logoalt Hacker News

walrus01yesterday at 9:06 PM1 replyview on HN

Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.

Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.

The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.


Replies

dongcarlyesterday at 9:11 PM

Can't speak to Iran, but we use QUIC for transport (with an experimental TCP/TLS mode).

I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/