The Iran Firewall: A preliminary report
blog.thc.org
blog.thc.org
https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
That said, CloudFlare, Firefox, and Chromium teams have all been working toward the evolving spec so one can hope that soon with eCH and DNS-over-HTTPS we will be able to have clients securely connect to servers without broadcasting the hostname to which they are connecting.
These firewalls are an exercise in having your cake and eating it too.
And we know this is what will happen as this is effectively what happened with domain fronting--where you simply use the wrong SNI instead of hiding it entirely--with all the large CDNs actively "fixing" this feature to prevent their customer's websites from being blocked by firewalls because of users who were using this to get around hostname restrictions.
Thankfully? in the case of Iran, many customers do not want to interact with Iran because of US export regulations, so if it breaks that, all the better ironically enough.
China, on the other hand... That's where it starts getting interesting. There's already been several prominent examples of companies self-censoring to appease the Chinese government.
What basis do you have for this claim? People make these claims constantly so confidently, but wherever I look all I see is that dictators have always been willing to make their nations incredibly poor.
> These firewalls are an exercise in having your cake and eating it too.
More to the point this isn't the Gordian Knot you think it is.
HTTPS isn't designed to prevent this. If you want to allow 'legitmate' access you just issues your own certs, and proxy requests. Universities etc can install your root cert and use your DNS servers.
So your assumption that “dictators will do the worst they can” is wrong. They will keep pushing the boundary outside the current Overton window but can’t do it in a snap. You force their hand by not providing alternatives and suddenly they’re stuck. They can’t just restrict feminist websites and claim that it is harming the social fabric then expand the net slowly. It is all or nothing as the OP explains.
In dictatorships where they need the populace, then they are in a tough spot, because the only way you get rich is having a developed population productive enough to tax, which you see in Singapore, China, Dubai and Iran somewhat.
It is this kind of authoritarian regime that needs the internet, but also wishes they didn't need the internet in the case of Iran and China.
CGP gray has a great youtube video summary explaining this: https://www.youtube.com/watch?v=rStL7niR7gs
So in essence, this is a positive move because even dictators willing to destroy their countries for power will have to make a choice on internet access well before they gain enough power to cut it off entirely.
Iran lost $17 billion in economic activity by cutting off the entire internet a few years ago for a week. They have not done that this time, making internet outages at specific times of day, etc.
Eventually, we'll end up with either uncensorable technology or a totalitarian government.
Also I'm not well-educated in that area, but I would expect that CDNs would allocate dedicated IP ranged for big customers like Microsoft or Apple. So state can ban more selectively, white-listing those ranges.
The current iteration of ECH is designed to be GREASEd which means browsers might just always do ECH with dummy values regardless, so either you block or you don't, you won't be able to selectively block ECH. This doesn't magically prevent the Great Firewall from working but does mean specifically host matching is degraded as intended.
Funny enough the children's "telephone game" is, in many Commonwealth countries, apparently called "Chinese whispers," at least according to my Londoner colleagues.
You probably don't pay them to uphold their power to close roads whenever they want, it's just a consequence of the aforesaid monopoly on violence.
If you think it's wrong, you can try to bring competition into the market, but if history is any indication you'd better make sure you have a lot of upper/middle-class people who agree with you first.
A parade or block party closure is a closure of a public road, so is closing the street and digging a tunnel.
A few projects are in similar territory but none I've seen are working at the layer of bypassing BGP. Many are just acting as an overlay; which works to an extent. https://github.com/yggdrasil-network/yggdrasil-go
It's probably begging for a different model of the "internet" and where data lives.
My requirements:
1. Offline-first applications that sync via a pub/sub DHT of trusted peers. More details here but basically allows bypassing BGP.
2. Trusted peers are routable via a determinstic pathing algoritm without exposing the recipient. (content addressable everything).
3. Automatically distribute storage and compute on all local devices a user has and or needs (it's so dumb and wasteful that I only use one computer at a time when I have hundreds at my home at different levels of compute from thermostat to fridge to laptop to desktop).
I've thought about this for a long time and planned many requirements out. I was very committed to working on it but then I lost motivation because I don't get along with most humans today and where the world seems to be going. It also sucks to have people think your ideas are crazy.
Oh well.
Global peer discovery is solved via mapping of identifiers via the reserved TLD, and via mutual TLS for identification and verification. So peers are basically pinned client certificates in your local settings.
Works for most cases, had to implement a couple of breakout tunnel protocols though, so that peer discovery works failsafe when known IPs/ASNs are blocked.
Relaying and scattering traffic works automatically, so that no correlation of IPs to scraped websites can be done by an MITM. Tunnel protocols are all generically implemented, DNS exfiltration, HTTPS smuggling, ICMP tunnels, and pwnat work already pretty failsafe.
