7 ms·
Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
- kotri 1y agoTerrible, this is Internet curfew. It's not uncommon to imagine they'd shutdown Internet across border during any war (like against Taiwan).
- hackernewsdhsu 1y agoThat's what's so great about LoRA. Decentralized txt msgs, ultra cheap radios people run at home or wherever. $10-35USD ON AMAZON. Least txts get through.
- phantomathkg 1y agoIt won't get you from where you are to China though.
- wkat4242 1y agoNo but something like WSPR or FT8 would. Needs a license though.
- elevation 1y agoFT8 has such a small payload that you couldn't fit an emoji, much less an average English sentence. There's no authentication so anyone can pretend to be you. Traditional methods of verifying the sender (HMAC) would take so many hours to transmit that the physical propagation paths you're communicating through will probably collapse before you deliver the smallest verified message. If you need to communicate information, FT-8 is not for you.
- wkat4242 1y agoAgreed but if you're trapped in a war zone, time is one thing you have. And equipment for FT8 is simple to build yourself. It's also very difficult to trace. And you can take up some fields used for other stuff and convert them to data (like the sender). This would be illegal on amateur bands since it's required to identify oneself but again in a war situation this is less relevant since any covert communication will probably be forbidden anyway. You do need a time source though. GPS is generally used for that but it doesn't need to be extremely accurate with FT-8 like with some other protocols. I would imagine using it for a regular "I'm ok" message for the home front in such a situation using pre-arranged contents.
- cedws 1y agoCan you recommend a guide? I’m interested in trying it out.
- Gigachad 1y agoLook up Meshtastic. It’s kinda fun. Can chat with random people around you. But I don’t think it’s really that useful unless you have a really good spot like an antenna on your roof with no trees or buildings in the way.
- int_19h 1y agoIt's not that finicky in practice. I live in a heavily wooded area and I can still see plenty of nodes, some pretty far away. Trees are actually somewhat helpful there because you can easily rig up a node up high by throwing a line over a branch.
- Gigachad 1y agoI live in the suburbs, not really any high rises around be but some townhouses, I can “see” 180 nodes, but I can’t reliably message my friend 1km away. I get a lot of messages on the public chat but if I send one it’s a 50/50 if it will be acknowledged by any nodes. I tried it while staying in a high rise hotel and the experience was great. Instant acknowledgement and super reliable communication
- int_19h 1y agoThat would be LoRa. LoRA is a different thing.
- hackernewsdhsu 1y ago[dead]
- downrightmike 1y agoAt a whole 3kbps and line of sight!
- kotri 1y agoLocal police already equipped with signal jammer cars. Usually only used in college entrance exam period. They also appeared in recent protest in Jiangyou city.
- eastbound 1y agoIn fact, it’s a common tactic to do something unusual, in a recurrent way, so people aren’t alerted when it happens for real. (When the Mossad stole 7 boats from a French port (that they had fully paid), they prepared a few months in advance by having the pilots start the engines every night at 23:00, pretending they needed it against the cold temperatures. When they day came, they started the engines and left, no-one saw it coming).
- vintermann 1y agoIt could also be a test to look for surprising things that break, in case they want to do this permanently at some later point.
- woooooo 1y agoHanlon's and Occam's razors point to it being a mistake by the GFW operators, imo. If it's on purpose, I think you have the most likely motivation.
- account42 1y agoYou shouldn't use razors haphazardly or you might cut yourself. A mistake that also weirdly increments some TCP fields for the three subsequent RST packets when that's not how the existing GFW devices behave would need some explanation before you could conclude it to be the most likely explanation.
- woooooo 1y agoA new hardware/software rollout is one of the more common breakage situations, though. It definitely could have been on purpose but my gamble is still on a fuckup with a new system rollout.
- mschuster91 1y agoIt was five boats [1], an good story nonetheless. Think whatever you want about Mossad, it can not be denied that these guys have balls. [1] https://en.wikipedia.org/wiki/Cherbourg_Project https://en.wikipedia.org/wiki/Cherbourg_Project
- wkat4242 1y agoCould you bring something like a starlink mini for backup i wonder? Id imagine this would be very worrying being stuck there as a foreigner in such a situation.
- preisschild 1y agohttps://www.theverge.com/2022/10/10/23397301/elon-musk-starlink-china-great-firewall-censorship https://www.theverge.com/2022/10/10/23397301/elon-musk-starl...
- methou 1y agoA friend of mine tried, no signal.
- NitpickLawyer 1y agoIf war breaks out, it'll likely be enabled.
- andrewinardeer 1y agoEntirely speculation.
- NitpickLawyer 1y agoOf course it is entirely speculation. But there are previous datapoints you can look at (i.e. iran).
- andrewinardeer 1y agoElon doesn't sell cars or Powerwalls in Iran.
