Live data from Hacker News

Tell HN: Russia has started blocking OpenVPN/WireGuard connections

news.ycombinator.com

61–70 of 268 posts

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#61
post #31

[flagged]

Everyone opposing the government either ends up falling from a hotel, or ends up in siberia, so you can’t blame the Russian people from being careful. At the same time, plenty people in the US are prepared to be boiled by trump…

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#62
post #31

[flagged]

It doesn’t seem fair to blame the populace that has been misinformed by their government. VPNs have been one of the best ways to hear external points of view and get more accurate information. How are they supposed to escape the boil and improve their lot if the government puts a lid on the pot and locks it? The VPN might be the only chance for them to know what’s actually happening in Ukraine and gain any sympathy.

And don’t be too quick to assume more authoritarian government isn’t coming for you. The more successful they are at this, the more likely it is to spread. I’m nervous because our water is definitely getting warmer in the US, and our next regime change might love to follow Russia and China’s examples on crowd control.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#63
post #44

Earlier quoted context omitted.

Can anyone confirm Shadowsocks works anymore? When I tried to use it a few years ago, it got blocked in a few days. To be honest, I think they are blocking anything that exchanges a lot of data with oversesas IPs, after hitting a certain threshold.

Shadowsocks and ShadowsocksR don’t work anymore in my experience in China or Iran. V2ray does which is the successor to those.

Shadowsocks does work against MITM attacks by my US ISP Comcast though. It is great software.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#64

I have the fortune to reside in Russia-controlled Donbas. Over here they have been blocking all WireGuard connections for a long time. OpenVPN seems to be blocked selectively depending on the host. The government and commerce must need it more than WireGuard. It isn't consistent. Different ISPs block different hosts and protocols at different times. I assume we are a kind of test and staging environment for censorshi…

How, technically, can they block wire guard? It can operate as pure UDP on any port. Are we referring to wireguard vendors like tailscale here?

This is what I was wondering. I don’t understand these VPNs too deeply (though I do occasionally administer an OpenVPN setup), but I was under the impression that they’re sending encrypted packets over UDP on arbitrary ports. That seems quite tough to analyze and block.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#65
post #153

Earlier quoted context omitted.

[stub for offtopicness]

Stay strong, hopefully, Russia will collapse and you'll be free - I may be naive but I still think there are enough Russians who can see this tragedy as the doing of a man who wants to continue to live the life of a king, and it's probably his only way of survival after so many murdering and prosecution.

[flagged]

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#66

I have the fortune to reside in Russia-controlled Donbas. Over here they have been blocking all WireGuard connections for a long time. OpenVPN seems to be blocked selectively depending on the host. The government and commerce must need it more than WireGuard. It isn't consistent. Different ISPs block different hosts and protocols at different times. I assume we are a kind of test and staging environment for censorshi…

OpenVPN looks more similar to regular https traffic, hence its a bit more difficult to fingerprint.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#67

I have the fortune to reside in Russia-controlled Donbas. Over here they have been blocking all WireGuard connections for a long time. OpenVPN seems to be blocked selectively depending on the host. The government and commerce must need it more than WireGuard. It isn't consistent. Different ISPs block different hosts and protocols at different times. I assume we are a kind of test and staging environment for censorshi…

How, technically, can they block wire guard? It can operate as pure UDP on any port. Are we referring to wireguard vendors like tailscale here?

Wireguard headers are fingerprintable.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#68
post #153

Earlier quoted context omitted.

[stub for offtopicness]

Stay strong, hopefully, Russia will collapse and you'll be free - I may be naive but I still think there are enough Russians who can see this tragedy as the doing of a man who wants to continue to live the life of a king, and it's probably his only way of survival after so many murdering and prosecution.

[dead]

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#69

Unfortunately, thanks to the Great Firewall of China, there has been a lot of resources put in to fingerprint VPNs and block them by state actors. Fortunately, however, there is equally years of some of the smartest minds on the planet working to bypass Chinese censorship, so there are some great OpenVPN alternatives. I really encourage you to look into something like Shadowsocks which Chinese people have found great…

Outline ( https://getoutline.org ) is even easier to deploy than Streisand in my experience and uses Shadowsocks.

This is really cool, thanks for sharing! I've been using Tail scale for a while, mostly because it's simple, but I don't love relying on some company for my VPN. Is this more like OpenVPN or Wireguard? Reading their site, it seems like it's closer to a traditional, OpenVPN-like connection, but I'm still interested in this over something like Nebula.

Re: Tell HN: Russia has started blocking OpenVPN/WireGuard connections

#70
post #8

Mullvad has a Wireguard obfuscation feature you can enable. Does that work for you?

no need, but thanks. daily routine become a more painful, because of two-way blocking. i even cant read new science paperwork from US universities, they're block whole ASN's. we're slowly moving to great firewall, i suppose.

[flagged]
Post reply on HN