“Two days ago the police came to me and wanted me to stop working on this”
github.com
github.com
Encryption is not enough. You need to disguise your VPN traffic to make it look like standard HTTPS sessions (since they don't block HTTPS). For example in a traditional HTTPS session, if the client browser downloads, say, a 500kB image over HTTPS, it will send periodical empty TCP ACK packets as it receives the data. But when using a VPN that encrypts data at the IP layer, these empty ACK packets will be encrypted, so The Great Firewall will see the client sending small ~80-120 bytes encrypted packets, and will count this as one more sign that this might be a VPN.
That's why people in China have to use VPN tools that most westerners have never heard of: obfsproxy, ShadowVPN, SoftEther, gohop, etc. All these tools try to obfuscate and hide VPNs. I have a lot of respect for all these Chinese hackers like clowwindy who try to escape censorship, as it takes more technical prowess than you think to design a VPN that works in China.
Source: worked there for a while
OpenVPN is like a prime suspect of a police procedural novel, it gets hunt down no matter what.
Personally experience: I did work for Microsoft Shanghai and VPN works just fine. You need to have the right set of tools, and better, have a good channel of negotiation with the government.
Also, international performance in general can be quite bad at peak times (i.e 30% packet loss), I suspect due to Comcast-style management of international transit. But if you buy a transit circuit from Unicom, no problem!
Edit: to add to the grand parent, I've actually found ssh -D/-w0 (for a TUN device) quite reliable from China. What I really want to do is run multiple connections from different end points with a routing protocol to do fast-failover.
Don't suppose you could explain to us network plebs how that would bypass the Great Firewall?
It also doesn't solve the problem of mobile access to Google Apps for Chinese workers (Google Play Store & apps are not bundled by many (any?) Chinese OEM handset makers or carriers. You can root & sideload, or you can purchase phones outside the country and ship them to your employees, but even if you do this, there is still no guarantee they'll be able to access Google's apps while on cellular networks.
Google Apps will also drain your battery if you are in a region where Google has no network-location data yet, because then Google will turn on your GPS, and send to their servers the pair of GPS-coords and strength of networks.
If you live in a suburb in Germany where almost no networks are known to Google, this means if you enable location services your GPS will try to get a fix 24/7, eating your battery in about 2 hours.
This is probably going to be an issue in China, too, considering that Google doesn’t have location data there.
But if you turn on WiFi and Location at the same time (which is not uncommon), then it will suck your battery dry in seconds. Turn any of those two off, and it works.
- High accuracy (GPS, wi-fi, mobile)
- Battery saving (Wi-fi, mobile)
- Device only (GPS)
From what you say, it sounds like 'Device only' would save more battery than 'Battery saving'?
I believe this is the reason why they use Atlassian[1] products, where rest of us would use trello, e.t.c.
[1] company that created jira
I thought it was just a consequence of being on spotty < 5mbps(ADSL?) connections. The internet situation was barely tolerable for a few weeks stay; I can't imagine what living in these conditions 24/7/365 is like.
"24/7" means 24 hours a day, seven days a week.
"24/365" means 24 hours a day, 365 days a year.
"24/7/365" means 24 hours a day, 7 days a week, 365 weeks a year?
I know, I know, it's become an idiom, and it's like "I could care less", and you can't try to understand it except as an atom that caries a meaning, but it just looks wrong to me.
Sorry - I'll now return you to your regular programming.
7 *days* per *week*
24 *hours* per *day*
365 *days* per... *year*
Why you'd read that as 365 weeks per year I'm not sure, because there's no pre-established convention that would lead you to interpret it that way (both 24 and 7 would have to be "per week"), and most people know there are 365 days in a year.Just trying to help. ;-)
24 hours a day, 7 days a week, 365 days a year.
That just really doesn't make sense at all. I know that the numbers means, and are for, but if someone is saying every hour in the year, to say 24/7/365 is just nonsense.Of course, this is a losing battle. People just don't care if what they say makes sense, they just say stuff and assume that people will understand. This is one of the things that makes language bizarre, miraculous, infuriating, and impossible to analyse. I note examples like this because they are caltrops on the road for NLP.
I would argue that no single statement can make sense. Sense is made when multiple statements are combined.
It's really all just about appropriate cognitive load. Every statement must be processed and it's great to be as accurate as possible and as accurate as the consensus agrees to.
Anything higher quality than that falls under the category of "great writing," which only a handful of people cherish.
> They are all relative timeframes by which
> a store my be closed; certain hours during
> the day, certain days during the week, and
> certain days during the year.
Huh. That's a way of interpreting it I'd never seen. Thank you. > Your inability to make sense of it doesn't
> affect the rest of us.
No, except that it may help people see that what they think is obvious isn't always obvious to others. > ... it is the result of a willful ignorance
> that you are bragging about.
Well, that's obviously your interpretation, but if others see it that way then it explains the hitherto mysterious yoyoing of points on my comments. > It doesn't make for very interesting trolling.
