China's Great Firewall Tests Mysterious Scans On Encrypted Connections
forbes.com
forbes.com
What information could the response to garbage possibly convey beyond: "how does this server respond to garbage"?
How would that even help with fingerprinting, which is his suggestion? Would there even be much variation in how different sshds would respond to that? So what could you do with that information? 30% of known Tor servers use sshd version X, so let's ratchet up the frequency of RST packets for connections to servers of version X? Seems like a long shot: that would be both a sophisticated attack and have pretty hamfisted results. And how could this information be used to find open relays? Just guilt by sshd version again, since statistically machines with open relays have a tendency to run version X of sshd?
I'd like to hear a security person come and talk instead of my wild speculations.
If the adversary is in the middle (MITM) they can read all your traffic and obtain the required entropy in real time. In this scenario, it doesn't matter how much entropy is contained in each packet because the adversary knows that information in real time. Thus the adversary will be able to inject packets to reset/terminate the TCP session, causing a Denial of Service situation.
Cryptographic protocols including SSH and TLS are designed to solve the majority of problems that MITM adversaries can cause. The notable exception is that these protocols rely on unprotected TCP sessions. MITM adversaries are still able to reset/terminate TCP sessions (when SSH/TLS protocols are detected).
IPSec protects not only the information transmitted, but the IP packet headers as well. An Authentication Header (AH)[1] is appended and verified to ensure that packets haven't been tampered with or forged. MITM session reset/termination attacks are therefore no longer possible because forged packets will be ignored.
[1] https://en.wikipedia.org/wiki/IPsec#Authentication_Header
My guess is that they're using it as a cheap way to tell the difference between most of the common protocols. (ie. ssh vs. openvpn vs. https, etc.)
No. But the point probably is: it is much easier and more economic to block the receiving end once by figuring out what it is than having to scan every single outgoing connection all the time.
Which would be a problem for the Chinese government HOW?
I think those very blunt ways of identifying "unwelcome" connections and then just blocking them looks like exactly the solution a government makes that doesn't twitch an eye at re-locating thousands because they want to build a dam right there.
So far encrypted traffic was a neat way of circumventing the control, now this could be trying to just plug those holes. Even if the handshake message does not say "OpenSSH xx...." at least the protocol response to random data would give them a clue and it is (sort of) more difficult to fix on a larger scale because they could always fine-tune the finger-printing.
Instead of monitoring and analyzing all outgoing connections all the time, they just figure out where they are going and then block the destination once and for all - sounds logical and neat.
vpns have been horribly bad the last few weeks
tunneling through ssh has also stopped working consistently.
I don't know anybody over here who has a good vpn anymore. It's got to be hurting business that collaborate internationally - the net goes down for a few minutes at a time, throughout the day.
Deleted comment
I can't imagined that this will stay the same for long, especially now that the GDP growth is down to 9% and likely to go down further. Next year they will even loosen the restrinctions on real estate purchase again, to get the economy going.
I have not noticed any drop off in connectivity when using my company's VPN, but I'm sure this is because this is an authorized VPN.
The most notable blow here is that people using solutions like FreeGate are getting heavily affected by this. Most Shanghainese people use this to connect to the outside world.
People like those of us reading this site probably won't have much trouble finding ways around it, but it seems people (esp. Chinese) who would normally hop the Great Firewall with ease using VPNs/proxy will have to put in more effort/get more technical to do that successfully, and i'm afraid that they won't want to bother.
Which means we'd be forced back to a 90's level of internet security at least for consumers, I'm sure corporations will be able to 'buy' the right to use encryption...
The last few weeks, the frequency of the probing has increased. This might mean the beta test period is nearing its end, and that this function is about to become more widely deployed."
EDIT: Downvoters, do you disagree? With the continuous attempts at controlling the internet and destroying people that get dirt on US corruption? SOPA is just the latest attempt. It wasn't the first, and if we beat it it won't be the last.
Posting via https works, however.
I have not been on the Tor network before and I do not plan to but it should be the persons choice of whether they access it or not.
China are like the dick head IT manager who turns off javascript at network group policy level, just because he can.
