Live data from Hacker News

Tell HN: The Internet situation inside Iran

news.ycombinator.com

131–140 of 198 posts

Re: Tell HN: The Internet situation inside Iran

#131
post #101
post #83

Signal is setting up proxies so users in Iran using Signal could update their proxy settings in the app to bypass the block for that at least. Not sure to what extent things are being blocked, but if you can get connections to SOME outside services, this might help people to organize means of communication. The proxies are also setup by people outside of Iran and it doesn't really matter if someone in Iran leaks a pr…

I set up several proxies, and only sent their addresses per mail. A Problem is that we have no idea which contact is trustful and which not, so in the end our proxies were blocked after a really short amount of time. Does anyone has successfully deployed such a proxy and it has actually been used without being blocked? Is there any best practice / experience? I am furthermore searching for a method to check whether i…

I think this needs to be approached with a throwaway mentality. You setup a proxy, it gets blocked, you setup a new one. I do agree that we cannot know who is reporting them or who is leaking the proxy addresses and ideally it would be great if a few people from within Iran could coordinate these and hand them out to other trusted people and have those share them out to friends/family/etc.

However, I think we shouldn't forget that we have no real way of knowing if any of this works in all regions, what sort of access/blocks people there need to go through to connect to even basic services. So maybe instead of being worried ONLY about these issues (which are more in line with our skill set), we should try and pressure our own elected officials to take some measures, any measures to help people there.

You can setup an Ansible playbook and automate the whole deployment without any issues. Most VPSes cost a few cents a day to run and could serve a lot of people. The technology aspect on our end has never been the bottleneck or the problem, but rather how to disseminate these bits of information to those who need them the most and how to actually stop this from happening yearly/monthly across the world.

So I guess what I'm trying to say is thank you for your efforts, keep it up and if you know people there who can spread information about these solutions, even better! We don't know for sure the restrictions we need to fight through, so it would be great to know more about that... And in the meantime, drop an email if nothing else, to your local representatives/elected officials and ask them to do something, anything at this point, to support people exercising their right to protest. Because it's quickly becoming an optional extra even in the West.

Re: Tell HN: The Internet situation inside Iran

#132
post #63

I wish you the best of luck. When similar events unfolded in Syria, people created redundant social networks of fake Facebook accounts. This seemed to work well. When captured and tortured, people would hand over credentials for one account. People would detect that network was "burned" and move to the next one. This gave the officials very little information, since the accounts did not reference real names, and loca…

According to my friend in Iran, Facebook has been banned for some time. Same with FB Messenger.

She has been successful using VPN and WhatsApp until today. I don't know if I'll ever hear from her again.

Re: Tell HN: The Internet situation inside Iran

#133

Earlier quoted context omitted.

I have not heard of Session before now. I don't want to seem insensitive to the Iran situation, but how does Session compare to other popular encrypted messaging services?

https://github.com/oxen-io Seems to be a fork from Signal by oxenio. It's selling point seems to be the crypto currency relation?

Yup, they are selling usernames for $

Re: Tell HN: The Internet situation inside Iran

#134

Earlier quoted context omitted.

I have not heard of Session before now. I don't want to seem insensitive to the Iran situation, but how does Session compare to other popular encrypted messaging services?

https://github.com/oxen-io Seems to be a fork from Signal by oxenio. It's selling point seems to be the crypto currency relation?

More decentralized and censorship resistant than Signal, which that is sitting on Google's servers. Google has the ability to shut Signal down if they wanted to or if asked to by the authorities, since Signal is helping others evade sanctions illegally without a license.

Signal also has a private cryptocurrency attached to it, most definitely used by criminals, scammers and even pump and dumped by the founders which one of them are the founders of Signal. (Yes. Moxie is part of it.)

Re: Tell HN: The Internet situation inside Iran

#135
post #75

What happened to starlink?

