<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	>
<channel>
	<title>Comments on: The Great Firewall of China: how it works, how to bypass it</title>
	<atom:link href="http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/</link>
	<description>All publication is a political act. All communication is propaganda. All art is pornography. All business is personal. All hail Eris. Vive les poissons rouges sauvages!</description>
	<lastBuildDate>Fri, 19 Mar 2010 11:41:20 +1100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ricecracker</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-31679</link>
		<dc:creator>Ricecracker</dc:creator>
		<pubDate>Wed, 27 Jan 2010 15:45:55 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-31679</guid>
		<description>This is a very old thread, but I feel I ought to tack on more for anyone else who comes along.  Take a penny, leave a penny, etc.  If the GFC was really as monstrous and godlike as everyone thinks, my expat friend and myself would not be able to comment so freely, would we?

Thank you for this information, fellows.  This confirms what I always suspected, but of course, I shall behave in my usual manner all the same.  I love China, and wouldn&#039;t ever want to be a lousy guest.  I don&#039;t think the GFC is anything more than a method to keep an extra billion people from hurting their own selves.  A lot of western criticism would have you believe that the majority of people here are miserable, or should be.  Contrast will do that to a point of view.  What I do think, though, is that the way it is set up right now looks too suspicious, even if it isn&#039;t intended to be.  It&#039;s embarrassingly clunky, but it&#039;s all they have to work with.  The hard-headedness implies the illusion of sophistication.

I couldn&#039;t imagine any entity being able to monitor internet activity of a community 24/7.  Even if there are devices put in place and even if there is a system designed to narrow their monitoring for specific &quot;naughty&quot; behaviour, there are just too many people in China.
It is normally offline activity that gets someone in trouble for something they do online, unless it is something super-serious, or unless you&#039;re completely careless.

Catching the people behind the Google phishing snafu is something everyone can say is impossible, after all.  They&#039;re either super-evasive, or they&#039;re the killers OJ has been looking for for over fifteen years.  I don&#039;t believe this country is directly responsible for that incident, but they are accountable, and they must set things right (I think they know it&#039;s in their best interest to).

&lt;ul&gt;
&lt;li&gt;Proxies get zapped regularly, but they&#039;re like buses.  A new one comes along.  Some suggest that the proxies themselves are gov&#039;t-run, so they can really nail the careless folks, but I sincerely doubt it.  Some suggest that you can get viruses easily through them, and that is something I am illiterate about.  The one I am using gives me a mountain of pop-ups on Firefox, but Chrome stifles them (it does not &quot;block&quot; them in the parlance of making the non-existent).&lt;/li&gt;
&lt;li&gt;YouTube might be banned, but there is a simple method to watching YouTube videos made available.  Type &quot;cn&quot; after you type &quot;www.youtube&quot; and before &quot;.com&quot;.  You cannot log in, you cannot comment (obviously), and you cannot click to continue onto other videos.  You can, however, use the search engine, which opens in a new tab in your browser (Firefox and Chrome, at least).&lt;/li&gt;
&lt;/ul&gt;

I don&#039;t know about the legality of any of these things, mind you.  Chinese law is cryptic to me, and I don&#039;t know if any one local person can offer me sufficient second-hand information.  One can stumble onto some sketchy content here, like in any country, and I wonder if it is only a matter of time if curiosity killed the cat.  Considering my awareness and my self-control, I feel confident.  I imagine accidental stumbling would be as likely dismissed here as it would anywhere else in the world, if it&#039;s ever brought to light in the first place.

I hope this helps, and if I am wrong on anything, I urge you to correct me.  As I said, I am not here to cause a fuss.  I love this country for many reasons; one of them being the incredible harmony for such a large populace.

