[HN Gopher] The Iran Firewall: A preliminary report
       ___________________________________________________________________
        
       The Iran Firewall: A preliminary report
        
       Author : chmaynard
       Score  : 169 points
       Date   : 2022-10-28 13:27 UTC (9 hours ago)
        
 (HTM) web link (blog.thc.org)
 (TXT) w3m dump (blog.thc.org)
        
       | LastTrain wrote:
       | I almost stopped reading at "neo-liberal", man that term is
       | getting boring, especially when used in non-sequitur fashion like
       | "The most severe disruption is when the regime turns off all cell
       | towers and all local Internet. They just pull the plug and it's
       | game over for any neo-liberal smart-arse that thinks
       | v2ray/tor/shadowsocks is the solution". WTF does that even mean?
       | What does the author think it means?
        
         | spamizbad wrote:
         | I think the author is suggesting global capitalism is effete
         | when it comes to combating state-sponsored censorship.... which
         | I think is true.
        
           | LastTrain wrote:
           | The most generous interpretation so far, but the bar is low.
           | To accept that applies here is to accept that what is going
           | on in Iran right now is entirely being orchestrated by
           | outside forces and the citizen protesters have no agency. I'm
           | familiar with this worldview, and I know the ilk that spread
           | it.
        
         | unethical_ban wrote:
         | I'm a liberal by most definitions but I didn't reject a decent
         | technical article by presumably an advocate of political
         | freedom in Iran because of my sensitive sensibility.
        
           | LastTrain wrote:
           | Did your sensibilities keep you from reading the rest of my
           | comment? Sadly, it didn't keep me from reading the article -
           | which had no interesting information on the GFI in particular
           | or even firewalls in general. I should have went with my gut
           | on this one.
        
         | dmos62 wrote:
         | > What does the author think it means?
         | 
         | A detestable person that thinks he can circumvent the regime?
         | Presumably a paleo-conservative (or whatever the opposite of
         | neo-liberal is in the mind of the blogger) would not be so
         | naive and would look at real "solutions", as opposed to the
         | neo-liberal, who is interested in non-solutions.
         | 
         | Pretty awful ideas floating around in this guy's head.
        
         | [deleted]
        
         | dmix wrote:
         | I'm not sure what he means by that. Is it just a tongue-in-
         | cheek description for the opposition to the Iranian party? Is
         | it used by the party to describe pro-western people locally? Or
         | is this just another overused Redditism?
        
           | LastTrain wrote:
           | It is a play on neo-con, which is a term that was used to
           | great affect in American conservative political circles to
           | ostracize those who would cooperate with the opposition party
           | - a.k.a. moderates. It is now used with similar goals by the
           | American far left (to the extent that such a thing exists..).
           | Both terms are often coopted by the the opposition party to
           | demonize moderate counterparts.
           | 
           | That said, it sounds cool to mouth-breathers so they often
           | use it completely out of context, like this author did.
        
             | xhevahir wrote:
             | That sense of "neoliberal" is peculiar to American
             | politics, as far as I can tell. I'd say it's more likely
             | the blogger means a person who wants free trade,
             | deregulation, etc.
        
               | LastTrain wrote:
               | I would say, given the sum total output we've seen by the
               | author (a blog with two articles), they have no idea what
               | it means, other than a vague sense that it is some kind
               | of sick burn. [Edit - look, I know the term has an
               | academic origin, but we aren't discussing academic
               | papers, I'm talking about how it is abused everyday in
               | the vernacular]
        
             | hot_gril wrote:
             | I've heard neocon many times, always in a different
             | context. As far as I'm concerned, the word has no meaning.
        
               | xhevahir wrote:
               | I don't see how it's any less meaningful than "liberal,"
               | or "conservative." Each of these terms labels a set of
               | family resemblances and is dependent on context.
        
               | hot_gril wrote:
               | "Liberal" is at least a really imprecise synonym for
               | Democrat party in the US, ditto for "conservative" and
               | Republican.
        
