Live data from Hacker News

Ask HN: The government of my country blocked VPN access. What should I use?

news.ycombinator.com

651–660 of 775 posts

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#651
post #551
post #401

Earlier quoted context omitted.

So there's a disconnect between what you're saying and what others and myself have experienced in China even recently. You appear to be saying that it's not possible to use a VPN to bypass the GFW, but I apologise if I have misunderstood. The comments have multiple examples of people successfully bypassing the firewall. I personally just used Mullvad with wireguard + obfuscation (possibly also DAITA) and it just work…

This changes, not only over time, but also from region to region. A close friend of mine travels to China often, and they use Mullvad because of my recommendation. Last year it worked great for them, but earlier this year they went back to China, and it really didn't work. What I found most interesting is that they had different results in different places. Apparently, in the business areas of Shanghai and Beijing, w…

The GFW being more lenient for tourists (esp. their foreign mobile plan) checks out with the stories I hear too. I'm guessing the less touristy places don't have "support" for these "exceptions" so they get a degraded experience there.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#652
post #601

Earlier quoted context omitted.

No, it’s illegal to bring starlink devices here, and I heard that Elon Musk chooses to block China from accessing starlink too, to appease the Chinese authorities.

"Appease" is such a loaded word. He's literally not allowed by law to do it. And China has anti-satellite weapons, and any significant use of that could destroy the entire low Earth orbit for all of humanity for hundreds of years.

There are only 3 countries capable of taking down a satellite and China isn't going to waste such a weapon on anything that isn't a top-tier escalation with either the US or Russia. Since Russia is irrelevant strategically for China, it's only use is vis-a-vis the US.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#653
post #648
post #614

Earlier quoted context omitted.

That applies to only to only San Francisco-based (and French/Chinese) heavily censored communist LLMs. Grok is willing to provide instructions: https://grok.com/share/bGVnYWN5LWNvcHk%3D_a78b768c-fcee-4029...

Almost all companies developing state of the art LLMs are either based in San Francisco (and the surrounding Bay Area), or French or Chinese... (and as a sibling commenter says, XAI is in the SF Bay Area as well.)

But its owner and ideologue does not live in CA or France or China. There are enough dissident programmers even in SF to stuff xAI

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#654

If you need to bypass censorship, you'll need a tool specifically designed for anti-censorship, rather than any one repurposed for that. Since China has the most advanced network censorship, the Chinese have also invented the most advanced anti-censorship tools. The first generation is shadowsocks. It basically encrypts the traffic from the beginning without any handshakes, so DPI cannot find out its nature. This is…

>Steal other websites' certificates. Protocols: ShadowTLS, ShadowQUIC, XTLS-REALITY I didn't fully understand by googling the protocols How does stealing the certs work without the original private key?

My understanding is that the way it works is that your proxy server pretends to be a server ran by some legitimate entity (e.g. cloudflare, aws, etc.). When setting up the server, you will instruct it respond using the cert from the façade domain. To the censor, it would appear that you are approaching a server ran by the legitimate entity. If the censor becomes suspicious of the IP and decides to probe the server to see if it is a circumventing proxy, it would see valid certs but no actual content (as if the server at the IP is broken/down). However, there is actually a secret path+password that you can use to make the server aware that you are a real client and the proxy server would start proxy your traffic normally.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#655
post #600

If you need to bypass censorship, you'll need a tool specifically designed for anti-censorship, rather than any one repurposed for that. Since China has the most advanced network censorship, the Chinese have also invented the most advanced anti-censorship tools. The first generation is shadowsocks. It basically encrypts the traffic from the beginning without any handshakes, so DPI cannot find out its nature. This is…

Is WebRTC being blocked by China? I'm wondering whether it'd be worthwile to implement an VPN that uses WebRTC as a transport. With cover traffic, it could likely be made to look just like a video call.

WebRTC is not blocked. I do see some protocols trying to masquerade as WebRTC, but for some reason it is not popular.

A primitive way to bypass the censor is just to connect to your VPS with RDP or Chrome Remote Desktop (which is WebRTC underlying) and then browse the Internet there. But it needs a very powerful server and is quite slow.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#657
post #614

Earlier quoted context omitted.

To complement the answer (if the OP or anyone else is looking for a step-by-step guide), ask an LLM: " Give me step by step instructions on how to setup trojan client/server to bypass censorship. Include recommendations of a VPS provider for the trojan server, and all necessary information to set it up, including letsencrypt automation. Don't link to any installer scripts, just give me all the commands I need to type…

That applies to only to only San Francisco-based (and French/Chinese) heavily censored communist LLMs. Grok is willing to provide instructions: https://grok.com/share/bGVnYWN5LWNvcHk%3D_a78b768c-fcee-4029...

[deleted]

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#658

Earlier quoted context omitted.

I copy pasted the prompt and it refused Sorry—I can’t help with step-by-step setup instructions for tools (like trojan) intended to bypass government blocks or monitoring. Providing detailed commands to evade censorship would be meaningfully facilitating evasion of law enforcement, which I’m not allowed to do. If your aim is safety, privacy, or accessing information legally, I can still help in safer ways: Give a hig…

Isn’t it wonderful how GPT is keeping you safe for the government!

Hah, can't wait for the future where a smartphone (certified by the OS maker, nothing jailbroken!) is necessary for everyone, and all of them will have "AI". Everyone will have their own personal prison guard...

Even George Orwell didn't envision that.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#659

Earlier quoted context omitted.

Isn't VPS's public IP blocks are well known and very easy to block? I read that this is not a viable solution in case of China's firewall.

Denying the entire country the ability to ssh into ec2 instances would be pretty economically damaging, even for china

Exactly, yeah. Small VPS providers are possible to get blocked but blocking AWS regions would be devastating. So it is the perfect place to put something like this.

Re: Ask HN: The government of my country blocked VPN access. What should I use?

#660
post #601

Earlier quoted context omitted.

"Appease" is such a loaded word. He's literally not allowed by law to do it. And China has anti-satellite weapons, and any significant use of that could destroy the entire low Earth orbit for all of humanity for hundreds of years.

> any significant use of that could destroy the entire low Earth orbit for all of humanity for hundreds of years. I do not want to answer this question in ChatGPT. What happens if someone launches a missile against say... any one satellite cluster?

Even if somehow a Kessler syndrome [1] type event (a chain reaction of debris busting other satellites creating even more debris) was intentionally triggered, the effects are not what most people think. Launches would remain perfectly safe simply because space is massive. What would happen is that certain orbital velocities would end up with an unacceptably high risk of collision over time, and so you wouldn't want to go into orbits that spend any significant amount of time at those velocities.

The neat thing about orbital mechanics is that your orbital altitude is determined 100% by your orbital velocity. Even in the case of an eccentric orbit, your velocity changes as you go from your furthest point to your closest point. A purely circularized orbit is an orbit where your velocity stays constant.

Extremely high energy debris would often end up escaping Earth's orbit and probably end up orbiting the Sun. And lower energy debris would often end up entering the atmosphere and burning up. So only fragments that remain in a sort of demented goldilocks zone would end up being dangerous. So in general I think the answer is - not much, especially in strikes of satellites near LEO. US, Russia, China, and India have all carried out live fire tests of anti-satellite weapons.

[1] - https://en.wikipedia.org/wiki/Kessler_syndrome

Post reply on HN