net4people / bbs

Forum for discussing Internet censorship circumvention
3.2k stars 75 forks source link

Large scale blocking of Reality and (relayed) WS + TLS protocols in Iran (MCCI; AS43358) #277

Open NikolajHansen23 opened 10 months ago

NikolajHansen23 commented 10 months ago

Starting a few days ago, there have been widespread reports that MCCI is blocking Reality-based VPNs in a matter of hours and with low traffic. Additionally, WS + TLS VPNs that take advantage of CDNs (e.g., Cloudflare) are barely working. Even if you use a domestic (Iranian) CDN (e.g., Arvan Cloud), which generally has access to a less censored Internet, they almost don't work anymore.

Here are some of my observations:

So, what are the next steps now? When this new system gets used on all the main providers in Iran, I don't think there will be much more options left. Using a domestic relay (whether a CDN or server) was always deemed the last resort to escape censorship.

Phoenix-999 commented 9 months ago

As I mentioned in my previous comments Buckle up your seat belt because the storm is about to start. 6 days left to anniversary of MAHSA AMINI**

⚠️Netblocks Confirmed: An internet disruption has been registered in #Iran for the second night in a row from ~1:00 am local time; Network data show connectivity falling down to 71% of ordinary levels 📉

IMG_20230911_060103_298.jpg

IMG_20230910_085543_671.jpg

A1s2xD commented 9 months ago

@Phoenix-999 Your speculations are absolutely correct :/

Phoenix-999 commented 9 months ago

And struggle continues

Netblocks Confirmed: Live metrics show a significant disruption to internet connectivity in Zahedan, #Iran; the incident continues the weekly pattern of regional internet shutdowns targeting anti-government protests, and comes on the eve of the anniversary of Mahsa Amini's death

photo_5775975060677443666_y copy

hawshemi commented 9 months ago

This has been routine since last year. It's because the prayers on Fridays every week in Zahedan.

Phoenix-999 commented 9 months ago

2023-09-23

Confirmed: An internet disruption has been registered in #Iran for the third time this month from ~1:00 am local time; Network data show connectivity falling down to 82% of ordinary levels 📉 photo_5805253522021792891_y

shakibamoshiri commented 7 months ago

I've come across a new and rather strange issue that I wanted to share with you all. Just in case anyone else is experiencing the same phenomenon or perhaps has a reasonable explanation for it.

I've created a new VPS server using a clean IP, carried out my usual setup and configuration routine, and generated the Reality configuration with a clean and whitelisted SNI on port 443. (VLESS+TCP+Reality)

Everything appeared to be in order until I conducted tests across various ISPs and in different cities to ensure that everything is functioning correctly as it should. The client app and software are identical and up-to-date with the latest version.

Interestingly, the same configuration that was functioning flawlessly in cities like Tabriz, Isfahan, and Shiraz is no longer operational in Tehran, the capital city. This issue is observed across multiple ISPs in Tehran.

I've attempted various whitelisted SNI options, but the outcome remains the same, BUT when I’ve changed the port number from 433 to any 4 or 5 digit number the same config with the same SNI working in Tehran as well as other cities with consistent and decent upload and download speeds.

Has anyone else encountered a similar issue?

2023-11-18-Saturday

Yes Unlike 4 years ago (Aban-98) full national blockage raises more attention
They advanced their strategy to apply restriction to a specific location
At the moment of writing this reply

restriction has begun to a next level.
No matter what the protocol is, the TLS handshake never completes (you can check WireShark)

You may look at this if you did not already How the Great Firewall of China Detects and Blocks Fully Encrypted Traffic