         | pvg wrote:
         | _Please don 't pick the most provocative thing in an article or
         | post to complain about in the thread. Find something
         | interesting to respond to instead._
         | 
         | https://news.ycombinator.com/newsguidelines.html
        
         | throwaway894345 wrote:
         | Eh, I don't like neo-liberal either, but its usage here made me
         | chuckle. I'm probably a "neo-liberal" since I generally believe
         | in human rights (including free speech) and also that
         | capitalism (for all its faults) has a dramatically better track
         | record than socialism or communism.
        
           | didibus wrote:
           | I was super confused by the authors use of neoliberal and I'm
           | also confused by how you use the term.
           | 
           | A liberal is someone who values individual freedoms and human
           | rights.
           | 
           | A neoliberal is someone who values deregulated economy,
           | privatization of all things, free markets, free trade, and
           | open economic borders.
           | 
           | The Iranian regime would be a conservative one, where they
           | value limited social rights that favor some social morals
           | over the individuals own, like what women/men can and can't
           | do, what you can and can't eat, what you can and can't drink,
           | what you can and can't teach or believe in, etc.
           | 
           | The Iranian economic model is a mixed bag, kind of a social-
           | caputalist mix, with lots of state owned and managed
           | enterprise, but also allowing private ones. That said it
           | comes with a lot of regulations to have them enforce the
           | conservative social norms.
        
         | eternalban wrote:
         | The Iranian regime classifies enemies ("counter
         | revolutionaries" in the old days). We have the hypocrites
         | "MEK", monarchists, a newly minted "meddlesome Shia" (mainly
         | Iraqis but basically any Shia who disagrees Khamenei is God's
         | Shadow on earth smh), and westernized youth "neo-liberals". So
         | OP's sentence makes perfect sense actually.
         | 
         | p.s.
         | 
         | Basically the occupation theocratic regime of IR positions
         | itself in its _propaganda to demoralize_ Iranian resistance by
         | prophecies of doom and gloom for Iran should it be cured of the
         | IR disease: there is ISIS or Daesh [or  "it will Syria 2.0"]
         | (aka terror); there is that crafty prince in KSA that wants
         | Iran to parition; there is the crafty sultan in Turkie (sic)
         | that has pan turk on his mind; and should the country remain
         | intact let there be no doubt that "neo-liberals" will do a
         | Greece or whatever to Iran.
        
         | technoooooost wrote:
         | Pretty sure he's joking around using iran's regime terms to
         | describe its dissidents
        
           | hot_gril wrote:
           | The top says this, which doesn't sound like a joke.
           | 
           | > The Internet is easily censored. The neo-liberals got their
           | arses kicked. The big players like Google/Apple/AWS are
           | partly to blame. China runs the GFI as a service.
        
             | killjoywashere wrote:
             | The point is the neo-liberals of Silicon Valley, who
             | essentially adopt a policy of splendid isolation, have
             | failed to protect democracy.
        
               | DeathArrow wrote:
               | Since when was their job to protect democracy?
        
               | killjoywashere wrote:
               | Since they claim US citizenship. Citizenship is a bit
               | more than your token to ride the bus.
        
               | nonrandomstring wrote:
               | Since the basis of their entire project [1] was given to
               | them as the output of an obscure DARPA project ostensibly
               | aimed at securing democracy in the world. It's not
               | written into a contract, just a sorta "moral obligation"
               | to, you know... not shit on the values of the people who
               | put you where you are.
               | 
               | [1] https://en.wikipedia.org/wiki/Internet
        
               | hot_gril wrote:
               | I agree that it's their job, I don't agree that they've
               | adopted a policy of isolation, but whatever. It's just
               | not a good way to start a tech article.
               | 
               | The author mentioned some of the blocking methods, so
               | that's cool.
        
         | ogurechny wrote:
         | It's just a media-friendly way to call people who believe that
         | money doesn't stink, and that to each what he deserves. Which
         | is true for most "successful" corporate functionaries whose
         | exuberance naturally depends on that same tight control over
         | user devices.
        
