If you think this is bad...
You can't even have a blog in China without authorization. It doesn't matter if you pay "AWS" for a machine. It won't open port 80 or 443 until you get an ICP recordal. Which you can only do if you are in China, and get the approval. It should also be displayed in the site, like a license plate. The reason "AWS" is in quotes is because it isn't AWS, they got kicked out. In Beijing, it is actually Sinnet, in Nginxia it's NWCD
You can only point to IPs in China from DNS servers in China - if you try to use, say, Route53 in the US and add an A record there, you'll get a nasty email (fail to comply, and your ports get blocked again, possibly for good).
In a nutshell, they not only can shutdown cross border traffic (and that can happen randomly if the Great Firewall gets annoyed at your packets, and it also gets overloaded during China business hours), but they can easily shutdown any website they want.
I added an A record for subdomain and pointed it at Chinese IP addresses. I wonder if I will get that angry email?
I think the real paranoid people use cloudHSM.
https://www.marvell.com/products/security-solutions/liquidse...
That's my take as well reading about how they handle firmware (sounds like they're using their own chips, presumably similar to how they use other hardware acceleration and offload)
But yeah, they can shutdown anything unless proxy server is widely used. as <Nearly 90% of Iranians now use a VPN to bypass internet censorship>.
So using DNS hosted outside won’t matter, because the destination Chinese IP will get blocked. Or if using outside hosting, it won’t matter, because anyone in China trying to access it will get blocked. Or anyone trying to publish anything to it the CCP doesn’t like. Presumably also with some follow up in-person ‘check-ins’.
The GFW is a pretty massive and actually impressively effective piece of technology, even if we don’t agree with it’s purpose.
If you allow connections to random websites outside of your jurisdiction then you're de facto allowing everything, because people can proxy arbitrary traffic that way. If you don't, you're effectively disconnecting your country from the global internet, which is not an impressive technological feat. Anybody with a backhoe can do a fiber cut.
It really isn’t dumb at all, and is quite difficult to get past.
It also auto detects ‘problematic’ content in near realtime for a huge swath of things. It does deep packet and content inspection, including of a bunch of encrypted traffic that it really shouldn’t be able to.
At massive (national) level scale.
Don’t get me wrong. It’s evil. But it’s an impressive bit of evil kit.
They made a list of tunnel systems that don't attempt to disguise themselves and then blocked them. That's not really that hard, and it meanwhile causes lots of innocuous things to be blocked. There are uses for a tunnel other than bypassing censorship.
The hard thing is to block the ones that actively attempt to look like something they're not, and release updates to change their profile whenever the authors notice it being blocked, while still allowing the thing they're attempting to look like.
> It also auto detects ‘problematic’ content in near realtime for a huge swath of things. It does deep packet and content inspection, including of a bunch of encrypted traffic that it really shouldn’t be able to.
All of this is assuming the content is being distributed unencrypted or is otherwise leaking its contents through e.g. having a specific data length, none of which an encapsulation method is required to expose.
The GFW is run by the definition of a Nation State Actor/NPT. They’re not perfect, or omniscient, but they aren’t fools or incompetent either.
And knowing all the people taking the ‘totally secret’ backdoor is not even a complex trick.
Folks like the NSA in the US have to stay in the shadows, and have a tiny budget and population to draw experts from. What do you think happens when they get to be direct, obnoxious, AND somewhat public in a national pride kind of way?
You're describing something that seems like an urban legend/coincidence. What technical means are you suggesting they're using to determine the contents of a voice chat over an encrypted connection?
> And knowing all the people taking the ‘totally secret’ backdoor is not even a complex trick.
That's assuming it can be distinguished from ordinary traffic.
If your device goes direct when you want to read the Wikipedia article on the Streisand Effect but you also have a browser that proxies traffic through a random AWS VPS in Virginia when you want to read about something they don't want you to know, how are they supposed to tell that the latter is that and not just a regular arbitrary third party webserver?
> Folks like the NSA in the US have to stay in the shadows, and have a tiny budget and population to draw experts from. What do you think happens when they get to be direct, obnoxious, AND somewhat public in a national pride kind of way?
It becomes easier to find way to thwart what they're doing because any random device can be used to determine if or how something is being blocked instead of only the devices of high-risk people who can't afford to test the fences.
Wait what? So I can DoS any Web site in China by creating a rogue DNS record that points to its IP address, even under a completely unrelated domain? How would they even find those records?
Seems like a very minor speed bump in your plan, though: presumably something like https://www.chinafirewalltest.com would achieve that, or send a few emails for folks to click.
https://de.wikipedia.org/wiki/Impressumspflicht (Mandatory real name & address, not only for business, but private persons with web presence, too.
