I have heard of shadowsocks for this purpose. I have not tried it myself but I recall having read it being used to hide VPN traffic behind the great firewall. A brief intro to it here:
Thank you. It's between this and SoftEther now
Keep in mind there's another very easy method to mess with wg traffic: breaking the connection once every 30 seconds or so. This won't affect the vast majority of real HTTPS connections but will ruin long lived connections like ssh or streaming.
Hi, is there a point to doing this? My ISP/any advanced DPI will still know that I'm using Wireguard
They are talking about how whoever or whatever you are trying to get around can still mess with your wg tunnels even if you are masking them as https
How can someone else mess with the timeout of my wg tunnel if I mask them as HTTPS traffic?
They can break the session every 30 seconds, which would be fine for a normal web session but mess with your wg tunnel
Would breaking a TCP session every 30 seconds be OK for something like video streaming/content browsing?
I wonder if I can automate the breaking and forming of session on clients. Hopefully Android has something that will let me do this, I'm sure I can figure something out on Linux
Please update the post if you found solution to this. Also check this out.
I have found 3 different possible solutions to the problem but not sure if anyone in the community has done this yet. Thanks for the link.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
Fewer Letters | More Letters |
---|---|
HTTP | Hypertext Transfer Protocol, the Web |
HTTPS | HTTP over SSL |
IP | Internet Protocol |
SSH | Secure Shell for remote terminal access |
SSL | Secure Sockets Layer, for transparent encryption |
TCP | Transmission Control Protocol, most often over IP |
TLS | Transport Layer Security, supersedes SSL |
UDP | User Datagram Protocol, for real-time communications |
VPN | Virtual Private Network |
7 acronyms in this thread; the most compressed thread commented on today has 6 acronyms.
[Thread #253 for this sub, first seen 30th Oct 2023, 16:40] [FAQ] [Full list] [Contact] [Source code]
Good bot
OpenVPN? You can literally set it to run on port 443 tcp
True, but I just figured that it is possible to run Wireguard with stunnel, the latter is used by OpenVPN to wrap packets in TLS and masquerade as HTTPS traffic. If I can do that, and convert UDP packets to TCP with the software I mentioned in the post (changing the port is trivial), then I could achieve what I want!
I used stunnel years ago to tunnel both openVPN and SSH traffic and it worked flawlessly. Looks just like https web traffic to dpi software. Beware though, that long open connections can also set off flags, so don't keep connection's open permanently.
Hey, can I ask which DPI software were you using, and how did you get access to it?
I see. Thanks, good to know. I'll see if I can automate opening and closing connections. However, I do think that a lot of applications (especially chat/video applications) maintain fairly long connections these days: long livestreams on YT, discord client, lemmy, Instagram etc. Basically, if you're consuming content online, there's a good chance that your device might keep the connection going.
With that said, it's important to blend in: I wonder if I can automate the disconnect-connect process on Android
Wireguard is e2e encrypted, no middleman can inspect the packets without the private keys.
I'm aware that it is encrypted, however DPIs can pick out Wireguard traffic (due to the behaviour of SSL used in the protocol) and can identify/deny Wireguard traffic. I don't want that to happen. OpenVPN has a way to mask its traffic, I'm trying to see if anyone has done anything of the sort with Wireguard
shadowsocks seems to be the best way for now.
Thank you. It's between this and SoftEther now
You can try putting it on pretty 443 or another tls port. It's not a perfect solution but it could help for your specific setup.
Unfortunately, that is not enough
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!