What's missing is UPnP support so that it behaves a little more gracefully when a router would be cooperative in nature, but after trying to implement the "specification" a bunch of times I skipped it for now.
Lots of work to be done though, and had to focus on couple of other things first before I can get back to the project.
The browser is part of a larger network that's trying to automate cyber threat intelligence on a peer to peer level, so clients, servers, websites and domains have a trust ratio and a history of trust to prevent misclassification of a new domain owner that e.g. defaced a website or tries to inject their malicious assets up unto previously trusted peers.
I like what you're doing. Do you have a Discord? Is it a solo project? Working with a team or just "community pull-requests?"
Curious about your trajectory.
The Stealth browser is kind of a solo project for now. It grew out of my personal intention to build a better architecture for a more efficient web scraper + browser that doesn't waste internet bandwidth, because I have pretty crappy internet abroad. But I'd love to grow a community out of it.
Before the 4chan attacks last year there were a couple of other devs that occasionally contributed to the project, but they faded slowly away with the discreditation campaigns against me/us. As the 4chan raids led to us realizing that we're better at building cyber intelligence + defense products, we also pivoted with the company to this area because of it. The threat analysis mechanisms and peer-to-peer networking parts (with trust ratio of nodes/edges/paths) are very similar in nature, so it was a good fit, technology-wise.
I'd still want to build the stealth browser further and make a better project out of it (especially with the RetroKit fork which is WebKit minus the tracking APIs), but I've pivoted with the company to a different area and that's currently the primary objective. As our country is regularly attacked by a lot of cyber threats right now, we've focussed our efforts on developing the cyber defense technologies.
Right now, stealth is primarily being used as a Web Scraper via it's node.js APIs by us. So it's still actively used and occasionally we'll push some features to the repository.
You need a lot less information "over the wire" when it doesn't move as far, and when you can speculate and predict what to render (ML/AI). What matters is the package and space more than anything. Go figure. That's also why "massively distributed compute/swarm computation" makes sense in this mesh like model you hint at.
The future is strictly local data unless we totally escape time dialation over large distances, whether or not we bypass speed of light limits.
The future is strictly a simulation if we are a multi-galaxy species, let alone spread across the galaxy. The only way to have a real-time conversation is to simulate the person/ego. The local copies would be as real/eventually consistent as possible over time.
It is already a thing but not common due to many limitations, mainly very short useful range.
Call it, determinitic-spontaneous-rendezvous-routing.
I guess this would require everyone to use a government-sanctioned DNS and that would require traffic on udp 53 to non-gov-dns servers blocked? I felt like this was glossed over a bit too quickly in the article
Block tcp/853 and most common public DNS servers and you can control resolving on 98% of devices.
In fact, if you live anywhere outside of the US, owning one "just in case" is good for future proofing your freedom, IMHO. Kind of like being armed.
Edit: in fact, starlink v2 global LTE-from-space coverage will be a true game changer for world freedom. We can only hope this comes to be sooner rather than later.
This is punishable and does get punished (rarely, I hear). Doesn't deter anyone.
Edit: it will also be quite difficult to detect electronically, judging by the fact that even Russia fails to jam these signals on the battlefield.
As for TX detection, you'd be surprised. Directional signals like starlink uplink are fairly hard to detect.
https://www.google.com/maps/@35.738824,51.5285095,19z/data=!...
Key word is bad days. Expats in China have noticed the same thing, with VPNs sporadically not working during summits, around certain holidays, etc but resuming afterwards. Also, for some reason certain VPNs work more consistently than others even though they use the same protocols as blocked services. Some speculate that the ones that continue to work are either honeypots or the companies behind them have (social) connections
Also, it's kind of poor taste to call those who want free(dom) internet there as "neo liberals"
This is a common and natural misconception. When the firewall gains a feature (i.e. the ability to block certain traffic) the VPN providers then have to figure out some technique to bypass it. This happens over and over again. The firewall isn't relaxing after the event, it is staying the same and the VPN provider has improved.
On your second point, I can't comment for all providers, but I've heard this rumour in a more specific context and can say that it is definitely at least sometimes false.
Years ago one provider that rhymes with krill was pretty consistent, but in the end it seemed one could get the most mileage(err uptime) by rolling their own v2ray instances on a VPS provider that had "Hong Kong" servers in Hangzhou.
Thanks, sincerely, for the note on language. I've used that insult a lot in the past.
I also had a string of international students do things like complain I was racist for asking questions and answers be repeated back in English, not just Mandarin. (And they weren't from Taiwan.)
It's true that America has no official language, but when folks like myself expressed that sentiment in the policy space, it was with the intent if someone speaks French, Spanish, or one of the many languages of the Native Americans could be given services in a manner they understad, as is their human right.