- Helmut10001 1y agoStarlink are very low orbit. Easy to bring down.
- veunes 1y agoThe infrastructure for that kind of control clearly already exists. What's unclear is how coordinated or deliberate these events are versus being side effects of testing or internal changes
- outworlder 1y ago> Terrible, this is Internet curfew. If you think this is bad... You can't even have a blog in China without authorization. It doesn't matter if you pay "AWS" for a machine. It won't open port 80 or 443 until you get an ICP recordal. Which you can only do if you are in China, and get the approval. It should also be displayed in the site, like a license plate. The reason "AWS" is in quotes is because it isn't AWS, they got kicked out. In Beijing, it is actually Sinnet, in Nginxia it's NWCD You can only point to IPs in China from DNS servers in China - if you try to use, say, Route53 in the US and add an A record there, you'll get a nasty email (fail to comply, and your ports get blocked again, possibly for good). In a nutshell, they not only can shutdown cross border traffic (and that can happen randomly if the Great Firewall gets annoyed at your packets, and it also gets overloaded during China business hours), but they can easily shutdown any website they want.
- UltraSane 1y agoAWS in China also doesn't have the Key Management Service, which leads to me to conclude it must be pretty secure. I added an A record for subdomain and pointed it at Chinese IP addresses. I wonder if I will get that angry email?
- bawolff 1y agoOr they just dont want to be put in the position of having to give out keys. I think the real paranoid people use cloudHSM.
- UltraSane 1y agoBoth KMS and CloudHSM are FIPS 140-2 Level 3 and AWS claims they cannot read private keys from KMS. The main difference is KMS uses IAM and the AWS REST API while CloudHMS uses PKCS #11/JCE and a separate permissions system.
- nijave 1y agoThe docs say both use HSM. Under "Secure" in the accordion menu https://aws.amazon.com/kms/features/#topic-0 https://aws.amazon.com/kms/features/#topic-0
- deleted 1y ago[deleted]
- chickenzzzzu 1y agoThink of how many people who have remote jobs with American companies couldn't connect to their meetings while they "work from home" while secretly being in China! Normally they have to fight VPN issues anyway, but having a sovereign state inject your packets is certainly a fun new one.
- ChrisMarshallNY 1y agoI suspect those connections worked fine. It’s good to know the boss.
- chickenzzzzu 1y agoI definitely appreciate that a percentage of so called "employees" are actually just full fledged Chinese nationals, living permanently in China, paid a salary to pretend to be an American who had their identity stolen. But there absolutely is also a non-negligible number of Chinese and Indian nationals, who have some type of visa status in the US (especially a green card) who spend many months in their original countries making $200,000 or more per year while living like royalty in their home countries :)
- bapak 1y agoThe green card isn't citizenship, you lose it if you don't live in the US. It's not like they don't know when you enter or exit the country.
- chickenzzzzu 1y ago6 months is a very long time.
- Wolfbeta 1y ago2019 feels like 6 months ago.
- jart 1y ago[flagged]
- JumpCrisscross 1y ago> Imagine what people would say about Cloudflare if they had an hour long outage That Cloudflare had an outage. Not America.
- flohofwoe 1y ago> That Cloudflare had an outage. Not America. You probably mean the USA? After all, it was China and not Asia which was responsible for the incident ;)
- spauldo 1y agoIn English, there is no continent named "America." It's unambiguously used to refer to the United States.
- johnisgood 1y agoI would not say "unambiguously" when it comes to natural languages. And no, "America" may have referred to the US when I was a kid and here in Central Europe we had Back to the Future type of shoes with the American flag, yeah, and I would not say unambiguously so. If someone says "America" to refer to a place, they really ought to specify if they want you to understand them.
- const_cast 1y agoBut America isn't a place. There's the Americas, as in plural, referring to the continents of North America and South America. So America is unassigned, hence why we assigned it to the USA colloquially.
- johnisgood 1y ago
- technics256 1y agoHow would one get around this if they found themselves in such a situation?
- est 1y agoIn this exact scenario, just use ports other than :443 But GFW certainly had the capability to block all ports. So no one really knew.
- SuperMouse 1y ago[dead]
- molticrystal 1y agoWell for starters recreate the situation and test out different approaches. Thanks to the detailed analysis that can be attempted. If I understand right, a good next step would would be with eBPF or some type of proxy ignore the forged RST+ACK at the beginning. Then it would come testing to see if sending a bunch of ACK packets, perhaps with sequence numbers that would when reconstructed could complete the handshake. Trying to send them alongside the SYN+ACK or even before if it can be predicted. Maybe try sending some packets with sequence id 0 as well to see what happens.
