Comment by tialaramex
5 hours ago
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.
Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.
Have you been to China? It is still super easy to bypass the Great Firewall with VPNs.
Until a time of "civil unrest" occurs, and suddenly your "super easy" VPN becomes entirely blocked at the very same moment you wish you had it the most.
They aren't stupid, they're not going to insta-block everything they can detect, giving away clues to people trying to evade it.
2 replies →
With pre-approved commercial VPNs yes. Set up your own unapproved VPN whether it’s IPSec or Wireguard or plain old SSH port forwarding, and see how fast it gets killed.
But of course the easiest approved “VPN” is just data roaming.
3 replies →
In times of low social unrest theyd rather create a list of dissidents than try to shut them down. Keeps unrest lower and then when they need to spin up the domestic security apparatus they already know who to watch
My guess is if you are in China they can MITM you with their own root certs.
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:
1 reply →
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS
I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".
If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.