15:57:46 #startmeeting tor anti-censorship meeting 15:57:46 Meeting started Thu Sep 7 15:57:46 2023 UTC. The chair is meskio. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:57:46 Useful Commands: #action #agreed #help #info #idea #link #topic. 15:57:52 hello everyone!!! 15:57:55 hi 15:57:56 here is our meeting pad: https://pad.riseup.net/p/tor-anti-censorship-keep 15:58:06 hihi o/ 15:58:14 feel free to add what you've been working on and put items on the agenda 15:59:10 we can wait few minutes for people to fill up what they being working on 15:59:58 Hi~ 16:00:41 the first topic is 'No webtunnel and conjure options at https://metrics.torproject.org/userstats-bridge-transport.html ' 16:00:50 I think that was already last week, but I missed it 16:01:26 is it already talked? did someone opened an issue on the metrics repo about it? 16:01:33 there's an open issue at https://gitlab.torproject.org/tpo/network-health/metrics/website/-/issues/40092#note_2935782 16:02:13 nice 16:02:39 then I guess we can move to the next topic, or is there something to discuss? 16:03:13 Upgrading Go toolchain for snowflake 16:03:17 shelikhoo: ??? 16:03:38 yes! that's me 16:04:13 so, right now snowflake's more recent version of dependencies requires a more recent version of go language toolchain 16:04:34 however, these more recent version of go tool chain is not supported by debian 16:04:57 (but support by tor's rbm/tor browser build system) 16:04:58 so 16:05:18 what version is the needed one? 16:05:34 if we upgrade go language tool chain version, then debian package support will break 16:06:15 https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/merge_requests/162 16:06:19 maybe 1.21 16:06:31 as indicated by some module 16:07:05 utls requires 1.20+ https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/merge_requests/164 16:07:54 mmm, keeping up with uTLS might be important to avoid being blocked... 16:08:04 there are many other breaks for other dependencies 16:09:03 there are about 5 broken dependencies updates from bot 16:09:04 @meskio it's developed already... t should be released this week or early next week 16:09:16 I think debian support should not be a blocker, I see it as it might be harder for people to contribute to if we need the latest version of go 16:09:21 hiro: nice, thank you 16:10:11 meskio: I don't think it is going to be that huge an issue, as it is not hard for developers in typical environment to update their build toolchain 16:10:21 cohosh, dcf1: do you have opinions here? 16:10:39 i was most worried about the debian packaging 16:10:50 if that's not an issue i think we should keep our dependencies up to date 16:11:05 yes, it will make harder to make a package for backports 16:11:11 but I'm not sure how many people use those 16:11:19 it's unfortunate we're being forced to abandon versions of go that are still supported 16:11:54 but i'm more worried about creating more headache later in the case of security vulnerabilities 16:13:42 I hear most voices saying 'let's update'... 16:13:42 yes, if should be less an issue if we have snowflake in let's say apt.torproject.org 16:14:24 I agree, we should get it the package there, and I'll try to figure out it 16:14:38 I think we should update now, and give priority to have snowflake into apt.torproject.orf 16:14:47 or something similar 16:14:55 +1 16:15:21 anything more on this topic? 16:15:51 EOF 16:15:56 release new snowflake version 16:16:09 yes, it is from me 16:16:51 so right now the support for android is broken for android API 30+ 16:17:08 and based on my testing, it is not related to package's targeted version 16:17:27 so we will need to release a new version of snowflake to fix that 16:17:29 cohosh: I see you have been generating Changelogs for past snowflake releases, Would you mind sharing it with me? 16:17:29 Would you mind sharing the command to generate it with me? 16:18:08 this issue will be fixed when we release a new version with workaround in it 16:18:24 oh I just write them manually 16:18:59 dcf: you have an merge request ready to be merged. Do you mind I merge it on your behalf? 