Slashdot Log In
Defeating China's National Firewall
Posted by
ScuttleMonkey
on Tue Jun 27, 2006 03:41 PM
from the obligitory-harry-potter-reference dept.
from the obligitory-harry-potter-reference dept.
Bruce Schneier is reporting on his blog that a recent paper is discussing how to defeat China's national firewall. From the article: "However, because the original packets are passed through the firewall unscathed, if both of the endpoints were to completely ignore the firewall's reset packets, then the connection will proceed unhindered! We've done some real experiments on this -- and it works just fine!! Think of it as the Harry Potter approach to the Great Firewall -- just shut your eyes and walk onto Platform 9¾."
This discussion has been archived.
No new comments can be posted.
Defeating China's National Firewall
|
Log In/Create an Account
| Top
| 370 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Publish and Perish (Score:5, Interesting)
(Last Journal: Wednesday September 22 2004, @11:13AM)
On the otherhand, the more they try to squeeze star systems, the more they will slip out of thier han (or something like that).
How to get drugs into USA (Score:4, Insightful)
See the parallel?
Re:How to get drugs into USA (Score:5, Funny)
Re:How to get drugs into USA (Score:4, Insightful)
(http://slashdot.org/ | Last Journal: Tuesday October 23, @05:31PM)
You forgot something... (Score:5, Funny)
(http://kadin.sdf-us.org/ | Last Journal: Tuesday October 16, @01:46PM)
You can pick up from "Here's how you can get those poor miserable people the drugs they want and need..."
Thanks!
Re:Drug Parallel (Score:5, Interesting)
Re:Drug Parallel (Score:4, Insightful)
(http://www.mises.org/rothbard/newliberty.asp | Last Journal: Tuesday August 22 2006, @09:54AM)
You do realize that this policy would justify every existing form of regulation and taxation? Income, after all, is nothing more than a straight trade, currency for labor. Even inheritance taxes would be justified, since inheritance is a gift from one person to another, and gifts are merely a subset of trades in which "goodwill" is traded for tangible property. What, then, would you consider a "forced" tax, since you have apparently chosen to define all taxes and regulations as "voluntary"?
More generally, any claim by a third party for a portion of the goods exchanged in any trade against the will of both the buyer and the seller must be considered theft from a libertarian point of view. That includes all taxes, which -- by definition -- differ from trades only in that they are coerced, i.e. non-voluntary. That has always been the libertarian position, despite the claims of the so-called Libertarian Party to the contrary. The LP has been sacrificing libertarian principles for political power for some time now; their present goals, while more liberal than the two major parties, are hardly "libertarian" in nature.
Re:Drug Parallel (Score:5, Insightful)
Re:How to get drugs into USA (Score:5, Insightful)
(http://cafepress.com/phototravel?pid=5934485)
There is no parallel. The prohibitions on freedom of speech on and information about the different forms of government are uniquely self-perpetuating. Prohibitions on alcohol, drugs, and almost anything else are not like that and can be abolished by the popular will within a reasonably democratic society because discussing them remains legal, even if using is not.
Re:Publish and Perish (Score:5, Informative)
(http://slashdot.org/ | Last Journal: Tuesday October 23, @05:31PM)
Re:Publish and Perish (Score:4, Funny)
Re:Publish and Perish (Score:4, Insightful)
(http://www.pleasantonplayhouse.com/)
But how will they know? You cannot tell if a remote host is responding to reset packets from your firewall, at least not directly. This seems like it will work.
Re:Publish and Perish (Score:5, Insightful)
If you had to send multiple resets for the same port pair, they're ignoring you.
Re:Publish and Perish (Score:5, Insightful)
Re:Publish and Perish (Score:5, Funny)
The sound you hear... (Score:4, Funny)
(http://alexadex.com/ad/index.fcgi?ref=22522 | Last Journal: Wednesday June 28 2006, @07:40AM)
Dear Guys, (Score:5, Funny)
Your Pal,
Wen
Duh ... just use Gopherspace (Score:4, Interesting)
Detectable and Illegal (Score:4, Interesting)
When are they going to realise... (Score:5, Insightful)
(http://www.poromenos.org/)
Re:When are they going to realise... (Score:5, Insightful)
(Last Journal: Sunday August 06 2006, @10:39PM)
Re:When are they going to realise... (Score:4, Informative)
National Firewall (Score:2)
Will it be able to deal with this enormous amount of traffic jamming into a "single point"?