RC</description>
		<content:encoded><![CDATA[<p>This is a very old thread, but I feel I ought to tack on more for anyone else who comes along.  Take a penny, leave a penny, etc.  If the GFC was really as monstrous and godlike as everyone thinks, my expat friend and myself would not be able to comment so freely, would we?</p>
<p>Thank you for this information, fellows.  This confirms what I always suspected, but of course, I shall behave in my usual manner all the same.  I love China, and wouldn&#8217;t ever want to be a lousy guest.  I don&#8217;t think the GFC is anything more than a method to keep an extra billion people from hurting their own selves.  A lot of western criticism would have you believe that the majority of people here are miserable, or should be.  Contrast will do that to a point of view.  What I do think, though, is that the way it is set up right now looks too suspicious, even if it isn&#8217;t intended to be.  It&#8217;s embarrassingly clunky, but it&#8217;s all they have to work with.  The hard-headedness implies the illusion of sophistication.</p>
<p>I couldn&#8217;t imagine any entity being able to monitor internet activity of a community 24/7.  Even if there are devices put in place and even if there is a system designed to narrow their monitoring for specific &#8220;naughty&#8221; behaviour, there are just too many people in China.<br />
It is normally offline activity that gets someone in trouble for something they do online, unless it is something super-serious, or unless you&#8217;re completely careless.</p>
<p>Catching the people behind the Google phishing snafu is something everyone can say is impossible, after all.  They&#8217;re either super-evasive, or they&#8217;re the killers OJ has been looking for for over fifteen years.  I don&#8217;t believe this country is directly responsible for that incident, but they are accountable, and they must set things right (I think they know it&#8217;s in their best interest to).</p>
<ul>
<li>Proxies get zapped regularly, but they&#8217;re like buses.  A new one comes along.  Some suggest that the proxies themselves are gov&#8217;t-run, so they can really nail the careless folks, but I sincerely doubt it.  Some suggest that you can get viruses easily through them, and that is something I am illiterate about.  The one I am using gives me a mountain of pop-ups on Firefox, but Chrome stifles them (it does not &#8220;block&#8221; them in the parlance of making the non-existent).</li>
<li>YouTube might be banned, but there is a simple method to watching YouTube videos made available.  Type &#8220;cn&#8221; after you type &#8220;www.youtube&#8221; and before &#8220;.com&#8221;.  You cannot log in, you cannot comment (obviously), and you cannot click to continue onto other videos.  You can, however, use the search engine, which opens in a new tab in your browser (Firefox and Chrome, at least).</li>
</ul>
<p>I don&#8217;t know about the legality of any of these things, mind you.  Chinese law is cryptic to me, and I don&#8217;t know if any one local person can offer me sufficient second-hand information.  One can stumble onto some sketchy content here, like in any country, and I wonder if it is only a matter of time if curiosity killed the cat.  Considering my awareness and my self-control, I feel confident.  I imagine accidental stumbling would be as likely dismissed here as it would anywhere else in the world, if it&#8217;s ever brought to light in the first place.</p>
<p>I hope this helps, and if I am wrong on anything, I urge you to correct me.  As I said, I am not here to cause a fuss.  I love this country for many reasons; one of them being the incredible harmony for such a large populace.</p>
<p>RC</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-31463</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Wed, 06 Jan 2010 02:51:24 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-31463</guid>
		<description>Also, I was doing this through a &quot;virtual server&quot; web host that I was renting from www.hub.org&lt;/a&gt;, but as Stil said, any UNIX-based hosting account that allows shell access via SSH should work.</description>
		<content:encoded><![CDATA[<p>Also, I was doing this through a &#8220;virtual server&#8221; web host that I was renting from <a href="http://www.hub.org" >http://www.hub.org</a>, but as Stil said, any UNIX-based hosting account that allows shell access via SSH should work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-31462</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Wed, 06 Jan 2010 01:25:59 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-31462</guid>
		<description>&lt;b&gt;@Stilgherrian&lt;/b&gt; &amp; &lt;b&gt;@stan&lt;/b&gt;: Stil has done a great job of explaining what I was doing, however there&#039;s one more trick that China started using late last year.

They&#039;re now screwing with DNS lookups for some sites, meaning that your web browser won&#039;t be able to get correct IP addresses for the sites you want to visit, even if you are using a SOCKS proxy via SSH tunnel as Stil describes.

