Live data from Hacker News

Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

gfw.report

81–90 of 195 posts

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#81

How is traffic controlled inside PRC? Is GFW a central hub for all traffic between all hosts? Or between residential ASNs and commercial ones only? In the UK and Iran a lot of censorship was implemented by leaning on ISPs at IP level (eg BT Cleanfeed) and with DNS blocks but I haven’t kept up to date with how networks might handle residential hosting. Maybe internal traffic is just all banned?

It's in operators but managed by the regional government.

So what's blocked differs by region

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#82

How is traffic controlled inside PRC? Is GFW a central hub for all traffic between all hosts? Or between residential ASNs and commercial ones only? In the UK and Iran a lot of censorship was implemented by leaning on ISPs at IP level (eg BT Cleanfeed) and with DNS blocks but I haven’t kept up to date with how networks might handle residential hosting. Maybe internal traffic is just all banned?

> How is traffic controlled inside PRC?

Unknown. I haven't seen any injected fake DNS or reset packets so far to domestic hosts. But there are rumors that Google's servers in Beijing (AS24424) was once black holed.

> Is GFW a central hub for all traffic between all hosts?

It's supposed to has centralized management system, but not a single hub.

> Or between residential ASNs and commercial ones only?

Yes, the injecting devices are deployed in IXPs, the AS borders. See .

> In the UK and Iran a lot of censorship was implemented by leaning on ISPs at IP level (eg BT Cleanfeed) and with DNS blocks but I haven’t kept up to date with how networks might handle residential hosting.

I believe Iran has more centralized system like China controlled by Tehran.

> Maybe internal traffic is just all banned?

No, internal HTTPS traffic is not banned in that hour.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#83
post #66
post #29

Earlier quoted context omitted.

Depends a lot whether Starlink decides to let you.

No it does not. Against a huge state adversary like China it does not matter. They have satellites looking down so they can quickly locate any starlink users. And then ... The only thing that could bypass is GPS + laser links (meaning physically aiming a laser both on the ground AND on a satellite). You cannot detect that without being in the direct path of the laser (though of course you can still see the equipment…

What makes it so that this kind of precision is required? I have little knowledge of the physics behind it, but a few decades ago, a local university had an open day where they bounced lasers off of a retro reflector on the moon to measure the distance: https://en.wikipedia.org/wiki/Lunar_Laser_Ranging_experiment...

The moon is 700 times farther away than the starlink satellites (or twice that, if you consider the bounce), so I find it hard to imagine that it would be impossible to communicate with much closer satellites over laser when both sides can have an active transmitter.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#84

Think of how many people who have remote jobs with American companies couldn't connect to their meetings while they "work from home" while secretly being in China! Normally they have to fight VPN issues anyway, but having a sovereign state inject your packets is certainly a fun new one.

Anyone operating in/around China who needs a real VPN has a service they pay for and use that isn't mainstream that isn't blocked (using V2ray or similar). There's a reason why Shadowrocket is the number 1 app on the app store. I'm sure there are a lot of cases of people using e.g., off-the-shelf VPN apps and have trouble, but power users in China are always running a VPN, usually to Japan, that doesn't have this problem.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#85
post #66
post #29

Earlier quoted context omitted.

Depends a lot whether Starlink decides to let you.

No it does not. Against a huge state adversary like China it does not matter. They have satellites looking down so they can quickly locate any starlink users. And then ... The only thing that could bypass is GPS + laser links (meaning physically aiming a laser both on the ground AND on a satellite). You cannot detect that without being in the direct path of the laser (though of course you can still see the equipment…

The aim doesn't need to be that accurate. Laser beams diverge due to diffraction. You can't break the laws of physics - a non-divergent laser beam would need to be infinitely wide. A 1cm wide laser beam of 700nm light will have a divergence width of approximately asin(0.0000007/0.01) which is 0.004 degrees, which is 14 arcseconds, which is very easily aimable using off-the-shelf components. People get a tracking accuracy around 1 arcsecond using standard hobbyist telescope mounts.

However, this solution is going to stop working when a cloud drifts past.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#86
post #2

Terrible, this is Internet curfew. It's not uncommon to imagine they'd shutdown Internet across border during any war (like against Taiwan).

> Terrible, this is Internet curfew. If you think this is bad... You can't even have a blog in China without authorization. It doesn't matter if you pay "AWS" for a machine. It won't open port 80 or 443 until you get an ICP recordal. Which you can only do if you are in China, and get the approval. It should also be displayed in the site, like a license plate. The reason "AWS" is in quotes is because it isn't AWS, the…

Not all Western companies comply with Beijing, like Route53, a name I've never heard of; Cloudflare seems to be most popular in China.

But yeah, they can shutdown anything unless proxy server is widely used. as .

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#87
post #40

Earlier quoted context omitted.

Yeah if I'd sneak off to work from another place I'd pick somewhere really nice. Not China.

China spans 9.6M km. It has some of the biggest and most modern megacities (Beijing, Shanghai, Chongqing, Shenzhen to name a few) and features ancient historical wonders like the Great Wall, Forbidden City and Terracotta Warriors. The nature spans salt lakes and rainbow mountains akin to South America, to the Northern Lights in Mohe down to karst formations of Guilin shared with Vietnam's Halong Bay. The cuisine is d…

None of that matters when it's not a safe place to be.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#88
post #86

Earlier quoted context omitted.

> Terrible, this is Internet curfew. If you think this is bad... You can't even have a blog in China without authorization. It doesn't matter if you pay "AWS" for a machine. It won't open port 80 or 443 until you get an ICP recordal. Which you can only do if you are in China, and get the approval. It should also be displayed in the site, like a license plate. The reason "AWS" is in quotes is because it isn't AWS, the…

Not all Western companies comply with Beijing, like Route53, a name I've never heard of; Cloudflare seems to be most popular in China. But yeah, they can shutdown anything unless proxy server is widely used. as .

AFAIK Route53 is AWS’s managed DNS product, not a company.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#89
post #88
post #86

Earlier quoted context omitted.

Not all Western companies comply with Beijing, like Route53, a name I've never heard of; Cloudflare seems to be most popular in China. But yeah, they can shutdown anything unless proxy server is widely used. as .

AFAIK Route53 is AWS’s managed DNS product, not a company.

OK, AWS again, I know it not only complies with Beijing but also Russia and many other dictatorships. Banned domain fronting and recently enforced S3 bucket-based subdomains for government to better inspect.

Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

#90

How would one get around this if they found themselves in such a situation?

Well for starters recreate the situation and test out different approaches. Thanks to the detailed analysis that can be attempted. If I understand right, a good next step would would be with eBPF or some type of proxy ignore the forged RST+ACK at the beginning. Then it would come testing to see if sending a bunch of ACK packets, perhaps with sequence numbers that would when reconstructed could complete the handshake.…

> ignore the forged RST+ACK

See in 2006. That won't work if RST/ACK was injected to both sides.

> Then it would come testing to see if sending a bunch of ACK packets, perhaps with sequence numbers that would when reconstructed could complete the handshake. Trying to send them alongside the SYN+ACK or even before if it can be predicted. Maybe try sending some packets with sequence id 0 as well to see what happens.

This is an interesting approach already being utilized, namely TCB desync. But currently most people tend to buy VPN/proxy services rather than studying this.

Post reply on HN