Damn you Mongolians! (Score:5, Funny)
Jeez, why is it everytime chinese build a wall, those damn mongolians gotta break it down?
They're not Mongolians... (Score:4, Informative)
They're Mongorians!
And before someone lambasts me for making fun of Engrish, I should clarify that I'm amused by all variations of the English language. A good number of my fellow Maltese citizens butcher English, for example, even though it's supposed to be a first language. Only in Malta can you fill your car up with pitlor (petrol), have your football team lose on a pineltri (penalty), and make windows out of enimielju (aluminium). By the way, those aren't Maltese words, those are what many Maltese people think the English words actually are. Oh, and they also think that Hoover, Jablo, Kenwood, and Geyser literally mean a vacuum cleaner, polystrene foam, a cake mixer, and a hot water heater, respectively.
Here's the South Park clip about Mongorians from YouTube [youtube.com].
Harry Potter??! (Score:2, Insightful)
(http://www.celardore.net/)
Maybe if the Chinese authorities found you on board this 'train', they could act like those terrible dementor things I guess.
Irresponsible (Score:3, Insightful)
Re:Irresponsible (Score:4, Insightful)
(Last Journal: Sunday November 05 2006, @05:31AM)
Why wait for the revolution before taking any other action? Your position is ridiculous.
-jcr
Re:Irresponsible (Score:5, Interesting)
(http://www.ceyah.org/~jandrese/ | Last Journal: Thursday September 13, @11:11AM)
Re:Irresponsible (Score:5, Insightful)
Re:Irresponsible (Score:4, Informative)
(Last Journal: Thursday July 28 2005, @05:46PM)
Huh? Why can't they have help? (Score:5, Insightful)
Just because a Revolution receives assisstance from the outside makes it no more or less legitimate.
SirWired
Why is revolution the only answer? (Score:4, Insightful)
Why do you think that the only legitimate way to deal with a bad government is to overthrow it, by election or force? What's wrong with getting a bad government to change its ways?
Do you think that any time a government is doing something bad, that the government should be overthrown (or voted out)? What if a government is doing some really wrong things, but it's also doing some good things? Suppose you think that a President has done one thing that's very wrong, but that aside from that one thing, he's done a fantastic job. Are you morally obliged to vote that President out? Imagine it's 1948. You think Truman did a terrible thing when he used nuclear weapons in Japan, but you approve of everything else he's done, and you don't like Dewey. Are you morally required to vote for Dewey anyway?
Do you think that armed rebellion is the only way for a non-democratic government to become democratic? If so, why do you think this? There are examples in recent history of non-democratic governments becoming democratic without a shot being fired (e.g., most of Eastern Europe). Or think about the way the U.K. changed from a non-democratic monarchy to a parliamentary democracy with a figurehead monarch.
Have you thought about what would be involved in overthrowing China's government by force? For some period of time, China would be without any government at all. Think how wonderful it would be for a country with a population of over a billion and a large supply of nuclear weapons to find itself suddenly without a government.
One way to get a government to stop trying to regulate something is to make its efforts to regulate it spectacularly ineffective. This happened in the United States with Prohibition. Why can't it happen in China?
DOS? (Score:3, Insightful)
This has the potential to triple the traffic through their firewall as resets are sent for every packet. So consequently, not only is it an illegal act of hacking (even by US standards) but the potential does exist for a resulting DOS attack that could take the firewall down completely.
Kids have to much time on their hands. No matter how "horrible" Chinese internet policy is by US standards, it's their damned network segment. Let them work it out for themselves.
It's not THEIRS (Score:5, Insightful)
The chinese internet doesn't belong to the chinese government, it belongs to the chinese people. When they have a real democracy then "they" (the people) can decide how to run it. Until then we shouldn't respect how "they" (the government) want to run the internet any more than we would if some bank robbers were holding hostages and "they" (the robbers) wanted to decide how to run the bank.
Re:the chinese government is illegitimate (Score:5, Interesting)
During the Chinese civil war, the Communist party was overwhelmingly supported by the people.
Your assertion that non-democratic societies are illegitimate suggests that most societies in history have been illegitimate. I'm not sure that's a particularly useful definition of legitimacy.
I don't kmow about China (Score:4, Informative)
(http://www.revis.co.uk/)
I used to use JAP [tu-dresden.de] (a similar project but the client was Java based and less transparent) but Tor is considerably faster. Throughput up to 60K/sec on a 512k/sec DSL line (as fast as it ever goes with no proxy) means that it's practical to use for all traffic and makes the needle much harder to find in the haystack.