A work-around exists in Firefox to send your DNS lookups via your SOCKS proxy (that is set up in the way that Stil describes above). Do this:

&lt;ol&gt;
&lt;li&gt;In the address box, type &lt;b&gt;about:config&lt;/b&gt; and press enter. You&#039;ll get a warning message telling you to be careful. Click proceed (or whatever it says).&lt;/li&gt;
&lt;li&gt;In the &quot;filter&quot; box at the top, type &lt;b&gt;network.proxy.socks_remote_dns&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;Under preference name, you should then see &lt;i&gt;&lt;b&gt;network.proxy.socks_remote_dns&lt;/b&gt;&lt;/i&gt;. It should be set to &lt;b&gt;&lt;i&gt;default, boolean, false&lt;/b&gt;&lt;/i&gt; under the other headers respectively. Double-click it; it should change to &lt;b&gt;&lt;i&gt;user set, boolean, true&lt;/b&gt;&lt;/i&gt;. (If you have an earlier version of Firefox than I do, you might find you get a pop-up box, in this case use the pop-up box to change the value to &quot;true&quot;.)&lt;/li&gt;
&lt;/ol&gt;

After making this change and the change that Stil describes above to your Firefox config, you&#039;ll probably need to restart Firefox for the changes to take effect. 

You&#039;ll find that if you disconnect the SSH session (or it drops by itself, which is common in China) you&#039;ll no longer be able to browse anything. In this case either restart the SSH session; or reverse the configuration changes to Firefox (i.e. remove the SOCKS proxy settings from network settings, and re-set &lt;b&gt;network.proxy.socks_remote_dns&lt;/b&gt; to &lt;b&gt;false&lt;/b&gt; in &lt;b&gt;about:config&lt;/b&gt;.

Have fun ;)</description>
		<content:encoded><![CDATA[<p><b>@Stilgherrian</b> &amp; <b>@stan</b>: Stil has done a great job of explaining what I was doing, however there&#8217;s one more trick that China started using late last year.</p>
<p>They&#8217;re now screwing with DNS lookups for some sites, meaning that your web browser won&#8217;t be able to get correct IP addresses for the sites you want to visit, even if you are using a SOCKS proxy via SSH tunnel as Stil describes.</p>
<p>A work-around exists in Firefox to send your DNS lookups via your SOCKS proxy (that is set up in the way that Stil describes above). Do this:</p>
<ol>
<li>In the address box, type <b>about:config</b> and press enter. You&#8217;ll get a warning message telling you to be careful. Click proceed (or whatever it says).</li>
<li>In the &#8220;filter&#8221; box at the top, type <b>network.proxy.socks_remote_dns</b></li>
<li>Under preference name, you should then see <i><b>network.proxy.socks_remote_dns</b></i>. It should be set to <b><i>default, boolean, false</i></b> under the other headers respectively. Double-click it; it should change to <b><i>user set, boolean, true</i></b>. (If you have an earlier version of Firefox than I do, you might find you get a pop-up box, in this case use the pop-up box to change the value to &#8220;true&#8221;.)</li>
</ol>
<p>After making this change and the change that Stil describes above to your Firefox config, you&#8217;ll probably need to restart Firefox for the changes to take effect. </p>
<p>You&#8217;ll find that if you disconnect the SSH session (or it drops by itself, which is common in China) you&#8217;ll no longer be able to browse anything. In this case either restart the SSH session; or reverse the configuration changes to Firefox (i.e. remove the SOCKS proxy settings from network settings, and re-set <b>network.proxy.socks_remote_dns</b> to <b>false</b> in <b>about:config</b>.</p>
<p>Have fun <img src='http://stilgherrian.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-31460</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Tue, 05 Jan 2010 20:49:46 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-31460</guid>
		<description>&lt;strong&gt;@stan:&lt;/strong&gt; I&#039;m not sure whether Daniel is even in in China any more, as his comment is over a year old.