16:18:59 https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/merge_requests/154 16:19:16 I am planning to revise !154 16:19:38 okay, I will go ahead and release new version of snowflake without this merge request 16:19:50 it can be included in new release 16:19:55 is that okay? 16:20:01 it's for the bridge anyway, it doesn't make a difference for clients really 16:20:36 cohosh: okay... I will try to write it myself... it will be in a slightly different format 16:20:48 dcf1: yes, it won't matter for client 16:20:59 okay, I think that all I have for this topic 16:21:02 EOF 16:21:14 great, thanks for making the release 16:21:26 snowflake-02 outage https://lists.torproject.org/pipermail/anti-censorship-team/2023-September/000311.html 16:21:52 I just found the cause of the outage, a whole university campus was disconnected for a few days 16:22:21 The timing matches up with the increase in client polls talked about on the mailing list, so I'm pretty sure that was the cause 16:22:22 oh, yikes! 16:22:40 wow 16:22:48 oooh! that is a hard problem to solve 16:23:18 that's all on that 16:23:38 woah 16:24:22 in the interesting links it seems to be a discussion point: 16:24:25 Firefox planning to ship ECH by default. Think about resurrecting meek-esni? 16:24:30 yes! ECH! 16:24:40 https://github.com/net4people/bbs/issues/280 16:24:42 https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/meek/-/issues/28168 16:24:53 yes, back when ESNI was under development, I made a version of meek (using the Firefox helper) that could use ESNI 16:25:21 I think it is too early for us to do anything, as otherwise ech will be blocked before it gain popularity 16:25:26 we could of course do the same thing with ECH, when it's judged that it's prudent to start trying that 16:25:54 I agree with shelikhoo, but we should keep it in mind to do it at some point 16:25:58 what I'm not sure is when 16:26:05 https://here.news/post/1b17e6fe-b45c-465f-a416-c8fac066bf37/%E4%B8%AD%E5%9B%BDgfw%E5%B0%81%E9%94%81%E4%BA%86cloudflare%E7%9A%841-1-1-1-%E5%92%8Cwarp%E5%AE%98%E7%BD%91%E7%9A%84https (Chinese) 16:26:06 I guess we should keep an eye to the adoption 16:26:17 actually the block have already started 16:26:30 ECH requires the usage of DNS over HTTPS 16:26:49 and china is starting to block DoH providers like cloudflare 16:26:57 ohhh :( 16:27:30 I don't think it's "starting" really, my impression was that lots of DoH was already blocked in China and had been for a long time 16:27:31 we could always do the same the browser do of trying ECH and fallback to non-ECH if it fails 16:28:01 There's the recent BBS thread claiming that blocking of 1.1.1.1 is new, but I'm not so sure it's really new. I'm not familiar with the telegram channel they got their information from. 16:28:42 1.1.1.1 is one of the DoH server that is often used by browser 16:28:58 while others are used by dns resolver 16:29:05 Also, side note, there may be good alternatives to using the Firefox helper for ECH. I learned of this project: https://github.com/SagerNet/sing-box which uses ECH via https://github.com/sagernet/cloudflare-tls which is forked from some Cloudflare TLS repository. 16:29:23 I don't think 1.1.1.1 per se is actually used by browsers. 16:29:59 Firefox uses, I think, mozilla.cloudflare-dns.com. It's the same service as 1.1.1.1 but different IP address (I believe) and obviously different SNI. 16:30:30 Anyway, there are other reasons to block 1.1.1.1 other than attacking ECH, it's also used by the Cloudflare WARP tunnel service. 16:31:20 (Which incidentally is problematic for circumvention, because as I understand it, Cloudflare will try to exit you from another place in your own country, if they have egress nodes there.) 16:31:29 WARP, that is. 16:32:32 I think in WRAP's case, cloudflare don't have any datacenter in china 16:32:34 This is the thread we're talking about btw. I'm not fully caught up on it. https://github.com/net4people/bbs/issues/280#issuecomment-1706267069 16:33:05 (for oridinary users) 16:33:25 shelikhoo: yes, that is my impression too, in China WARP works more like a proxy that gets you out of the country. 16:34:47 yes... 16:36:06 EOF from me 16:36:13 ok, so I read that we should do ECH at some point in meek (and I would say as signaling channel for snowflake/moat too), but not yet 16:36:28 yes, not yet, just know that it's a possibility 16:36:54 +1 16:37:35 moving on, there is an update of the daily operations of snowflake-01: https://opencollective.com/censorship-circumvention/projects/snowflake-daily-operations/updates/2023-august-update 16:38:18 and I think this is all in our agenda, any last topics to discuss? 16:39:19 then, I will close the meeting 16:39:24 #endmeeting