I find it disappointing that you think I'd troll.If the sole holiday were a single Golden Week sometime in the year, the idiom may indeed have been "24/7/52", but holidays are simply scattershot like that.
It's not that the individual segments relate to each other. Rather they answer three sets of questions:
What are your daily hours? All of them. 24 hours / day.
What weekdays are you open? Again, all of them. 7 days/week.
What holidays do you observe per year? None, we're open 365 days/year.
Since there's rarely a monthly cycle to business closings and there aren't a standard number of days per month, that's elided.
It also helps to realize that human timekeeping is really based on three independent phenomena which are utterly unrelated. There are day-based units: seconds, minutes, and hours are all subdivisions of the period of rotation of Earth about its axis.
The month is based on the Moons orbit about Earth. That it is roughly 30 days is a notional convenience, similarly its rough divisibility by 4 into 7 day periods. The week is entirely synthetic (though profoundly persistent).
And the year on Earth's orbit about the Sun. Again, relationship to days and months are entirely arbitrary.
That's why it often seems time units are arbitrary. They are.
There's a brief book which Kay's this ought and traces the calendar through time, The Seven Day Cycle.
24 hours in a day, 7 days in a week, 52 weeks in a year.
Whoever doesn't stay home during the Christmas period in the US gets accolades from management, so there's incentive to work if you're career-focused.
And I'll add that "I could care less" derives from the earlier "I couldn't care less", which makes a lot more sense. See http://blog.dictionary.com/could-care-less/
In my experience splitting my time between North America and China, the difference is not terribly noticeable once you invest in a solid VPN -- which everyone does.
The network speeds here are generally far better than NA -- in tier 1 and tier 2 cities at least. If you're accessing site in China, i.e., not going through the GFW, the average is far better than you'd find in the US. However the GFW slows everything down. However, there are a handful of VPN providers that specialize in getting through the GFW: notably Astrill and ExpressVPN. This those on my phone, tablet, and laptop it's easy, you'd never know you were in China -- expect the odd day when you have to hunt for a different server. Most experienced developers here subscribe to one of them.
Also, a lot of tech companies subscribe to "international lines". Pretty much all the ISPs offer them to business customers. They are expensive but they work very well. Usually about US$1k/mo to US$3k/mo on contract. The international lines are just hard lines to Hong Kong.
Now, on previous trips I experienced what you mentioned. It seemed really like there was some machine learning going on, and after using a VPN for a while the connection would get bad. But I guess it might not be machine learning, there might just be a huge number of humans watching your traffic - which would explain why it is so inconsistent.
The thing that worked best for me is just using ssh -D (on most days). Our workplace uses ssh a lot for secure communication with outside china, so that couldn't possibly be blocked without hindering our work (and I believe 'they' have no interest in that). So whenever I had to access something for work that was sillily blocked (argh gmail), I just used the ssh connection that was open anyway.
And what most ppl do when facing this? They choose a local service instead of Twitter, Facebook, Youtube, Google. See, censorship is only a part (though a vital part) of the grand scheme.
I assume 9 years later (don't know what the modern tech for web stuff is these day, but I assume encryption plays a key part) they're doing just as intrusive inspection and filtering of data.
Traditional VPNs such as PPTP/IPsec as well as various forms of obfuscated proxies are generally not interfered with unless something major happens. A lot of the alleged "censorship" are actually symptoms of high latency and packet loss on home connections.
So... could you avoid detection by passing an SSH tunnel through a PPTP VPN? Add enough layers, and the censors might not bother to unwrap all of them.
Note that Chinese government does not have backdoor access to those US websites, nor do they control a significant fraction of Internet infrastructure.
https://github.com/clowwindy/ShadowVPN
"Removed according to regulations."
https://github.com/shadowsocks/shadowsocks-iOS/issues/124#is...
Let me just find the nearest cliff to jump off.
I use an unencrypted PPTP VPN and the connection is really fast and stable here (Shenzhen, China Telecom). I have tried OpenVPN and ssh but both were much slower. FWIW, I don't believe using a VPN is illegal in China (though operating a VPN service without a license most likely is) and pretty much every single foreigner I know uses one.
I have noticed they have multiple situation, for example when everything's quiet internet is not so bad (despite the fact bandwidth is extremely low for huge amount of people), but when some news came out about government corruption, guess what ? some vpn does not work . In 2009 green movement they closed every https connection.(maybe that was red alert situation)
p.s : https://en.wikipedia.org/wiki/Deep_packet_inspection
p.s. : I use vps from netherlands for bypassing firewall. but It takes huge amount of time and a little money.but the point is 99.999% people don't have this option (I use shadowsocks, sometimes another tunnels) so they use internet the way is or some software like freegate and other but with extremely low speed unbearable lag.
p.s. : pptp, l2ps and others are closed right now. even president rohani couldn't manage the situation . I have heard he did want to do something but supreme leader and his people stopped him.
As a Chinese netizen I don't know if I should be proud that we have world-class advanced technology or be ashamed. Possibly ashamed.