       | Roark66 wrote:
       | You know what is crazy. I recently heard 20% of adult population
       | in Iran is in Revolutionary Guard. This puts things into context
       | for anyone who says "why don't people just overthrow the
       | dictatorship". However, there were dictatorships with an even
       | stronger hold on their population that fell. Usually for economic
       | reasons. I hope Iran's regime will follow.
        
         | blacksmith_tb wrote:
         | Hmm, that seems way too high? They're a branch of the
         | military[1], which is the biggest standing army in the Middle
         | East, but even the whole army comes to about a million for a
         | country of 86M.
         | 
         | 1:
         | https://en.wikipedia.org/wiki/Islamic_Revolutionary_Guard_Co...
        
       | ghostpepper wrote:
       | "All blacklisted domains resolve to 10.0.34.35"
       | 
       | I guess this would require everyone to use a government-
       | sanctioned DNS and that would require traffic on udp 53 to non-
       | gov-dns servers blocked? I felt like this was glossed over a bit
       | too quickly in the article
        
         | justsomehnguy wrote:
         | DNS is running on udp/53. It's beyond trivial to absolutely
         | transparently NAT it to anything you want.
         | 
         | Block tcp/853 and most common public DNS servers and you can
         | control resolving on 98% of devices.
        
         | vel0city wrote:
         | Probably more like all the local ISPs DNS servers resolve that,
         | or that there's potentially some DNS rewriting going on. Its
         | not too hard to rewrite basic DNS traffic. DNS is not
         | encrypted, its payloads are very structured, and quite small.
        
         | tenebrisalietum wrote:
         | More like the whole country is behind a giant CGNAT. NAT is
         | good for security, eh?
        
       | whatsthatabout wrote:
       | Pretty crazy that a country can just completely block all
       | internet outside of what they want to be accessible... One app
       | that came to my mind reading this is Briar [1] - no real internet
       | required, can connect to other briar participants via bluetooth
       | and WiFi. Sadly only for Android...
       | 
       | [1] https://briarproject.org
        
         | Thaxll wrote:
         | It's not crazy, internet is like public roads, they can decide
         | to close them anytime they want.
        
           | culi wrote:
           | Who's "they" and why are we paying to uphold their power to
           | make this decision whenever they want
        
             | vkou wrote:
             | We aren't doing anything, The Iranian government chooses to
             | control what happens to electricity within their borders.
             | It's one of the fundamental points of state sovereignty.
        
               | culi wrote:
               | The example given was "public roads"
        
         | vbezhenar wrote:
         | Why would I want to connect to other briar participants? I want
         | to connect to hacker news. It might be useful for terrorists or
         | protesters, but for ordinary people - not sure.
        
       | pyinstallwoes wrote:
       | The only real solution long-term is completely peer-to-peer ad-
       | hoc networking that doesn't depend on BGP.
       | 
       | A few projects are in similar territory but none I've seen are
       | working at the layer of bypassing BGP. Many are just acting as an
       | overlay; which works to an extent. https://github.com/yggdrasil-
       | network/yggdrasil-go
       | 
       | It's probably begging for a different model of the "internet" and
       | where data lives.
       | 
       | My requirements:
       | 
       | 1. Offline-first applications that sync via a pub/sub DHT of
       | trusted peers. More details here but basically allows bypassing
       | BGP.
       | 
       | 2. Trusted peers are routable via a determinstic pathing algoritm
       | without exposing the recipient. (content addressable everything).
       | 
       | 3. Automatically distribute storage and compute on all local
       | devices a user has and or needs (it's so dumb and wasteful that I
       | only use one computer at a time when I have hundreds at my home
       | at different levels of compute from thermostat to fridge to
       | laptop to desktop).
       | 
       | I've thought about this for a long time and planned many
       | requirements out. I was very committed to working on it but then
       | I lost motivation because I don't get along with most humans
       | today and where the world seems to be going. It also sucks to
       | have people think your ideas are crazy.
       | 
       | Oh well.
        
