5 ms·
I lived in China for a while and there were several waves of VPN blocks. Also very few VPN services even try to actively support VPN-blocking nations anymore. A
by joshryandavis 1y ago
I lived in China for a while and there were several waves of VPN blocks. Also very few VPN services even try to actively support VPN-blocking nations anymore. Any commercial offering will be blocked eventually.
What I settled on for decent reliability and speeds was a free-tier EC2 hosted in an international region. I then setup a SOCKS5 server and connected my devices to it. You mentioned Cloudflare so whatever their VM service is might also work.
It's very low profile as it's just your traffic and the state can't easily differentiate your host from the millions of others in that cloud region.
LPT for surviving the unfree internet: GitHub won't be blocked and you'll find all the resources and downloads you need for this method and others posted by Chinese engineers.
Edit: If you're worried about being too identifiable because of your static IP, well it's just a computer, you can use a VPN on there too if you want to!
- la_mezcla 1y agoOut of all VPS providers out there, why did you chose one of the most, if not the most, expensive ones - AWS, EC2?
- wulfstan 1y agoWhen I worked in China (not for long periods but frequently enough that the Great Firewall became an irritant) I hosted an OpenVPN server on port 443 and/or port 22 of a server I owned. That worked sufficiently well most of the time.
- ykl 1y agoThis doesn't work anymore; the GFW no longer detects VPN connections by port but instead by performing deep packet inspection to characterize the type of traffic going over every connection. Using this technique in combination with some advanced ML systems, they're able to detect any encrypted VPN connection and cut it off; it's basically not possible to run any kind of outbound VPN connection (even to private servers) from inside of China anymore, and it's usually not even possible to _tunnel_ a VPN connection through some other protocol because the GFW now detects that too. Stepping back and looking at it from a purely technical perspective, it's actually insanely impressive. Here's a USENIX paper from a few years ago on how it is done: https://gfw.report/publications/usenixsecurity23/en/ https://gfw.report/publications/usenixsecurity23/en/
- IshKebab 1y ago> it's basically not possible to run any kind of outbound VPN connection (even to private servers) from inside of China anymore. Really? Because the paper you linked says they don't block any TLS connections so you can just run a VPN over TLS: > TLS connections start with a TLS Client Hello message, and the first three bytes of this message cause the GFW to exempt the connection from blocking.
- ykl 1y agoGive it a try if you want; it doesn't work. For TLS traffic they track what the connection looks like over time; a TLS connection for normal web traffic versus a VPN connection tunneling through TLS apparently look different enough that they can detect and cut it off.
- moduspol 1y agoWorth noting is that OpenVPN’s TCP TLS mode does not work that way. It’s essentially the UDP protocol messages except wrapped into TCP. The initial handshake is not a normal TLS client hello. Not sure about other SSL VPNs.
- 77pt77 1y ago> it's basically not possible to run any kind of output VPN connection (even to private servers) from inside of China anymore. What if you run your own HTTPS server that look semi-legitimate and just encapsulate it in that traffic? Can they still detect it? What about a VPS in HK? Is this even doable?
- tossit444 1y agov2ray and similar servers do exactly that, and I would assume they're still working as they're actively developed.
- tracker1 1y agoAssuming they don't MITM SSH, you should still be able to use something like wireguard over an SSH tunnel. At least I would think.. it's all SSH traffic as far as any DPI listener is concerned, you'd of course need to ensure the connection signature through another vector though.
- 77pt77 1y agoWhich is ridiculous because OpenVPN is trivial to identify, even when over TCP since it's different from "regular" HTTPS/SSL traffic. Why they chose this I have no idea. You can even port share. 443 -> Web server for HTTPS traffic 443 -> OpenVPN for OpenVPN traffic Still trivial to identify and not uncommon for even public WiFi to do so. Since I changed to tailscale+headscale with my own derp server all these issues have disappeared (for now).
- moduspol 1y agoIt’s basically the same as the UDP mode, except wrapped into TCP. Presumably because that’s simpler than redesigning it from the ground up for TCP. So the handshake and such will not look like a normal TLS handshake.
- ranger_danger 1y agoSoftEther works over "regular" TLS at least, you can even reverse-proxy it.
- redleader55 1y agoThe VM instance is good for setting up a VPN tunnel, but it's not good in terms of bandwidth if it's hosted in. Because of DPI capacity, China has a very limited amount of "real internet" bandwidth. A more capable setup is to have one VM on each side of the firewall on an hosting service with peering between inside and outside - Aliyun (Alibaba Cloud) is an example. The "inside" VM could be just "socat UDP4-RECVFROM:<port>,fork UDP4-SENDTO:<remote>:<port>" or something done using netfilter. Like others commented in this thread, having an obfuscator is a good idea to ensure the traffic is not dropped by DPI. When the inevitable ban comes and your VPN stops working, rotate the IP of the external VPN and update the firewall/socat config to reflect it. Usually, the internal VM's IP doesn't need to be updated.
- 77pt77 1y agoHow easy is it to get a VPS in China. Could HK work?
- redleader55 1y agoHK "outside" the firewall, for now. It's where you would place the outside VM.
- 77pt77 1y agoBut does access to HK go throught the firewall?
- redleader55 1y agoThe access from mainland to HK goes through the firewall, the access from HK to the normal internet is unrestricted as far as I know. The communication between the two VMs still needs to be obfuscated and encrypted. The only reason for the VM inside the Chinese Internet is higher bandwidth.
- bekicot 1y agoGitHub was briefly blocked a couple of years ago in Indonesia. SSH was also blocked briefly by one of the largest mobile providers.
- ivanjermakov 1y agoIsn't VPS's public IP blocks are well known and very easy to block? I read that this is not a viable solution in case of China's firewall.
- QuadmasterXLII 1y agoDenying the entire country the ability to ssh into ec2 instances would be pretty economically damaging, even for china
- joshryandavis 1y agoExactly, yeah. Small VPS providers are possible to get blocked but blocking AWS regions would be devastating. So it is the perfect place to put something like this.
- ivanjermakov 1y agoBlocking - yes, heavily rate limiting - already happening.
- thenthenthen 1y agoGithub is blocked 90% of the time here in China. It is weird.
- joshryandavis 1y agoOh really? That's surprising.
- Havoc 1y ago>the state can't easily differentiate I'd be very surprised if the GFW DPI can't pick up SOCKS5 protocol. More likely version is the handful of people with both ability and means to do this are simply not worth going after