Live data from Hacker News

OpenGFW: an open source implementation of China's Great Firewall

github.com

51–55 of 55 posts

Re: OpenGFW: an open source implementation of China's Great Firewall

#51
post #11

> Help you fulfill your dictatorial ambitions This bullet on their features list made my day LOL :)

It is funny but let’s hope someone doesn’t take it seriously or use it in that capacity else they’re gonna have to explain it in court

Re: OpenGFW: an open source implementation of China's Great Firewall

#52
post #45
post #44

Earlier quoted context omitted.

How about the whole Zero Trust concept where network is assumed hostile and every service is properly authed?

compliance != security. Good luck telling the auditor about zero trust.

Your company hires the audit. Interview the to find one that gets zero trust.

Re: OpenGFW: an open source implementation of China's Great Firewall

#53
post #14

I been seeing people on Twitter mocking the project, but I need it... You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers. With this project, it's hopeful that in the future I can just not putting their domains in the TLS w…

> You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers. You mean hardware products, right? In this case putting them in a separate VLAN would help. I you mean software running on your machine, you can set up a proxy and bloc…

Mainly TV, TV box and phones with non-open-source ROMs etc. These devices do need Internet connection for normal operations, which is why it's so hard to block suspicious traffic from them.

Re: OpenGFW: an open source implementation of China's Great Firewall

#54
post #14

I been seeing people on Twitter mocking the project, but I need it... You have no idea how much time I've wasted trying to block some products from pinging their home server with curious data stream, but failed to do so because I can't be bothered to sit my ass in front of Wireshark to sniff out all their DoH servers. With this project, it's hopeful that in the future I can just not putting their domains in the TLS w…

Link? To Twitter?
Post reply on HN