China Tor bridge blocking details
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Wed, 4 Apr 2012 20:19:27 +0100
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
--===============0365397823== Content-Type: multipart/signed; boundary="nextPart1457243.9F0xUjjNWB"; protocol="application/pgp-signature"; micalg=pgp-sha256 Content-Transfer-Encoding: 7bit --nextPart1457243.9F0xUjjNWB Content-Type: Text/Plain; charset="us-ascii" Content-Transfer-Encoding: 7bit http://www.v3.co.uk/v3-uk/news/2165733/swedish-researchers-uncover-key-chinas-tor-blocking Looks like they look for a header that looks like a connection to a bridge, then try to do a handshake. This is surprisingly sophisticated - I had expected they just created thousands of gmail accounts and harvested all the bridges by email. Also, they appear to be able to create unidentifiable IP addresses on demand, meaning that the opennet protection schemes based on IP scarcity are not going to work. This won't work as-is with Freenet because Freenet doesn't do handshakes unless you have the keys. However there may be (more complicated) ways to identify the traffic, and the above implies they may be sophisticated enough to implement them. It does mean that obfuscation (stego) is increasingly important. --nextPart1457243.9F0xUjjNWB Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEABEIAAYFAk98nr8ACgkQYUNbc3WUHYgDtgCfU1INCUrtLXUjXcqrAaNft9zY ssUAn3muWg7qffUTx/+AcBEhA+MIoaae =7FZf -----END PGP SIGNATURE----- --nextPart1457243.9F0xUjjNWB-- --===============0365397823== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Tech mailing list [email protected] https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech --===============0365397823==--