However the technique he describes requires you having access to a Linux / Unix / OS X server outside China already set up to allow remote access to the command line via an encrypted link. That&#039;s the &quot;SSH&quot; or &quot;secure shell&quot; he describes -- the &quot;shell&quot; being the command line and the &quot;secure&quot; bit being the encryption. If you do not already have this in place, nothing else he refers to will help you.

It&#039;s possible to purchase an appropriate account on a shared server for a few dollars a month. It&#039;s offered by most hosting companies, and the thing to ask is whether their accounts have &quot;shell access&quot;.

The rest of the procedure has two parts, which are about setting up what&#039;s called a &quot;SOCKS proxy&quot; to forward all your web requests to that remote server, which then passes them on to the website you&#039;re trying to visit.

&lt;ol&gt;
&lt;li&gt;Open a Terminal window on your Mac. You&#039;ll find Terminal under &quot;Applications&quot; then &quot;Utilities&quot;. Choose a random number above 1024, say 9999. You&#039;ll also need to know the address of your remote server and your username and password. Type the command &lt;code&gt;ssh -ND 9999 username@yourremoteserver.com&lt;/code&gt; where &lt;code&gt;yourremoteserver.com&lt;/code&gt; is the address of the server, and log in with your password on that server. You won&#039;t see anything, but this creates an encrypted tunnel between port 9999 on your Mac and the remote computer. It lasts until you press &lt;code&gt;control-C&lt;/code&gt; in the Terminal window to stop it, or the tunnel breaks for some reason.&lt;/li&gt;
&lt;li&gt;In your web browser&#039;s network settings, tell it to use a SOCKS proxy using the SOCKS server &lt;code&gt;localhost&lt;/code&gt; and port &lt;code&gt;9999&lt;/code&gt;. This tells the web browser to push all requests down that encrypted tunnel. Done.&lt;/li&gt;
&lt;/ol&gt;

As Daniel notes, this will make &lt;em&gt;all&lt;/em&gt; your web browsing slow as every web page is being requested via your remote server outside China. He therefore has a trick with that PAC file so only certain websites go through the SOCKS proxy. I&#039;ve no idea how that is set up, though, as that&#039;s even more advanced systems administration.

If all of this is new language, well, this is how professional systems administrators and network engineers build things. There is a &lt;em&gt;vast&lt;/em&gt; amount of material on these tools online if you search for their names.

There are downloadable commercial tools like HotSpotShield, but if that&#039;s stopped working then either you may just need to download a new version -- or maybe China has simply blocked access to HotSpotShield&#039;s servers since they&#039;re now so well known.</description>
		<content:encoded><![CDATA[<p><strong>@stan:</strong> I&#8217;m not sure whether Daniel is even in in China any more, as his comment is over a year old.</p>
<p>However the technique he describes requires you having access to a Linux / Unix / OS X server outside China already set up to allow remote access to the command line via an encrypted link. That&#8217;s the &#8220;SSH&#8221; or &#8220;secure shell&#8221; he describes &#8212; the &#8220;shell&#8221; being the command line and the &#8220;secure&#8221; bit being the encryption. If you do not already have this in place, nothing else he refers to will help you.</p>
<p>It&#8217;s possible to purchase an appropriate account on a shared server for a few dollars a month. It&#8217;s offered by most hosting companies, and the thing to ask is whether their accounts have &#8220;shell access&#8221;.</p>
<p>The rest of the procedure has two parts, which are about setting up what&#8217;s called a &#8220;SOCKS proxy&#8221; to forward all your web requests to that remote server, which then passes them on to the website you&#8217;re trying to visit.</p>
<ol>
<li>Open a Terminal window on your Mac. You&#8217;ll find Terminal under &#8220;Applications&#8221; then &#8220;Utilities&#8221;. Choose a random number above 1024, say 9999. You&#8217;ll also need to know the address of your remote server and your username and password. Type the command <code>ssh -ND 9999 <a href="mailto:username@yourremoteserver.com">username@yourremoteserver.com</a></code> where <code>yourremoteserver.com</code> is the address of the server, and log in with your password on that server. You won&#8217;t see anything, but this creates an encrypted tunnel between port 9999 on your Mac and the remote computer. It lasts until you press <code>control-C</code> in the Terminal window to stop it, or the tunnel breaks for some reason.</li>
<li>In your web browser&#8217;s network settings, tell it to use a SOCKS proxy using the SOCKS server <code>localhost</code> and port <code>9999</code>. This tells the web browser to push all requests down that encrypted tunnel. Done.</li>
</ol>
<p>As Daniel notes, this will make <em>all</em> your web browsing slow as every web page is being requested via your remote server outside China. He therefore has a trick with that PAC file so only certain websites go through the SOCKS proxy. I&#8217;ve no idea how that is set up, though, as that&#8217;s even more advanced systems administration.</p>
<p>If all of this is new language, well, this is how professional systems administrators and network engineers build things. There is a <em>vast</em> amount of material on these tools online if you search for their names.</p>
<p>There are downloadable commercial tools like HotSpotShield, but if that&#8217;s stopped working then either you may just need to download a new version &#8212; or maybe China has simply blocked access to HotSpotShield&#8217;s servers since they&#8217;re now so well known.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stan</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-31453</link>
		<dc:creator>stan</dc:creator>
		<pubDate>Tue, 05 Jan 2010 09:09:31 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-31453</guid>
		<description>Almighty Daniel,

