Hello! I've got experience working on censorship circumvention for a major VPN provider (in the early 2020s). - First things first, you have to get your hands on actual VPN software and configs. Many providers who are aware of VPN censorship and cater to these locales distribute their VPNs through hard-to-block channels and in obfuscated packages. S3 is a popular option but by no means the only one, and some VPN prov…
Mullvad is a bad choice for this particular case because they publish all their IPs, which makes them very easy to block. You should look into VPN providers that do not publish their IPs and that have a wide range of IP classes and multiple ASNs, which look like ordinary networks not associated with VPNs. In my experience, NordVPN and ExpressVPN have many of these.
Ask HN: The government of my country blocked VPN access. What should I use?
481–490 of 775 posts
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#482I lived in China for a while and there were several waves of VPN blocks. Also very few VPN services even try to actively support VPN-blocking nations anymore. Any commercial offering will be blocked eventually. What I settled on for decent reliability and speeds was a free-tier EC2 hosted in an international region. I then setup a SOCKS5 server and connected my devices to it. You mentioned Cloudflare so whatever thei…
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#483Re: Ask HN: The government of my country blocked VPN access. What should I use?
#484Shadowsocks used to be the thing that _really_ worked in CN. Not sure what's current there. AWS ap-southeast-3 should still be up, and isn't in a different partition like CN, govcloud, iso etc. So a VM there and a vpc peer in the US should get you around a lot of stuff.
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#485Hello! I've got experience working on censorship circumvention for a major VPN provider (in the early 2020s). - First things first, you have to get your hands on actual VPN software and configs. Many providers who are aware of VPN censorship and cater to these locales distribute their VPNs through hard-to-block channels and in obfuscated packages. S3 is a popular option but by no means the only one, and some VPN prov…
> First things first, you have to get your hands on actual VPN software and configs. It would be nice if one of the big shortwave operators could datacast these packages to the world as a public service.
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#486Earlier quoted context omitted.
DAITA was introduced after my time in the industry, but this isn't a new idea (though as far as I know, it's the first time this kind of thing's been commercialized). It's clever. It tries to defeat attacks against one of the tougher parts of VPN connections to reliably obfuscate, and the effort's commendable, but I'll stop short of saying it's a good solution for one big reason: with VPNs and censorship circumventio…
Have you heard about Safing's "SPN"? Could you comment on that?
The way they describe it makes it sort of sound like split tunneling and geotunneling can be done with DNS.
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#487IMO, the safest route for an individual with tech competency is to setup a small instance server in the cloud outside your country and use ssh port forwarding and a proxy to get at information you want. For an example of a proxy service https://www.digitalocean.com/community/tutorials/how-to-set-... That will give you a hard to snoop proxy service that should completely circumvent a government blockaid (they likely a…
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#488Please consider the potential consequences of circumventing the ban. Do what you do, but above all stay safe!
Re: Ask HN: The government of my country blocked VPN access. What should I use?
#489Re: Ask HN: The government of my country blocked VPN access. What should I use?
#490Earlier quoted context omitted.
I just spent 3 months in China this summer. The GFW has become much more sophisticated than I remember. I found only one method that reliably worked. That was to use Holafly (an international eSIM provider) and use its built-in VPN. China largely doesn’t care if foreigners get around the GFW, I guess. Another method that usually worked was ProtonVPN with protocol set to Wireguard. Not sure why this worked, it’s defin…
Holafly (and other "travel" eSim providers) have been caught routing traffic through China. https://www.itnews.com.au/news/travel-esims-secretly-route-t...
IP blocks are routinely bought and sold, and hence their geo location database entries are not reliable.
If you’re physically in the EU or the UK and your traffic is routed through China it would be unusably slow and immediately noticeable to non-technical users.