back
▲ 439 points

Tell HN: Russia has started blocking OpenVPN/WireGuard connections

by itvision·2y ago·234 comments·view on hn ↗
For the past three days Russians have been unable to use their VPN services working via OpenVPN/WireGuard protocols, and some even have reported that in certain situations SSH connections have stopped working.

The prospect of an isolated Russian interweb has become oh so real.

As a person currently residing in Russia I can confirm that I've been unable to connect to my favourite VPN provider for the past three days, not even its official application works.

I've not seen any discussions on the English-peaking Internet, not it's been in the news for some reasons despite its importance in preserving freedom of information and opinions.

In the Russian internet it's being hotly debated here: https://habr-com.translate.goog/ru/companies/xeovo/articles/...

More on the topic: https://torrentfreak.com/tag/russia/

234 comments
Unfortunately, thanks to the Great Firewall of China, there has been a lot of resources put in to fingerprint VPNs and block them by state actors.

Fortunately, however, there is equally years of some of the smartest minds on the planet working to bypass Chinese censorship, so there are some great OpenVPN alternatives.

I really encourage you to look into something like Shadowsocks which Chinese people have found great success in using over the last several years.

In your case, however, it's worth mentioning that if you can't connect at all then it's likely they've blocked the commercial IPs of the VPN nodes.

It's quite sad that projects like Streisand[0] were archived, but I'm sure there are other alternatives that might make it just as easy to roll onto a server.

[0] https://github.com/StreisandEffect/streisand

Outline (https://getoutline.org) is even easier to deploy than Streisand in my experience and uses Shadowsocks.
Shameless plug, there is also wstunnel (i am its author) https://github.com/erebe/wstunnel/, hope you enjoy.
Should point out when people go into the Sturm und Drang of the Great Firewall, that it was largely built by corporate America.

https://www.wired.com/2008/05/leaked-cisco-do/

What's the current legal risk of using a VPN in China or Russia these days? I found a couple articles about people getting charged, but none I know to be reputable or particularly well written.
Can anyone confirm Shadowsocks works anymore? When I tried to use it a few years ago, it got blocked in a few days.

To be honest, I think they are blocking anything that exchanges a lot of data with oversesas IPs, after hitting a certain threshold.

I imagine that is something that is not "top secret" that Xi can easily share with Putin and something that could be applied almost immediately to routers in Russia. That sucks that Russians can't see other perspectives. It doesn't seem to matter a lot since 80% of Russians still support him mindlessly, but those other 20% can help set a seed of doubt on his atrocities and autocratic lies but not if they can't get info.
v2ray is a great alternative
I have the fortune to reside in Russia-controlled Donbas. Over here they have been blocking all WireGuard connections for a long time. OpenVPN seems to be blocked selectively depending on the host. The government and commerce must need it more than WireGuard.

It isn't consistent. Different ISPs block different hosts and protocols at different times. I assume we are a kind of test and staging environment for censorship in Russia.

In the interest of anonymity I am not going to respond to your questions.

They called the Chinese to help with their experience like 6 months after the start of the war as they realised some young people could access news outside the official channels.

They have been testing it since then.

In China once their AI systems or whatever decides that you are using a VPN you will be punished by increasingly blocking your Internet for more and more time.

Russian here, living in Russia.

My paid VPN provider stopped working months ago. Then my self-hosted Outline server stopped working. Then my self-hosted OpenVPN stopped working too. Both were hosten on Digital Ocean (Frankfurt).

What currently works for me is self-hosted Outline running on an US server, but I suspect that won't last long.

Looks like I have no choice but to learn how to self-host XRay. A smart friend told me that it still works and is hard to block, but unfortunately he has no personal experience with it -- and no need for it anymore, since he emigrated to another country.

Does anyone here have any experience with XRay / XTLS-Reality?

I don't believe it is true. They might block commercial solutions, but i'm using Wiregiard with exit point in Netherlands right now, works fine (although on certain providers, I've seen some throttling, but that could just be coincidental)

UPD: I asked some friends, some of them have faced probmes. I guess it is not protocol block, but instead combination of protocol and "suspicious" server. Mine has stuff other then VPN running on it, so it might have flown under the radar.

Hey there! Lots of experience with this having lived in China for 2 years. I recommend you look into xray-core or v2ray.

https://github.com/v2fly/v2ray-core

https://github.com/XTLS/Xray-core

Here are my configs: https://github.com/acheong08/notes/tree/main/xray

Why this over WireGuard or OpenVPN or commercial solutions? Because it’s obfuscated and you’re much less likely to get caught. Try hosting a small game server on the same machine as well so the traffic doesn’t look too out of place.

What is interesting is that since 2022 a lot of sites and host services decided to ban access from Russia. Quite often to a very simple things - nothing related to technology. And I don't remember anybody outside Russia found it crazy. (I am too lazy for VPN and accessed through web.archive.org to the most of the stuff). So, when Russia closes some access it is an attack on the freedom. And when West blocks access from Russia it is protection of the freedom :)

For example, I found about some 'world oldest tree' competition through the news that it banned trees from Russia. Curious enough, I found their site and.... it rejected me by IP.

Typing this from Moscow, over OpenVPN. I have been around the country over the last year and am yet to experience protocol-level blocks (although there are credible reports this happened, just not in my experience). It seems like the current wave is about blocking popular providers. Folks with own server, like myself, are not a target so far.

I'd expect the government to cool down expansive internet censorship until the "elections" in March, since hitting the preapproved outcome figures will be harder this way.