These are our colleagues designing and implementing these tools of oppression. We should ask them why they exercise their talents in this way.
Chief among these was the Three Kingdoms War when up to 40 million are reckoned to have perished in military operations and from the destructive consequences of warfare. This is an enormous number, considering that the global population at that time is unlikely to have exceeded 400 million. More recently, the Taiping Rebellion claimed more than 20 million lives while the civil war that brought the Communist Party to power resulted in 7.5 million deaths, over and above the 20 million estimated to have been killed in the roughly contemporary Japanese invasion.
This is not the history we were taught at school but Chinese leaders are well aware of these facts.
When disorder breaks out in China, things turn very nasty indeed.
It is best, therefore, to avoid disorder at almost any cost."
That is why.
Or would you prefer to have China descend into the chaos of Rwanda or Sudan ?
If they are using oppression to avoid disorder, they better have long term plan. Otherwise they are digging their own grave.
Not many people fear of chaos in the USA and not because they have the best firewall.
There are not millions of doomsday preppers in the US. And their obsession is not representative of public will or sentiment.
The comment you're replying to said: >Not many people fear of chaos in the USA and not because they have the best firewall
So you seem to be saying that if the US had a Great Firewall the nutjobs who spend half their salary on underground bunkers and armament wouldn't. That's a pretty silly argument.
Incidentally, in most of those Chinese conflicts (4 out of 5 I believe), they were right. Many other wars were similar : starts with "immigration", numbers increasing, conflict, open conflict (and mass death), repression (of the losing side). Extermination is often tried but rarely succeeds. Well it succeeds in causing mass death, but it doesn't succeed in the sense that extermination is the result.
Also, when quoting large blocks of text it is usually helpful to source that quote.
Oh I just gave away so much secret. I'm so doomed. Everything above are just made up stories. Don't believe me. Don't track me down. Please.
and i wonder if filling the apple form helped them finding him or it was just bad timing
It turned out that RDP actually worked pretty well. I did hesitate to post this in case it's seen by the wrong people(!), though given it's a while since it was necessary to use, it may be blocked by now anyway.
I wonder if it was available because it was relatively little known and, if so, what other little known protocols might be available.
https://en.m.wikipedia.org/wiki/2007_Chinese_anti-satellite_...
http://www.history.com/this-day-in-history/chinese-counterat...
http://nationalinterest.org/feature/deadly-lessons-the-last-...
But if they can't shut it down via technology, they'll most likely shift to individual enforcement and harassment. In that case they have to chase people one at a time, so to get widespread effectiveness they have to make sure that each individual case frightens as many people as possible. That means that the individuals targeted will be punished more severely.
Enforcement 101.
A: "No, 1.2kpbs is not enough, thanks but I prefer censorship."
Is that what you're saying?
Pretty much all the ISPs sell "international lines" as well. But only as part of their business packages. Usually it will run for about US$1k/mo - US$3k/mo with minimum 1-2 year contract for their "starter" package. Most tech companies in my area have them; they work very well. Essentially they are a hardline to Hong Kong and they ration out to subscribers.
They key thing to understand about the GFW is that it's not about general censorship of the population. Frankly the government doesn't care if someone who is middle class, i.e., invested in the status quo, gets around the GFW. They are more concerned about conservatives in lower classes trying to organize to stop the move towards capitalism. And it's mostly about protecting the market now so local companies can get access to these lower classes as their position improves and they join the middle class.
It's not just international companies. Chinese companies are all about going overseas now. China is now a next exporter of investment. Plus it seems every company with an app that has a moderate amount of success wants to reach Chinese outside of the China -- they have more money -- and so need to integrate with blocked services like FB. And exporting Chinese online games to other developing nations is really taking off.
"Reason for Recommending: Reliable connection, fast speed. Fast customer support."
What do you mean by 'reliable'? What do you mean by 'fast'? Are you talking about latency or throughput?
"Reason for not recommending: sometimes hard to connect"
How many times out of ten? Using which VPN protocol(s)? Was this using PPTP, or OpenVPN over stunnel?
I run my own VPN servers (for myself and friends) but of course there is some ongoing maintenance effort to add new servers to replace those for which latency and/or throughput have declined. If there were a site with specific data about different companies' performance (over time), that would help me to decide whether it's still worth the effort.
In other words, steganography.
Most of the detection is focused on blocking vpns and they are very good and disrupting vpn traffic
For ssh it sometimes work for a few days then the whole IP/host is blocked.
I did not have to time try obfsproxy, shadowsock or whatever, but it really really sucked, to make things worse, my Nexus phone could not get any updates etc either, as Google is also _fully_ blocked, I felt I was back to Stone age there.
It's a pretty sophisticated arms race that's lead to some cool stuff, notably pluggable transports (like the obfsproxy you mentioned): https://www.torproject.org/docs/pluggable-transports.html.en
Unfortunately the companies that enable this deep packet inspection are often American companies working overseas. My friend who used to work at Cisco said they had internal slide decks about the improvements they could make to the Chinese firewall. Then there's Bluecoat in Sunnyvale (https://www.bluecoat.com/) building the censorship systems for the middle east.