       | meitham wrote:
       | I recollect few years ago when the US ordered all western
       | services to be blocked to Iranian citizens, it was a big outcry
       | when Gitlab and Github published blogs confirming their
       | implementation of the Iran blockade. To me the west lost all
       | moral arguments criticizing Iran for doing the same within their
       | own country.
        
         | arcticbull wrote:
         | One is used as punishment to correct behavior, one as control.
         | 
         | [edit] This is the same way that if I go out and throw someone
         | into my basement it's 'kidnapping' but when the police do it to
         | me, it's an arrest.
         | 
         | Jokingly this comment has the same vibes. [1]
         | 
         | [1]
         | https://twitter.com/dril/status/473265809079693312?s=20&t=gD...
        
           | thiagoharry wrote:
           | Its good to be the self-proclaimed global policeman.
        
             | arcticbull wrote:
             | I don't think anyone's a self-proclaimed global policeman,
             | and America has become of late increasingly reluctant to
             | extend their influence. I'm not American. My personal
             | position is that the world would be worse off if America
             | were to cede their influence because the vacuum would be
             | filled by China, Russia or both. These forces all keep each
             | other in balance and maintain the current detente.
             | 
             | This is one of the most peaceful times in world history,
             | after all.
             | 
             | With that in mind, no, I don't support the Iranian regime.
             | Positions should be evaluated piecemeal, it doesn't matter
             | what you think about America's other positions, it doesn't
             | need your personal 'moral high-ground' sign-off to be in
             | the right on this one.
        
           | [deleted]
        
         | DeathArrow wrote:
         | And it's not like the West isn't blocking sites and even taking
         | down sites that aren't breaking the law.
        
         | [deleted]
        
       | johnklos wrote:
       | This is difficult to read. The author confuses nouns and proper
       | nouns and isn't clear about who it is they're referring to (who
       | are the neo-liberals, for instance?).
       | 
       | I understand that not everyone is as good at writing as others,
       | but it really doesn't take much effort to ask someone to
       | proofread.
       | 
       | Otherwise, this is a good start, even though it lacks details and
       | examples.
        
         | deusum wrote:
         | Conceptually, it was interesting. I can forgive it for lacking
         | details, as a "preliminary report", too.
         | 
         | But the whole, "neo-liberal arses" bit gave it the sense of an
         | unhinged author or untrustworthy narrator.
        
           | LastTrain wrote:
           | Conceptually, I clicked it and thought I would learn
           | something about the Iranian firewall, but instead I ended up
           | at "The Hackers Choice" blog, a blog with exactly two
           | articles, and read a confusing rant along with a laundry list
           | of firewall techniques talked about in vague enough terms
           | that I learned absolutely nothing, other than to be skeptical
           | about this source going forward.
        
         | nibbleshifter wrote:
         | English isn't the writers first language, for a start.
         | 
         | The weird use of the term neoliberal is pretty common in
         | European liberal-as-in-freedom left leaning circles.
        
           | rocketbop wrote:
           | I've lived in three European countries including the one I
           | was born in and I've never heard that term being used in that
           | way.
        
           | computerfriend wrote:
           | I have never heard the term "neoliberal" outside of US
           | politics.
        
       | neither_color wrote:
       | _On bad days:_
       | 
       | Key word is bad days. Expats in China have noticed the same
       | thing, with VPNs sporadically not working during summits, around
       | certain holidays, etc but resuming afterwards. Also, for some
       | reason certain VPNs work more consistently than others even
       | though they use the same protocols as blocked services. Some
       | speculate that the ones that continue to work are either
       | honeypots or the companies behind them have (social) connections
       | 
       | Also, it's kind of poor taste to call those who want free(dom)
       | internet there as "neo liberals"
        
         | computerfriend wrote:
         | > but resuming afterwards.
         | 
         | This is a common and natural misconception. When the firewall
         | gains a feature (i.e. the ability to block certain traffic) the
         | VPN providers then have to figure out some technique to bypass
         | it. This happens over and over again. The firewall isn't
         | relaxing after the event, it is staying the same and the VPN
         | provider has improved.
         | 
         | On your second point, I can't comment for all providers, but
         | I've heard this rumour in a more specific context and can say
         | that it is definitely at least sometimes false.
        