You can use wstunnel to bypass firewall. I had many feedbacks from chinese/turkish/iranian people using it with success. Easy to setup also with static binaries.

https://github.com/erebe/wstunnel/

Maybe it's the right place to advertise Snowflake. It's a browser extension that allows people to bypass Tor censorship if I understood correctly : https://snowflake.torproject.org/
Because of the issues with OpenVPN/Wireguard blocking, a few months ago I completely switched to shadowsocks which I think mostly works. But it looks like https://github.com/amnezia-vpn/amneziawg-go -- is the way to go, which is an obfuscated wireguard.
It's worth mentioning that the Russian government has a plan to completely detach the country from the wider Internet. This system has already been tested and is available at the flick of a switch.

Unfortunately, it's probably a matter of time until this system is activated for real and the Iron Curtain drops to the floor. Then Putin will find some way to blame the West and rally against us.

Try SquareX's disposable browser - works for me in China and is basically Remote Browser Isolation but for consumers. It seems free right now - https://www.sqrx.com
Working around DPI blocks is possible as long as you can get your hands on foreign VPS. Just invent your own protocol and use it for yourself. Wrap it with HTTPS or even HTTP, nobody's has resources to analyse every single website protocol.

However some huge ingress/egress traffic to unknown website with few random pages looks very suspiciously. So it's possible to select those websites using statistics analysis.

Now the question to hackers: how do I hide tunnelled traffic so its statistics does not look suspicious?

Ideally one would use some CDN webserver (like cloudflare or amazon), however without encrypted SNI, host is extractable with DPI.

And here I am writing this post via Wireguard VPN through my home router marking traffic to an outside VPN gate with ease.
I haven't been able to use my OpenVPN server since August 2023. All connections are reset. Surprised someone could still use it. Perhaps it was rolled out on a per-ISP basis.
Might be a case of me being too stupid to use ctrl + f

But its very much worth mentioning that Russia has totalitarian laws that criminalize the use of vpns.

Hello, this project can help you solve some problems, but the problems you have are far more complicated than we imagined, so there may not be a good solution for you.

https://github.com/Useful-open-source-project/Share-vpn-buil...

  OpenVPN/WireGuard, a protocol similar to VPN, has been identified. What we use now is a proxy protocol. It is not probabilistically recognized by VPN protocol operators or firewalls. After all, they can also enter AI to help them improve their firewalls, so we  We also have to find ways to resist or improve our agency agreement so that he is no longer afraid of the firewall.
I had a friend recently visit China and he needed access to the real internet and the VPN providers he had used before were blocked.

It took me all of 10 minutes to set up a OpenVPN server in East Asia on DigitalOcean. The container even comes with a client installer that has the parameters preloaded.

Worked fine.

Most probably related with the revolts started in the Russian republic of Bashkortostan the last week.
Some good news amidst this doom and gloom: I just installed AmneziaVPN (https://amnezia.org) on my VPS and it works great so far -- and pretty fast as well.
Mullvad has a Wireguard obfuscation feature you can enable. Does that work for you?
During the protests in Belarus in 2020, internet was blocked with DPI, and OpenVPN and WireGuard also didn't work. Same situation with Outline. The only too that worked was Psiphon: https://psiphon.ca/ Looks like police in Russia uses DPI as well, so Psiphon might work too.
Ten years ago, I was working for a US post-production company that produced a one-off game show in China. We used OpenVPN to monitor our servers, but it was being blocked. I ended up setting up a new OpenVPN server using obfsproxy, and it worked. It might be worth trying in your situation: https://community.openvpn.net/openvpn/wiki/TrafficObfuscatio...
I want to point out that many sites still work without any VPN, including this site. And not all foreign sites are blocked, but only those included in special lists.
With some luck they end up blocking their own troll farms.
Russians at this point are somewhat accepting the latest shenanigans of Roskomnadzor and in some cases are even somewhat supportive of it ("necessary evil"). So part of why there is not a lot of discussion on the English internet is that not even on the Russian internet there is not a ton of discussion about it.

VPNs stop and continue working on a somewhat regular schedule for a long time at this point.

Bashkiria is heating up with thousands on the streets for two days in a row, plus moscow rolling blackouts just kicked in.
> The prospect of an isolated Russian interweb has become oh so real.

none of the comments below have picked up on this specific thing but Russia has done exercises on exactly this topic. they seem much more prepared to do it / want to appear to be willing to do it than any other large country that isn't already a police state.

Information control is just one part of how totalitarian regimes maintain that control. Western media is full of stories of the Russian "meat grinder" that would probably incense Russians, so it's probably in Putin's best interests to control how many Russians can actually see that.
I wonder how this will affect political discourse in the USA. Legitimate question. I’m not concerned with “sides”, more interested to know if there will be less “division/fiery rhetoric”. There seems to have been a systemic psyops campaign from foreign actors into US political “hot” topics.
As far as I know https://github.com/apernet/hysteria is the latest proxy protocol (used in China). Maybe try this
IKEv2 hasn't worked since last fall (and mine was self-hosted). They keep upgrading the DPI.
For what it's worth I tried NordVPN in China recently and all the servers were blocked. Totally useless. But weirdly, when I connected to the internet over cell data on my phone, there was no blocking at all...
Any hints on how they're doing it and at which layer? DPI at the 7:th layer?
Writing this from Moscow over private OpenVPN instance hosted on Hetzner by a friend of mine. Sometimes it stops working. It's been like that for a couple of years like that.
This thing works perfectly well: https://xtls.github.io/

I provide some server nodes to certain people there.

I highly recommend hans to bypass such shenanigans: https://github.com/friedrich/hans