Jigsaw-Code / Intra

An experimental tool that allows you to test new DNS-over-HTTPS services on Android
Apache License 2.0
1.54k stars 260 forks source link

Please change default cipher suite #461

Open BK8000L opened 2 years ago

BK8000L commented 2 years ago

they blocked chacha cipher that intra uses in our country, please change it to aes NON ECDHE

BK8000L commented 2 years ago

someone might listen, dont say anything that can help them please. So nothing about this comes on google

BK8000L commented 2 years ago

ok it doesnt matter, every day they block a cipher

bemasc commented 2 years ago

Can you point to a report about the blocked cipher?

BK8000L commented 2 years ago

@bemasc there is no report because many people dont speak english and its hard to reach internet when every VPN app with TLS isnt working

bemasc commented 2 years ago

Can you tell me what country you are referring to?

BK8000L commented 2 years ago

tur kme nist an @bemasc people from another issues begging for code in russian and tur km en are from there

BK8000L commented 2 years ago

i managed to get it working with empty sni. so this app can unblock youtube, but not regular dnscrypt. i watched traffic dump in wireshark, but i dont understand how it works. Do you do client hello fragmentation and bypass tcp_rst or something?

bemasc commented 2 years ago

Thanks for the info.

Yes, see https://github.com/Jigsaw-Code/outline-go-tun2socks/blob/master/intra/split/retrier.go#L113