Live data from Hacker News

The Iran Firewall: A preliminary report

blog.thc.org

41–50 of 143 posts

Re: The Iran Firewall: A preliminary report

#41
post #2

This is difficult to read. The author confuses nouns and proper nouns and isn't clear about who it is they're referring to (who are the neo-liberals, for instance?). I understand that not everyone is as good at writing as others, but it really doesn't take much effort to ask someone to proofread. Otherwise, this is a good start, even though it lacks details and examples.

English isn't the writers first language, for a start.

The weird use of the term neoliberal is pretty common in European liberal-as-in-freedom left leaning circles.

Re: The Iran Firewall: A preliminary report

#42

On bad days: Key word is bad days. Expats in China have noticed the same thing, with VPNs sporadically not working during summits, around certain holidays, etc but resuming afterwards. Also, for some reason certain VPNs work more consistently than others even though they use the same protocols as blocked services. Some speculate that the ones that continue to work are either honeypots or the companies behind them hav…

> but resuming afterwards.

This is a common and natural misconception. When the firewall gains a feature (i.e. the ability to block certain traffic) the VPN providers then have to figure out some technique to bypass it. This happens over and over again. The firewall isn't relaxing after the event, it is staying the same and the VPN provider has improved.

On your second point, I can't comment for all providers, but I've heard this rumour in a more specific context and can say that it is definitely at least sometimes false.

Re: The Iran Firewall: A preliminary report

#43
post #31

I recollect few years ago when the US ordered all western services to be blocked to Iranian citizens, it was a big outcry when Gitlab and Github published blogs confirming their implementation of the Iran blockade. To me the west lost all moral arguments criticizing Iran for doing the same within their own country.

One is used as punishment to correct behavior, one as control.

[edit] This is the same way that if I go out and throw someone into my basement it's 'kidnapping' but when the police do it to me, it's an arrest.

Jokingly this comment has the same vibes. [1]

[1] https://twitter.com/dril/status/473265809079693312?s=20&t=gD...

Re: The Iran Firewall: A preliminary report

#44
post #2

This is difficult to read. The author confuses nouns and proper nouns and isn't clear about who it is they're referring to (who are the neo-liberals, for instance?). I understand that not everyone is as good at writing as others, but it really doesn't take much effort to ask someone to proofread. Otherwise, this is a good start, even though it lacks details and examples.

English isn't the writers first language, for a start. The weird use of the term neoliberal is pretty common in European liberal-as-in-freedom left leaning circles.

I have never heard the term "neoliberal" outside of US politics.

Re: The Iran Firewall: A preliminary report

#45

On bad days: Key word is bad days. Expats in China have noticed the same thing, with VPNs sporadically not working during summits, around certain holidays, etc but resuming afterwards. Also, for some reason certain VPNs work more consistently than others even though they use the same protocols as blocked services. Some speculate that the ones that continue to work are either honeypots or the companies behind them hav…

Neoliberal is usually used as a pejorative towards "liberals" who prioritise economic growth/profit over human dignity/freedom. Think: the Blair administration in the UK.

Re: The Iran Firewall: A preliminary report

#46

I almost stopped reading at "neo-liberal", man that term is getting boring, especially when used in non-sequitur fashion like "The most severe disruption is when the regime turns off all cell towers and all local Internet. They just pull the plug and it's game over for any neo-liberal smart-arse that thinks v2ray/tor/shadowsocks is the solution". WTF does that even mean? What does the author think it means?

I'm a liberal by most definitions but I didn't reject a decent technical article by presumably an advocate of political freedom in Iran because of my sensitive sensibility.

Re: The Iran Firewall: A preliminary report

#47
post #31

I recollect few years ago when the US ordered all western services to be blocked to Iranian citizens, it was a big outcry when Gitlab and Github published blogs confirming their implementation of the Iran blockade. To me the west lost all moral arguments criticizing Iran for doing the same within their own country.

And it's not like the West isn't blocking sites and even taking down sites that aren't breaking the law.

Re: The Iran Firewall: A preliminary report

#48
post #19
post #15

The snooping of unencrypted SNI in the TLS handshake is a known weakness that is still mostly unresolved despite four years of standardization effort. The encrypted SNI work has been revised and updated to encrypted ClientHello and is still technically an IETF draft and not yet formalized in an RFC: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ That said, CloudFlare, Firefox, and Chromium teams have all been…

Wait I'm confused. I remember reading a bunch of reports about how China started blocking TLS 1.3 because of encrypted SNI (eSNI) years ago?

Some people interested in the Great Firewall wrote up weirdness they saw with one particular prototype of eSNI years back. A game of Telephone later this became nonsense like "China blocks TLS 1.3" but actually if you do that what you get isn't web sites stripped of protection but connection errors. Which is indeed what happens for some sites from the other side of the Great Firewall, but we just say China blocks those sites, because that is what they do. Protocol versions are not crucial to them.

The current iteration of ECH is designed to be GREASEd which means browsers might just always do ECH with dummy values regardless, so either you block or you don't, you won't be able to selectively block ECH. This doesn't magically prevent the Great Firewall from working but does mean specifically host matching is degraded as intended.

Re: The Iran Firewall: A preliminary report

#49
post #6

Pretty crazy that a country can just completely block all internet outside of what they want to be accessible... One app that came to my mind reading this is Briar [1] - no real internet required, can connect to other briar participants via bluetooth and WiFi. Sadly only for Android... [1] https://briarproject.org

It's not crazy, internet is like public roads, they can decide to close them anytime they want.

Who's "they" and why are we paying to uphold their power to make this decision whenever they want

Re: The Iran Firewall: A preliminary report

#50

Earlier quoted context omitted.

The top says this, which doesn't sound like a joke. > The Internet is easily censored. The neo-liberals got their arses kicked. The big players like Google/Apple/AWS are partly to blame. China runs the GFI as a service.

The point is the neo-liberals of Silicon Valley, who essentially adopt a policy of splendid isolation, have failed to protect democracy.

Since when was their job to protect democracy?
Post reply on HN