Why do American companies sell this kind of stuff to China and non-democracies in the middle east? They must rationalize it in someway, but I think it's wrong.
Pursuit of the almighty Free Market without regard for scruples or morality. Basically, public corporations base success only on money. If you as an executive refuse to bow down before Mammon[1,2] then you are replaced by someone who will. Seealso Charles Stross' excellent Invaders From Mars[3]. The Chinese government and other regimes pay big money for these tools.
[1] https://en.wikipedia.org/wiki/Mammon [2] https://en.wikipedia.org/wiki/Mammon_%28Dungeons_%26_Dragons... [3] http://www.antipope.org/charlie/blog-static/2010/12/invaders...
1. if you need custom vpn, why even have apple devices?!
2. why focus on vpn over their network instead of mesh?
It's based on SoftEther VPN, which happens to be open-source and cross platform.
I'm using it for most of my VPN setups and I've generally found it to be superior to OpenVPN in every aspect (performance, usability, protocol support, obfuscation, etc).
I recall the same thing occurring in Shanghai with many of the popular webmail services, they'd work briefly, usually just long enough to log in and get a glimpse at an inbox, then it would time out endlessly and that'd be it.
Internal policy dictates this, all over the world.
Email is usually on self-hosted Exchange.
Corporate firewall blocks stuff like Youtube and Facebook - also the same over the world, but some users with the business need can access whatever the business need dictates.
Some large companies just bypass the national firewall for speed reasons - this is negotiated with the government on an individual basis - pragmatically this makes sense, as the traffic is 100% encrypted back between fixed sources and destinations, and inspecting it just wastes resources for all parties. Some corporations may also have their websites for the public access bypass any filtering, also for speed reasons (for example, internet banking).
1. https://github.com/shadowsocks/shadowsocks-go/blob/master/sh...
2. https://github.com/shadowsocks/shadowsocks-go/blob/master/cm...
(Not the best code, a couple of race conditions in there)
Yes, setting up a VPS provider would be the most common way. There are Shadowsocks implementations that supports multiple users so that more than one person can use it simultaneously. There are also commercial solutions for Shadowsocks that you can just purchase an account instead of setting up your own server.
People have built successful VPN services using Shadowsocks, and they are available on many platforms, like routers and embedded systems.
And the iOS version is more or less the author's recent efforts to build a VPN client that can run on non-jailbroken iPhone, much like Cisco AnyConnect.
I think shadowsocks' popularity as a whole concerns the chinese government, so they do their usual rooting out the leader thing: now that shadowsocks org is headless in the literal sense (no owner, no main repo), they hope its development will die out.
There are plenty of people on HN who are i) wealthy ii) interested in beating censorship.
It'd be nice to see some effort going into creating software to beat censorship; having excellent translations of the documentation into a variety of languages; etc.
freegate is a traditional http proxy or socks proxy built by Falun Gong (https://en.wikipedia.org/wiki/Falun_Gong). They built lots of software with the same technology: freegate gpass freeu dynapass... People share this kind of banned software sending to each others just like teenagers share adult videos. After update of GFW, it become un-available and un-usable.
openvpn turns break GFW as a business, people sells openvpn account at $1.66 a month regularly. They sell this kind of services package including pptp l2tp ssh openvpn to those who need a free network.
goagent is a free software written by Phus Lu. It use Google's application engine as server so you can use it without paying money.So it replaced openvpn since it cost $0. After China banned Google, this way become more and more hard.
shadowsock is a protocol designed by clowwindy. It become a environment. People use python, C, nodejs, golang, rust, obj-c, java to write their own client and server. Some organization share their server for free, some people sell account and provide high speed. shadowvpn works as a VPN while shadowsocks works as a socks5 proxy, but share the same technology.
This is the end of shadowsocks. I means recently more and more evidence shows that GFW has finally find a way to recognize shadowsocks's packets. Then they stopped the development of shadowsocks.
That's all. The winter of China's network comes.
Is there technical reason to believe that shadowsocks or similar technology is the last stand against automated censorship?
I would just say this is just yet another stage in the censorship/anti-censorship cycle.
There's no guarantee that "the censorship arms race" will continue, even in your specific nation-state.
For example, I bet there's not much anti-censorship software being developed in North-Korea, because people don't want themselves and their entire families tortured to death.
The real problem here is not that we might be lagging behind governments with our anti-censorship tools. The real problem is the existence of governments to begin with, because as long as they do, they will want to control their subjects as closely as possible.
Policitians and the real rulers behind the scenes are all psychopaths.
They see us as human livestock, and any one of them would be perfectly happy with a global North-Korea, as long as they personally would be in the tiny ruling elite, with all the riches and power a psycho could ever dream of.
Hmm... okay, so they defeat shadowsocks by recognizing the packets.