It's a dying shame that /. is censored in China... (Score:1)
for those who didn't read harry potter (Score:4, Funny)
(http://127.31.33.7/)
This should take a while to plug (Score:5, Interesting)
Just a thought.
the_crowbarBad example! (Score:5, Funny)
(http://tribbin.nl/)
Or you just type in:
idspispopd = Walk through wall in noclip style
Unless the web server also ignores reset packets.. (Score:1)
"However, because the original packets are passed through the firewall unscathed, if both of the endpoints were to completely ignore the firewall's reset packets, then the connection will proceed unhindered!"
"Defeat China's Great Firewall: Take 37" (Score:1)
America is beginning to have it's own firewall. (Score:2)
Gambling too. Using phone lines to bet shouldn't be illegal. Encroaches on civil liberties.
Just a scratch on the surface (Score:2, Insightful)
Spoofed resets don't work against a modern OS (Score:2, Informative)
A third party spoofer can play games with the TCP Timestamps to effectively shut down a connection and he only has to be near-realtime. Send the right value and all of the legitimate packets get dropped by the OSes PAWS checks. I'll leave that one as an exercise to the reader.
Great walls not so great in China (Score:3, Interesting)
(http://genesoldiers.webforte.com/)
This sort of reminds me of the way the Mongols defeated the Great Wall of China.
Did they tear the wall down? No.
Did they march around one end of the wall? No.
They simply bribed a guard to open the gates.
Maybe China shouldn't be so fixated on walls.
Defeating US immegration policy... (Score:1, Troll)
We would be offended if China would try to defeat US or EU labor laws, immigration policy, or othther domestic or international policies.
Cisco will be upset! (Score:3, Insightful)
Then he'll go home to his wife and kids, proud that he's done a good job. If you're here, raise your hand.
Kind of funny, eh, that repression has been outsourced to us now. (Yes, Cisco helped set up the great firewall, sold the equipment, and worked extensively to prevent free access by Chinese citizens.)
Harry Potter? (Score:1)
(Last Journal: Sunday November 11, @03:52AM)
Been there...the firewall isn't a big deal (Score:1, Interesting)
Personally I used vpn software to get around a bunch of these issues. However I could have been arrested and charged with crimes against the state for even possessing the software. Let alone using it.
The Great Chinese Firewall is a sham...if the government wants to get you they'll just watch what you type. ALL hotel connections are monitored, maybe not continuously but they are monitored.
-anon because I still need to travel in China on occasion.
China's Great Intrusion Detection System (Score:2)
Disgusting (Score:1)
(http://fark.com/)
Use a VPN and bypass local restrictions (Score:2)
* PublicVPN.com
* HotspotVPN.com
* SpotLock (via iPass)
* iPig
Some (most?) of them also allow VoIP access, so you can bypass those pesky local telcos.
Modern-day Hsiung-Nu (Score:1)
The Firewall's Not the Problem (Score:2, Interesting)
I won't count on it. (Score:1)
(http://stormtower.invisionplus.net/)
This has less to do with the great firewall ... (Score:1)
Allowing a unknown, unauthorized third party to reset a connection.
Bruce described this could be used as a DOS attack. This is the essence.
The great firewall of China is a popular example, because of the political dimension.
Mention this as a defeat for the great firewall of china is a way of packaging the message.
might as well move to kent state (Score:1)
great firewall of china (Score:1)
We run an encrypted ssl vpn for our company data, which the chinese authorities are probably a little nervous about us using in china for obvious reasons. What I find is that after about 24 hours usage , the internet goes mysteriously down a lot of the time. This would be the response to somebody who's firewall was rejecting their block packets surely. They just shut down your access to the net unless you play by their rules....and probably take you out the back and shoot you in the back of the head if you keep breaking their rules.....
After another 5 years of George W, that's where you'll probably be at in the "land of the free" too
The cure is lag?!? (Score:2)
(http://www.deepnines.com/)
leave it to china to turn lag into something good.
Re:Long term solution... (Score:1)
(http://jrascher.wordpress.com/ | Last Journal: Thursday June 22 2006, @10:09PM)
Re:HAXORED BY CHINESE! (Score:3)
(http://slashdot.org/~Spy+der+Mann/journal/ | Last Journal: Saturday November 10, @01:50AM)
Firewall 1,306,313,812; Haxors 1 ?
Re:The real question is (Score:2)