           | neither_color wrote:
           | Thanks for clarifying. I admit it's anecdotal but was
           | wondering if these new features are rolled out automatically
           | or with humans deploying them? If the latter it might explain
           | why expats in China have said it [access to VPNs] gets worse
           | at times.
           | 
           | Years ago one provider that rhymes with krill was pretty
           | consistent, but in the end it seemed one could get the most
           | mileage(err uptime) by rolling their own v2ray instances on a
           | VPS provider that had "Hong Kong" servers in Hangzhou.
        
           | another_story wrote:
           | I'm not sure this is entirely the case, though probably
           | partly so. I think they do track known VPN servers and closer
           | to congress sessions cut those off. I had a number of self
           | hosted setups that would get cut off at those times only to
           | come back on later.
        
         | nibbleshifter wrote:
         | Neoliberal is usually used as a pejorative towards "liberals"
         | who prioritise economic growth/profit over human
         | dignity/freedom. Think: the Blair administration in the UK.
        
         | dontbenebby wrote:
         | >Also, it's kind of poor taste to call those who want free(dom)
         | internet there as "neo liberals"
         | 
         | Thanks, sincerely, for the note on language. I've used that
         | insult a lot in the past.
         | 
         | I also had a string of international students do things like
         | complain I was racist for asking questions and answers be
         | repeated back in English, not just Mandarin. (And they weren't
         | from Taiwan.)
         | 
         | It's true that America has no official language, but when folks
         | like myself expressed that sentiment in the policy space, it
         | was with the intent if someone speaks French, Spanish, or one
         | of the many languages of the Native Americans could be given
         | services in a manner they understad, as is their human right.
         | 
         | It was not a rhetorical devie meant to me wielded by agents of
         | a foreign power.
         | 
         | I ended up accepting an alaprazolam script, following a string
         | of failed antidepressants, navigating the social mileau of
         | "they treat me like an international student because I know who
         | the spies are and refuse to just... hire me somewhere... as
         | their system crashes around them"
         | 
         | This was in the lead up to, and during, the Summer of Snowden
         | -- I was really pissed that no one would hire me into private
         | industry and civil society... well all I can say about so
         | called "civil" society is Epstein didn't kill himself.
         | 
         | (Happy spooky season!)
        
       | gbarut wrote:
       | Somebody should post this to Google contacts. They just had this
       | claims about security and working for the ppl with the Hacking
       | Google series on yt.
        
         | arbitrage wrote:
         | Google knows already. They just don't care.
        
           | [deleted]
        
       | throwaway0x7E6 wrote:
       | >Some operators use a whitelist and block all other websites.
       | 
       | the ultimate fate of the internet
        
         | [deleted]
        
       | buzzwords wrote:
       | I tried helping my Iranian friend to get around the internet
       | restrictions. I have to agree with the author most big players
       | could not give a flying f*ck. Even signal can't be bothered to
       | address verification SMS issue.
        
         | [deleted]
        
       | hot_gril wrote:
       | > Instead, the TCP 3-way handshake won't complete (the syn-ack is
       | dropped).
       | 
       | Sounds like my internet connection in grad student housing about
       | 10% of the time, except the initial SYN is dropped. Pings and
       | everything else are fine.
        
         | ilyt wrote:
         | I remember one guy in my company had hard-on on blocking every
         | way to tunnel out of our network (...that was not required by
         | anyone, he was just security nut).
         | 
         | We had sites blacking out because he decided DNS tunnelling bad
         | so he blocked anything with low TTL. Meanwhile simple POC DNS
         | tunnel worked fine..
        
       | keyme wrote:
       | Air dropping starlink terminals onto protesters is the solution.
       | 
       | In fact, if you live anywhere outside of the US, owning one "just
       | in case" is good for future proofing your freedom, IMHO. Kind of
       | like being armed.
       | 
       | Edit: in fact, starlink v2 global LTE-from-space coverage will be
       | a true game changer for world freedom. We can only hope this
       | comes to be sooner rather than later.
        
