So not only does he have to deal with the ridiculously hostile environment being a programmer in Iran. He's also blind. That truly gives some perspective on things.
I don't know if that should be expected (cruft would be harder for assistive devices to read) or unexpected (he can't see; how can he keep it clean?)
Thank you a lot for your well wishes.
Let's perform a gedankenexperiment. There is a country A that "misbehaves" — e.g. threatens its neighbourhoods and promises to hit them with nuclear weapons ASAP (in other words, promises nuclear offense). Quick note: in this context "country A" means "government of country A". There is also a country (or an alliance) B that is overwhelmingly more wealthy than A, has more military might and political power. What do you think B should do? Here are the options:
1) ignore A until it directly threatens B;
2) use B's military, crush A's government, help A's people to rebuild the country;
3) apply political and economical pressure to A, which in practice means "make A citizens' life miserable so they deal with A's government themselves". It's sometimes possible to apply the pressure selectively (e.g. to A's elites).
I agree with you that it's a morally ambivalent situation. However, I strongly believe that an embargo (including "digital" one) causes less casualties than "boots on the ground". Moreover, democracies don't fight each other, so in this scenario A is (most likely) a dictatorship. Dictatorships are bad and I believe that wealthy countries should care about long-term wellbeing of citizens of other countries, at least for their own self-interest. Your opinions may differ, but it would be wrong to brush off the whole issue with "political mess created by dumb people".
During those times my both parents were having small private firms and were trying to make end's meet which were difficult enough with the collapsing economy and inflation and having no political connections with the ruling class (they despised the serbian nationalism and were being active in the then-opposition parties) sure didn't help them.
The one occasion I will never forget is when my parents decided to go to Hungary to try to buy some glazes for my mother's pottery shop. They would've bought some 20-30 kilos, smuggled it in our car and that would've been enough for a next few months. When the shopkeeper in the Hungary heard they are from Serbia he decided that he wouldn't want to sell them anything because "embargo and war and stuff" and so my parents came home empty handed. They came to the shop as private individuals and must have mentioned briefly where they would be taking the merchandise (they both spoke hungarian) but the shopkeeper kept looking at them as if they were personally responsible for all the things that were going in the Bosnia at the time. We didn't have to close the shop, a few weeks later they found another supplier and bought from there but it really left a bitter taste in their mouths.
(shameless plug: this is now my brother's pottery shop who inherited it from our mother who passed away 6 years ago, this is a small promo video he did some time ago)
The US & UK overthrew Iran's parliamentary democracy, and installed the Shah. (https://en.wikipedia.org/wiki/1953_Iranian_coup_d'%C3%A9tat)
The US is the world's most hyperviolent bully. (Just compare its capacity and use of violence to any other entity.) Bullies generally don't admit they're bullies, despite all evidence, and swear they're justified when smashing their victims.
If embargoes are pursued after decades with no evidence that they are beneficial, then calling them "dumb" is not so unjustified.
Sorry for not giving you the information you were looking for.
Digital embargo is more appropriate IMHO.
> You shouldn’t really hate them (Docker) because they are doing what they have to do.
I'd love to. This is a dream that I'm striving for.
> do you want to go to the trouble of getting him a visa?
Now, that'd be a tough one for anyone to answer.
And as someone in Austin who has seen how insanely hard it is to find a good culture fit despite a large pool of "talent," yes, I'd jump through hoops to find someone as humble and self-motivated. Unfortunately, I'm just not in a position to do so at my current place.
I run all my traffic through Finland usually because they have fairly strong data protection laws, especially compared to the UK where I live.
It's also a nice way to get around traffic shaping and other invasive measures from your ISP. During peak hours I have better speeds for Netflix and the likes through Finland than without VPN.
Thanks a lot! I'll definitely try this one out!
My setup:
Cheap VPS server in Hong Kong [1] (5USD/month, 512 RAM, 2Mbit port) running the ShadowSocks server (libev version). I have upgrade the port to 20Mbits for an extra 10USD/month. The port could be upgrade to 50Mbits for 25USD/month.
