Re: China Tor bridge blocking details
Ian Clarke <[email protected]> Wed, 4 Apr 2012 14:34:02 -0500
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <CAFbwM5EXmt+Lztjs3e6_qbRr7x4kEeOYyJ7HN1VxZn5SY0GZCQ@mail.gmail.com> |
--===============0255290901== Content-Type: multipart/alternative; boundary=14dae934121da7861104bcdf82e9 --14dae934121da7861104bcdf82e9 Content-Type: text/plain; charset=ISO-8859-1 This is the motivation behind "silent bob", something we were talking about way back in 2002-2003. Ian. On Wed, Apr 4, 2012 at 2:19 PM, Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>wrote: > > http://www.v3.co.uk/v3-uk/news/2165733/swedish-researchers-uncover-key-chinas-tor-blocking > > Looks like they look for a header that looks like a connection to a > bridge, then try to do a handshake. This is surprisingly sophisticated - I > had expected they just created thousands of gmail accounts and harvested > all the bridges by email. > > Also, they appear to be able to create unidentifiable IP addresses on > demand, meaning that the opennet protection schemes based on IP scarcity > are not going to work. > > This won't work as-is with Freenet because Freenet doesn't do handshakes > unless you have the keys. However there may be (more complicated) ways to > identify the traffic, and the above implies they may be sophisticated > enough to implement them. It does mean that obfuscation (stego) is > increasingly important. > > _______________________________________________ > Tech mailing list > [email protected] > https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech > -- Ian Clarke Founder, The Freenet Project Email: [email protected] --14dae934121da7861104bcdf82e9 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable This is the motivation behind "silent bob", something we were tal= king about way back in 2002-2003.<div><br></div><div>Ian.<br><br><div class= =3D"gmail_quote">On Wed, Apr 4, 2012 at 2:19 PM, Matthew Toseland <span dir= =3D"ltr"><<a href=3D"mailto:toad-EI5O+8PHWbJeeLb3ft/[email protected]">[email protected]= ndns.org</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"><a href=3D"http://www.v3.co.uk/v3-uk/news/21= 65733/swedish-researchers-uncover-key-chinas-tor-blocking" target=3D"_blank= ">http://www.v3.co.uk/v3-uk/news/2165733/swedish-researchers-uncover-key-ch= inas-tor-blocking</a><br> <br> Looks like they look for a header that looks like a connection to a bridge,= then try to do a handshake. This is surprisingly sophisticated - I had exp= ected they just created thousands of gmail accounts and harvested all the b= ridges by email.<br> <br> Also, they appear to be able to create unidentifiable IP addresses on deman= d, meaning that the opennet protection schemes based on IP scarcity are not= going to work.<br> <br> This won't work as-is with Freenet because Freenet doesn't do hands= hakes unless you have the keys. However there may be (more complicated) way= s to identify the traffic, and the above implies they may be sophisticated = enough to implement them. It does mean that obfuscation (stego) is increasi= ngly important.<br> <br>_______________________________________________<br> Tech mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech" ta= rget=3D"_blank">https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tec= h</a><br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>Ian= Clarke<br> Founder, The Freenet Project<br>Email: <a href=3D"mailto:ian@freenetproject= .org" target=3D"_blank">[email protected]</a><br> </div> --14dae934121da7861104bcdf82e9-- --===============0255290901== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Tech mailing list [email protected] https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech --===============0255290901==--