net4people / bbs

Forum for discussing Internet censorship circumvention
3.2k stars 75 forks source link

sorry you cant grow up older that this #240

Open IMIEEET opened 1 year ago

IMIEEET commented 1 year ago

the title is actually true. if you remember its been a while since iran activated "Forced safe search" on google with dns spoofing returning forcesafesearch.google.com ip instead of normal google.com. BUT you could start your own DoT or DoH server to prevent that. thats until this early morning they blocked the whole range of 142.250.x.x and some of 142.251.x.x which is normal ips of google. this affected most of the websites if you used a Encrypted DNS including ALL Services of google (drive.google.com, mail.google.com and other *.google.com) also broke most of other websites since they use gstats and ad services. it affected on TCI home internet and MCI mobile networks. tell me if any other isp affected too. since im writing this its fixed now but im writing this anyway to inform anyone who did not noticed to be aware of how far they gone for very little people who relied on Encrypted DNS. so be ready they may do it again Permanently. NOTE: its was not affected by ip of datacenters (you could use a vpn on a iran server with DoT DNS upstream to bypass that since i personally dont like to use a vpn as far as i can because thats faster so dont prank me on this XD)

saveiran2023 commented 1 year ago

hey thank you for your concern what do you suggest if that happen?

IMIEEET commented 1 year ago

hey thank you for your concern what do you suggest if that happen?

Well as i said using a full vpn only for google is not good for performance. You can connect to any vpn remove the default route table so only google ip ranges go through vpn. Also i found that google services are accessible on all of their ips so forcing ip of forcesafesearch to other google services other than search engine is useless and cause problem on people using bare dns. Thats probably the reason people were talking in Twitter about yesterday problem on wesites not loading properly.