I have found using ShadowSocks [0] to work best for me here in China. VPNs create one connection for all traffic (which is easier for China's GFW to detect/block/slow down). ShadowSocks creates a new TCP/UDP connection for each connection that it proxies. My setup: Cheap VPS server in Hong Kong [1] (5USD/month, 512 RAM, 2Mbit port) running the ShadowSocks server (libev version). I have upgrade the port to 20Mbits for…
As someone who is pretty much oblivious to how the censorship works in China: Why do you use such a slow and expensive VPS, and why Hong Kong?
Https is an improvement, but they still use machine learning to make estimates on encrypted contents of packets. If packets going to and from a location (i.e. Your vpn server) meet some criteria with some confidence, they perform attacks on that connection and subsequent connections To the same endpoint. I'm not sure on the specifics, but these attacks will cause ~90% of that connection's traffic to drop. The system is dynamic, so your countermeasures have to be as well.
I'm guessing HK because it's physically and politically close. It's considered Chinese territory, but not under China's GFW. I've heard from friends that GFW censorship is more aggressive around sensitive times (i.e. Tiananmen square anniversary) and news.
If any of this is wrong or inaccurate, someone please correct me. I'd love to have a better mental model of the GFW so that I could better work remotely from there.