As a fellow Beijinger (going 18 years now) and sufferer of not being able to connect to facebook I beg you for help. I am a computer moron, I just bought my first Mac, and my HotSpotShield doesn&#039;t work anymore. From your post I get that you dont have the same problems but the rest is rocket science to me. Please can you explain in simple english what the hell are you doing to get out from behind the wall!!!

Cheers, 
Stan</description>
		<content:encoded><![CDATA[<p>Almighty Daniel,</p>
<p>As a fellow Beijinger (going 18 years now) and sufferer of not being able to connect to facebook I beg you for help. I am a computer moron, I just bought my first Mac, and my HotSpotShield doesn&#8217;t work anymore. From your post I get that you dont have the same problems but the rest is rocket science to me. Please can you explain in simple english what the hell are you doing to get out from behind the wall!!!</p>
<p>Cheers,<br />
Stan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-19636</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Sun, 10 May 2009 21:55:06 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-19636</guid>
		<description>&lt;strong&gt;@Chris:&lt;/strong&gt; Even though you didn&#039;t leave a valid email address, I&#039;ll let your comment through and even link to &lt;a href=&quot;http://www.freedur.com/&quot;&gt;Freedur&lt;/a&gt; because it&#039;s further demonstration that there are &lt;em&gt;plenty&lt;/em&gt; of ways to get around simplistic firewalls.

