This bullet on their features list made my day LOL :)
OpenGFW: an open source implementation of China's Great Firewall
11–20 of 55 posts
Re: OpenGFW: an open source implementation of China's Great Firewall
#12Re: OpenGFW: an open source implementation of China's Great Firewall
#13Re: OpenGFW: an open source implementation of China's Great Firewall
#14You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers.
With this project, it's hopeful that in the future I can just not putting their domains in the TLS whitelist, even when they use DoH.
---
Off topic but BTW: "Fully Encrypted Traffic" is really a confusing term that can only be understood correctly if the context is correct too. How about calling those protocols "High Entropy" (HighE)? Which IMO is more specific than calling it "Fully Encrypted". It's just my two-cents suggestion.
Re: OpenGFW: an open source implementation of China's Great Firewall
#15I'm shocked that nobody is worried that this lowers the barrier to implementation for other dictatorial governements.
Re: OpenGFW: an open source implementation of China's Great Firewall
#16I been seeing people on Twitter mocking the project, but I need it... You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers. With this project, it's hopeful that in the future I can just not putting their domains in the TLS w…
Re: OpenGFW: an open source implementation of China's Great Firewall
#17Re: OpenGFW: an open source implementation of China's Great Firewall
#18I been seeing people on Twitter mocking the project, but I need it... You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers. With this project, it's hopeful that in the future I can just not putting their domains in the TLS w…
I briefly read a paper, I suspect it's more complex than "high entropy".
So I still believe "High Entropy" is a better description than "Fully Encrypted Traffic".
I mean, you can pack the entire data stream in Base64 after sending them through a SHA256 pipeline, and it will still be "Fully Encrypted", but the entropy (in terms of traffic classification by content scanning) is not the same compare to doing it without the Base64 step.
Re: OpenGFW: an open source implementation of China's Great Firewall
#19Would be funny if this ends up like War Thunder. Some random chinese official making a pull request out of spite because some implementations are not as how the real GFW is doing it.
Re: OpenGFW: an open source implementation of China's Great Firewall
#20Well...it's very suitable for people outside of mainland China to experience what Chinese people experience online.