frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025

https://gfw.report/blog/gfw_unconditional_rst_20250820/en/
119•kotri•2h ago

Comments

kotri•2h ago
Terrible, this is Internet curfew. It's not uncommon to imagine they'd shutdown Internet across border during any war (like against Taiwan).
hackernewsdhsu•2h ago
That's what's so great about LoRA. Decentralized txt msgs, ultra cheap radios people run at home or wherever. $10-35USD ON AMAZON. Least txts get through.
phantomathkg•1h ago
It won't get you from where you are to China though.
wkat4242•1h ago
No but something like WSPR or FT8 would. Needs a license though.
cedws•1h ago
Can you recommend a guide? I’m interested in trying it out.
Gigachad•53m ago
Look up Meshtastic. It’s kinda fun. Can chat with random people around you. But I don’t think it’s really that useful unless you have a really good spot like an antenna on your roof with no trees or buildings in the way.
eastbound•1h ago
In fact, it’s a common tactic to do something unusual, in a recurrent way, so people aren’t alerted when it happens for real. (When the Mossad stole 7 boats from a French port (that they had fully paid), they prepared a few months in advance by having the pilots start the engines every night at 23:00, pretending they needed it against the cold temperatures. When they day came, they started the engines and left, no-one saw it coming).
vintermann•1h ago
It could also be a test to look for surprising things that break, in case they want to do this permanently at some later point.
woooooo•1h ago
Hanlon's and Occam's razors point to it being a mistake by the GFW operators, imo.

If it's on purpose, I think you have the most likely motivation.

wkat4242•1h ago
Could you bring something like a starlink mini for backup i wonder? Id imagine this would be very worrying being stuck there as a foreigner in such a situation.
methou•1h ago
A friend of mine tried, no signal.
NitpickLawyer•1h ago
If war breaks out, it'll likely be enabled.
andrewinardeer•1h ago
Entirely speculation.
NitpickLawyer•1h ago
Of course it is entirely speculation. But there are previous datapoints you can look at (i.e. iran).
Helmut10001•1h ago
Starlink are very low orbit. Easy to bring down.
Zacharias030•53m ago
how though?
4gotunameagain•51m ago
https://en.wikipedia.org/wiki/2007_Chinese_anti-satellite_mi...

Every major power has polluted near Earth space as a show of power.

cyberax•31m ago
One missile for one satellite? This gets expensive really fast.
therein•26m ago
They follow well defined orbits and propellant limited. You could easily cover their trajectory with some shrapnel and attack it one lane at a time.
perihelions•16m ago
Not feasible. That would entail putting shrapnel into orbit (unlike extant anti-sat weapons which are short-range suborbital), which means a fully orbital launch for every satellite target orbit. There's hundreds[0] of Starlink orbital groups already, so that'd require hundreds of independent orbital launches in a short timescale—far beyond China's launch capabilities today.

[0] https://planet4589.org/space/con/star/planes.html

(On general principles, you could argue you'd need 1:1 launch vehicle parity (number, not payload) to defeat a satellite constellation this way. For each satellite launch, you'd need one corresponding anti-satellite launch into that same, newly-defined orbit).

perihelions•42m ago
Very expensive to take down 10-100k at once. No one today has that many antisat-capable missiles stockpiled.

Relevant, Chinese domestic media reporting on China's own perspective:

https://www.scmp.com/news/china/science/article/3178939/chin... ("China military must be able to destroy Elon Musk’s Starlink satellites if they threaten national security: scientists" (2022))

> "Researchers call for development of anti-satellite capabilities including ability to track, monitor and disable each craft / The Starlink platform with its thousands of satellites is believed to be indestructible"

"Easy to bring down" vs. "believed to be indestructible"—some tension there!

progbits•54m ago
No it won't but if it did would take just few hours for china to shoot a bunch of them down and with how tightly packed their orbits are the debree would take care of the rest.
senectus1•34m ago
potentially very dangerous for everyone if they did that. could make it impossible for even them to make a launch. Kessler Syndrome is nothing to toy with.
audunw•25m ago
I’m not so sure debris would help take down other satellites in that orbit. The orbit is very low so much of the debris that ends up with a deviation in its orbit will fall down. Even if it doesn’t there’s still air resistance up there which may cause more of the debris to deorbit before jt has time to hit other satellites.

And I doubt China would want to make LEO impossible to move through anyway. It’d affect China badly as well

stevage•1h ago
Depends a lot whether Starlink decides to let you.
mryall•32m ago
Starlink connects you to the internet via a ground station in the country where you are registered, and the antenna will also only operate in an approved zone (depending on your country and account type). You cannot use it in China.
preisschild•22m ago
https://www.theverge.com/2022/10/10/23397301/elon-musk-starl...
veunes•36m ago
The infrastructure for that kind of control clearly already exists. What's unclear is how coordinated or deliberate these events are versus being side effects of testing or internal changes
outworlder•32m ago
> Terrible, this is Internet curfew.

If you think this is bad...

