Earlier quoted context omitted.
Correct, both Google and Amazon told Signal not to use them for domain fronting: https://signal.org/blog/looking-back-on-the-front/
Gross! I wonder what motivated these decisions inside Amazon & Google. This likely affects the Tor project domain fronting as well. We really should not have let the majority of internet traffic be served by a small handful of giant companies without some legal protections as to what they're allowed to do.
Help users in Iran reconnect to Signal
221–230 of 417 posts
Re: Help users in Iran reconnect to Signal
#222Re: Help users in Iran reconnect to Signal
#223Earlier quoted context omitted.
That article notes that Signal has been domain fronting since 2016. I think google has cracked down on it more recently though, and hence Signal has had to circumvent censors in a new way
And this new way, while less convenient, is arguably superior due to its decentralisation. They’re not just going after one service they’re now going after people all around the world running these proxies. Just set one up myself took 15 minutes and that includes setting up a fresh VPS. Just thinking what the best way to share it is.
The best idea I've had so far is using a CNAME response to a very common DNS query which would pass a basic filter, like I'd ask for "mail.mydomain.com" and it would respond with a CNAME pointing to the actual proxy. I have dead domains which I have configured with null records for MX and stuff (so spammers can't abuse them), I could hide the name of my proxies in the MX records a CNAMEs and nobody would be the wiser...
The trick is getting the word out on how to do it - like "hey everyone, just ask random domains for "mx.domain.com" and use the 30 level MX" or something which would pass as legit traffic. Maybe...
Re: Help users in Iran reconnect to Signal
#224Earlier quoted context omitted.
Even worse, what happens when they MITM all of the installs because the docker container has really bad security such as: RUN wget http://nginx.org/download/nginx-1.18.0.tar.gz https://github.com/signalapp/Signal-TLS-Proxy/blob/master/ng... Installing via HTTP, with no verification of installer seems like a reallyyyyy bad idea.
I noticed the same thing, and filed an issue [1]. The first reply does not fill me with a lot of confidence (but it's unclear to me whether the person is affiliated with the project or not). [1] https://github.com/signalapp/Signal-TLS-Proxy/issues/6
Re: Help users in Iran reconnect to Signal
#225Earlier quoted context omitted.
if they block can block tor what makes you think they can't block these proxies? furthermore if you use tor you can use the existing network of bridges/relays as well as their pluggable transports protocol to avoid DPI/traffic analysis.
Signal is taking a leaf out of Telegram's book here in crowd-sourcing censorship circumvention which has worked so well for Telegram in Russia, especially. One could use censorship evading VPNs like Tor, Lantern, Shadowsocks, Psiphon in addition to using these proxies. They all have different evasion mechanisms. The thing that works for user-run proxies is, it is like a hydra, you censor one proxy another crops up.
Regardless, I hope this does actually end up working, and allows Iranians to use Signal without a prolonged cat-and-mouse game.
Re: Help users in Iran reconnect to Signal
#226Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…
I just set up one of these Signal proxies. Hope it helps you and others in your country communicate freely and safely. [1] Regarding Tor: if you want a Signal-like app that uses an onion router look at Session. [2] It uses the same encryption protocol and very similar UI to Signal but routes all traffic through the Loki network so your traffic passes through three nodes. It is an onion network like Tor. One other ben…
1. An associated crypto-currency (not outright bad but weird smell IMO) [1]
2. Abandoned perfect forward secrecy and deniability [2]
3. Never completed an audit (though supposedly one is in progress) [3]
There are a million and one encrypted chat programs out there. Why should I use this one?
[1]: https://github.com/oxen-io/oxen-mobile-wallet
[2]: https://getsession.org/session-protocol-technical-informatio...
Re: Help users in Iran reconnect to Signal
#227Earlier quoted context omitted.
Correct, both Google and Amazon told Signal not to use them for domain fronting: https://signal.org/blog/looking-back-on-the-front/
Gross! I wonder what motivated these decisions inside Amazon & Google. This likely affects the Tor project domain fronting as well. We really should not have let the majority of internet traffic be served by a small handful of giant companies without some legal protections as to what they're allowed to do.
But I would be 100% against any law that required them to allow domain fronting. It's fine if they want to, but requiring them to basically open up/leave open a hole in their systems is not right.
Re: Help users in Iran reconnect to Signal
#228Almost everyone in these comments is asking questions of various degrees of pedantry or outright dissing signal/moxie/no federation/whatever... Just spin up a server if you can spare the expense and help some people out. Action > inaction. edit: you can get the connection details via @appliedlambdas on twitter!
Re: Help users in Iran reconnect to Signal
#229Earlier quoted context omitted.
I think FB’s policy is to comply with local laws regardless of ethical concerns?
There are a few requests reported: https://transparency.facebook.com/government-data-requests/c...
Re: Help users in Iran reconnect to Signal
#230Earlier quoted context omitted.
Correct, both Google and Amazon told Signal not to use them for domain fronting: https://signal.org/blog/looking-back-on-the-front/
What about Cloudflare?