The comments from people obviously never having been into a restricted country are hilarious. There are a few, most likely shadow approved, VPN providers that work. I refuse to believe they are just smarter than the GFW. I am convinced they are sanctioned and monitored. Which is fine if you never have any beef with the government. Which you never know you do until you do. Stuff like socks5/shadowsocks and wireguard h…
Can't you use a "sanctioned" VPN to tunnel your connection to a "real" VPN or any wireguard endpoint? They could still be able to find out you're using a VPN, but not monitor your traffic.
How the great firewall of China detects and blocks fully encrypted traffic [pdf]
161–170 of 289 posts
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#162This paper is nice, but it goes over some finer technical things. So, not about the great wall, but there's projects out there, like this one https://github.com/salesforce/ja3 , which talk about how you can fingerprint fully encrypted traffic(TLS/HTPS). There's a great section in the Readme "How it works" that goes over it. Would be surprising if the great wall doesn't do this, when some open source firewall will.
Chrome randomizes the ClientHello these days[1], so JA3 is obsolete in that sense. You could still build a fingerprint off of the common advertised TLS parameters, disregarding their order. The linked paper references an incident where the list of ciphersuites were used to detect Tor-obfs connections[2][3]. [1] https://www.fastly.com/blog/a-first-look-at-chromes-tls-clie... [2] https://gitlab.torproject.org/legacy/tr…
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#163Earlier quoted context omitted.
We have a satellite office in Dubai. I know their static IP. When they connect to our imap/smtp server they are coming in from another IP. I never looked into it deeply but assumed their connection is being diverted for inspection. (If true, they would probably not be below performing industrial espionage with the data they are accessing)
I've debugged connection issues with someone in China. The same person, using the same browser and at the same time, showed up in the logs of two cloud apps with different IP addresses. The applications were adjacent in the cloud, same network config and everything. We figured there was always redirection, and we were never seeing their "true" IP address. A simpler test is to search "what is my IP" and compare the va…
Even when we had physical machines in Chinese data centers it didn't mean that our service was reachable from all ISPs. In 2010 we gave up on that and just started using Akamai China CDN with our servers in Europe.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#164I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…
I wonder if the whole tor obsf4 and snowflake business works with the GFW.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#165Earlier quoted context omitted.
When I was in China in 2019, the VPN built into google fi actually got me around the GFW with zero effort. I didn’t even realize it until I caught myself checking American social media unhindered. My experience is most younger and tech savvy people have a VPN. It’s common / casual, like speeding your car by 10mph on the highway. Most people are not persecuted for using a VPN, I assume that’s reserved for people who t…
I think China doesn’t care if foreigners use a VPN, it’s their own people they want to keep under control.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#166I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…
Many years back I was running a socks proxy for access while in China and I found that it worked great in Shanghai but was rapidly blocked (or degraded in some fashion) in Hangzhou. That seemed internal and not edge but I do no really know how they were interfering with it. Given Hangzhou's tech expertise it just may be the ISP there was more capable and up to date?
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#167Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#168I was wondering about simply using VPNs, which is not mentioned in the article at all, but checking GFW on Wikipedia, it tells: > The use of VPNs in China can provide individuals access to the international internet, but in China, it can be a potential legal risk. In 2017, the Chinese government declared all unauthorized VPN services to be illegal.[94] An example of the use of this punishment is Vera Zhou, a student…
More context about this WikiPedia excerpt: → https://www.chinafile.com/extensive-surveillance-china → https://www.rfa.org/cantonese/news/student-01272020075256.ht... It looks like 周月明 (Vera Yueming Zhou) was sent to a Chinese concentration camp mostly because she was part of a religious minority and not necessarily for using a VPN to access the University of Washington’s website. > Vera was living in her hometown of…
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#169The comments from people obviously never having been into a restricted country are hilarious. There are a few, most likely shadow approved, VPN providers that work. I refuse to believe they are just smarter than the GFW. I am convinced they are sanctioned and monitored. Which is fine if you never have any beef with the government. Which you never know you do until you do. Stuff like socks5/shadowsocks and wireguard h…
idk if i'm smarter than the GFW but every time I rolled my own censorship-circumvention tool it worked well, even the most lazy way worked. I've never used any VPN provider. And FYI even unchanged WireGuard still works, though there seems to be some offline traffic analysis looking for that, so once a week you'd wake up to your VPN connection broken and had to change ListenPort on the server.
The only annoying thing for me is: f- you AWS, egress too damn expensive!
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#170Earlier quoted context omitted.
More context about this WikiPedia excerpt: → https://www.chinafile.com/extensive-surveillance-china → https://www.rfa.org/cantonese/news/student-01272020075256.ht... It looks like 周月明 (Vera Yueming Zhou) was sent to a Chinese concentration camp mostly because she was part of a religious minority and not necessarily for using a VPN to access the University of Washington’s website. > Vera was living in her hometown of…
Exactly. This is the period when Muslim ethnic groups like the Uigurs were being rounded up on any pretense to be reeducated into not wanting to be separatists anymore (often with no indication that they had anything to do with separatism other than their ethnicity.) Seeing the VPN pop up was more than enough of an excuse. Calling it a "genocide" is 99% propaganda, but it was obviously a sinofication meant to get rid…
"sinofication" sounds a lot like "eliminating the existing culture" which sounds a lot like genocide. Genocide is more than just murdering everyone like in some of the most well known cases like the Holocaust -- it includes elimination of an ethnic group by any means possible, including "nativification"