For DNS I use ChinaDNS [2] to automatically filter out bad DNS results from China's censorship. It works by sending DNS queries to all multiple DNS server at the same time (give it a few local DNS servers and foreign DNS servers). The foreign DNS connections are tunneled through ShadowSocks.
ShadowSocks can work as a Socks5 proxy, tunnel or transparent proxy [3]. Socks5 is the easiest to use and can even do DNS lookups on the server. I use the transparent proxy [3] option, since it allows selecting which traffic should go over the proxy.
The socks5 option will try to proxy localhost & lan conections to the proxy server.
An optimized list of subnets can be generated using bestroutetb [4]. I load the subnets for China (can private LAN) into an ipset hash and use iptables rules to exclude those subnets from going over the proxy.
ChinaDNS [2] and bestroutetb [4] could be used for VPNs too. This could be used when trying to access different services (US, UK, etc..) that don't allow access from outside their country. Use one VPN for US and another for UK, then use bestroutetb [4] to build subnet lists for each country route traffic over the correct VPN.
2. https://github.com/shadowsocks/ChinaDNS
3. https://github.com/shadowsocks/shadowsocks-libev/blob/master...
4. https://github.com/ashi009/bestroutetb
edit: fix formatting and port prices.
Https is an improvement, but they still use machine learning to make estimates on encrypted contents of packets. If packets going to and from a location (i.e. Your vpn server) meet some criteria with some confidence, they perform attacks on that connection and subsequent connections To the same endpoint. I'm not sure on the specifics, but these attacks will cause ~90% of that connection's traffic to drop. The system is dynamic, so your countermeasures have to be as well.
I'm guessing HK because it's physically and politically close. It's considered Chinese territory, but not under China's GFW. I've heard from friends that GFW censorship is more aggressive around sensitive times (i.e. Tiananmen square anniversary) and news.
If any of this is wrong or inaccurate, someone please correct me. I'd love to have a better mental model of the GFW so that I could better work remotely from there.
What I am paying for good latency & bandwidth on that server is cheap compared to other providers.
Hong Kong is very close to me (Guangzhou), so latency is low (around 9-10ms).
Here is the latency I am seeing right now:
1. Ping to DigitalOcean VPS server in San Franciso: 270ms
2. Ping to 36cloud.com VPS server: 10ms
3. Ping from 36cloud VPS to DigitalOcean VPS: 160ms
4. Proxy running on DigitalOcean VPS server in San Franciso: 274ms, DL: 3Mbits, UL: 4Mbits
5. Proxy running on 36cloud.com VPS server: 178ms, DL: 8Mbits, UL: 5Mbits
The last two are from using speedtest.net with the same speedtest server in SF. So the VPS in HK save me almost 100ms of latency. which greatly improves browsing speed.
The client and server software VPN Gate uses is the open source SoftEther VPN [2], which I also use to host and connect to my own VPN. It's pretty great.
https://github.com/jlund/streisand
Good luck!
Works great for websites, but can SOCKS5 transparently redirect DNS traffic? In the end I setup an OpenVPN server and setup port redirecting for DNS.
This comment is not ok.
If you're the person who contacted me through an email, I just replied to you! If not, I'll paste my response here:
----------
Hi Dan! You won’t believe how glad i am that you decided to contact me regarding this, rather than making a decision about me in your mind and not speaking about it. Thank you. Your email made me realize that I had made a mistake there that we developers often do, namely forgetting to explain the context and thinking that the reader already knows it. In Iran, we don’t have many women who go as far as a Masters degree in computer science. Even if they do, they don’t usually enter the workforce as a DevOps or software engineer. This was what I meant with “can you believe it?” — the fact that this lady had gotten so far is unbelievable. I know where you’re coming from, though. Whenever I reveal on the web that I’m a blind programmer, many people talk between themselves and say, “he’s a blind programmer! Can you believe it?” A lot of people in those circles raise an objection about this choice of words, saying that, “Why do you think it’s incredulous for him to code?” So, yes, I should have seen this misunderstanding coming. You’re awesome. I’ll go and change it immediately. Thanks again. Best, Parham
There are ways.
Take notice.