Same for Domain/DNS(which applies to everything in the European Union))
If it's on purpose, I think you have the most likely motivation.
A mistake that also weirdly increments some TCP fields for the three subsequent RST packets when that's not how the existing GFW devices behave would need some explanation before you could conclude it to be the most likely explanation.
Every major power has polluted near Earth space as a show of power.
[0] https://planet4589.org/space/con/star/planes.html
(On general principles, you could argue you'd need 1:1 launch vehicle parity (number, not payload) to defeat a satellite constellation this way. For each satellite launch, you'd need one corresponding anti-satellite launch into that same, newly-defined orbit).
Starlink satellites are pretty low and experience a lot of drag, with square-cube law working against you. Your shrapnel's orbit will likely decay pretty rapidly.
Relevant, Chinese domestic media reporting on China's own perspective:
https://www.scmp.com/news/china/science/article/3178939/chin... ("China military must be able to destroy Elon Musk’s Starlink satellites if they threaten national security: scientists" (2022))
> "Researchers call for development of anti-satellite capabilities including ability to track, monitor and disable each craft / The Starlink platform with its thousands of satellites is believed to be indestructible"
"Easy to bring down" vs. "believed to be indestructible"—some tension there!
And I doubt China would want to make LEO impossible to move through anyway. It’d affect China badly as well
Also, fairly easy to find from the air.
The only thing that could bypass is GPS + laser links (meaning physically aiming a laser both on the ground AND on a satellite). You cannot detect that without being in the direct path of the laser (though of course you can still see the equipment aiming the laser, so it doesn't just need to work it needs to be properly disguised). That requires coherent beams (not easy, but well studied), aimed to within 2 wavelengths of distance at 160km (so your direction needs to be accurate to 2 billionths of a degree, obviously you'll need stabilization), at a moving target, using camouflaged equipment.
This is not truly beyond current technology, but you can be pretty confident even the military doesn't have this yet.
The moon is 700 times farther away than the starlink satellites (or twice that, if you consider the bounce), so I find it hard to imagine that it would be impossible to communicate with much closer satellites over laser when both sides can have an active transmitter.
However, this solution is going to stop working when a cloud drifts past.
Not really, because you'd be using a frequency that passes through clouds. A snow storm or hail is impenetrable, and there are weather events that cause a 1-2 second blackout, as well as cause refraction (which is mostly a challenge in reaiming the beam fast enough to compensate), but anything in the air is fine. Clouds, mist, ... But is aiming at a 1 arcsecond target moving across the sky at at least 1 degree per second from a normal (ie. moving) building really doable with "standard hobbyist telescope mounts" ?
I know 5 years ago we were still doing this with lasers on rockets toward planes, because planes can just keep their angle to a rocket essentially constant. I know there's experiments doing direct laser to satellite, no idea how well that works.
The clouds are however much more of a problem than you're suggesting. One promising infrared band is around 10 microns, but a thick cloud will still scatter that. You'd need a 20cm wide laser beam at that wavelength for it to diverge to a beam width of around 10 arcseconds. Which is basically a reasonably-sized telescope, working in reverse.
Alternatively, you could go for millimeter waves, which would pass through the clouds reasonably well, but then you're well outside the realms of "laser" and into the standard directional dish antenna. And it'd have to be a very large dish to give you a narrow beam. For instance, a rather unsubtle 2 metre wide dish with a 1mm wavelength will give a beam that diverges by 100 arcseconds. And there will probably be omnidirectional leakage which the dastardly authorities are likely to be able to detect. At least visible and infra-red leakage can be easily blocked and concealed, but radio is much harder.
Not true anymore.
> and the antenna will also only operate in an approved zone (depending on your country and account type). You cannot use it in China.
This is still correct.
Though India doesn't have a great firewall so it's much less of an issue for foreigners visiting there.
It’s still true because in order to be operating in a country Starlink has to get approval from the Gov and if the Gov requires Starlink to have to connect through a ground station then they’ll either comply or not operate in that country
There's no authentication so anyone can pretend to be you. Traditional methods of verifying the sender (HMAC) would take so many hours to transmit that the physical propagation paths you're communicating through will probably collapse before you deliver the smallest verified message.
If you need to communicate information, FT-8 is not for you.
You do need a time source though. GPS is generally used for that but it doesn't need to be extremely accurate with FT-8 like with some other protocols.
I would imagine using it for a regular "I'm ok" message for the home front in such a situation using pre-arranged contents.
I tried it while staying in a high rise hotel and the experience was great. Instant acknowledgement and super reliable communication