upvote
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.

Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.

reply
Have you been to China? It is still super easy to bypass the Great Firewall with VPNs.
reply
With pre-approved commercial VPNs yes. Set up your own unapproved VPN whether it’s IPSec or Wireguard or plain old SSH port forwarding, and see how fast it gets killed.

But of course the easiest approved “VPN” is just data roaming.

reply
I used Wireguard to my home residential internet almost exclusively the last time I was in China. 2 weeks, no issues.
reply
You were probably using mobile data (roaming) or hotel WiFi for a hotel approved to host foreigners. Go do it from a residential network.
reply
When I was living in China in 2009, my apartment came with wifi. I noticed I would get shut down often, and made a game of it based on what content I typed in chats to friends back home. But it got old quickly, and then I went to the router in my apartment to reset it and install some custom firmware when I realized the wifi pw they gave me wasn't to the router or modem in my apartment. I factory reset it and had much better access and was able to easily circumvent the great wall after that. Foreigner internet certainly exists, but in my experience it was much more limiting.
reply
2009 was a different time. GFW didn’t work at all for IPv6 traffic or any IPv6 tunneling protocol. It also didn’t employ any statistical packet size analysis. You could go to SixXS and grab a V6 address, and enjoy the uncensored V6 internet. No encryption was needed.
reply
Guess you weren't living near the Urumqi, Xinjiang rioting? Almost a year of severe internet restrictions.
reply
That's correct. This was in Nanjing.
reply
I was there in 2023.

You're describing exactly the opposite of what I found to be the facts on the ground. My connection to a residential address in the United States was allowed for a couple of days at a hostel, then blocked. It was never allowed over (Chinese) mobile data.

But it was completely fine over the internet service to my apartment. The home internet service and the mobile service were provided by the same company in a bundled plan. I was always curious what they were doing.

reply
deleted
reply
Until a time of "civil unrest" occurs, and suddenly your "super easy" VPN becomes entirely blocked at the very same moment you wish you had it the most.

They aren't stupid, they're not going to insta-block everything they can detect, giving away clues to people trying to evade it.

reply
What makes you so sure this is the case?

If there's civil unrest, they can of course essentially turn off the internet, but there's a distinction between "the internet can route around censorship" and "the internet can be blocked in its entirety (or near entirety)"

reply
deleted
reply
In times of low social unrest theyd rather create a list of dissidents than try to shut them down. Keeps unrest lower and then when they need to spin up the domestic security apparatus they already know who to watch
reply
My guess is if you are in China they can MITM you with their own root certs.
reply
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
reply
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

  1. Make it illegal to distribute a browser that distrusts their CA

  2. Make it illegal to run a browser that distrusts their CA

  3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
reply
Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.
reply
“Make it illegal to…” that has never in human history prevented anything from happening. Cannot increase the risk? Of course, but laws do not stop humans from humaning.

Furthermore, doing any of the things you listed would isolate all legitimate network traffic as well as any undesirable traffic, fully shuttering all Chinese manufacturing businesses from global requests via the web. This hat would happen then? Phone calls, emails, and even physical mail would become the new norm and most of the Chinese economy would collapse under the weight of not being able to hop on a Zoom with a client that wants tooling made for its aluminum manufacturing molds.

So besides my point of the black market your hypothesis of total control misses all the other pressures that exist that make what you’re proposing infeasible on its face. Only a place like North Korea that is willing to be a pariah state is old be willing to take the economic and social costs associated with your proposal, and they’ve only been able to do that because their abominable regime was in place before the internet existed and they pre-built controls very late in the game.

Tl;dr simply because a country _could_ do something doesn’t mean it’s realistic for reasons outside of basic networking concepts.

reply
deleted
reply
This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.

Doesn’t require cracking crypto or any funny business around forcing people to install stuff.

reply
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
reply
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS

I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.

reply
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.

I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".

If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.

reply