‹ BackHN Continuity

Thread

Court agrees with EFF: Utah's VPN law demands a technical impossibility

802 points · 405 comments · hn_acker

  1. usernomdeguerre · · focus · HN ↗
    >As we’ve said time and time again: the internet will always route around censorship.

    Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.

    Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.

    Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.

    1. tialaramex · · focus · HN ↗
      The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

      Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

      The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

      1. nazcan · · focus · HN ↗
        My guess is if you are in China they can MITM you with their own root certs.
        1. hnav · · focus · HN ↗
          Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
        2. JoshTriplett · · focus · HN ↗
          Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
          1. ndriscoll · · focus · HN ↗
            If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

              1. Make it illegal to distribute a browser that distrusts their CA
            
              2. Make it illegal to run a browser that distrusts their CA
            
              3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
            1. JoshTriplett · · focus · HN ↗
              Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.
            2. Gigachad · · focus · HN ↗
              This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.

              Doesn’t require cracking crypto or any funny business around forcing people to install stuff.

            3. mrzimmerman · · focus · HN ↗
              “Make it illegal to…” that has never in human history prevented anything from happening. Cannot increase the risk? Of course, but laws do not stop humans from humaning.

              Furthermore, doing any of the things you listed would isolate all legitimate network traffic as well as any undesirable traffic, fully shuttering all Chinese manufacturing businesses from global requests via the web. This hat would happen then? Phone calls, emails, and even physical mail would become the new norm and most of the Chinese economy would collapse under the weight of not being able to hop on a Zoom with a client that wants tooling made for its aluminum manufacturing molds.

              So besides my point of the black market your hypothesis of total control misses all the other pressures that exist that make what you’re proposing infeasible on its face. Only a place like North Korea that is willing to be a pariah state is old be willing to take the economic and social costs associated with your proposal, and they’ve only been able to do that because their abominable regime was in place before the internet existed and they pre-built controls very late in the game.

              Tl;dr simply because a country _could_ do something doesn’t mean it’s realistic for reasons outside of basic networking concepts.

              1. [deleted] · · focus · HN ↗

                [deleted]

          2. someonebaggy · · focus · HN ↗
            Useless. You still don't get the connection unless you trust the MITM. You either disable CT, or you don't get a connection.
            1. JoshTriplett · · focus · HN ↗
              That&#x27;s a different case where they&#x27;re not trying to be surreptitious. For that case, see <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49937347">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49937347 and my response.
      2. tenacious_tuna · · focus · HN ↗
        &gt; Things China can&#x27;t do: Magically &quot;downgrade&quot;, &quot;decrypt&quot; or &quot;intercept&quot; the secure protocols we use every day like HTTPS

        I mean... They could, though, no? If they control the gateways they could drop any traffic that isn&#x27;t encrypted with some root cert that allows them to decrypt in transit packets.

        1. tialaramex · · focus · HN ↗
          &gt; If they control the gateways they could drop any traffic that isn&#x27;t encrypted with some root cert that allows them to decrypt in transit packets.

          I&#x27;m sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world&#x27;s telephone calls using a device built into your batmobile - but this isn&#x27;t a Hollywood movie and so traffic isn&#x27;t in fact &quot;encrypted with a root cert&quot;.

          If for any of a variety of reasons the Chinese authorities don&#x27;t want your connection to exist they&#x27;ll terminate the connection, exactly as I described in my earlier comment.

      3. kccqzy · · focus · HN ↗
        Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.

        Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.

        1. anamexis · · focus · HN ↗
          Have you been to China? It is still super easy to bypass the Great Firewall with VPNs.
          1. HDThoreaun · · focus · HN ↗
            In times of low social unrest theyd rather create a list of dissidents than try to shut them down. Keeps unrest lower and then when they need to spin up the domestic security apparatus they already know who to watch
          2. Terr_ · · focus · HN ↗
            Until a time of &quot;civil unrest&quot; occurs, and suddenly your &quot;super easy&quot; VPN becomes entirely blocked at the very same moment you wish you had it the most.

            They aren&#x27;t stupid, they&#x27;re not going to insta-block everything they can detect, giving away clues to people trying to evade it.

            1. anamexis · · focus · HN ↗
              What makes you so sure this is the case?

              If there&#x27;s civil unrest, they can of course essentially turn off the internet, but there&#x27;s a distinction between &quot;the internet can route around censorship&quot; and &quot;the internet can be blocked in its entirety (or near entirety)&quot;

              1. someonebaggy · · focus · HN ↗
                They&#x27;re probably sure because it has happened previously each time there was &quot;civil unrest&quot;.
            2. [deleted] · · focus · HN ↗

              [deleted]

          3. kccqzy · · focus · HN ↗
            With pre-approved commercial VPNs yes. Set up your own unapproved VPN whether it’s IPSec or Wireguard or plain old SSH port forwarding, and see how fast it gets killed.

            But of course the easiest approved “VPN” is just data roaming.

            1. anamexis · · focus · HN ↗
              I used Wireguard to my home residential internet almost exclusively the last time I was in China. 2 weeks, no issues.
              1. kccqzy · · focus · HN ↗
                You were probably using mobile data (roaming) or hotel WiFi for a hotel approved to host foreigners. Go do it from a residential network.
                1. [deleted] · · focus · HN ↗

                  [deleted]

                2. hellojesus · · focus · HN ↗
                  When I was living in China in 2009, my apartment came with wifi. I noticed I would get shut down often, and made a game of it based on what content I typed in chats to friends back home. But it got old quickly, and then I went to the router in my apartment to reset it and install some custom firmware when I realized the wifi pw they gave me wasn&#x27;t to the router or modem in my apartment. I factory reset it and had much better access and was able to easily circumvent the great wall after that. Foreigner internet certainly exists, but in my experience it was much more limiting.
                  1. kingforaday · · focus · HN ↗
                    Guess you weren&#x27;t living near the Urumqi, Xinjiang rioting? Almost a year of severe internet restrictions.
                    1. hellojesus · · focus · HN ↗
                      That&#x27;s correct. This was in Nanjing.
                  2. kccqzy · · focus · HN ↗
                    2009 was a different time. GFW didn’t work at all for IPv6 traffic or any IPv6 tunneling protocol. It also didn’t employ any statistical packet size analysis. You could go to SixXS and grab a V6 address, and enjoy the uncensored V6 internet. No encryption was needed.
                3. thaumasiotes · · focus · HN ↗
                  I was there in 2023.

                  You&#x27;re describing exactly the opposite of what I found to be the facts on the ground. My connection to a residential address in the United States was allowed for a couple of days at a hostel, then blocked. It was never allowed over (Chinese) mobile data.

                  But it was completely fine over the internet service to my apartment. The home internet service and the mobile service were provided by the same company in a bundled plan. I was always curious what they were doing.

                  1. someonebaggy · · focus · HN ↗
                    Probably just differing equipment. The Great Firewall isn&#x27;t one giant firewall, it&#x27;s just the sum total of a million different &quot;plug in for censorship&quot; rack-mount boxes, from several different brands, plugged into ISPs all over the country.
          4. whimsicalism · · focus · HN ↗
            very much depends on the region in my experience, i found it was a game of cat &amp; mouse against their traffic pattern sniffers.
          5. someonebaggy · · focus · HN ↗
            China knows them all and allows it. Whenever there&#x27;s a protest, they flip the &quot;actually block VPNs now&quot; switch and almost no bypass method works.
          6. rikima_ · · focus · HN ↗
            yes. buy a random esim card from trip.com whenever you visit china and problem is solved. it&#x27;s also super cheap. 10Gb 30days for 5 bucks.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.