Live data from Hacker News

How the great firewall of China detects and blocks fully encrypted traffic [pdf]

gfw.report

31–40 of 289 posts

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#31
Interesting that it's cracking down on Shadowsocks with obfuscation plugins. SS w/ v2ray was more or less the gold standard when I was going there from 2017 to 2019.

Back then, certain times (early June, big government meetings) would see a crackdown on VPNs where, so far as I could tell, they just threw down crude blanket blocks on anything they sorta-kinda knew was a VPN but couldn't procedurally target-block. It would (usually) still connect but be rate-limited to essentially nothingness.

I always got the vibe that they sort of informally tolerated VPNs above a certain threshold of sophistication, figuring that they were more interested in blocking the low-hanging fruit that the unwashed masses could easily use, rather than something more sophisticated that only a few techno-nerds could utilise. As other posters have said, they'd know who was doing it and preferred to come knocking with a rubber hose if those people caused too much in the way of issues.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#33
post #2

Seems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...

Why would they let that happen? Doesn't seem to make any sense to me if it's how you describe it.

Yes, that is why I also found it interesting. As to their motives - I cannot comment.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#34

Earlier quoted context omitted.

that's mentioned at the end of Page 17. The author tells it's a short term solution: "This is merely a stopgap measure, as the censor can enable their censorship for UDP." It doesn't seem that there are any (long term) solution to bypass the rules ...

steganography?

Hiding the encrypted messages so that it looks like other normal traffic. Like encoding your encrypted message (subtly) in the pixels of an image (like noise).

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#35

Can you bring a Starlink and then just don't really care?

Maybe you can, but the Chinese "VPN law" used some wording like "unauthorized communication channels" without further definition. They can just call Starlinks "unauthorized" and start confiscating them, just like what they did to the satellite dishes for receiving foreign TV signals.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#36
post #2

Seems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...

Wireguard is detected within the first minute of usage and blocked. The ping is a dead giveaway.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#38
post #2

Seems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...

I'd go for ssh if I was trying to bypass it. At least legally I can claim that I'm just sshing to my aws server and not be jailed for using vpn.

using ssh for proxying is getting blocked within the first minute.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#39
post #15

Earlier quoted context omitted.

We have a satellite office in Dubai. I know their static IP. When they connect to our imap/smtp server they are coming in from another IP. I never looked into it deeply but assumed their connection is being diverted for inspection. (If true, they would probably not be below performing industrial espionage with the data they are accessing)

Is the IMAP/SMTP connection not encrypted?

Doesn't matter if the government mandates MITM and forces install of root certs on all clients.

Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]

#40
post #18

On the other hand, this shows GFW authors are more, and more considerate of the collateral damage, which is a surprise. It seems GFW has indeed became good enough to frustrate casual users to trigger uproar when windows update, or AWS ip ranges go belly up, or something. VPN authors should chose the maximum collateral damage strategy to frustrate GFW authors, make China as close as possible to completely cutting off…

From my understanding, this is what TOR did for some time. They tried to make it look as close as possible to HTTPS.
Post reply on HN