However I will mention that a third-party system like this also gives that third party the potential to monitor all of your Internet traffic, so choose carefully!</description>
		<content:encoded><![CDATA[<p><strong>@Chris:</strong> Even though you didn&#8217;t leave a valid email address, I&#8217;ll let your comment through and even link to <a href="http://www.freedur.com/">Freedur</a> because it&#8217;s further demonstration that there are <em>plenty</em> of ways to get around simplistic firewalls.</p>
<p>However I will mention that a third-party system like this also gives that third party the potential to monitor all of your Internet traffic, so choose carefully!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-19620</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 10 May 2009 06:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-19620</guid>
		<description>Try &lt;a href=&quot;http://www.freedur.com/&quot;&gt;freedur.com&lt;/a&gt;, it&#039;s the easiest solution around.</description>
		<content:encoded><![CDATA[<p>Try <a href="http://www.freedur.com/">freedur.com</a>, it&#8217;s the easiest solution around.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: the great firewall &#171; Get Shouty</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13672</link>
		<dc:creator>the great firewall &#171; Get Shouty</dc:creator>
		<pubDate>Tue, 05 Aug 2008 09:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13672</guid>
		<description>[...] The Great Firewall of China: how it works, how to bypass it      No Comments so far  Leave a comment   RSS feed for comments on this post. TrackBack URI    Leave a comment Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: &lt;a href=&quot;&quot; title=&quot;&quot;&gt; &lt;abbr title=&quot;&quot;&gt; &lt;acronym title=&quot;&quot;&gt; &lt;b&gt; &lt;blockquote cite=&quot;&quot;&gt; &lt;cite&gt; &lt;code&gt; &lt;del datetime=&quot;&quot;&gt; &lt;em&gt; &lt;i&gt; &lt;q cite=&quot;&quot;&gt; &lt;strike&gt; &lt;strong&gt; [...]</description>
		<content:encoded><![CDATA[<p>[...] The Great Firewall of China: how it works, how to bypass it      No Comments so far  Leave a comment   RSS feed for comments on this post. TrackBack URI    Leave a comment Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: &lt;a href=&quot;&quot; title=&quot;&quot;&gt; &lt;abbr title=&quot;&quot;&gt; &lt;acronym title=&quot;&quot;&gt; &lt;b&gt; &lt;blockquote cite=&quot;&quot;&gt; &lt;cite&gt; &lt;code&gt; &lt;del datetime=&quot;&quot;&gt; &lt;em&gt; &lt;i&gt; &lt;q cite=&quot;&quot;&gt; &lt;strike&gt; &lt;strong&gt; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: China US Relations. Fair And Balanced. &#124; Business88</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13668</link>
		<dc:creator>China US Relations. Fair And Balanced. &#124; Business88</dc:creator>
		<pubDate>Mon, 04 Aug 2008 10:29:45 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13668</guid>
		<description>[...] [Note: The changes to the words in the quote above were made by this blog and were not a part of the original article. I made those changes to avoid becoming a victim of China&#8217;s GFW. [...]</description>
		<content:encoded><![CDATA[<p>[...] [Note: The changes to the words in the quote above were made by this blog and were not a part of the original article. I made those changes to avoid becoming a victim of China&#8217;s GFW. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: China Law Blog</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13665</link>
		<dc:creator>China Law Blog</dc:creator>
		<pubDate>Mon, 04 Aug 2008 05:43:34 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13665</guid>
		<description>&lt;strong&gt;China US Relations.  Fair And Balanced....&lt;/strong&gt;

Howard French of the New York Times just came out with an exceedingly thoughtful and balanced piece on the progression of rights in China, entitled, &quot;Despite Flaws, Rights in China Have Expanded.&quot; The content of the article tracks the title and it is...</description>
		<content:encoded><![CDATA[<p><strong>China US Relations.  Fair And Balanced&#8230;.</strong></p>
<p>Howard French of the New York Times just came out with an exceedingly thoughtful and balanced piece on the progression of rights in China, entitled, &#8220;Despite Flaws, Rights in China Have Expanded.&#8221; The content of the article tracks the title and it is&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13657</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Sat, 02 Aug 2008 22:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13657</guid>
		<description>I&#039;ve edited Daniel&#039;s comment to link to his .PAC file as a separate download.

Also, a friend sent me another, different list of what&#039;s blocked in China, this time from &lt;a href=&quot;http://chinadigitaltimes.net/2004/08/the-words-you-never-see-in-chinese-cyberspace/&quot;&gt;&lt;em&gt;China Digital Times&lt;/em&gt;&lt;/a&gt;. Thanks, Stu.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve edited Daniel&#8217;s comment to link to his .PAC file as a separate download.</p>
<p>Also, a friend sent me another, different list of what&#8217;s blocked in China, this time from <a href="http://chinadigitaltimes.net/2004/08/the-words-you-never-see-in-chinese-cyberspace/"><em>China Digital Times</em></a>. Thanks, Stu.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13650</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Fri, 01 Aug 2008 13:54:11 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13650</guid>
		<description>&lt;strong&gt;@Daniel:&lt;/strong&gt; You walk as a God amongst Men. The formatting of your comment goes astray thanks to WordPress&#039; over-smartness, will fix tomorrow. That is very valuable information, thank you.</description>
		<content:encoded><![CDATA[<p><strong>@Daniel:</strong> You walk as a God amongst Men. The formatting of your comment goes astray thanks to WordPress&#8217; over-smartness, will fix tomorrow. That is very valuable information, thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13649</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Fri, 01 Aug 2008 12:43:47 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13649</guid>
		<description>Hi Stil!