         | missedthecue wrote:
         | Until having a starlink terminal on your roof becomes
         | punishable by death. You can try to hide them visually, but
         | Iran could always detect them electronically if they want to
         | put in the effort.
        
           | keyme wrote:
           | Half the households in Iran have an illegal satellite dish on
           | the roof to receive disallowed TV from abroad.
           | 
           | This is punishable and does get punished (rarely, I hear).
           | Doesn't deter anyone.
           | 
           | Edit: it will also be quite difficult to detect
           | electronically, judging by the fact that even Russia fails to
           | jam these signals on the battlefield.
        
             | modeless wrote:
             | Satellite TV dishes don't transmit. Jamming and detection
             | are very different.
        
               | keyme wrote:
               | TV dishes transmit very clearly in the visible light
               | spectrum :)
               | 
               | As for TX detection, you'd be surprised. Directional
               | signals like starlink uplink are fairly hard to detect.
        
               | walrus01 wrote:
               | One needs to only google "iran satellite dish
               | confiscation" to see the low tech methods used. They
               | occasionally go on binges of confiscating and destroying
               | receive-only tv satellite dishes.
        
               | keyme wrote:
               | Random satellite imagery of Tehran. Count the dishes.
               | 
               | https://www.google.com/maps/@35.738824,51.5285095,19z/dat
               | a=!...
        
               | imwillofficial wrote:
               | As a submarine comms expert, this is more true than you
               | might realize.
        
         | honkler wrote:
         | ever heard of antisatellite missiles?
        
           | keyme wrote:
           | Unfeasible against SpaceX who have a higher mass to orbit
           | capability than the rest of the world combined, soon many
           | times over.
        
         | joisig wrote:
         | Why only outside of the US?
        
           | lasfter wrote:
           | Presumably if there's a problem within the US, Starlink would
           | be compromised.
        
             | keyme wrote:
             | Indeed. You would need a starlink competitor from another
             | jurisdiction to fight US censorship if that comes to be.
        
         | pvg wrote:
         | There's a pretty long history of dropping radio transmitters
         | for people to use in violently authoritarian environments. Not
         | without specialized uses but declaring it 'the solution' seems
         | like overpromising things a bit.
        
       | LinuxBender wrote:
       | FWIW here [1] is an option that should still work. I would be
       | curious to hear from people in Iran if this no longer works and
       | they are blocking SSH to VPS nodes.
       | 
       | [1] - https://news.ycombinator.com/item?id=33025954
        
       | dweekly wrote:
       | The snooping of unencrypted SNI in the TLS handshake is a known
       | weakness that is still mostly unresolved despite four years of
       | standardization effort. The encrypted SNI work has been revised
       | and updated to encrypted ClientHello and is still technically an
       | IETF draft and not yet formalized in an RFC:
       | 
       | https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
       | 
       | That said, CloudFlare, Firefox, and Chromium teams have all been
       | working toward the evolving spec so one can hope that soon with
       | eCH and DNS-over-HTTPS we will be able to have clients securely
       | connect to servers without broadcasting the hostname to which
       | they are connecting.
        
         | dweekly wrote:
         | Follow along on Chromium support here:
         | https://bugs.chromium.org/p/chromium/issues/detail?id=109140...
        
         | vbezhenar wrote:
         | And it means that state firewalls will just block all CDNs.
        
           | novok wrote:
           | The idea is you force them to choose the entire effective
           | internet or nothing, which is not an economic self own even
           | most dictatorships are willing to make.
           | 
           | These firewalls are an exercise in having your cake and
           | eating it too.
        
             | saurik wrote:
             | But it doesn't end there... they block the CDN that
             | implements this feature, and then the CDN's customers--who
             | probably didn't care much about the benefits this gives to
             | some of their users but are now losing access to some large
             | customer base--start complaining and migrating off the CDN,
             | which results in the CDN pulling back on the feature.
             | 
             | And we know this is what will happen as this is effectively
             | what happened with domain fronting--where you simply use
             | the wrong SNI instead of hiding it entirely--with all the
             | large CDNs actively "fixing" this feature to prevent their
             | customer's websites from being blocked by firewalls because
             | of users who were using this to get around hostname
             | restrictions.
        