> Then they stopped the development of shadowsocks.
But if they already had shadowsocks beat, why do they make a public show of shutting it down?
Sounds more like they recognize that they don't have the GFW technology to defeat shadowsocks on-going development over time. Which suggests all you need is a new developer.
For example, if their capabilities to identify shadowsocks traffic is not particularly specific, filtering would result in undesirable impact on other traffic. They can also have other out-of-band estimates for the extent of shadowsocks use (presence of the software on seized or searched equiment, observed chatter, informants, etc).
a: build a method of detection and prevention and
b: find and coerce developer to stop improving software,
#b is required assuming the developer(s) is considered to be an above average adversary. When there is no silver bullet solution a cat+mouse game is inevitable. That further increases the value of this action.
#a being done at same time as #b has an effect on the collective behavior of the adversary. I'm sure various members for the RIAA and MPAA are wondering how they could have dealt with "filesharing" in a similar manner during the Napster days. But in the end it only buys you time in a cat+mouse games. meh, im sure there is some sun tzu art of war blah blah somewhere saying the same. more poetically of course.
Even if it does get completely removed, a duplicate exists on GitLab: https://gitlab.com/mba811/shadowsocks-iOS (No guarantee that it has all the commits prior to deletion, or that it hasn't been modified from the original in some way.)
I can only hope the police in clowwindy's country don't know how to switch GitHub branches.
;)
I'm saying that the result is not going to be so different, as in people will still use shadowsocks to circumvent the firewall and won't get "disappeared" or whatsoever.
Edit: letters
Because it's the same SHA, and because of the way git works, we know that all the history before it is exactly the same on GitHub and GitLab.
Someone in this subthread mentioned something about a commit hash. This is important.
https://github.com/shadowsocks/shadowsocks-iOS/issues/124#is...
Even with root account, you are not in full control of your Mac - you are sandboxed by Apple.
It's a big step in the wrong direction [opinion], especially because it does nothing to verify "integrity". It prevents changes to the System directory by conventional means (and injection into system processes).
If malware were to figure out a way to disable SIP from userland, it could install itself in such a way that nothing short of disabling SIP could uninstall it.
(I have limited experience with OS X - only briefly played around with driver development and bootloaders in the 10.4 era with osx86 - and I did have to boot from the DVD a few times when I made the system unbootable.)
This raises the question, what good is root if it's not really root anymore?
It's easier than that. It's just a kernel argument to disable it. Simply add "rootless=0" to your boot-args and you have control of your machine back.
I'm running the 10.11 beta and I've already had to disable rootless because I like to have /usr/local as a symlink to somewhere else and by default the rootless configuration prevents writes to /usr. :-/
They know that rootless will break some applications/drivers, plus some types of development may need it disabled.
https://www.reddit.com/r/osx/comments/3hv3kk/update_on_rootl...
The idea is that a combination of a SecureBoot-style trusted boot sequence and technologies like Intel's SGX instructions to create an area that is protected from everything else, root included.
Ever since (heavily controlled) iOS was accepted by the tech crowd as a replacement for a proper General Purpose Computer, we've been slowly loosing more and more control. At least there seems to be workarounds for this particular OSX "feature". It is incredibly important to stop this trend now; it will be a lot harder to work around these restrictions when it gets hardware support.
However, this argument falls down a little if malware doesn't actually need to modify system files, which it doesn't for most typical evil stuff I can think of.
Since all System locations will now be signed (as part of the move to SIP), it means that the basic Apple recovery partition will be able to purge any such malware by a simple signature verification.
"all dtrace probes that target a system restricted process will not be matched" (i.e. will fail unless SIP is disabled).
But lets say you don't find a vulnerability in SIP userland detection, and instead find a kernel exploit to get around the protection:
If malware were to figure a way around it, then even antivirus software can't uninstall it. Only Apple can. It's not FUD.
SIP holes will be found, and Apple will patch them just like other security flaws.
With the condition that you have to upgrade to the very latest system :)
At the very least, the OS needs to be reinstalled from an off-disk source, and that's assuming you haven't been hit by something sophisticated enough to put itself in firmware. We're fast approaching an era where you need to trash the hardware. You should never trust an OS install that was ever compromised, and making it more difficult to do so is a good thing in my book.
[1] https://developer.apple.com/library/prerelease/mac/documenta...
I'd read a book written by LinYutang, called My Country and My People. All my understandings of my country after reading this book are not same as nowaday China.
What's wrong? I don't know. I just wanna have freedom for Googleing. I just wanna the people in this country be happy not only because they get enough to eat.
The right to be forgotten impedes on total information awareness and the desire to make the perfect rational decision with your money.
This is a good thing. Total information is not perfect information because of bias and context. Someone seeking such information will process it through a biased lens and never attain perfection. In that case, the individual under the lens will lose out.
I hope one day I'll live in a country where I have freedom to write any code I like without fearing.
I believe you guys will make great stuff with Network Extensions.
Cheers!”