It was not a rhetorical devie meant to me wielded by agents of a foreign power.
I ended up accepting an alaprazolam script, following a string of failed antidepressants, navigating the social mileau of "they treat me like an international student because I know who the spies are and refuse to just... hire me somewhere... as their system crashes around them"
This was in the lead up to, and during, the Summer of Snowden -- I was really pissed that no one would hire me into private industry and civil society... well all I can say about so called "civil" society is Epstein didn't kill himself.
(Happy spooky season!)
Nope, thanks, do not promote this shitty KGB-affiliated service.
Also if you're talking seriously about privacy - forget about all services hard-locked on SMS or phone numbers.
Sounds like my internet connection in grad student housing about 10% of the time, except the initial SYN is dropped. Pings and everything else are fine.
We had sites blacking out because he decided DNS tunnelling bad so he blocked anything with low TTL. Meanwhile simple POC DNS tunnel worked fine..
I understand that not everyone is as good at writing as others, but it really doesn't take much effort to ask someone to proofread.
Otherwise, this is a good start, even though it lacks details and examples.
But the whole, "neo-liberal arses" bit gave it the sense of an unhinged author or untrustworthy narrator.
The weird use of the term neoliberal is pretty common in European liberal-as-in-freedom left leaning circles.
[edit] This is the same way that if I go out and throw someone into my basement it's 'kidnapping' but when the police do it to me, it's an arrest.
Jokingly this comment has the same vibes. [1]
[1] https://twitter.com/dril/status/473265809079693312?s=20&t=gD...
this is literally trying to control, just on a different level.
I was probably a little un-clear in my response though, I meant in one case the goal of the administration was to control and repress the people in direct opposition to my values and that of many others. In the other case, the goal is to control the administration and erode their ability to do so.
This is one of the most peaceful times in world history, after all.
With that in mind, no, I don't support the Iranian regime. Positions should be evaluated piecemeal, it doesn't matter what you think about America's other positions, it doesn't need your personal 'moral high-ground' sign-off to be in the right on this one.
> The Internet is easily censored. The neo-liberals got their arses kicked. The big players like Google/Apple/AWS are partly to blame. China runs the GFI as a service.
The author mentioned some of the blocking methods, so that's cool.
A detestable person that thinks he can circumvent the regime? Presumably a paleo-conservative (or whatever the opposite of neo-liberal is in the mind of the blogger) would not be so naive and would look at real "solutions", as opposed to the neo-liberal, who is interested in non-solutions.
Pretty awful ideas floating around in this guy's head.
That said, it sounds cool to mouth-breathers so they often use it completely out of context, like this author did.
Seems like this was a real movement but isn't so relevant anymore, and now people are misusing the term. Now "hawkish" or "interventionist" is pretty close to the old meaning of neocon. I'm willing to accept it as a term for a historical movement, but if someone tells me X newly relevant person is a neocon, I'll basically discard that.
p.s.
Basically the occupation theocratic regime of IR positions itself in its propaganda to demoralize Iranian resistance by prophecies of doom and gloom for Iran should it be cured of the IR disease: there is ISIS or Daesh [or "it will Syria 2.0"] (aka terror); there is that crafty prince in KSA that wants Iran to parition; there is the crafty sultan in Turkie (sic) that has pan turk on his mind; and should the country remain intact let there be no doubt that "neo-liberals" will do a Greece or whatever to Iran.
A liberal is someone who values individual freedoms and human rights.
A neoliberal is someone who values deregulated economy, privatization of all things, free markets, free trade, and open economic borders.
The Iranian regime would be a conservative one, where they value limited social rights that favor some social morals over the individuals own, like what women/men can and can't do, what you can and can't eat, what you can and can't drink, what you can and can't teach or believe in, etc.
The Iranian economic model is a mixed bag, kind of a social-caputalist mix, with lots of state owned and managed enterprise, but also allowing private ones. That said it comes with a lot of regulations to have them enforce the conservative social norms.
Hacked femtocells? SDR? Something more clever?
Distribute eSIMs to everyday people.
The pirate operator takes all the risk and technical difficulties.
Unless we're talking about something like smuggled two way satellite terminals.
Having these pirate base stations mesh together is also achieveable. Freeing end user equipment from the requirement to mesh (not achieveable).
I mean, 10 bucks for an AP isn't far fetched whereas LTE antennas alone would explode in budget, even when considering to use OsmocomBB with super old hardware/phones.
And every phone these days got Wi-Fi anyways. Most meshnet solutions rely on Wi-Fi so you wouldn't even need to implement much software for peering.
the ultimate fate of the internet
1: https://en.wikipedia.org/wiki/Islamic_Revolutionary_Guard_Co...