             | aliraheem wrote:
             | > which is not an economic self own even most dictatorships
             | are willing to make.
             | 
             | What basis do you have for this claim? People make these
             | claims constantly so confidently, but wherever I look all I
             | see is that dictators have always been willing to make
             | their nations incredibly poor.
             | 
             | > These firewalls are an exercise in having your cake and
             | eating it too.
             | 
             | More to the point this isn't the Gordian Knot you think it
             | is.
             | 
             | HTTPS isn't designed to prevent this. If you want to allow
             | 'legitmate' access you just issues your own certs, and
             | proxy requests. Universities etc can install your root cert
             | and use your DNS servers.
        
               | hnews_account_1 wrote:
               | It is game theory. Consider what happens in the real
               | world - it is strictly easier for Iran or any country
               | with a competent infrastructure to just shut down the big
               | internet pipelines for retail customers. They don't do
               | that. China has spent untold amounts of money creating a
               | stupidly effective surveillance state which is still
               | _technically_ open to the internet. Why?
               | 
               | So your assumption that "dictators will do the worst they
               | can" is wrong. They will keep pushing the boundary
               | outside the current Overton window but can't do it in a
               | snap. You force their hand by not providing alternatives
               | and suddenly they're stuck. They can't just restrict
               | feminist websites and claim that it is harming the social
               | fabric then expand the net slowly. It is all or nothing
               | as the OP explains.
        
             | vbezhenar wrote:
             | CDNs are not entire effective internet.
             | 
             | Also I'm not well-educated in that area, but I would expect
             | that CDNs would allocate dedicated IP ranged for big
             | customers like Microsoft or Apple. So state can ban more
             | selectively, white-listing those ranges.
        
         | aorth wrote:
         | Wait I'm confused. I remember reading a bunch of reports about
         | how China started blocking TLS 1.3 because of encrypted SNI
         | (eSNI) years ago?
        
           | tialaramex wrote:
           | Some people interested in the Great Firewall wrote up
           | weirdness they saw with one particular prototype of eSNI
           | years back. A game of Telephone later this became nonsense
           | like "China blocks TLS 1.3" but actually if you do that what
           | you get isn't web sites stripped of protection but connection
           | errors. Which is indeed what happens for some sites from the
           | other side of the Great Firewall, but we just say China
           | blocks those sites, because that is what they do. Protocol
           | versions are not crucial to them.
           | 
           | The current iteration of ECH is designed to be GREASEd which
           | means browsers might just always do ECH with dummy values
           | regardless, so either you block or you don't, you won't be
           | able to selectively block ECH. This doesn't magically prevent
           | the Great Firewall from working but does mean specifically
           | host matching is degraded as intended.
        
           | dweekly wrote:
           | I don't know anything about that (and I'm pretty sure TLS 1.3
           | doesn't mandate ECH since ECH isn't even finished
           | standardizing!) but you can check to see if your browser
           | supports ECH by visiting https://tls-ech.dev/
        
       | keyme wrote:
       | Another idea: create an easy way to set up pirate LTE base
       | stations.
       | 
       | Hacked femtocells? SDR? Something more clever?
       | 
       | Distribute eSIMs to everyday people.
       | 
       | The pirate operator takes all the risk and technical
       | difficulties.
        
         | walrus01 wrote:
         | This doesn't in any way solve the problem of getting traffic
         | in/out of the country, where all local ISPs are legally
         | obligated to singlehome themselves to the government ASN.
         | 
         | Unless we're talking about something like smuggled two way
         | satellite terminals.
        
           | keyme wrote:
           | IMHO connectivity to the global internet is less important
           | than local communication between protesters in geographic
           | proximity.
           | 
           | Having these pirate base stations mesh together is also
           | achieveable. Freeing end user equipment from the requirement
           | to mesh (not achieveable).
        
         | [deleted]
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2022-10-28 23:01 UTC)