Live data from Hacker News

How the great firewall of China detects and blocks fully encrypted traffic [pdf]

gfw.report

91–100 of 289 posts

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#91
post #41

I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…

Many years back I was running a socks proxy for access while in China and I found that it worked great in Shanghai but was rapidly blocked (or degraded in some fashion) in Hangzhou. That seemed internal and not edge but I do no really know how they were interfering with it. Given Hangzhou's tech expertise it just may be the ISP there was more capable and up to date?

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#93
post #86
post #41

I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…

There's a more straightforward way: roam with a foreign sim card. Roaming traffic is tunneled to your home telco and for whatever reason the tunnel isn't inspected at all. With the advent of esims you can buy a roaming sim and use it on your phone within minutes.

Can you activate it while abroad though? After I moved away from the UK I still had to have a UK mobile phone for various things. My UK sim would stop working after about a year away. When buying a new one I had to get someone in UK to put it in their phone to let it at least once connect to the home network. Without it the card would be useless. Is using foreign sim cards now easier?

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#94

Given HTTPS traffic is mostly permitted, could one obfuscate VPN traffic over http/3 (which I believe is UDP)?

Could China implement a MitM proxy for HTTPS traffic like many companies do?

No.

Companies get around ssl issues by minting their own root CAs and configuring their workstations to trust them. China has no (technical) way of forcing you to trust their root CA

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#97
post #93
post #86

Earlier quoted context omitted.

There's a more straightforward way: roam with a foreign sim card. Roaming traffic is tunneled to your home telco and for whatever reason the tunnel isn't inspected at all. With the advent of esims you can buy a roaming sim and use it on your phone within minutes.

Can you activate it while abroad though? After I moved away from the UK I still had to have a UK mobile phone for various things. My UK sim would stop working after about a year away. When buying a new one I had to get someone in UK to put it in their phone to let it at least once connect to the home network. Without it the card would be useless. Is using foreign sim cards now easier?

There are esims explicitly targeted to travelers. Those are the ones you want. In my experience they don't have any activation restrictions like the ones you describe

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#98
China doesn't realize how much they are being held back by meaningless investments of time and expertise on this. They spend almost the same %GDP as the US does on the US military as on their internal suppression forces.

Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#99
post #2

Seems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...

I'd go for ssh if I was trying to bypass it. At least legally I can claim that I'm just sshing to my aws server and not be jailed for using vpn.

> At least legally I can claim that I'm just sshing to my aws server and not be jailed for using vpn.

Your mistake is assuming that China has rule of law. If you're in China and you upset Xi enough, you get jailed/disappeared even if you technically didn't break any laws on the books.

Post reply on HN