There are relatively few countries in which the government both could and would interfere with someone's publication of code, and I think only in China is there both widespread computer use and internet access, on the one hand, and state security actors (the civil police, actually) who have the sophistication and funding to intervene with specific projects such as this one.
Did you mean to ask what country he was in?
https://www.washingtonpost.com/blogs/the-switch/wp/2014/07/2...
http://www.csoonline.com/article/2947377/network-security/pr...
Both those conferences occur in a single country, one which was not even able, under its own laws, to effectively suppress the distribution of cryptographic code when it was legally considered to be militarizable as a weapon.
And the point isn't that they weren't able to suppress crypto code; it's that they tried.
> Since World War II, many governments, including the U.S. and its NATO allies, have regulated the export of cryptography for national security considerations, and, as late as 1992, cryptography was on the U.S. Munitions List as an Auxiliary Military Equipment. ...
> As of 2009, non-military cryptography exports from the U.S. are controlled by the Department of Commerce's Bureau of Industry and Security. Some restrictions still exist, even for mass market products, particularly with regard to export to "rogue states" and terrorist organizations. Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license
> ... Other countries, notably those participating in the Wassenaar Arrangement, have similar restrictions.
It's not about interfering with someone's publication of code. It's about neutralizing threats to rulers' rule.
China's rulers shut this guy down because his tool might enable too much free speech among the masses, which, in turn, would pose a threat to the government's rule.
As for the idea that "it couldn't happen here!", see how the US government "interfered" with someone's publication of articles: https://www.youtube.com/watch?v=dUYMPZ4nEOY
It's probably even more insidious, because simply confirming the existence of an NSL can be a crime punishable by significant custodial sentences. In the USA, posting "The police asked me to delete this code" could land in you federal pound you in the ass prison for 10+ years.
"Or rsync your data to Japanese Servers (Linode, GMO, etc) and ask your customers to download through http or https."
We've used Amazon CDN before even for Chinese customers and they have closest node in Hong Kong - they still(Chinese) have difficulties to download our packages. I doubt using Japanese server would solve our problem. Thanks anyway.
Back to your question, the answer is YES, use a proxy, which is less expensive, or buy a dedicated private virtual line from a Chinese ISP, which is more stable.
You can setup a fast proxy by carefully selecting the routing path. Nowadays, the CN2 cable (http://www.ctamericas.com/content.asp?pl=627&sl=637&contenti...) is a good choice.
Now imagine, one manager coming to you with an idea:
"Hey, here is a great way to make big money: we fire all our expensive US workers and move the whole production chain to China, people are much cheaper there and governement will keep it that way!"
Would you adore such a greedy $$$hole and make him manager of the century?
Just another crazy idea: Imagine we would produce all our hardware for all our communication devices in a country with such an authoritarian neandertal-government! Oh, wait...
The original repositories have been/are being reset. (Some branches were not removed.)
Non-obvious ways to search for forks as the network graph is unavailable for larger projects.
https://github.com/search?utf8=&q=shadowsocks+language%3APyt...
https://api.github.com/repos/shadowsocks/shadowsocks-iOS/for...
And you can paginate like this:
https://api.github.com/repos/shadowsocks/shadowsocks-iOS/for...
Were the repos mirrored anywhere, or would that present a risk to the original author?
What is described was a visit from the police in which they asked him to take down his own Github distribution. He clearly hasn't been arrested, and although he may be being fined, he doesn't mention it. You will notice that his message encourages others to continue work and is generally unhappy and defiant.
If this was a matter of any seriousness with regards to state security, it seems more likely to me that the repositories would be simply shut down without explanation.
My expectation based on my own few encounters with the regular civil police[1] is that those who specialize in computer matters are unlikely to be idiots; I assume they will know how version control systems work. It would probably be overly cheeky of him to actually contribute to someone's fork, or work on similar software, but there shouldn't be any negative consequences based on what we've heard.
My experience in China is limited, and someone else might offer contradictory insights, but that's what my expectation would be based on that experience so far.
[1] an edit to clarify: "In China."
> GitHub will not automatically disable forks when disabling a parent repository. This is because forks belong to different users, may have been altered in significant ways, and may be licensed or used in a different way that is protected by the fair-use doctrine. GitHub does not conduct any independent investigation into forks. We expect copyright owners to conduct that investigation and, if they believe that the forks are also infringing, expressly include forks in their takedown notice.
I appreciate the efforts of clowwindy and it's talented developers and hope the development keep going.
That might be nice if some independent organization take ownership of the project so other individuals feel safer contributing to it.
This is a scary wake up.
PS: nice to see you here. :)
You can tell when a country is either totalitarian or when it's heading that way when they begin seeking increased control over the media, when your communications are subject to routine governmental monitoring, when you can become criminally suspect for having cash, when they're afraid of you being able to encrypt anything because it might be Terror/ChildPorn (read as "forming plots against them"), etc.
Most of all, they don't want to end up dead like Saddam and Qaddafi.
