14 ms·
Staying ahead of censors in 2025
- mmsc 9mo agoDoes anybody know what the situation is like in China these days? What's the most commonly used tool for proxying now? Does basically all network leaving China still get ratelimited at a few megabytes per second?
- vgk_sys 9mo agoEasy the bypass; v2ray vless vmess trojan. No as long as you pay CN2 GIA rate. Not ratelimited just oversubscribed and bad peering. Purchase the hundred dollar per mbps CN2 GIA dedicated bandwidth its no problem.
- bubbi 9mo ago[dead]
- pigggg 9mo agoFolks using nyanpass setup for first hop into a near China hosting provider, then it's usually two additional hops within Asia and then the internet. There's a whole industry / ecosystem of folks who sell this - and set rate limit controls based upon how much you pay etc.
- wartywhoa23 9mo ago> What's the most commonly used tool for proxying now? https://github.com/XTLS/Xray-core https://github.com/XTLS/Xray-core
- mlrtime 9mo agoNothing to add other than I have no idea what the list of tech in the replies are here, and I consider myself somewhat up to date on most tech... strange world.
- vgk_sys 9mo agowhen wireguard work at line rate speed why bother with so much custom obfuscation it half the speed ?
- vbezhenar 9mo agoI visited China last year. I had a lot of issues accessing some known VPN services. My main tool to avoid censorship was using my foreign roaming and then I used VLESS on my VPS. Both approaches worked for me. I'm not sure about rate limited by few megabytes per second, as I had rate limits like few bytes per second, when I tried to use ssh as a proxy. Few megabytes per seconds sounds like a perfect connectivity to me.
- _k2vp 9mo agoCurrently in China (as a visitor). Wireguard literally just works (to a VPS). Mullvad works as a commercial provider, just slower. Xray-core (vless, Trojan) if you're paranoid. I have my own proxy over syncthing relays https://github.com/acheong08/syndicate https://github.com/acheong08/syndicate which I use to proxy to my home in the UK (residential IP) without exposing any ports. I get rate limited to around 10mbps in Chongqing. Was slightly higher in Beijing.
- bwv848 9mo ago> Wireguard literally just works https://github.com/net4people/bbs/issues/558 https://github.com/net4people/bbs/issues/558
- theasisa 9mo agoDoes this offer any benefits over Tailscale and having an exit node at home?
- _lvbh 9mo agoI do have that as well. I've noticed that sometimes all network connections out of the country gets blocked. With syncthing, there are relays within China that can be used which may be in less restrictive provinces. Kind of a best case, worst case scenario thing such that I can switch between as necessary. WireGuard best case, Xray-core fallback, syncthing worst case
- iwontberude 9mo ago[flagged]
- keepamovin 9mo agoLegal question for the Tor team (disclaimer, I love Tor and use it in BrowserBox): - Does Tor need an OFAC license to supply to Russian and Iranian (and other sanctioned entities)? What's your approach to stay compliant and globally helpful? I know 50% of your funding comes from US government (or did a few years back, still?), does this give you extra pathways to engage those regions? I'm wondering because the system would seem to fall under ITAR due to its encryption, and even if non-ITAR is still a cyber product and these countries are heavily OFAC listed rn. This is relevant for me right now as I was recetnyl contact by a significant entity in a sanctioned region with a massive deal for BrowserBox. Applying for an OFAC license to see if it's possible to serve them (but we have to make final determination on ethics/legal even if license is approved, I guess). My feeling is that broad sanctions don't hurt the things they are meant to but punish people in all countries from forming transnational links that might actually help to prevent conflicts and build relations however small. Idk, just my reflections after encountring this situation.
- greyface- 9mo ago> supply > product OFAC regulates international trade. Isn't Tor's publication an act of pure speech, rather than commerce? They're not charging for it, and they aren't physically moving any goods across borders. How could Tor be subject to any restrictions here? (not a lawyer, just someone who naively thought the Crypto Wars ended in the 90s)
- vscode-rest 9mo agoEncryption isn’t ITAR.
- deleted 9mo ago[deleted]
- keepamovin 9mo agoI'm not sure that's why I'm asking.
- octoberfranklin 9mo ago> massive deal OFAC applies to trade, like your "massive deal". OFAC's original authority comes from a law titled, literally "The Trading With the Enemy Act". Tor publishes free software, asking nothing in return. That isn't trade. Neither are those evangelists who broadcast sermons on shortwave radio -- they certainly "serve" Iran in the sense that people in that country can hear their broadcasts. "Cyber product" lolwut? I think you have been breathing too many beltway fumes.
- Fiveplus 9mo agoThe section on conjure is fascinating. For those who haven't followed the refraction networking space, the idea of leveraging unused address space at the ISP level is something academic papers have proposed for years [1]. Seeing it deployed in the wild is huge. The hardest part of this has always been non-technical by the way. Convincing ISPs to cooperate. If the Tor project has managed to get ISPs to route traffic destined for unallocated IPs to a station that handles the handshake, it completely breaks the censor's standard playbook of IP enumeration. You can't just block a specific subnet without risking blocking future legitimate allocations. I'd be curious to know if these are smaller, sympathetic ISPs or if they managed to partner with larger backbone providers. I'm interested to hear more about this. [1] look up tapdance
- piekvorst 9mo agoI doubt that Russian ISP would cooperate.
- deleted 9mo ago[deleted]
- kgeist 9mo ago>It completely breaks the censor's standard playbook of IP enumeration. You can't just block a specific subnet without risking blocking future legitimate allocations At least in Russia, they don't really care about collateral damage. Currently, without a VPN, I can't open like 30-50% links on Hacker News (mostly collateral damage after they banned large portions of IPs)
- mos87 9mo agoIt's just half the Internet now after the late October blockage
- photios 9mo ago> No mention of EU chat control > No mention of "age verification" > No mention of people arrested for Twitter posts in the UK and the EU What did they mean by this?
- vscode-rest 9mo agoFollow the money. Five eyes pay for TOR to exist.
- commandersaki 9mo agoSimilar to how CIA has a technology fund that gave money to Signal; because they use it?
- jmnicolas 9mo ago> because they use it? My hunch is because they have a backdoor in it.
- webdoodle 9mo agoThey are using the backdoor they bought and paid for in both Signal and Tor.
- DANmode 9mo agoThey don’t need to pwn Signal, they pwn the baseband of your phone. Since…yknow, before 2013.
- morserer 9mo agoThey don't necessarily need one to do their jobs. Signal is centralized, hosted on AWS, and through a mixture of legal procedures codified by US law and their bundled gag orders (PR/TT order, SCA warrant, FISA 702, and usage of NSLs) that can be extended for significant lengths of time and, occasionally, in de facto perpetuity, all metadata (who is talking to who, when, from where) can be monitored in real-time without Signal ever being informed. Combined with existing legal procedures for telecoms and VOIP providers for real-time + retrospective location tracking by phone number/associated IMEI/IP address by way of tower connectivity (this framework is required by law [specifically, CALEA] to be implemented by default for all users, not after the fact nor on-request), that's enough data to escalate to standard law enforcement procedures if an incriminating link is found, whereby the phone's internal message history can be dumped either through private (ex.: Cellebrite) or functionally coercive legal means (refusing to decrypt data can get you jail time if you are the subject of an investigation, and deletion of data such as via duress pins etc can get you a destruction of evidence charge), at which point all of your messages can be dumped. And this all ignores the fact that firmware for basebands and cryptoprocessors (and most other hardware components in all devices) is closed-source, proprietary code, and that Signal piggybacks off of device encryption for at-rest message data instead of reimplementing it in userland. (This feature used to exist and was removed, but can be re-added through the Molly fork.) I've also known protesters who have also had Signal geoblocked at the site of a protest the moment it was slated to start, forcing members of said protest to fall back to unencrypted methods at crucial times. Being centralized and using US-based cloud infra does a lot to compromise anonymity and security, even if message content isn't immediately readable. Luckily, Signal is not vulnerable to push notification interception, but if you want a great real-world example of how gag-ordered dragnet metadata surveillance visible to both domestic and foreign governments (by way of international intelligence agreements) can look for massive corporations rendered helpless by this legal framework, that's a great case study to look into. https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/ https://www.reuters.com/technology/cybersecurity/governments... Throwing out the accusation of apps being "backdoored" just obscures the real, de facto "backdoors" that are US law.
- throwfaraway135 9mo agoConsidering the staggering number of arrest for online/offensive communications in England & Wales, we should add Britain to the list of Russia and Iran 2017: ~5,500 arrests 2019: ~7,734 arrests 2023: ~12,183 arrests
- nomilk 9mo agoI was also surprised the post focusses on Rus/Iran when Australia, UK, and many more countries (Malaysia, Thailand) have/are introducing laws to prevent large swaths of free speech (banning mediums by age, banning conversation by topic, or by making speaking one's mind online too risky, as almost anything now can be interpreted as 'offensive' or 'hate speech').
- Guestmodinfo 9mo agoIndia why forget us. Only thing is you may not find exact data.
- RobotToaster 9mo agoTor is primarily funded by the US State department, that's why.
