Show HN: Wa-tunnel – HTTP Tunneling through Whatsapp
github.com
github.com
I assume one could also create a tunnel over reddit chat connect to the Internet, but I never did that.
By default, reddit did not work though, as their fastly CDN endpoint is different from stripe's, also the stripe's endpoint did not correctly sign TLS for reddit.com. But setting a Host header of old.reddit.com on that fastly IP successfully downloaded the page.
When I still had phone network by the coast, I set up iodine IP over DNS tunnel, but it did not work, even though DNS requests worked on that WiFi. Maybe they had some sort of protection specifically for iodine.
Tor's "meek" pluggable transport uses it, but only supports a couple of cdns as you need to run infra behind the CDN which costs money.
As for Iodine, I used to run a few public DNS tunnel servers with it for people. Its a pain in the ass to get working reliably.
I used a program called Packet capture that registers as a VPN connection in Android and routes all traffic trough itself. I saw some external IPs with TLS data when visiting the captive portal: http://upload.4a.si/pcap.jpg
When I sent a request to one IP address, I learned from the response that I've reached a fastly endpoint. The response was an error page, claiming they host no one with this domain. I knew from a talk by reddit sysadmins that they use the fastly CDN, so I added a Host header with a value of old.reddit.com:
curl -ikH Host:\ old.reddit.com https://151.101.0.176/r/Slovenia.json
Then I added a rule in software AdAway for Android (this one is used for DNS blacklisting to remove ads based on DNS queries and requires root access - changes /etc/hosts AFAIK) to overwrite old.reddit.com to this IP address.
I can't remember how I tricked the web browser into ignoring invalid certs.
I think the only risk is that if you have a real client running it reports the invalid messages and WhatsApp uses this as a signal to van your account.
So I think Meta/WA can opt to decrypt any suspicious messages they come across.
It must be either message size, or WhatsApp using a separate host name for attachments.
Much easier to implement than encrypted package inspection.
How does Whatsapp choose to ban people? Total messages sent? Then increasing the message size doesn't stop you from being banned, it just makes it take longer before you're banned. Messages/second? Then avoiding the ban by a message size restriction seems like a very clumsy way of doing it; it would be much more straightforward to avoid the ban by limiting the messages/second.
Never did IP with it, but i worked with a team that jerry rigged this to transmit some telemetry from a remote location where external data access was cutoff for several weeks using portable radios.
In our case, we embedded some data in a QR code. It was one of the more fun little projects but only marginally practical.
https://upload.wikimedia.org/wikipedia/commons/e/e5/Analogue...
I mean if this doesn't charge you up the yahoo per message, might be viable in a very limited circumstance?
A Personal Hotspot lets you share the cellular data connection of your iPhone or iPad (Wi-Fi + Cellular) when you don't have access to a Wi-Fi network. adb shell settings put global tether_dun_required 0
Problem solved - your ISP now allows tethering.it's still my go-to for sharing one system's vpn, but wow oh wow oh wow do i wish i knew some good alternatives. i really want something that works over ssh, but i begin to think that ssh is an inescapably bad starting point for these efforts.
This is it!
This solution is great for permanently bootloader-locked phones (which is unfortunately, most phones).
Alternatively, if installing a custom OS is an option, most Android forks remove the tethering restrictions. I use and highly recommend GrapheneOS [1] if you have a supported phone (Pixels only as of now). DivestOS and LineageOS have much wider device support. ProtonAOSP and CalyxOS are other options for Pixels and a few others.
[1] https://github.com/GrapheneOS/os-issue-tracker/issues/70
Even there, there’s some differences as prioritization works differently when you are using pool resources.
Tethered traffic is usually routed differently. Almost all cellular data traffic is CGNATed or proxied, and different priority is assigned to different types of traffic.
