Live data from Hacker News

The Iran Firewall: A preliminary report

blog.thc.org

11–20 of 143 posts

Re: The Iran Firewall: A preliminary report

#12

I almost stopped reading at "neo-liberal", man that term is getting boring, especially when used in non-sequitur fashion like "The most severe disruption is when the regime turns off all cell towers and all local Internet. They just pull the plug and it's game over for any neo-liberal smart-arse that thinks v2ray/tor/shadowsocks is the solution". WTF does that even mean? What does the author think it means?

> What does the author think it means?

A detestable person that thinks he can circumvent the regime? Presumably a paleo-conservative (or whatever the opposite of neo-liberal is in the mind of the blogger) would not be so naive and would look at real "solutions", as opposed to the neo-liberal, who is interested in non-solutions.

Pretty awful ideas floating around in this guy's head.

Re: The Iran Firewall: A preliminary report

#13

I almost stopped reading at "neo-liberal", man that term is getting boring, especially when used in non-sequitur fashion like "The most severe disruption is when the regime turns off all cell towers and all local Internet. They just pull the plug and it's game over for any neo-liberal smart-arse that thinks v2ray/tor/shadowsocks is the solution". WTF does that even mean? What does the author think it means?

I'm not sure what he means by that. Is it just a tongue-in-cheek description for the opposition to the Iranian party? Is it used by the party to describe pro-western people locally? Or is this just another overused Redditism?

Re: The Iran Firewall: A preliminary report

#14
post #8
post #2

This is difficult to read. The author confuses nouns and proper nouns and isn't clear about who it is they're referring to (who are the neo-liberals, for instance?). I understand that not everyone is as good at writing as others, but it really doesn't take much effort to ask someone to proofread. Otherwise, this is a good start, even though it lacks details and examples.

Conceptually, it was interesting. I can forgive it for lacking details, as a "preliminary report", too. But the whole, "neo-liberal arses" bit gave it the sense of an unhinged author or untrustworthy narrator.

Conceptually, I clicked it and thought I would learn something about the Iranian firewall, but instead I ended up at "The Hackers Choice" blog, a blog with exactly two articles, and read a confusing rant along with a laundry list of firewall techniques talked about in vague enough terms that I learned absolutely nothing, other than to be skeptical about this source going forward.

Re: The Iran Firewall: A preliminary report

#15
The snooping of unencrypted SNI in the TLS handshake is a known weakness that is still mostly unresolved despite four years of standardization effort. The encrypted SNI work has been revised and updated to encrypted ClientHello and is still technically an IETF draft and not yet formalized in an RFC:

https://datatracker.ietf.org/doc/draft-ietf-tls-esni/

That said, CloudFlare, Firefox, and Chromium teams have all been working toward the evolving spec so one can hope that soon with eCH and DNS-over-HTTPS we will be able to have clients securely connect to servers without broadcasting the hostname to which they are connecting.

Re: The Iran Firewall: A preliminary report

#16

I almost stopped reading at "neo-liberal", man that term is getting boring, especially when used in non-sequitur fashion like "The most severe disruption is when the regime turns off all cell towers and all local Internet. They just pull the plug and it's game over for any neo-liberal smart-arse that thinks v2ray/tor/shadowsocks is the solution". WTF does that even mean? What does the author think it means?

Pretty sure he's joking around using iran's regime terms to describe its dissidents

Re: The Iran Firewall: A preliminary report

#17
post #15

The snooping of unencrypted SNI in the TLS handshake is a known weakness that is still mostly unresolved despite four years of standardization effort. The encrypted SNI work has been revised and updated to encrypted ClientHello and is still technically an IETF draft and not yet formalized in an RFC: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ That said, CloudFlare, Firefox, and Chromium teams have all been…

Follow along on Chromium support here: https://bugs.chromium.org/p/chromium/issues/detail?id=109140...

Re: The Iran Firewall: A preliminary report

#18
post #13

I almost stopped reading at "neo-liberal", man that term is getting boring, especially when used in non-sequitur fashion like "The most severe disruption is when the regime turns off all cell towers and all local Internet. They just pull the plug and it's game over for any neo-liberal smart-arse that thinks v2ray/tor/shadowsocks is the solution". WTF does that even mean? What does the author think it means?

I'm not sure what he means by that. Is it just a tongue-in-cheek description for the opposition to the Iranian party? Is it used by the party to describe pro-western people locally? Or is this just another overused Redditism?

It is a play on neo-con, which is a term that was used to great affect in American conservative political circles to ostracize those who would cooperate with the opposition party - a.k.a. moderates. It is now used with similar goals by the American far left (to the extent that such a thing exists..). Both terms are often coopted by the the opposition party to demonize moderate counterparts.

That said, it sounds cool to mouth-breathers so they often use it completely out of context, like this author did.

Re: The Iran Firewall: A preliminary report

#19
post #15

The snooping of unencrypted SNI in the TLS handshake is a known weakness that is still mostly unresolved despite four years of standardization effort. The encrypted SNI work has been revised and updated to encrypted ClientHello and is still technically an IETF draft and not yet formalized in an RFC: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ That said, CloudFlare, Firefox, and Chromium teams have all been…

Wait I'm confused. I remember reading a bunch of reports about how China started blocking TLS 1.3 because of encrypted SNI (eSNI) years ago?
Post reply on HN