Terminals have to get in-country and there needs to be usable ground stations in the same cell as the terminal. Good luck getting a terminal to Tehran where the police are apparently gleefully destroying satellite dishes. Even if you got an intact terminal there's no ground station nearby. StarLink has been given special dispensation to operate in Iran. This is not the same as air dropping a warehouse worth of termin…

I wonder how internet quality scales of antenna size. Would a covert antenna with a quarter of the area of a regular antenna give you somewhat usable internet?

Re: Tell HN: The Internet situation inside Iran

#136

Earlier quoted context omitted.

This is a good recommendation. Using Tor sounds good in theory, but it's too far easy to identify all of the Tor connections and identify the residences connected to them. I would suggest using SSH tunnels on whatever port a given server normally communicates on. If this is 443, connections should just look like normal web browsing on an ISP level. If the server is used to transmit other data over TLS using that port…

> If this is 443, connections should just look like normal web browsing on an ISP level Except that it doesn't look like TLS - depending on what the traffic inspection capabilities look like I imagine someone speaking SSH on port 443 is pretty incriminating :/

ssh over 443 is likely to be rather common since most firewalls leave 443 alone

Re: Tell HN: The Internet situation inside Iran

#138

Back in the 80's, I remember that people were protesting without internet and mobile phones, with very successful results. They bought down the iron curtain after all. The most sophisticated technology they used was the printing press, for printing and distributing fliers, newspapers and censored books. Underground groups were organized in cells too, without phones, email or apps. Right now, it seems like those who u…

> Back in the 80's, I remember that people were protesting without internet and mobile phones, with very successful results.

Back then, the governments didn't have that either. Pigs on the streets with barely working (or understandable) radios, outdated huge paper maps, and if they were lucky a barely working chopper for a bit of aerial surveillance. The only tools were water cannons, batons, tear gas that didn't work against drunk people, shields and live ammo.

These days, the abilities of governments in counter-protesting are absurd:

- each pig has not just a radio with high quality audio transmission, but also a digital data channel for streaming video and other intel in both directions

- tons of surveillance cameras with high definition imaging sensors

- cheap-ass drones

- there are multiple vendors offering "data fusion" for command centers. Think of platforms that fuse everything into one cohesive environment: a Google Maps map and satellite view, with individual position markers for each unit, live feeds from thousands of surveillance cameras, live feeds from officer body cameras, live feeds from drones and choppers, AI analyzing all of that to predict movements of the masses, incoming firehose feeds from Twitter and Facebook...

- highly effective tear gases, mobile walls on tanks to lock down streets [first photo of 1], tasers, rubber bullets, LRAD acoustic weapons and other non-deadly tools for crowd control

It's hard to mount successful protest against nations that have half the stuff I just described, and as HK shows all but impossible against a nation that does have this kind of abilities.

[1] https://www.hrw.org/news/2018/12/14/france-police-crowd-cont...

Re: Tell HN: The Internet situation inside Iran

#139
post #84
post #56

Can people use a steganography app to communicate via innocuous images? 1. Take a picture. 2. Use app to insert message into picture, encrypt with passphrase. 3. SMS picture to friend or upload to Iranian equivalent of imgur (if any is up). 4. Friend loads picture into app and types passphrase to get message. I'm not sure what a good choice of app would be, but something good must exist?

Is there any good open source or publicly usable steganography software with reasonable UX? Page 1 of Google shows this thing called OpenStego. I've heard of steganography but have no idea what tools are reputable in this space.

Does steganography break when Social media sites reprocess images? I.e. do you need to access the underlying raw bytes?

Re: Tell HN: The Internet situation inside Iran

#140
Yes, V2Ray VMess and ShadowSocks are the most reliable tools. They were fully tried and tested in China, where has a similiar issue.

Deploy a proxy server is the first step. Take the experiences from China:

1. Always try to pretend to be a normal traffic. Your ISP, DC, all the entities alongside your network, they will all try to detect you and ban/jail you. In China, they detect the symbol of unnormal traffic, record everyone using the default proxy port, training ML model to find proxy users. If your gov does not have the tech, I believe China Gov will surely exports them.

2. Always beaware about the help. Gov may publish some honeypot VPN to monitor the opponent. The public server or deployment script may have backdoor or virus.

That's a war never end.

Post reply on HN