Live data from Hacker News

The Iran Firewall: A preliminary report

blog.thc.org

121–130 of 143 posts

Re: The Iran Firewall: A preliminary report

#121

The only real solution long-term is completely peer-to-peer ad-hoc networking that doesn't depend on BGP. A few projects are in similar territory but none I've seen are working at the layer of bypassing BGP. Many are just acting as an overlay; which works to an extent. https://github.com/yggdrasil-network/yggdrasil-go It's probably begging for a different model of the "internet" and where data lives. My requirements:…

Most of the things you mentioned are implemented in the "Browser" that I've built. It's using multicast DNS to discover neighboring running instances and it has an offline cache first mentality, which means that e.g. download streams are shared among local peers.

Global peer discovery is solved via mapping of identifiers via the reserved TLD, and via mutual TLS for identification and verification. So peers are basically pinned client certificates in your local settings.

Works for most cases, had to implement a couple of breakout tunnel protocols though, so that peer discovery works failsafe when known IPs/ASNs are blocked.

Relaying and scattering traffic works automatically, so that no correlation of IPs to scraped websites can be done by an MITM. Tunnel protocols are all generically implemented, DNS exfiltration, HTTPS smuggling, ICMP tunnels, and pwnat work already pretty failsafe.

What's missing is UPnP support so that it behaves a little more gracefully when a router would be cooperative in nature, but after trying to implement the "specification" a bunch of times I skipped it for now.

Lots of work to be done though, and had to focus on couple of other things first before I can get back to the project.

The browser is part of a larger network that's trying to automate cyber threat intelligence on a peer to peer level, so clients, servers, websites and domains have a trust ratio and a history of trust to prevent misclassification of a new domain owner that e.g. defaced a website or tries to inject their malicious assets up unto previously trusted peers.

[1] https://github.com/tholian-network/stealth

Re: The Iran Firewall: A preliminary report

#122

Earlier quoted context omitted.

How exactly are you going to "bypass BGP" on the global Internet? Reaching your trusted peers depends on routing, which means BGP (at least for anything outside of your ASN.)

By having a determinstic way to talk based on what you want to talk about. Call it, determinitic-spontaneous-rendezvous-routing.

Sorry, but this makes no sense to me. Can you explain this a bit more?

Re: The Iran Firewall: A preliminary report

#123
post #79

Another idea: create an easy way to set up pirate LTE base stations. Hacked femtocells? SDR? Something more clever? Distribute eSIMs to everyday people. The pirate operator takes all the risk and technical difficulties.

Why go for LTE when Wi-Fi is so much more feasible?

I mean, 10 bucks for an AP isn't far fetched whereas LTE antennas alone would explode in budget, even when considering to use OsmocomBB with super old hardware/phones.

And every phone these days got Wi-Fi anyways. Most meshnet solutions rely on Wi-Fi so you wouldn't even need to implement much software for peering.

Re: The Iran Firewall: A preliminary report

#124
post #108

Earlier quoted context omitted.

How exactly are you going to "bypass BGP" on the global Internet? Reaching your trusted peers depends on routing, which means BGP (at least for anything outside of your ASN.)

Well if you want to get rid of BGP then it probably doesn't make sense to talk about ASNs since BGP is a way to connect ASNs... That being said, it does seem very pie-in-the-sky to imagine the entire global internet using decentralized routing without some sort of backbone infra that is at least moderately centralized. There is just too much data. I could imagine mesh networks being more feasible if we were still liv…

Maybe it is too much data for devices that have to share a channel. But lasers (think: old TV remotes using infrared) do not have to share channels with each other, and can be very high-bandwidth and more difficult to snoop on indeed. Mirrors could even be used for relaying, to save lots of compute. Like fiber cables piercing through the air itself!

Re: The Iran Firewall: A preliminary report

#125

Earlier quoted context omitted.

> which is not an economic self own even most dictatorships are willing to make. What basis do you have for this claim? People make these claims constantly so confidently, but wherever I look all I see is that dictators have always been willing to make their nations incredibly poor. > These firewalls are an exercise in having your cake and eating it too. More to the point this isn't the Gordian Knot you think it is.…

It is game theory. Consider what happens in the real world - it is strictly easier for Iran or any country with a competent infrastructure to just shut down the big internet pipelines for retail customers. They don’t do that. China has spent untold amounts of money creating a stupidly effective surveillance state which is still technically open to the internet. Why? So your assumption that “dictators will do the wors…

No post body was provided.

Re: The Iran Firewall: A preliminary report

#126

The only real solution long-term is completely peer-to-peer ad-hoc networking that doesn't depend on BGP. A few projects are in similar territory but none I've seen are working at the layer of bypassing BGP. Many are just acting as an overlay; which works to an extent. https://github.com/yggdrasil-network/yggdrasil-go It's probably begging for a different model of the "internet" and where data lives. My requirements:…

AirDrop? This is maybe the largest deployed peer-to-peer solution. Sad that it is iOS only.

Re: The Iran Firewall: A preliminary report

#127
post #61

Earlier quoted context omitted.

And it means that state firewalls will just block all CDNs.

The idea is you force them to choose the entire effective internet or nothing, which is not an economic self own even most dictatorships are willing to make. These firewalls are an exercise in having your cake and eating it too.

I agree, this is the best approach. With every improvement, technology increases the amount of tyranny required of governments to maintain the same level of control they had before. They used to be able to block specific sites, now they will have to block everything and cut themselves off from the internet.

Eventually, we'll end up with either uncensorable technology or a totalitarian government.

Re: The Iran Firewall: A preliminary report

#128
post #31

I recollect few years ago when the US ordered all western services to be blocked to Iranian citizens, it was a big outcry when Gitlab and Github published blogs confirming their implementation of the Iran blockade. To me the west lost all moral arguments criticizing Iran for doing the same within their own country.

One is used as punishment to correct behavior, one as control. [edit] This is the same way that if I go out and throw someone into my basement it's 'kidnapping' but when the police do it to me, it's an arrest. Jokingly this comment has the same vibes. [1] [1] https://twitter.com/dril/status/473265809079693312?s=20&t=gD...

>to correct behavior

this is literally trying to control, just on a different level.

Re: The Iran Firewall: A preliminary report

#129
post #63

Air dropping starlink terminals onto protesters is the solution. In fact, if you live anywhere outside of the US, owning one "just in case" is good for future proofing your freedom, IMHO. Kind of like being armed. Edit: in fact, starlink v2 global LTE-from-space coverage will be a true game changer for world freedom. We can only hope this comes to be sooner rather than later.

Why not airdrop AKM assault rifles and lots of ammo then? The protesters could use the weapons to overthrow the government. Much more effective than Starlink when your government has a monopoly on violence.

Re: The Iran Firewall: A preliminary report

#130
post #8

Earlier quoted context omitted.

Conceptually, it was interesting. I can forgive it for lacking details, as a "preliminary report", too. But the whole, "neo-liberal arses" bit gave it the sense of an unhinged author or untrustworthy narrator.

Conceptually, I clicked it and thought I would learn something about the Iranian firewall, but instead I ended up at "The Hackers Choice" blog, a blog with exactly two articles, and read a confusing rant along with a laundry list of firewall techniques talked about in vague enough terms that I learned absolutely nothing, other than to be skeptical about this source going forward.

IDK. Not knowing THC is like not not knowing the CCC or 2600. It is more on you ;-)
Post reply on HN