- kotri 1y ago> ignore the forged RST+ACK See <Ignoring the Great Firewall of China> in 2006. That won't work if RST/ACK was injected to both sides. > Then it would come testing to see if sending a bunch of ACK packets, perhaps with sequence numbers that would when reconstructed could complete the handshake. Trying to send them alongside the SYN+ACK or even before if it can be predicted. Maybe try sending some packets with sequence id 0 as well to see what happens. This is an interesting approach already being utilized, namely TCB desync. But currently most people tend to buy VPN/proxy services rather than studying this.
- billy99k 1y ago
- neuroelectron 1y ago[flagged]
- rfoo 1y agoPretty sure it's an incident.
- veunes 1y agoBut "good reason" depends a lot on your perspective
- outworlder 1y agoThere's no good reason to do that.
- preisschild 1y agoYeah, dont want their citizens to voice anti-CCP thoughts
- vachina 1y ago[flagged]
- ch3nyang 1y agoNot only individuals, but also major companies were locked down. If this was a dry run for "certain measures" in the future, I can't believe how much of a blow it would cause to the economy. Therefore, I think this was more of a human error.
- account42 1y agoDetermining the scope of the impact would also be part of such a dry run. And if it is meant to be used along some kind of military action then it's going to throw the economy into chaos anyway.
- gorgoiler 1y agoHow is traffic controlled inside PRC? Is GFW a central hub for all traffic between all hosts? Or between residential ASNs and commercial ones only? In the UK and Iran a lot of censorship was implemented by leaning on ISPs at IP level (eg BT Cleanfeed) and with DNS blocks but I haven’t kept up to date with how networks might handle residential hosting. Maybe internal traffic is just all banned?
- inemesitaffia 1y agoIt's in operators but managed by the regional government. So what's blocked differs by region
- kotri 1y ago> How is traffic controlled inside PRC? Unknown. I haven't seen any injected fake DNS or reset packets so far to domestic hosts. But there are rumors that Google's servers in Beijing (AS24424) was once black holed. > Is GFW a central hub for all traffic between all hosts? It's supposed to has centralized management system, but not a single hub. > Or between residential ASNs and commercial ones only? Yes, the injecting devices are deployed in IXPs, the AS borders. See <Internet censorship in China: Where does the filtering occur?>. > In the UK and Iran a lot of censorship was implemented by leaning on ISPs at IP level (eg BT Cleanfeed) and with DNS blocks but I haven’t kept up to date with how networks might handle residential hosting. I believe Iran has more centralized system like China controlled by Tehran. > Maybe internal traffic is just all banned? No, internal HTTPS traffic is not banned in that hour.
- aaron695 1y ago[dead]
- Eddy_Viscosity2 1y agoThe most depressing is that what happens in China, will eventually happen in the west too. I'm sure certain US, UK, and EU bureaucrats are already crafting campaigns about how this ability will 'save the children' and that it should be implemented immediately (politicians and certain other selected people will be exempt of course).
- pas 1y agoThere's nothing inevitable about this. Civil society needs to organize, coordinate, and spend money on PR about this. Right now liberal people mostly sit back and wait for things to get better, it's not enough. (Also going and walking up and down is not really effective.)
- Eddy_Viscosity2 1y agoIt is inevitable, because the means by which civil society can organize, coordinate, and spend money on PR about this, are all firmly in the control of a very few people. These same people are generally on the side of more centralized control, because they are the ones who will wield it.
- lossolo 1y ago> Right now liberal people mostly sit back and wait for things to get better First they came for the socialists, and I did not speak out because I was not a socialist. Then they came for the trade unionists, and I did not speak out because I was not a trade unionist. Then they came for the Jews, and I did not speak out because I was not a Jew. Then they came for me and there was no one left to speak for me.
- Eddy_Viscosity2 1y agoPrecisely. Works every time. It's a like zero-day exploit on society.
- lyu07282 1y agoWell slightly updated version today would be: Immigrants, Anti-Zionists, Socialists, Homeless, Welfare recipients, ...
- daft_pink 1y agoAs an aside, it’s incredible how many internal chinese websites are completely unsecured with a certificate and don’t use HTTPS and require login.
- deleted 1y ago[deleted]
- armchairhacker 1y ago> A Brief, Incomplete, and Mostly Subjective History of Chinese Internet censorship and its countermeasures https://danglingpointer.fun/posts/GFWHistory https://danglingpointer.fun/posts/GFWHistory Posted 6 days ago (https://news.ycombinator.com/item?id=44898892 https://news.ycombinator.com/item?id=44898892)
- Alex-Programs 1y agoThanks for sharing this. I researched this for my A level project a few years ago, and this is a really neat cross reference. I didn't mention V2Ray as much.
- tiahura 1y agoShouldn’t the rest of the world be blocking connections from China.
- bell-cot 1y agoThat'd be somewhat more workable than blocking importation of anything made in China. Somewhat.