For 95% of users, there’s no problem at all. When people push the limits, they find themselves in a pickle. I’m familiar with an organization with >50k devices across 4 major carriers 4-5 years ago. They probably had <500 people who required some sort of exception, ranging from a different plan to a more appropriate device and plan, to someone doing something crazy. (One guy was running a small field office off of a Samsung tablet)
The more pressing issue is that bootloader unlocking isn't as ubiquitous as one might like.
Tethering on a plan that doesn't allow it is like showing up at an all-you-can-eat buffet and leaving with a backpack full of food.
This is why that, when phones tether, those tethered packets are routed separately so that the cell carrier can throttle them when needed to maintal quality of service for everyone else.
By tethering/tunneling through your normal connection, they can't do this, and if this became an epidemic they would either need to do thorough DPI and heuristics to detect and block the tethering/ban the user, or over-provision their towers to handle the varied traffic volumes of both regular cell phone activity and people watching 4k Netflix on their TV through their phone.
launches bittorrent client on the phone
You can get plans that support tethering or mobile LANs - they aren’t even that expensive. Carriers will usually prioritize those connections lower than public safety or mobile phone connections to ensure better user experience. LTE and 5G fixed home plans are an easy example of this available to consumers.
"You are paying for a water service, what does it matter how the water is consumed?" Though of course there are big differences. An obvious one is that water companies aren't profiting off these restrictions like mobile operators at least partially are. And since water is either heavily regulated by or entirely ran by governments, the cost to the consumer doesn't necessarily represent the true cost.
(The California restriction even seems reasonably well enforced. When buying a 2.5 GPM shower head on Amazon[2] you'll get an error if you try to ship it to a California address. Most eBay sellers enforce this as well, though not quite all of them.)
[0] https://www.federalregister.gov/d/2020-27280/p-56
[1] https://www.build.com/ca-compliant/c133273#:~:text=Residenti...
[2] https://smile.amazon.com/showerhead-2.5GPM-that-wont-ship-to...
What's egregious is ISPs also enforcing _how_ I'm allowed to consume the data I'm paying for. So the fork analogy is much more appropriate.
See also: modern intellectual "property" laws & enforcement, the businesses that push for it (typically large companies with a wealth of IP), the organizations that facilitate the control of information (governments, Microsoft, Google, Apple, Netflix, etc.), and the business models that depend on it.
There are cases where the benefits are worth a reduction in freedom, but this ain't it.
A better analogy is a gas station which charges more for gas that goes into sports cars than gas that goes into minivans.
Where ISPs cross the line is by trying to also enforce _how_ I can consume the data I'm paying for. Having plans that restrict tethering is consumer-hostile, plain and simple. Whether I'm tethering or not has no relation to how much data I consume. They can continue to restrict bandwidth and data limits if I go overboard, but I'll be damned if I allow them to tell me how I can use it.
So if we're going with the buffet analogy, then it's like them saying I can only use a fork to eat, as someone mentioned above.
Premium gas costs more. Race cars need race gas — that costs even more.
Any chance this was inspired by "Wikipedia over WhatsApp"?
By the way your implementation looks way nicer than what I was working with before.
The answer is yes, this could be used if WhatsApp wasn't blocked.
But since it blocked in China, you would first need to bypass the firewall anyway.
groups is weird, the media have the index encrypted but the contents use a shared app key.
commercial accounts are also odd. it's encrypted with the business and whatsapp keys, so employees from both can read the messages.
then here there's the api issues. you are not using a full client, but sending your access token plus the plain text message for it to be encrypted on their servers.
even worse, in this example it's not even you using the api, but you are using twillo's api, who then uses metabook's api for whatsbook. so it's plain text all the way across those.
disclaimer: IANAL
This hypothesis assumes that carriers can increase prices and the public will still pay them. If so, it follows that they are now leaving money on the table, which sounds unlikely.
I think it was Tim Hardford who wrote about something similar in his book "The Undercover Economist", in the context of the spectrum auctions in the different countries.