VPN services blocked in Sri Lanka as information controls tighten
netblocks.org
netblocks.org
On another note, I recently set up a Tor bridge with pluggable transports to help those in choked areas. It was a fun homelab challenge, and a good way to spread my privilege of having a free connection.
Sounds like security theater. Using port knocking isn't going to hide the fact there's a SSH connection between you and some server. If anything, having a non standard configuration (non standard port number or port knocking) makes you more suspicious.
Unless you were to attract the attention of somebody in government, and they forced an ISP to escalate an issue to the 3rd or 4th tier of network engineering running the core of the bigger ASes there, they're not going to be doing that. It's not the chinese GFW.
So unless somebody cares to inspect your traffic flow in particular and notices that it's openvpn traffic on 443 and not normal TLS1.2 traffic, it's likely to work.
Firefox has build-in DNS over HTTPS. That will help.
I don't understand why one ISP is still allowing Nord and express vpn through. If anyone is open to debug this and help create a work around I'd love help. Feels like a good time to test things.
In the meantime people are using dubious vpn providers and are opening themselves up as easy targets. I dread what would happen if a malicious party created a vpn with malicious intent and then spent some bucks on targeted advertising in SL on the app stores.
This block is such a shit move really. It's become the gov's default crisis time response in the name of national security.
You should have better luck with something like Shadowsocks, or even better, Shadowsocks over a SSH tunnel. There are probably better and more potent alternatives that I'm not familiar with. If you just want to do regular web browsing, a simple thing to try is to just use "ssh -D" for a SOCKS5 proxy and configure your browser to use the proxy.
Also, a possible first step in debugging is to run the same server setup in the same country as the client and see whether it allows you to connect to a domestic server. If it doesn't, it's probably a problem with your client/server setup as the state's firewall probably doesn't need to block domestic VPN connections.
I'm right now using Nord via their ovpn files. Somehow it made its way through one ISP ruleset.
For my digital ocean box, I asked someone else to use tunnelblick with the ovpn file I provided them to see if it worked (they were in another country) and it worked. This makes me believe it's most likely a country level issue.
In general though I'd like to learn about networking more thoroughly and set up a censorship resistant option which I can help others to setup and share as well later on. Any primers/pointers are appreciated too. I'll start with all the things you mentioned though.
Other than that, do investigate DNS on HTTPS and DNS on TLS. I recommend setting up something like dnscrypt-proxy to serve as the DNS resolver for your LAN.
Currently, I'm using Algo[0] setting up VPN and use Wireguard[1] connect to it, both of them are working perfectly than other solutions I have used.
[0] https://github.com/trailofbits/algo [1] https://www.wireguard.com/
https://www.thehindu.com/news/international/sri-lanka-bans-d...
His GitHub went quiet after that, but as wiremaus points out, he seems to be alive and well based on his twitter posts.
https://translate.google.com/translate?hl=en&sl=zh-CN&u=http...
shakes Magic 8 ball
My guess is it's a combination of what the Sri Lankan poster above mentioned combined with a reaction to further technical escalation by the citizenry.
Unfortunately, there are too many unknowns w.r.t. Sri Lanka's government/cultural values for me to even hazard a guess as to what the endgame is beyond minimizing net driven attempts to organize.
What I do see potentially transpiring, however, is someone figuring out how to host basic net based communication within the country; odds are though, the government feel themselves sufficiently equipped to take down in country rabble rousing, and possibly aim to keep outside influences from inflaming things further.
Best thing you can do if you want to get out, is find the IP addresses for your particular of site, and use that. DNS based blocking does squat if you're maintaining your own registry of IP->Domain Name bindings. If they catch on and start trying to IP block, well, welcome back to the pre/early internet days. Hopefully you know someone willing to host you a forwarding proxy.
Stay safe Sri Lanka folks.
Shutting down communication channels rarely helps defuse such situations, though. It leads to more isolation, more rumors, more enmity.
Historically, the people here have engaged in "knee-jerk" violence following an initial inflammatory incident; see:
https://en.wikipedia.org/wiki/Black_July
https://en.wikipedia.org/wiki/2018_anti-Muslim_riots_in_Sri_...
In the second incident listed above, social media was used both as a vector to spread hate speech and misinformation, and also to help mobs organize.
Regarding the current social media block: at the start, I felt this to be reasonable, as it made sense to slow the spread of misinformation/hate speech for a couple of days, until people's emotions cool down. However, the blocks still continue - and I see no clear justification for continuing them for so long.
I believe there's a lot of potential for CDNs and major sites to offer anti-censorship pass through traffic with HTTP/2 via CONNECT. By having a multiplexed protocol with multiple streams that spans "normal" traffic and tunneled traffic, it should be harder to identify. This would allow major sites or CDN providers to provide service to those people behind such bans and possibly require governments to break a significant portion of the web in order to institute those blocks. I think it's valuable to increase the damage done by government blocking so we can ensure that mainstream persons are sufficiently upset by this conduct. I also think CloudFlare and other major CDN providers should be the ones to provide this type of VPN access either as a product or as a special case offering for people in countries who censor the web.
I realize there are many businesses who wouldn't damage their primary offerings to provide such a secondary service. But it only takes one or two companies to increase the collateral damage of the bans, and thus make them much more costly for the governments imposing them.
Cloudflare also built and opensourced a rust implementation of wireguard which will likely back the service [0], but unfortunately, they didn't collaborate with upstream.