Re: China Tor bridge blocking details

Ian Clarke <[email protected]> Wed, 4 Apr 2012 14:34:02 -0500
Newsgroups gmane.network.freenet.technical
Message-ID <CAFbwM5EXmt+Lztjs3e6_qbRr7x4kEeOYyJ7HN1VxZn5SY0GZCQ@mail.gmail.com>
--===============0255290901==
Content-Type: multipart/alternative; boundary=14dae934121da7861104bcdf82e9

--14dae934121da7861104bcdf82e9
Content-Type: text/plain; charset=ISO-8859-1

This is the motivation behind "silent bob", something we were talking about
way back in 2002-2003.

Ian.

On Wed, Apr 4, 2012 at 2:19 PM, Matthew Toseland
<toad-EI5O+8PHWbJeeLb3ft/[email protected]>wrote:

>
> http://www.v3.co.uk/v3-uk/news/2165733/swedish-researchers-uncover-key-chinas-tor-blocking
>
> Looks like they look for a header that looks like a connection to a
> bridge, then try to do a handshake. This is surprisingly sophisticated - I
> had expected they just created thousands of gmail accounts and harvested
> all the bridges by email.
>
> Also, they appear to be able to create unidentifiable IP addresses on
> demand, meaning that the opennet protection schemes based on IP scarcity
> are not going to work.
>
> This won't work as-is with Freenet because Freenet doesn't do handshakes
> unless you have the keys. However there may be (more complicated) ways to
> identify the traffic, and the above implies they may be sophisticated
> enough to implement them. It does mean that obfuscation (stego) is
> increasingly important.
>
> _______________________________________________
> Tech mailing list
> [email protected]
> https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
>



-- 
Ian Clarke
Founder, The Freenet Project
Email: [email protected]

--14dae934121da7861104bcdf82e9
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

This is the motivation behind &quot;silent bob&quot;, something we were tal=
king about way back in 2002-2003.<div><br></div><div>Ian.<br><br><div class=
=3D"gmail_quote">On Wed, Apr 4, 2012 at 2:19 PM, Matthew Toseland <span dir=
=3D"ltr">&lt;<a href=3D"mailto:toad-EI5O+8PHWbJeeLb3ft/[email protected]">[email protected]=
ndns.org</a>&gt;</span> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><a href=3D"http://www.v3.co.uk/v3-uk/news/21=
65733/swedish-researchers-uncover-key-chinas-tor-blocking" target=3D"_blank=
">http://www.v3.co.uk/v3-uk/news/2165733/swedish-researchers-uncover-key-ch=
inas-tor-blocking</a><br>


<br>
Looks like they look for a header that looks like a connection to a bridge,=
 then try to do a handshake. This is surprisingly sophisticated - I had exp=
ected they just created thousands of gmail accounts and harvested all the b=
ridges by email.<br>


<br>
Also, they appear to be able to create unidentifiable IP addresses on deman=
d, meaning that the opennet protection schemes based on IP scarcity are not=
 going to work.<br>
<br>
This won&#39;t work as-is with Freenet because Freenet doesn&#39;t do hands=
hakes unless you have the keys. However there may be (more complicated) way=
s to identify the traffic, and the above implies they may be sophisticated =
enough to implement them. It does mean that obfuscation (stego) is increasi=
ngly important.<br>


<br>_______________________________________________<br>
Tech mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech" ta=
rget=3D"_blank">https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tec=
h</a><br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>Ian=
 Clarke<br>

Founder, The Freenet Project<br>Email: <a href=3D"mailto:ian@freenetproject=
.org" target=3D"_blank">[email protected]</a><br>
</div>

--14dae934121da7861104bcdf82e9--

--===============0255290901==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Tech mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
--===============0255290901==--