Live data from Hacker News

China Tells Carriers to Block Access to Personal VPNs by February

bloomberg.com

21–30 of 141 posts

Re: China Tells Carriers to Block Access to Personal VPNs by February

#21
post #16
post #6

Time to get funds for 443 port vpn startups. ;) Hint: TLS encrypted traffic following an appropriate browser-style handshake cannot be distinguished from "legitimate" https.

Yes, it can. By watching the size and timing of flows with 'regular HTTPS' traffic vs 'VPN HTTPS' traffic, it can be distinguished.

If you can calculate the difference, couldn't a VPN force their traffic to mimic that difference as well?

Re: China Tells Carriers to Block Access to Personal VPNs by February

#22
post #16
post #6

Time to get funds for 443 port vpn startups. ;) Hint: TLS encrypted traffic following an appropriate browser-style handshake cannot be distinguished from "legitimate" https.

Yes, it can. By watching the size and timing of flows with 'regular HTTPS' traffic vs 'VPN HTTPS' traffic, it can be distinguished.

So write a program that emulates 'regular HTTPS' traffic patterns. On the technical side of things, I'm pretty sure the VPNs have the upper hand in this game of cat and mouse.

Re: China Tells Carriers to Block Access to Personal VPNs by February

#23
post #20

Previously, there was an implicit understanding that the Great Firewall was in place to prevent unauthorised access to the Internet by the masses. This is to prevent them from being influenced by foreign media, prevent too much information leakage of citizen info (e.g. via facebook), and to give Chinese tech companies a monopoly in China. If, however, you had the will and ability to use VPN software, the government u…

Non-sense. Just check online articles and blogs to see when they started to block stuff like linux ipsec vpn. You may also check the reports on how/when they "talk" to the shadowsocks vpn author to force him to stop working on the project.

  > they "talk" to the shadowsocks vpn author to 
  > force him to stop working on the project.
just some side note...

the author of shadowsocks vpn is "her", a girl goes by the id "clowwindy"...

Re: China Tells Carriers to Block Access to Personal VPNs by February

#24

China is one black swan event away from an economic collapse and possible Arab spring. The authoritarian Chinese government is starting to have some sense of fear now. Between the 300%+ gdp/debt ratio, second real estate bubble bursting in shanghai/tier1 cities, huge spike in shadow lending, stalled stock market, complete frozen capital control, Trump's 100 day ultimatum to China regarding trade deficit, demographics…

China undoubtedly faces many challenges, as you fairly point out.

However, there's a long history in China that determines the thinking of both the government and its people. That view is that a strong centre leads to a peaceful and prosperous China, while a weak centre leads to confusion and chaos. An Arab Spring-like event isn't as likely, there just isn't the same desire to be liberated.

No one would challenge the centre unless they were prepared to go all the way. And there's a very powerful state security apparatus ready to come down hard if they do.

Re: China Tells Carriers to Block Access to Personal VPNs by February

#25

China is one black swan event away from an economic collapse and possible Arab spring. The authoritarian Chinese government is starting to have some sense of fear now. Between the 300%+ gdp/debt ratio, second real estate bubble bursting in shanghai/tier1 cities, huge spike in shadow lending, stalled stock market, complete frozen capital control, Trump's 100 day ultimatum to China regarding trade deficit, demographics…

Watch USDCNY and CNH/CNY spreads.

Re: China Tells Carriers to Block Access to Personal VPNs by February

#27
post #10

With China, there is a big difference between what is said, what is law and what is actually enforced. What's likely to happen is that there will be a crack down, some satisfying numbers will be shown to officials, and then everything will become back to normal soon after. There has been this kind of talk about cracking down on VPN before, and it's still available, so wait and see

I have a hunch that these kind of news had been circulated before, officials threw a few sacrificial lambs in to reach the quota, then the headlines fade slowly into background.

Re: China Tells Carriers to Block Access to Personal VPNs by February

#28
post #22
post #16

Earlier quoted context omitted.

Yes, it can. By watching the size and timing of flows with 'regular HTTPS' traffic vs 'VPN HTTPS' traffic, it can be distinguished.

So write a program that emulates 'regular HTTPS' traffic patterns. On the technical side of things, I'm pretty sure the VPNs have the upper hand in this game of cat and mouse.

GFW does not just inspect traffic, it actively probes server IP:ports looking for its responses, can replay packets you sent legitimately, and can impersonate IP addr behind GFW.

As in, it is not only a passive observer periodically resetting connections, it will also make its own to test the waters

Re: China Tells Carriers to Block Access to Personal VPNs by February

#29
post #20

Earlier quoted context omitted.

Non-sense. Just check online articles and blogs to see when they started to block stuff like linux ipsec vpn. You may also check the reports on how/when they "talk" to the shadowsocks vpn author to force him to stop working on the project.

> they "talk" to the shadowsocks vpn author to > force him to stop working on the project. just some side note... the author of shadowsocks vpn is "her", a girl goes by the id "clowwindy"...

clowwindy is male. the current maintainer of shadowsocks is a female.

Re: China Tells Carriers to Block Access to Personal VPNs by February

#30
post #16
post #6

Time to get funds for 443 port vpn startups. ;) Hint: TLS encrypted traffic following an appropriate browser-style handshake cannot be distinguished from "legitimate" https.

Yes, it can. By watching the size and timing of flows with 'regular HTTPS' traffic vs 'VPN HTTPS' traffic, it can be distinguished.

Statistical analysis of traffic flow in encrypted communications to determine the type of traffic has been done effectively. There was a paper a few years ago against VoIP protocols specifically.
Post reply on HN