upvote
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

reply
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.

Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.

reply
Have you been to China? It is still super easy to bypass the Great Firewall with VPNs.
reply
With pre-approved commercial VPNs yes. Set up your own unapproved VPN whether it’s IPSec or Wireguard or plain old SSH port forwarding, and see how fast it gets killed.

But of course the easiest approved “VPN” is just data roaming.

reply
I used Wireguard to my home residential internet almost exclusively the last time I was in China. 2 weeks, no issues.
reply
You were probably using mobile data (roaming) or hotel WiFi for a hotel approved to host foreigners. Go do it from a residential network.
reply
When I was living in China in 2009, my apartment came with wifi. I noticed I would get shut down often, and made a game of it based on what content I typed in chats to friends back home. But it got old quickly, and then I went to the router in my apartment to reset it and install some custom firmware when I realized the wifi pw they gave me wasn't to the router or modem in my apartment. I factory reset it and had much better access and was able to easily circumvent the great wall after that. Foreigner internet certainly exists, but in my experience it was much more limiting.
reply
2009 was a different time. GFW didn’t work at all for IPv6 traffic or any IPv6 tunneling protocol. It also didn’t employ any statistical packet size analysis. You could go to SixXS and grab a V6 address, and enjoy the uncensored V6 internet. No encryption was needed.
reply
Guess you weren't living near the Urumqi, Xinjiang rioting? Almost a year of severe internet restrictions.
reply
That's correct. This was in Nanjing.
reply
I was there in 2023.

You're describing exactly the opposite of what I found to be the facts on the ground. My connection to a residential address in the United States was allowed for a couple of days at a hostel, then blocked. It was never allowed over (Chinese) mobile data.

But it was completely fine over the internet service to my apartment. The home internet service and the mobile service were provided by the same company in a bundled plan. I was always curious what they were doing.

reply
deleted
reply
Until a time of "civil unrest" occurs, and suddenly your "super easy" VPN becomes entirely blocked at the very same moment you wish you had it the most.

They aren't stupid, they're not going to insta-block everything they can detect, giving away clues to people trying to evade it.

reply
What makes you so sure this is the case?

If there's civil unrest, they can of course essentially turn off the internet, but there's a distinction between "the internet can route around censorship" and "the internet can be blocked in its entirety (or near entirety)"

reply
deleted
reply
In times of low social unrest theyd rather create a list of dissidents than try to shut them down. Keeps unrest lower and then when they need to spin up the domestic security apparatus they already know who to watch
reply
My guess is if you are in China they can MITM you with their own root certs.
reply
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
reply
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

  1. Make it illegal to distribute a browser that distrusts their CA

  2. Make it illegal to run a browser that distrusts their CA

  3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
reply
Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.
reply
“Make it illegal to…” that has never in human history prevented anything from happening. Cannot increase the risk? Of course, but laws do not stop humans from humaning.

Furthermore, doing any of the things you listed would isolate all legitimate network traffic as well as any undesirable traffic, fully shuttering all Chinese manufacturing businesses from global requests via the web. This hat would happen then? Phone calls, emails, and even physical mail would become the new norm and most of the Chinese economy would collapse under the weight of not being able to hop on a Zoom with a client that wants tooling made for its aluminum manufacturing molds.

So besides my point of the black market your hypothesis of total control misses all the other pressures that exist that make what you’re proposing infeasible on its face. Only a place like North Korea that is willing to be a pariah state is old be willing to take the economic and social costs associated with your proposal, and they’ve only been able to do that because their abominable regime was in place before the internet existed and they pre-built controls very late in the game.

Tl;dr simply because a country _could_ do something doesn’t mean it’s realistic for reasons outside of basic networking concepts.

reply
deleted
reply
This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.

Doesn’t require cracking crypto or any funny business around forcing people to install stuff.

reply
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
reply
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS

I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.

reply
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.

I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".

If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.

reply
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.

So there is a route around censorship, but maybe the public doesn't really care about it.

reply
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
reply
How I have heard it described is using a VPN in China is like smoking weed in the US. It’s widely done even if illegal and you’d have to be seriously unlucky to get in trouble. You’d at most get a warning.

People with more first hand experience can probably explain it better but it doesn’t seem that strict. China is not North Korea, their aims seem less about preventing people from learning about the world and more preventing non compliant foreign tech companies having Chinese users.

reply
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
reply
That's the way it was explained to me. Letting the fringe do what they're going to do anyway while inoculating the majority to outside influence is the goal and the difficulty setting is dynamic.
reply
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.

I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.

reply
We have a data center in Utah.. And I'm sure some of our customers are storing "adult" material.. Are we now banned?
reply
It's never been true.

The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.

That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.

reply
What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP
reply
Having the power of violence behind you makes technical hacks mostly irrelevant.
reply
The internet will always route around censorship in principled western nations.

It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.

I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...

But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.

reply
deleted
reply
It seems like Utah could do mostly do this by intercepting all consumer traffic.
reply
Just buy the surveillance equipment from Russia and get it done.
reply
With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?

A VPN/proxy could exist at almost any single address at any given time.

reply
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
reply
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.

> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.

https://gulfnews.com/world/mena/iran-official-says-starlink-...

reply
There will always be >0 people who find a way around censorship, that's about it. It's not bad AND ineffective, that's a contradiction.
reply
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.

To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.

Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.

And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.

reply