Live data from Hacker News

How the great firewall of China detects and blocks fully encrypted traffic [pdf]

gfw.report

101–110 of 289 posts

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#101

China doesn't realize how much they are being held back by meaningless investments of time and expertise on this. They spend almost the same %GDP as the US does on the US military as on their internal suppression forces. Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.

It is not the goal of the CCP to advance China as it is to keep themselves in power.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#102
The comments from people obviously never having been into a restricted country are hilarious. There are a few, most likely shadow approved, VPN providers that work. I refuse to believe they are just smarter than the GFW. I am convinced they are sanctioned and monitored. Which is fine if you never have any beef with the government. Which you never know you do until you do.

Stuff like socks5/shadowsocks and wireguard have long been useless. Imagine being in your house, and you want to go out, without anyone seeing you. No matter how well you try, just the attempt itself reveals you are trying - thus you are caught. Same for escaping GFW. A sanctioned VPN or RDP that stays alive without metering, is your best option.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#104
I am a total obfuscation noob. How far does their DPI go? I am guessing Tor and stuff have tried hiding it inside lots of different protocols and file types (I think I read something about that at some point). Is it to the point of hiding it as part of a html doc (like under a specific tag or something). At what point do we move towards having executable Javascript generate the encrypted text which then is decrypted?

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#106
post #73
post #15

Earlier quoted context omitted.

We have a satellite office in Dubai. I know their static IP. When they connect to our imap/smtp server they are coming in from another IP. I never looked into it deeply but assumed their connection is being diverted for inspection. (If true, they would probably not be below performing industrial espionage with the data they are accessing)

Speaking of satellites, the ones in geosynchronous orbit, how can Chinese block those?

“We will shoot your satellite if you don’t block access while over China”.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#107

I was wondering about simply using VPNs, which is not mentioned in the article at all, but checking GFW on Wikipedia, it tells: > The use of VPNs in China can provide individuals access to the international internet, but in China, it can be a potential legal risk. In 2017, the Chinese government declared all unauthorized VPN services to be illegal.[94] An example of the use of this punishment is Vera Zhou, a student…

More context about this WikiPedia excerpt:

https://www.chinafile.com/extensive-surveillance-china

https://www.rfa.org/cantonese/news/student-01272020075256.ht...

It looks like 周月明 (Vera Yueming Zhou) was sent to a Chinese concentration camp mostly because she was part of a religious minority and not necessarily for using a VPN to access the University of Washington’s website.

> Vera was living in her hometown of Kuytun (Kuitun) in Ili Prefecture, an area directly north of the Tian Shan mountains that borders Kazakhstan. She had been trapped there since 2017, when—in the middle of her junior year at the University of Washington, where I was an instructor—she had taken a spur-of-the-moment trip back home to see her boyfriend, a former elementary school classmate. Using digital surveillance tools, the Kuytun police had noticed that Vera had used a Virtual Private Network in order to access websites such as her university Gmail account. Given her status as a member of a Muslim minority group, this could be deemed a “sign of religious extremism.”

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#108

China doesn't realize how much they are being held back by meaningless investments of time and expertise on this. They spend almost the same %GDP as the US does on the US military as on their internal suppression forces. Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.

Get used to it; we will soon be a part of China's "community of common destiny".

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#109

China doesn't realize how much they are being held back by meaningless investments of time and expertise on this. They spend almost the same %GDP as the US does on the US military as on their internal suppression forces. Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.

I wouldn't be so sure that it's a bad idea. Look how social media has damaged democracy around the world. US democracy is stuck in a bit of a death spiral - https://www.theatlantic.com/ideas/archive/2021/04/how-stop-m.... I hate repression, but they've been at it for thousands of years and I'm no longer super confident we have something better (see citizens united, roe v wade, affirmative action). China's life expectancy just beat the US.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#110
post #90
post #65

The exact reverse engineered algorithm of the GFW is on page 4. It looks very reasonable (given what they are trying to achieve with it). The easiest bypass I can think of would be to tunnel your connections via TLS. For example socks server tunneled via SSH which in turn is tuneled via TLS to your gateway. Or perhaps you can somehow get your SSH client to transmit "GET " at the beginning of the connection, have the…

If it’s over https, an outside observer has no way of knowing your stream started with a GET. Unless they’ve tapped ssl certificates, but that would be major news

They are tapped into SSL certificates, those that are generated in China. Plus wherever the Chinese intelligence managed to install their "plugins".
Post reply on HN