It's a big loss of face for the present leaders to change their policy. But we keep on hearing the phrase from within China: "Perhaps the new generation of leaders taking over in October 2012 will have different ideas about web censorship". If the policy is going to change, it'll be soon after this time when no government leaders "lose face".
The US and EU are also preparing to challenge China at the WTO claiming the Great Firewall violates free trade. If the US and EU can get their timing and level of prodding right, the Firewall might be dismantled. China's already given their web businesses such as Baidu enough startup advantage from the Firewall, and will probably find other ways to give advantage to subsequent startups.
But... the infrastructure's already there in China to block foreign websites. Anything that exists but isn't used will be used again sooner or later by some politician, so thanks to Cisco et al the Firewall will always exist even if "dismantled" under WTO enforcement. Just like the US military is there to defend the integrity and borders of the Union, to be used as a last resort, but gets used to invade Iraq for cheap oil.
For the same reasons a startup is nimbler than a big corporation for changing things, larger countries are slower than smaller countries for making significant change. India is lucky because it's had a tradition of democracy and freedom for quite some time. They already had cultural momentum in that direction, so they don't need to change anything to align with what you want. Similar for Japan. China, you're asking them to reverse the pull of gravity.
I've worked in teams that were focused on creating big vision cultural and organizational change in big corporations. I can't even begin to imagine how difficult it would be in a big government, especially one of China's size, and one where there is no easy allowance for diversity of opinions.
For example, China's central government is huge on trying to stamp out corruption. However, despite the number of executions they continually carry out for corruption matters and the dissatisfaction of the populace, it is logistically impossible to keep a handle on all of the regional and local governments. It's a huge complicated machine, and I'd warrant that it's even more complicated than the US government's operations, judging from what I've seen living in China.
No offense, but you seem to miss the point. You've just cited a different political bar at which [government] censorship is okay. I'm not saying child pornography is okay, but it's just a different line in the sand.
There should be more policing on the internet as a whole, I just don't agree with how far they go.
When they banned Google search months ago, that was because of political agenda over user censorship.
I do understand what you mean, I just think there can be clear cut boundaries you can draw.
It's also not a matter of preference but a matter of what is right and wrong?
Who defines right and wrong?
Is it right or wrong to look for abortion clinics? What about just doing research on abortion? How about stem cells? Should I be able to use bit torrent? After all, I can torrent Ubuntu releases, or copies of mp3's, or child pornography - and there's no way to tell the difference.
Is it wrong to look up information that makes your government look bad? How about someone else's government?
You are measuring a totalitarian regime against your own values of freedom and call their actions "pathetic" because they don't allow personal choice of having encrypted traffic?
You must have no understanding of China and its politics and the meaning of their censorship and their Great Firewall... that's like saying "Hitler was a real dork because he did not allow free speech and freedom of art which are totally awesome and everyone should be allowed to draw what they want!".
People are using VPNs to bypass the firewall therefore the people inside of China do not want the restriction so it's obvious that the people inside do not want to be restricted.
So yes, I deem what they are doing from a government level pathetic as it doesn't stand for what the whole nation wants. So it's not MY values of what I call freedom but my understanding of what a majority of the people inside China actually want.
If people didn't want that then there would be no need for encrypted traffic to connect to sites that the firewall would class an inappropriate.
Do you really think that the majority of Chinese citizens use VPNs to bypass the firewall?
So I would say yes, a lot of people are using a VPN to bypass the firewall
http://www.google.ca/publicdata/explore?ds=d5bncppjof8f9_...
Given this data, it's impossible to say that the majority of people in China do not want the restriction. Rather, I'd say the majority of people in China do not care because they're not on the Internet anyway. And once they get on the Internet, do they care about Youtube? No, Tudou and Youku have free licensed streaming for anything they could care about, including now licensed stuff for Western movies and TV shows. Facebook? Everyone's on QQ. Twitter? They got weibo and it's growing gangbusters and is the only real outlet for political dissatisfaction; so it's immensely popular. Twitter clients and apps? Heck, everyone's making one for weibo.
Some users want access to Facebook and the like, sure. But how many? Nobody really knows because that data is suspect when it is available. But even if nobody was interested, it's still such a huge market that even a small subset would create enough revenues for these companies to make a profit. That's why they exist. Because the market is so large anyway and it's low hanging fruit.