I&#039;m writing from Beijing, and as you may know I&#039;ve been here for 6 months studying Mandarin Chinese, and I&#039;ll be here for about another year.

The internet filter is a very interesting and variable thing to observe! My personal method of bypassing is to run an SSH connection to a shell server overseas, and establish a SOCKS proxy over the SSH connection. It&#039;s very easy to do, the standard ssh client has this capability built in. I have set up keyfile authentication for my SSH session, so all I need to do is click one icon to bring up my SSH session and SOCKS tunnel. And from there all I need to do is set my application/s to use the SOCKS proxy. On my Mac it is very easy to do so, as there is a central preference setting for proxies.

I soon found this a bit too slow for all my connections, however, so I wrote a Proxy Auto-Configuration File (.PAC) file which sends connections to only certain URLs via the SOCKS tunnel, and sends the rest direct. If the SOCKS tunnel is unavailable, it attempts to go direct.

In case anyone is interested, here is &lt;a href=&quot;http://stilgherrian.com/wp-content/uploads/2008/08/daniel.pac&quot;&gt;my current PAC file&lt;/a&gt;.

I have had no problem reading your article and accessing those links, I even downloaded RSF&#039;s little &quot;Blogger&#039;s Handbook&quot; without incident. 

I think some of the most interesting things that you raise are the elements of the system that encourage &quot;self-censorship&quot; as well as simple shifts in behaviour. For example, the seemingly random nature of some blocking does give the impression that someone is watching. I can talk for 30 minutes on MSN with a friend and mention topics like Tibet and Xinjiang / Urumqi etc, but then inexplicably, the connection might stop working... was it because I said something I shouldn&#039;t have? And you think to yourself... well, to avoid the hassle next time, I&#039;ll just talk about something else.

Access to most overseas sites is very very slow here. I supposedly have a 512KB cable (ethernet) connection here, but accessing anything overseas is like dial-up speed. You eventually think &quot;why bother waiting?&quot; and look at more local content instead. This is probably particularly so if you&#039;re Chinese, and you find it a whole lot easier to read Chinese than English (even if you&#039;ve studied it). A good case is Google - the overseas editions of Google are painfully slow to access (even though Google use Akamai, so they should be well optimised), so even when searching in English I&#039;ll often prefer to use Google&#039;s local site, which has been censored.

You do have to wonder how much the slow overseas access is due to congested links, and how much is on purpose. It certainly has an effect on behaviour.

