configure manually: https://developers.google.com/outline/docs/guides/service-providers/websockets https://developers.google.com/outline/docs/guides/service-pr...
- outrage 1y agoYou can try using forks of existing protocols. Those are usually harder to detect. My country also blocks OpenVPN and Wireguard, but AmneziaWG works great for me.
- robobro 1y agoI'm in also indonesia and nordvpn is still working fine for me, but you may want to consider trying socks5 via ssh as others are suggesting
- montekristooGDB 1y ago[dead]
- deleted 1y ago[deleted]
- robobro 1y agoI'm in also indonesia and nordvpn is still working fine for me, but you may want to consider trying socks5 via ssh as others are suggesting.
- Aloha 1y agoI would just configure a VPS outside the country and tunnel thru that
- draneone 1y agouse vless/xray, barely blockable by anything
- barnacl437 1y agowoah, another country blocking discord again? (well, mine don't, just surprised) quick resort: you can use quad9 or nextdns if they are just using the classic dpi blocking thing. if these just doesnt work, then there is psiphon. its an anti surveillance kit iirc. other comments might include more options. i just want to list the ones that i've tried and used.
- JOHN-DAN 1y agoI'm also curious about your thoughts on the GFW. To be frank, I don't think it's as effective as you might expect.
- kingsteeit 1y ago[dead]
- lrvick 1y agossh socks proxy over port 443 should work in most situations
- suryavamsi 1y ago[dead]
- ssh-wrapper 1y agoBased on your question, i worked on a wrapper of wstunnel, wrapping ssh into wesockets. You could maybe use it to setup a socks proxy, provided that someone helps you setup the 'unwrapping' endpoint. https://github.com/cecemel/ssh-over-http-wrapping-service https://github.com/cecemel/ssh-over-http-wrapping-service
- dabockster 1y agoSee if your community can establish some kind of mesh network connection to someone outside of the country. You'd have to trust everyone on it with your life (quite literally in this case), but it would work.
- rostislaved 1y agoI would say there are two options: 1. (Easy, fast but someday it will be blocked, because it is relatively easy to block) Just buy vpn. Mullvad and "Private Internet Access" are ones of the best. 2. (Requires experience, not fast, but the most reliable and flexible). Get a VPS (server) somewhere and install your own VPN. VLESS is the best at this moment