They have valid fears of that becoming reality. Just like other politicians....
The only hope is for oil to just run out.
Governments, by definition, are meant to "Govern". Most see that the the rules of governance that they, as experts, have defined, should be "The Only Rules". They have a vested (if only intellectual, but rarely is this the case) interest in seeing people follow these rules. Any discussion, or debate, regarding alternative rules, is obviously being pushed by people who don't know what they're talking about.
It's oppression based on consensus and bureaucracy. Sometimes it's nefariously directed, but often it's just pigheadedness and arrogance that lead to decisions like this being made.
Although, sometimes it's just downright manipulative pricks holding the reigns. Hopefully this is less frequent than it actually appears to be. I'm giving these governments the benefit of the doubt, though they haven't done much in recent years to deserve it.
Did he ask a lawyer? Because it looks to me there are two possibilities. One, he was not doing anything illegal in which case the police had no authority to stop his activities. Two, he was indeed doing something illegal in which case he can be glad he got out of it with what appears to be only a warning.
- Hey guys, we are on front page of HN again!
- Yaay, lets upvote!!!
> The Streisand effect is the phenomenon whereby an attempt to hide, remove, or censor a piece of information has the unintended consequence of publicizing the information more widely, usually facilitated by the Internet.
Further, please consider that you don't have to kill a thing to control it. Even when something is technically possible, and arguably inevitable, it can still be neutered and effectively subdued. It's all fine and well to say things that suggest the human spirit will always triumph - that's optimism - but the human body can still be held in chains. A technical solution that is only accessible to a tiny set of people, under the right theoretical conditions, does not make freedom a solved problem.
His contact information doesn't look readily available online.
Did Chinese authorities contact Github, which readily complied with information that led to him being located?
Cops can do a lot of things, but they don't pull information from thin air. Github would be one source of information.
It's odd that this entire, and very popular, discussion on HN doesn't delve into how this individual was found.
It's also interesting that your reply is from a new account with only this comment.
Again, how the Github user was actually located by Chinese police was not disclosed or even discussed here. It's interesting that mentioning this has resulted in two comments by new accounts, solely to blame Chinese authorities as discovering the user on their own, with no evidence for it.
It would make more sense to just send a DMCA takedown for that plus all forks to ensure that the streisand effect doesn't come into play. Because now I gotta grab a fork and squirrel it away - even though I'm in the US I feel like this is important stuff to keep.
I'm not saying it's right. I think there needs to be a stipulation in the DMCA to allow service providers to actually be able to research and think about the take down request. As it stands right now - you can send a DMCA takedown for any github repo and github MUST ASAP disable that repo - no questions asked. Of course - asking to take down a repo filled with material that isn't copyright to you could get you into legal trouble. However, I doubt people in China care about US laws - especially if they are the government themselves. Would you sue the Chinese government for wrongful DMCA takedown of your github repo?
I find it interesting that the Chinese police have told him to shut it down, but have not put any restrictions on telling people he's been told to shut it down.
Who has the greater freedom in this respect?
See my reply here [1].
> I find it interesting that the Chinese police have told him to shut it down, but have not put any restrictions on telling people he's been told to shut it down.
Don't you think that signals there is more to the story? I doubt some friendly people knocked on his door and asked him nicely to remove the code. Then after he did it - they told him to have a nice day and left him with some tea and biscuits.
My gut feeling is there is more to the story than what is in the one line comment in the issue tracker.
I hope one day I'll live in a country where I have freedom to write any code I like without fearing."
I claim that the west is hardly better: Just say "copyright law".
People who do not yield to the GFW already made backups of all the repos under github.com/shadowsocks. And new tools to bypass the GFW is under development.
however,browse github has been harder in 2015.
I love my motherland but i really hate what the government has done.
sorry for my poor english
Features
Shadowsocks is a cross-platform tunnel proxy which can help you get through firewalls.
This iOS version is for non-jailbroken devices. It has two features.
A web browser with all the traffic going through a Shadowsocks proxy A background global proxy, with some restrictions Install
Available on the App Store
Please visit the App Store.
As a web browser
Shadowsocks works as a multi-tab web browser. It's really easy to use.
Tap the + button to open menu. Tap Settings to configure Shadowsocks proxy settings. Tap New Tab to open a new Tab. Tap URL field on the top to input URL. Swipe a tab to scroll the tabs. Hold and press a tab to swap tabs. If you've changed Proxy Mode, a restart is needed to take effect. (Kill the app, then open the app again). As a global proxy
Shadowsocks works as a background global PAC proxy, with some restrictions.
Only works with Wi-Fi network. But we are working on the cellular network. Only works for a few minutes. Due to iOS restrictions, Shadowsocks can't keep running in the background. It's killed after you leave it for a while. To keep it running for an extended period of time, you have to come back to the Shadowsocks app every few minutes. So it's a little tricky to use global proxy.