- iamnothere 9mo agoDepends on what you mean by primarily. US government funding is still the largest single portion of their funding, but they are trying to diversify. Most funding comes from non-government sources: https://blog.torproject.org/financials-blog-post-2023-2024/ https://blog.torproject.org/financials-blog-post-2023-2024/
- aprilthird2021 9mo agoYes. I think social media or app bans should count as well, as well as consequences for things posted on social media which are simply opinions. I think killing of journalists should count as well (so probably India, Israel, etc.) And I think also frivolous suits lodged by the govt at people for their speech. So that would include suing Twitter users for making jokes about the FBI director girlfriend, etc. One of the biggest things to censor speech the US is doing is forcing the sale of TikTok to government friendly group. There are many ways governments censor our speech, and they seem, sadly, to be increasing worldwide
- entropyneur 9mo agoHonest question: why no mention of China? I assume they've given up earlier due to lack of resources?
- reop2whiskey 9mo ago[dead]
- meowmeowmeowa 9mo ago[dead]
- mos87 9mo agoDo they have official instructions on how to setup (which URLs for STUN, etc - there are a couple required) TOR via Snowflake on desktop (bc on Android it all seems to be bundled inside Orbot)?
- grumbel 9mo agoWhy is Tor making it so difficult to change the region/ExitNode then? Geo-Blocking is by far the most prevalent form of online censorship and while Tor can work around it, it requires fiddling with config files and restarting the service instead of clicking a button.
- immibis 9mo agoPatches welcome, but try to design it in a way that spreads load proportionally to the bandwidth available in each country.
- NoiseBert69 9mo agoI'd really love to see native DNS Tunneling in Tor.
- KnuthIsGod 9mo ago[flagged]
- iTCart 9mo agoThe "Mimicry" Angle (Best for technical discussion) The shift from "obfuscation" to "mimicry" is the real story here. In 2025, "random-looking" traffic is itself a signature for DPI. Tools like WebTunnel that mimic standard HTTPS/SNI and Conjure that hides in unused ISP space force censors into a "collateral damage" dilemma: they can't block Tor without breaking their own web.
- fguerraz 9mo agoYou can’t fix censorship with tech. The only solution is booting the facists out.
- jmnicolas 9mo agoYou won't find many historical examples of fascists being booted out by the people. The only successful revolutions are piloted by a small elite with further interests that may not coincide with the people.
- lurk2 9mo ago> You won't find many historical examples of fascists being booted out by the people. Every fascist regime that has ever existed has been ousted by war, revolution, or the vote. There are no fascist regimes left, unless you expand the definition of the term to mean “any authoritarian regime,” in which case there are plenty of historical examples of popular revolt. > The only successful revolutions are piloted by a small elite with further interests that may not coincide with the people. This isn’t true.
- galangalalgol 9mo agoAuthoritarian regimes very rarely get reverted if they aren't external powers ruling a separate group. Can you give some examples where it happened? I don't know of any that lasted very long.
- jimnotgym 9mo agoI think we could have a more thoughtful discussion if people didn't start off with an assumption that the way the US manages free speech is unquestionably better than the rest of the world. Take a breath and think before you write. It seems to me that what you are allowed to say in the US is very dependent on how much the person you are saying it about is able to spend on lawyers, for instance.
- llmslave2 9mo agoYou're absolutely right, in that the US's libel laws are too strong and benefit the rich.
- orloffm 9mo agoRussia was already complicated two years ago, most of-the-shelf VPNs blocked, and with Intel/Microsoft websites blocking themselves due to sanctions it was rather difficult to set up a fresh laptop - it couldn't download drivers, and obvious channels were all blocked. This year they've blocked almost all of the VPNs and additionally calls in all messenger apps and FaceTime. The only thing that works is Outline - but one has to set up the server somehow, and if you're in Russia without a western credit card it might be difficult to do. For some reason the iOS app for Outline is still in the Russian App Store.
- amifree 9mo ago[dead]
- 1vuio0pswjnm7 9mo ago"As the severity of censorship in Russia has increased, WebTunnel has also received several fixes, such as SNI imitation and safe non-WebPKI certificate support with certificate-chain pinning to ensure it can withstand more kinds of censorship, including SNI allowlisting and the rapid blocking of distributed bridges." "SNI imitation" and "non-WebPKI certificate support" sounds like it could be useful for purposes other than evading censorship in any particular country Discerning web users around the globe might also be interesting evading data collection, surveillance and ads by so-called "tech" companies, for example https://blog.torproject.org/introducing-webtunnel-evading-censorship-by-hiding-in-plain-sight/ https://blog.torproject.org/introducing-webtunnel-evading-ce...
- nephihaha 9mo agoI love how this goes on about Iran and Russia but not the obvious issues elsewhere.
- Slava_Propanei 9mo ago[dead]
- yanoleaf 9mo agoOh now you care, while conservatives were censored since 2020...