I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…
How the great firewall of China detects and blocks fully encrypted traffic [pdf]
91–100 of 289 posts
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#92Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#93I’ve done so much experimentation with GFW pre pandemic while staying in China for extended period of times. I was always amazed at how quickly they would catch up on my shadowsocks, random ssh tunnels…etc. 48 hours top before I had to rotate IPs. This report seems to indicate this is now instant? Fwiw My most reliable trick ended up piggie-backing off of a physical line going into Hong Kong from Shenzhen, and when r…
There's a more straightforward way: roam with a foreign sim card. Roaming traffic is tunneled to your home telco and for whatever reason the tunnel isn't inspected at all. With the advent of esims you can buy a roaming sim and use it on your phone within minutes.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#94Given HTTPS traffic is mostly permitted, could one obfuscate VPN traffic over http/3 (which I believe is UDP)?
Could China implement a MitM proxy for HTTPS traffic like many companies do?
Companies get around ssl issues by minting their own root CAs and configuring their workstations to trust them. China has no (technical) way of forcing you to trust their root CA
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#95What kind of websites does China block?
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#96Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#97Earlier quoted context omitted.
There's a more straightforward way: roam with a foreign sim card. Roaming traffic is tunneled to your home telco and for whatever reason the tunnel isn't inspected at all. With the advent of esims you can buy a roaming sim and use it on your phone within minutes.
Can you activate it while abroad though? After I moved away from the UK I still had to have a UK mobile phone for various things. My UK sim would stop working after about a year away. When buying a new one I had to get someone in UK to put it in their phone to let it at least once connect to the home network. Without it the card would be useless. Is using foreign sim cards now easier?
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#98Maybe it's good for the world that they burn so much talent and wealth on adding inefficiency to their internal information exchange.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#99Seems like UDP is completely exempt, which would allow UDP-based VPNs, like Wireguard through. SSH is also exempt...
I'd go for ssh if I was trying to bypass it. At least legally I can claim that I'm just sshing to my aws server and not be jailed for using vpn.
Your mistake is assuming that China has rule of law. If you're in China and you upset Xi enough, you get jailed/disappeared even if you technically didn't break any laws on the books.
Re: How the great firewall of China detects and blocks fully encrypted traffic [pdf]
#100Deeply unethical stuff. Why are Chinese people not currently trying to overthrow this garbage?