4 ms·
By default using a SOCKS proxy (which, using ssh -D is probably the easiest and most common way to do this) in most browsers doesn't solve this problem as DNS r
by michh 13y ago
By default using a SOCKS proxy (which, using ssh -D is probably the easiest and most common way to do this) in most browsers doesn't solve this problem as DNS resolving is still done locally.
As they're messing with DNS, you'll still be connecting to their evil version of YouTube through your SSH tunnel. In Firefox this behaviour can be changed by toggling network.proxy.socks_remote_dns in about:config.
Of course, setting up an actual tunnel (i.e. on a lower network layer) would be better but that's a bit more complicated to do.
- Jugurtha 13y agoWhat happens when you change the default DNS on the router level to OpenDNS or Google. (i.e: Telnet to the router, and change DNS there).
- michh 13y agoThat's the whole point: they seem to be using deep packet inspection to mess with all DNS traffic regardless of the DNS server being used.
- Jugurtha 13y agoAha, I see. I'll look this up in addition to what kijin said (sshuttle). It's not like our government is blocking anything (there were rumors it was blocking Facebook in 2011, but it wasn't true as I was able to log in without any issue. It was just slow, but it's not like we have the fastest internet here). But it's nice to know. Thanks for the clarification.
- stayparanoid 13y agoWere you logging in on the actual facebook? how can you tell? Logging in isn't a proof that that is the real facebook, dude. And doesn't "It was just slow" ring any bell?
- Jugurtha 13y agoIt wasn't slower than many times where nothing was happening. Internet here just sucks. Whether it's peace and birds are singing, or scortched earth, it's all the same. Plus how can you tell it isn't the actual Facebook if everything is there, status, etc, comments, pictures. I can chat with other users, send messages, etc.
- alyxr 13y agoWhy isn't it default behavior to route dns through socks?
- michh 13y agoAFAIK it's a legacy thing. SOCKS4 didn't support it, SOCKS5 did but using that functionality changes behaviour depending on which SOCKS version the remote end happens to use.
- toast0 13y agoThere are decent reasons for either way, the real question is why isn't there a visible option for it.
- kijin 13y agoIf you're on *nix, sshuttle is the tool you want. It's ssh tunnel on steroids, and it works with every program even if they're not configured to use a SOCKS proxy (such as Flash). It's also faster because it avoids the TCP-over-TCP problem that the usual SOCKS proxy entails. sshuttle --dns -v -r username@servername 0/0 https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle
- michh 13y agoThat's going to come in useful, bookmarked, thanks!