Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

(I live in China) I would advise against VPN entirely. I am unsure about the state ability to decrypt the content of the connection (heavily depends on how the VPN is configured really — weak and legacy ciphers, etc.). But they will detect it and eventually you'll start dropping packets like crazy.

A simple way to evade all of this is to use shadowsocks with a strong cipher and strong password between your computer in China and your server outside of it. Don't use any free server and don't use any commercial shadowsocks offerings. Set it up yourself, it's pretty easy.

On the mobile phone side of things. I wouldn't trust anything. Especially Apple that has been very complaisant with local authorities.

China plays a tactical game: they pretend (or we suspect, and they want us to) that they can do a lot of things. But nobody knows the extent of what they are actually capable of.



shadowsocks is on their radar now...and they have been able to detect its usage with some success, unfortunately...

i.e. The Random Forest Based Detection of Shadowsock's Traffic, https://ieeexplore.ieee.org/document/8048116/

I don't really understand what kind of scientists would do such researches to help the government carry out the censorship more efficiently, over their fellow people...it's either those intellectuals have no brain, or no heart...


this is correct, SS is on the radar and is not as dependable as it used to be, there is a variant of SS that is said to be an improved version but it is still not 100% dependable.


Used to live in China. Can vouch completely for the Shadowsocks approach. It can't be blocked yet. Set up an endpoint at home or on EC2 and configure Streisand. Works great on mobile and desktop.


But shadowsocks is a VPN. What makes it better than other offerings?


Shadowshocks is not a VPN at all. It's a connectionless SOCKS5 proxy. No hand-check, no key exchange, no protocol agreement. VPN is not made to be undetected, only secure in the sense of data encryption. Shodowsocks has broader objectives.

See https://shadowsocks.org/ for info.


> It's a connectionless SOCKS5 proxy.

On your local workstation, it exposes itself as a SOCKS5 proxy. But to communicate with the shadowsocks server, it uses a proprietary protocol which is not SOCKS5 and does have a key exchange process. Either way, these details don't affect its ability to be detected.

> VPN is not made to be undetected

"VPN" is not just one technology. Many vendors of VPN software do claim that their software is made to be undetectable. One example is shadowsocks, but there are other vendors who also claim that.


Thanks for the info, couple of things I didn't know. What I meant by "it's not a VPN" was mainly it doesn't make your computer part of another private network.


or he could just use roaming mobile data which are not subject to great firewall




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: