HNHacker News
TopNewBestAskShowJobs

justDankin

263 karma · joined June 13, 2020

submissionscomments
justDankin··on CensorWatch – Help understand internet censorship in India
I work as a researcher at the The Centre for Internet and Society (CIS), where we've been actively studying internet censorship in India over the last year.

We've built CensorWatch, an android app which crowdsources measurements of internet censorship. This allows us to study censorship from different vantage points, which would otherwise be impossible to do at our scale.

If you live in India, please consider running it! It's completely anonymous, does not store any personal information, does not require any app permissions, and can be deleted after running (takes roughly 30 minutes). More information here -- https://cis-india.github.io/censorwatch/

justDankin··on How India Censors the Web
We released a subset of the data along with the paper (~5K hostnames), can be accessed at https://github.com/kush789/How-India-Censors-The-Web-Data

The app uses a more updated list (roughly 10K hostnames)

justDankin··on How India Censors the Web
Unfortunately we don't have the expertise or bandwidth to make that :/
justDankin··on How India Censors the Web
I'm one of the authors of the paper in the post, we're trying to extend this work by crowdsourcing censorship measurements from different vantage points in India.

We've compiled these tests into an android app, please consider running it if you live in India and would like to contribute to the research :) https://play.google.com/store/apps/details?id=com.censorwatc...

It's completely anonymous, doesn't require any permissions, and does not store any user related information.

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Ah yes, my bad. I meant to say ESNI

Read https://gfw.report/blog/gfw_esni_blocking/en/ some time back, recalled it incorrectly

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
You never know. Could be a mistake where they were trying to block a certain path due to some search result of copyright infringement, but ended up banning the domain itself. One can only guess.

Reddit and Github have previously been temporarily banned in India due to similar "mistakes"

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Well, they could block TLS1.3 entirely (which would force hosts to drop down to 1.2 for connections)

GFC does this, I really hope it doesn't happen here

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Haha yeah, I've been procrastinating for the last 5 years now
justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Yes! That's a great observation

However, the reason I went for probing the entire path is because the TTL itself can be spoofed

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Yeah there was a huge outcry about it on Twitter some time back.

P.S. From the screenshot, it looks like you're trying to connect to [http]://duck.., hence shifting to https works.

This also hints towards a mixture of plain old http censorship and https censorship, which Airtel (in fact all ISPs) do randomly

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Yes, that was the case
justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
I haven't been able to test that yet, neither am aware of any research which answers that question.

IMO the only way to do that would be to either (i) block the IP (high collateral blocking) or (ii) block TLS 1.3 itself (GFC does this).

A major blocker in answering this is finding a potentially blocked website that also supports TLS 1.3

justDankin··on Identifying Airtel middleboxes that censor HTTPS traffic
Using the TTL, we figured out that the censor kicks in at the kth hop. This kth box belonged to Airtel.

If a box was censoring after Airtel, we would have received a clean response (ICMP timeout) at hop k as well. Of course, the TTL itself can change during the run, but that wouldn't happen for so many cases :)

justDankin··on Investigating TLS Blocking in India
Thanks for running it! We are in the data collection stage at this moment, will definitely be publishing our findings and releasing the data publicly.

P.S. Our previous paper talks about censorship in India, albeit the data is from just one vantage point https://arxiv.org/abs/1912.08590

As for circumvention, TLS 1.3 + ESNI + DoH should do the trick. Firefox has the capability to enable these options

justDankin··on Investigating TLS Blocking in India
I'm new to HN(3 months, low karma). Maybe that's the reason? Not sure what would be the correct way to "fix" this

Thanks for vouching!

justDankin··on Investigating TLS Blocking in India
You can delete it after running. Each run on an (ISP, state) combination gives a new test point.

Thanks!

justDankin··on Investigating TLS Blocking in India
DoH just by itself won't help unfortunately, since it just fetches the DNS (btw, only Airtel, ACT, BSNL, and MTNL bother with DNS censorship).

ISPs have been looking at the cleartext hostname in the TLS handshake to block these connections

As someone correctly pointed out, greentunnel does much more than DoH.

justDankin··on Investigating TLS Blocking in India
TLS1.3 + ESNI is a robust solution, Firefox has the option of enabling it.

Cloudflare has a great page which allows to check this https://www.cloudflare.com/en-gb/ssl/encrypted-sni/

justDankin··on Investigating TLS Blocking in India
Pretty much yes, unless ISPs start blocking IPs as well. We haven't seen this in India (at least yet)
justDankin··on Investigating TLS Blocking in India
I'm one of the authors of the post, we're trying to extend this work by crowdsourcing censorship measurements from different vantage points in India.

We've compiled these tests into an android app, please consider running it if you live in India and would like to contribute to the research :) https://play.google.com/store/apps/details?id=com.censorwatc...

It's completely anonymous, doesn't require any permissions, and does not store any user related information.

justDankin··on Amazon added a non-compete after the employee entered the U.S. on an L1B visa
A question I have as a fresh graduate in the industry. For a company like Amazon, wouldn't a huge chunk of tech companies be competitors? Does the non compete span the entire product range of Amazon's services, or just the team/project you were working on?

For example, Amazon and Google both have cloud services. If I'm working for AWS, would my non compete prevent me from working for Google, or just Google cloud?