China systematically hijacks internet traffic: researchers
itnews.com.au
itnews.com.au
Bruce Schneier's blog post on this paper: https://www.schneier.com/blog/archives/2018/10/chinas_hackin...
You basically can't bgp hijack without breaking basic internet connectivity for the legit users of the IP space (where it is intended to be announced to peers and transits), so anything lasting more than 30 seconds will generate a huge flurry of phone calls and noc emails.
There are third party services you can pay, and software you can set up yourself to watch for bgp announcements for "your" Arin/ripe/apnic/whatever prefixes, and generate alerts based on that. Pretty common stuff with Linux based systems (FRR, etc) that can hold the entire global v4+v6 routing table in RAM and do quick analysis on it.
Google "bgp hijack", this is a well known issue in the ISP operational community. RPKI validation of announced routes and best common practices for what you accept from your bgp neighbors go a long way.
In addition, network traffic at ISP level are never intended to be secure. That's why we have/need end-to-end encryption.
Maybe it's time we started using Tor hidden services for everything.
It's theoretically impossible to have a language that is sound, complete and decidable. It's probably also impossible to have an internet that is open, robust and secure.
Which one of "open, robust, secure" do you think Tor doesn't meet?
You can pick any 3 concepts and group them together like that, but it doesn't mean you can't have all 3, e.g. a house can be "large, cheap, and well-decorated" (e.g. if it is in the middle of nowhere).
What's the usability problem? Just that you have to download Tor Browser instead of Firefox?
The usability of setting up a hidden service is actually easier than getting an SSL certificate.
The fact that this is possible today seems incredible to me when i think of the number of times i've heard cybersecurity and cyberespionage was a priority of the US security agencies during the last decade.
Like whoa, are you even aware of what you are suggesting? This is completely false.
I think most people exaggerate the technical capabilities of the Chinese government and how interesting they are for them. Sure, we shouldn't be naive, but a drop of realism is always good.
I don't know the person who asked the question, whether he is a realistic government target or just some normal person but there are enough reports of cache poisoning, VPN control/blocking and Chinese hijinks to know that if you are worried about them, don't connect. Mind you, the same fear applies to the US and UK as well.
[0] https://en.wikipedia.org/wiki/Transport_Layer_Security#SSL_2...
A simple way to evade all of this is to use shadowsocks with a strong cipher and strong password between your computer in China and your server outside of it. Don't use any free server and don't use any commercial shadowsocks offerings. Set it up yourself, it's pretty easy.
On the mobile phone side of things. I wouldn't trust anything. Especially Apple that has been very complaisant with local authorities.
China plays a tactical game: they pretend (or we suspect, and they want us to) that they can do a lot of things. But nobody knows the extent of what they are actually capable of.
See https://shadowsocks.org/ for info.
On your local workstation, it exposes itself as a SOCKS5 proxy. But to communicate with the shadowsocks server, it uses a proprietary protocol which is not SOCKS5 and does have a key exchange process. Either way, these details don't affect its ability to be detected.
> VPN is not made to be undetected
"VPN" is not just one technology. Many vendors of VPN software do claim that their software is made to be undetectable. One example is shadowsocks, but there are other vendors who also claim that.
i.e. The Random Forest Based Detection of Shadowsock's Traffic, https://ieeexplore.ieee.org/document/8048116/
I don't really understand what kind of scientists would do such researches to help the government carry out the censorship more efficiently, over their fellow people...it's either those intellectuals have no brain, or no heart...
A couple of weeks ago, I was asked by a friend who was traveling in China at the time to set up a VPN for him so he could use Gmail and other Google services there...I went for the easy way and used the OpenVPN for him, but to our disappointment, with that VPN tunnel, he still could not access google search page while many other pages on other domains were fine...I spent a few hours trying to figure out why, and then I came across these discussion,
https://superuser.com/questions/1187525/vpn-to-avoid-the-gre...
https://www.quora.com/Can-Openvpn-still-bypass-the-GFW-of-Ch...
My friend and I haven't experimented further; but I think one way that might work is to chain multiple VPNs or perhaps obfuscate your protocol a bit (i.e. make some minor customization yourself)...
http://security.riit.tsinghua.edu.cn/share/classify_encrypte...
But if the government completely blocks out VPN uses in the country, lots of international business operating there will suffer and then they will complain, which is not something the government can ignore (at least not always)...VPN whitelist could be a solution, but I don't know how well that is implemented (if it has been implemented) -- not to mention keeping a perfect consistent whitelist at that scale would be difficult...in addition, there is always some false positive/negative in their flow pattern analysis -- those are statistical approaches after all...so there is some grey area here...
Anyway, back to that openvpn experiment I did with my friend, many websites were still accessible with my openvpn tunnel -- although Google was not among those sites -- this seems to imply that they were doing some package semantic analysis (i.e. deep packet inspection)...
OpenVPN has been offlimits in China for like 8 years now.
Please read the article before commenting.
So from an outside perspective the US and China are pretty much the same thing in that regard.
To top it off, the five eyes nations are spying on each other - so even if you're a citizen of one you're tolerating being spied upon by four other surveillance apparati that aren't accountable to you.
https://en.wikipedia.org/wiki/And_you_are_lynching_Negroes
Or if you prefer, the contemporary form:
https://en.wikipedia.org/wiki/Whataboutism
——
This varient is particularly useful against anybody with a social justice argument. Let’s say I complain about Google and what appears to be systemic support for sexual coercion by male managers. You can trot out, “But it’s far worse at Uber, did you complain then? No? Have you taken an Uber since then? You have? You have no right to complain now.”
Or maybe I say that migrant children have been separated from their families. “You’re a Canadian. Did you speak out against Residentual Schools? No? Then shut up about migrant families.”
It’s endlessly applicable.