Hacker News new | ask | show | jobs
by tryauuum 41 days ago
Like in Russia

    - drop wireguard / OpenVPN packets crossing the country border
    - analyze https traffic to detect traffic patterns not matching https fully and block such connections
1 comments

The state of the art, "xray-reality", is not blockable. It's a legit tls connection with data smuggled inside it.
Are you taking from the experience that this is not blockeable in Russia?

EDIT: I might be confusing vless/xray/reality but seems like there are no problems to block it based on ip reputation + tls fingerprint + amount of connections https://habr.com/ru/articles/1044396/

Of course this would block some valid websites but when has government cared about that

The IPs are Cloudflare, the TLS fingerprint is uTLS Chrome, and the number of connections with xhttp is the same as your normal browsing.

If you are willing to block browsing all ordinary web sites fronted with a CDN, then yes you can block reality/xhttp. You cannot, however, differentially block it via any of the three things you mentioned.

They are willing to break some cloudflare-fronted websites. That's already a reality in Russia.

The government (any government) hates its citizens and the freedoms it had to allow them