Set up proxy settings in shadowsocks. Copy this link http://127.0.0.1:8090/proxy.pac Open iOS Settings -> Wi-Fi -> i icon on the right of your connected Wi-Fi -> HTTP Proxy. Choose Auto, paste the link in the URL field. Tap back. Other apps now go through the proxy. If they don't, kill and restart them. Come back every few minutes to keep Shadowsocks running in the background.
Can the author reach the US by whatever mean and apply for political asylum? That 'fear that they will suffer persecution due to: ... Political opinion'[0] seems legit.
[0] http://www.uscis.gov/humanitarian/refugees-asylum/asylum
Frankly I don't know if we are that country. :(
http://dailyprincetonian.com/news/2003/05/peng-riaa-settle-i...
US citizens can use any encryption they wish.
I used to use commercial openvpn provider , and after a while I config my own openvpn server in my own vps . they both lose connection after 2 3 min. right now I am using shadowsocks and I have other options in case of something goes wrong.
Well, yes. A noose, for example. I completly sympathise with those the flee - but change in any country csn really only come from within. Often with help from outside - but without a force of change within - a real force - there will be no real change.
you'll have to to be wealthy enough to afford finding a way out. you'll have to be willing to leave your family/friends. you'll have to be willing to leave the place you might be very attached to. you'll have to be willing to put up with all the bullshit and xenophobia you'll be faced with, once you arrive in your "safe" destination.
It's not just about being attached to your friends or to a place. A lot of people would love to leave their country, but aren't allowed to.
All countries have oppressive regimes. Some are just moreso than others, and some target different people than others.
This is utterly destructive thinking, anyway. If the only hope, the only spark for change, flees, then there can never be improvement.
If everyone in China left China, and assuming the rest of the world is living as a family of four (play along), then every home in the world outside of China would have to take in one Chinese refugee.
"Leave" is not a viable strategy at scale.
In the USA, there is the fundamental notion of "consent of the governed" - if enough people won't submit, the government cannot function.
Also, Chinese are not prevented from leaving the country, que the opposite. Enormous efforts have been spent in sending a lot of student abroad and bringing foreign teachers in (I have been one of them). The thing is for most people here not being able to Facebook is of minor importance compared to access to cheap and good food, secure cities and an environment where they don't feel people look down on them. So, many Chinese students come back to China after abroad studies, despite all the problems in China, and amongst them GFW is the last important.
It happened elsewhere in this thread as well: https://news.ycombinator.com/item?id=10103364. The end state of that one was Hitler, the end state of this one was jingoism. There aren't many end states.
This subthread turned so pathetic that I wonder if we should create overflow pages for these. The bottom of a regular thread seems too good for them.
There can be a lot inherently wrong with technology, and there quite often is.
There are definitely some arguments that we could have used conventional explosives for those purposes, but my point is that a nuke is just a tool, its the people who decide to use it admirably or despicably.
Imagine this device: It only has button, pressing it will torture every human beeing in earth for 100 years and then wipe out what's left. Trying to disassemble or analyze it will do the same.
Would this still classify as "just a tool"? (peaceful uses: explaining the importance of restraint etc.)
This is not supposed to be an analogy, but a serious question, because I don't believe that guns dont't kill people. And if we disagree on such a fundamental question, I don't think an internet debate could have a sensible outcome .
I don't deny that nuclear technology has contributed to some of the worst calamities to befall humanity, I simply disagree that they have ONLY done negative things.
For instance, yes, a gun is a tool designed to kill a thing. Some guns are specifically designed to kill people.
But the technology of gunpowder propelled projectiles has peaceful applications. For instance, one of the early uses was to propel a rope to distressed boats and ships so that passengers could be rescued.
Likewise with the hypothetical device you have described. Sure, sounds terrible. But what are the underlying technologies it is built upon? Unless you've tapped into some sort of fundamental evil force of the universe, there are probably some pretty awesome technologies involved, that would have peaceful, useful applications in another device that wasn't so awful.
Just a caveman assessment of "atom bomb bad, flower good" is intellectually weak. The atomic bomb created a balance of power, the destruction of which would have resulted in countless wars and deaths.
A wannabe cold warrior fantasy of "without the nuke, the godless Commies would have put the boot to the civilized world" is just as intellectually weak. I thought this furious jerking off over Regan-era revisionist talking points was passé in the current century.
We've noticed over and over how generic tangents are the gateway to flamewars. Tangents about something specific ("off-topic, but I once worked with that group...") are often interesting, but generic tangents dilute discussion and not infrequently eventuate in Hitler.
It's arrogant for us to believe that we are on the 'free' side of the firewall. I don't see how one side is more free than the other - Both sides are subjected to constant brainwashing by various media - Be it at the hands of a suppressive government or those of greedy corporations.
One thing that really surprised me about Russian and Chinese people though is how well they take care of their friends and family (for example, they are often very willing to share their money to help each other) and how genuine they are compared to westerners. I know it's a big generalization but it's something I noticed.
With that said, I'm of the radical belief that no internet communication should be blocked, inspected, or analyzed etc... but thanks for such a piquant response.