The practice of impairing your access for a short time after you do something &quot;naughty&quot; also encourages self censorship. For example, occasionally the BBC Chinese website is accessible through the firewall, and I can read a couple of articles. But if I happen to click on one of the articles that has some &quot;controvertial&quot; content, then my whole access to the entire site (including the English language pages) is gone for a while. It seems easier to avoid the trouble and just click on some less-controvertial article.</description>
		<content:encoded><![CDATA[<p>Hi Stil!</p>
<p>I&#8217;m writing from Beijing, and as you may know I&#8217;ve been here for 6 months studying Mandarin Chinese, and I&#8217;ll be here for about another year.</p>
<p>The internet filter is a very interesting and variable thing to observe! My personal method of bypassing is to run an SSH connection to a shell server overseas, and establish a SOCKS proxy over the SSH connection. It&#8217;s very easy to do, the standard ssh client has this capability built in. I have set up keyfile authentication for my SSH session, so all I need to do is click one icon to bring up my SSH session and SOCKS tunnel. And from there all I need to do is set my application/s to use the SOCKS proxy. On my Mac it is very easy to do so, as there is a central preference setting for proxies.</p>
<p>I soon found this a bit too slow for all my connections, however, so I wrote a Proxy Auto-Configuration File (.PAC) file which sends connections to only certain URLs via the SOCKS tunnel, and sends the rest direct. If the SOCKS tunnel is unavailable, it attempts to go direct.</p>
<p>In case anyone is interested, here is <a href="http://stilgherrian.com/wp-content/uploads/2008/08/daniel.pac">my current PAC file</a>.</p>
<p>I have had no problem reading your article and accessing those links, I even downloaded RSF&#8217;s little &#8220;Blogger&#8217;s Handbook&#8221; without incident. </p>
<p>I think some of the most interesting things that you raise are the elements of the system that encourage &#8220;self-censorship&#8221; as well as simple shifts in behaviour. For example, the seemingly random nature of some blocking does give the impression that someone is watching. I can talk for 30 minutes on MSN with a friend and mention topics like Tibet and Xinjiang / Urumqi etc, but then inexplicably, the connection might stop working&#8230; was it because I said something I shouldn&#8217;t have? And you think to yourself&#8230; well, to avoid the hassle next time, I&#8217;ll just talk about something else.</p>
<p>Access to most overseas sites is very very slow here. I supposedly have a 512KB cable (ethernet) connection here, but accessing anything overseas is like dial-up speed. You eventually think &#8220;why bother waiting?&#8221; and look at more local content instead. This is probably particularly so if you&#8217;re Chinese, and you find it a whole lot easier to read Chinese than English (even if you&#8217;ve studied it). A good case is Google &#8211; the overseas editions of Google are painfully slow to access (even though Google use Akamai, so they should be well optimised), so even when searching in English I&#8217;ll often prefer to use Google&#8217;s local site, which has been censored.</p>
<p>You do have to wonder how much the slow overseas access is due to congested links, and how much is on purpose. It certainly has an effect on behaviour.</p>
<p>The practice of impairing your access for a short time after you do something &#8220;naughty&#8221; also encourages self censorship. For example, occasionally the BBC Chinese website is accessible through the firewall, and I can read a couple of articles. But if I happen to click on one of the articles that has some &#8220;controvertial&#8221; content, then my whole access to the entire site (including the English language pages) is gone for a while. It seems easier to avoid the trouble and just click on some less-controvertial article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yewenyi</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13648</link>
		<dc:creator>yewenyi</dc:creator>
		<pubDate>Fri, 01 Aug 2008 11:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13648</guid>
		<description>I was at a Cisco conference recently and saw a feature being touted and thought, I&#039;d bet they developed that in conjunction with the Chinese government for the Chinese government.</description>
		<content:encoded><![CDATA[<p>I was at a Cisco conference recently and saw a feature being touted and thought, I&#8217;d bet they developed that in conjunction with the Chinese government for the Chinese government.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://stilgherrian.com/politics/the-great-firewall-of-china-how-it-works-how-to-bypass-it/#comment-13638</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Fri, 01 Aug 2008 03:06:33 +0000</pubDate>
		<guid isPermaLink="false">http://stilgherrian.com/?p=1798#comment-13638</guid>
		<description>&lt;strong&gt;@Neerav:&lt;/strong&gt; It&#039;s no secret that &lt;em&gt;Crikey&lt;/em&gt; doesn&#039;t exactly pay top rates, so it&#039;s difficult for them to insist on exclusivity forever. To tell the truth, we&#039;ve never spoken about it properly. However I always leave a day or more before re-posting, and they do get the occasional free story and other support.</description>
		<content:encoded><![CDATA[<p><strong>@Neerav:</strong> It&#8217;s no secret that <em>Crikey</em> doesn&#8217;t exactly pay top rates, so it&#8217;s difficult for them to insist on exclusivity forever. To tell the truth, we&#8217;ve never spoken about it properly. However I always leave a day or more before re-posting, and they do get the occasional free story and other support.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
