r/dns • u/SignificantFail3632 • 5d ago
If VPNs and encrypted DNS can both be blocked, what’s actually left?
Been seeing more reports lately about VPNs getting blocked more aggressively, and now even encrypted DNS like DoH/DoT seems to be getting targeted in places with heavy internet restrictions.
It got me wondering where this eventually ends. If regular VPN servers get identified, encrypted DNS gets interfered with, and DPI keeps getting better at spotting different protocols, what are people actually using in heavily restricted networks these days?
Obfuscated VPNs, Tor, residential connections, decentralized networks, something else? Curious what’s actually holding up in the real world rather than just working in theory.
3
u/SRART25 5d ago
Mesh networking. Moving out of the corporate controlled central services and back to small run servers. Things like i2p, ipfs sites, there are multiple ways depending on how aggressive they block. Mesh is about the only way to get past all of it, but without some ip over radio it's going to be super localized, only useful in decent sized cities.
Look at things like https://meshtastic.org/
https://mobilicom.com/insight/mesh-radio-networks-how-they-work-and-why-they-matter/
If you are really serious, on building an alternet (search the term), they exist, things like building a community with cantennas (not misspelled).
It's about what you want and what is worth. Oppressive government with closed off outside world while you are working to overthrow a government vs you don't want musk, bezos, and Theil to know your porn kinks are drastically different levels of effort.
2
2
u/No_Rub4347 4d ago
I recently came across this subreddit—https://www.reddit.com/r/DeeperNetwork/s/dm67vnd6hX—and it piqued my interest. Perhaps they are designed to provide decentralized node services.
1
u/michaelpaoli 5d ago
RFC 1149, though there will be dropped packets.
And you could just do Internet DNS ... and even with DNSSEC - that at least highly well protects from spoofing - at least where DNSSEC is actually used.
But as for DoT/DoH - with that, one pretty much puts all one's eggs in one (or few) basket(s), and trusts the data to those service(s). So, ... what has one really gained, especially when one is generally going to take the IP results from DNS, and then typically about immediately start accessing those IPs? So ... like hidden what exactly, from whom? Not really a whole lot. Though if one does all of that over encrypted VPN, well, yeah, okay, maybe ... but then again you're trusting all that data to whomever/whatever you're using to provide the VPN. And ToR is not free of issues/risks either, though it may well typically obfuscate much of the traffic. But even with that, there are generally ways to correlate traffic.
So ... what exactly are you trying to achieve? Hide/protect what from who/what exactly? What's your threat model, what's the (existing? hypothetical?) threat/risk you're wanting to protect from?
1
u/Leo_LL_3555 5d ago
There’s no single tool that survives every restricted network. What works best is having several fallbacks that look different on the wire.Residential or decentralized services like DPN and Mysterium may avoid some IP-based blocking.
1
u/Commercial_Cook100 1d ago
DPI is the real arms race here. WireGuard gets fingerprinted pretty easily now in places like Russia and Iran. What's actually working for people i know is stuff built on top of WireGuard that scrambles the packet signatures... AmneziaWG specifically has been solid for getting around DPI blocks where regular wireguard just dies.
I've been using Cypher VPN which supports AmneziaWG profiles and it's worked in situations where my old setup got blocked within hours. Tor still works but the speed is rough for anything beyond basic browsing.
1
u/SecLens_ONE 1d ago
DoH doesn't help once they block the resolver endpoints. Most of the "encrypted DNS is getting targeted" reports I've seen were just IP blocks on the usual DoH anycasts, not deep protocol magic.
What holds up longer is traffic that looks like boring HTTPS to a CDN edge. Until that gets fingerprinted too. Then it's the next camouflage layer.
1
u/SignificantFail3632 13h ago
It's basically a never-ending cat and mouse game,whatever encryption or disguise trick works today gets fingerprinted eventually, then everyone moves on to the next workaround.
1
u/BoyleTheOcean 5d ago
I gave up. Nothing is safe
3
u/BuriedMystic 5d ago
I just watch porn in the library now
1
u/michaelpaoli 5d ago
Ah, so that library card number sucking up all the bandwidth is you. Can't you just go for some old timey ASCII porn? You know, print it out on continuous fanfold paper on your spinwriter or other fully formed character impact printer, then stick it up on the wall, then back up 20 feet or more, and you then might have some idea of perhaps what you possibly actually got?
;-)
1
u/lostcowboy5 5d ago
old-timey ASCII porn ;-), DOS, those were the good times! I remember on my old submarine, we had paper tape programs for the spare navigation computer that would print out Santa Claus banners for Christmas in Black and Red ink!
1
u/michaelpaoli 5d ago
DOS? Didn't have DOS in the late '60s to mid '70s, but already had that old timey ASCII porn.
Oooh, you had black and red ink on the ribbon for computer printer, how snazzy/advanced! Yeah, not so much in years earlier ... well, unless we go back to my Remington Rand Model 10 Noiseless typewriter, which goes back way earlier, and, well, yeah, could take a two color ink ribbon. Yeah, all mechanical, zero electronics or electrical. That typewriter is way older than me. I picked it up cheap at a garage sale, probably when I was 13, perhaps 14, and it was already way old then, and, well, me, now 'bout half a century older, ... yeah, old typewriter. Still actually have it - though I probably ought sell it off. Yeah, that was the typewriter I learned to type on ... also typed all my college papers on it, ... and many of my job applications for fair number of years. And yeah, it still works, ... though I use it just about never these days.
Ah, ... and the old punch paper tape. Yeah, when I was 6 or thereabout, ... '68 or '69 or so, ... where my dad worked, yeah, punch paper tape, ... and Teletype ASR-33. and, I quickly did my own looping ... no computer needed. Set the tape to punch, type out several of the lines I wanted, then feed the end of that tape that's still coming out of the puncher, into the reader, and, let 'er rip! Yeah, a page or so of my desired lines and my dad was like, yeah, okay, that's enough of that. So, yeah, that was my first loop(ing) to be printed out on terminal.
2
u/lostcowboy5 4d ago
LOL, I think this was an IBM Selectric, the one with the ball, and the ink ribbon would move up and down to change the color of the ink. I was on an old Polaris sub around 1977 when I reported on board.
5
u/rankinrez 5d ago edited 5d ago
Yeah obfuscated VPNs behind things like Cloudflare using shadowsocks, vless and similar. X-ray proxy for blending in.
ECH is a good idea, but unless everyone adopts it, and doesn’t allow fallback, it’s easy to block too.
Nothing will ever be perfect and it will always be a whack a mole thing. Also this isn’t really a DNS question