Rendered at 05:05:42 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
soltanov 16 minutes ago [-]
Fixing the code is only half of incident response. Without an advisory, affected-version range, and downstream notification, users cannot know whether they remain exposed.
usernomdeguerre 1 hours ago [-]
I get the impression that much of Xray's usage is in mainland China, do many other ecosystems use it? If not, why not?
Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected.
But perhaps they cover for usecases one doesn't see outside the gfw.
amritananda 35 minutes ago [-]
You can also use it to get around captive portals where some traffic is still allowed. Some Airline flights where messaging services are free only check the SNI, so setting the Xray domain to whatsapp.com or something similar usually works.
ranger_danger 27 minutes ago [-]
What if ESNI/ECH is being used?
amritananda 4 minutes ago [-]
I'm assuming you'll have to configure your DNS to use the captive portal DNS which would defeat ECH. The only time I was able to get this working as a captive portal bypass I was using a hardcoded remote IP as my Xray host so DNS wasn't an issue.
ranger_danger 41 minutes ago [-]
There are other countries that routinely block traffic like Iran or Russia, but there are also some simple methods that go right past the GFW many times, like VPN traffic that is tunneled through regular TLS, or even just plain SSH.
The "new hotness" is randomizing your TLS fingerprints and masquerading as legitimate web traffic/domains, as well as tunnel/proxy/VPN setups that utilize multiple endpoints at once to spread out the "suspicion" of all your traffic going through a single host all the time.
35 minutes ago [-]
sekisusam 54 minutes ago [-]
[dead]
eriwang915 4 hours ago [-]
Xray-core's pinnedPeerCertSha256 treated an inserted leaf as the pinned cert, and the fix commit never called it a vulnerability.
LoganDark 53 minutes ago [-]
Your LLM left out the clear hypocrisy and the part where the fixed version still had a vulnerability
Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected.
But perhaps they cover for usecases one doesn't see outside the gfw.
The "new hotness" is randomizing your TLS fingerprints and masquerading as legitimate web traffic/domains, as well as tunnel/proxy/VPN setups that utilize multiple endpoints at once to spread out the "suspicion" of all your traffic going through a single host all the time.