You can't even have a blog in China without authorization. It doesn't matter if you pay "AWS" for a machine. It won't open port 80 or 443 until you get an ICP recordal. Which you can only do if you are in China, and get the approval. It should also be displayed in the site, like a license plate. The reason "AWS" is in quotes is because it isn't AWS, they got kicked out. In Beijing, it is actually Sinnet, in Nginxia it's NWCD

You can only point to IPs in China from DNS servers in China - if you try to use, say, Route53 in the US and add an A record there, you'll get a nasty email (fail to comply, and your ports get blocked again, possibly for good).

In a nutshell, they not only can shutdown cross border traffic (and that can happen randomly if the Great Firewall gets annoyed at your packets, and it also gets overloaded during China business hours), but they can easily shutdown any website they want.

UltraSane•20m ago
AWS in China also doesn't have the Key Management Service, which leads to me to conclude it must be pretty secure.

I added an A record for subdomain and pointed it at Chinese IP addresses. I wonder if I will get that angry email?

chickenzzzzu•1h ago
Think of how many people who have remote jobs with American companies couldn't connect to their meetings while they "work from home" while secretly being in China!

Normally they have to fight VPN issues anyway, but having a sovereign state inject your packets is certainly a fun new one.

ChrisMarshallNY•1h ago
I suspect those connections worked fine.

It’s good to know the boss.

chickenzzzzu•1h ago
I definitely appreciate that a percentage of so called "employees" are actually just full fledged Chinese nationals, living permanently in China, paid a salary to pretend to be an American who had their identity stolen.

But there absolutely is also a non-negligible number of Chinese and Indian nationals, who have some type of visa status in the US (especially a green card) who spend many months in their original countries making $200,000 or more per year while living like royalty in their home countries :)

bapak•1h ago
The green card isn't citizenship, you lose it if you don't live in the US. It's not like they don't know when you enter or exit the country.
chickenzzzzu•1h ago
6 months is a very long time.
Wolfbeta•1h ago
2019 feels like 6 months ago.
esseph•1h ago
Feels more like 20 years ago.

So much has happened since then...

buckle8017•57m ago
There is no magic amount of time.

If you get a green card and leave the us for any amount of time, on return the border agent makes a determination on the spot if you intended to live abroad.

Less than six months is simply less suspicious than more.

tietjens•1h ago
How common can this really be? And what kind of companies? I’m finding it really hard to imagine this to be widespread.
Ayesh•1h ago
I live in a popular Digital Nomad friendly country, and myself included, work with Europe/American companies roughly matching their time zones.

Now, the people I work with know that I'm not really located in the same time zone, but I know people who don't bother to mention it. I rarely get phone calls, but I have a roaming connection active for banking/OTP/etc. Plenty of cheap cafes with great WiFi (500mbps+ almost everywhere), and several times cheaper too.

wkat4242•1h ago
Yeah if I'd sneak off to work from another place I'd pick somewhere really nice. Not China.
chickenzzzzu•1h ago
You say that because you don't hold a Chinese or Indian passport. Now think of those who do, who have family obligations, food preferences, local bank accounts.
dbetteridge•1h ago
Have you ever been to China?

Because they have some of the most beautiful scenery and buildings I've seen and I've been to dozens of countries.

Personally I wouldn't go there for remote work, because the internet interference is a pain but a holiday definitely.

djtango•46m ago
China spans 9.6M km. It has some of the biggest and most modern megacities (Beijing, Shanghai, Chongqing, Shenzhen to name a few) and features ancient historical wonders like the Great Wall, Forbidden City and Terracotta Warriors.

The nature spans salt lakes and rainbow mountains akin to South America, to the Northern Lights in Mohe down to karst formations of Guilin shared with Vietnam's Halong Bay.

The cuisine is diverse and dishes popular in places like Xi'an reveal lasting influences dating back to the Silk Road.

If you can't find "somewhere really nice" amongst the myriad people and locations you haven't tried.

chickenzzzzu•1h ago
Sadly much more common than it should be. The durations vary widely, but with the price of airline tickets and the nature of corporate software engineering jobs, it's extremely easy to self-justify a month abroad. The US government allows 6 months officially for green card holders.

If it wasn't literally 10x cheaper to live abroad than it is to live in Seattle/San Jose, it wouldn't be as prevalent. And not to mention, the quality of life is often better at the 10x cheaper price as well.

I can give you as much proof as you would like!

esseph•1h ago
Lookup the North Korean version of this with the laptop farms

Example: https://www.justice.gov/opa/pr/justice-department-announces-...

veunes•34m ago
How many people suddenly "lost internet" mid-meeting and had to blame it on their router...
jart•1h ago
It's kind of disingenuous to call that blocking. Imagine what people would say about Cloudflare if they had an hour long outage.
JumpCrisscross•1h ago
> Imagine what people would say about Cloudflare if they had an hour long outage

That Cloudflare had an outage. Not America.

flohofwoe•36m ago
> That Cloudflare had an outage. Not America.

You probably mean the USA? After all, it was China and not Asia which was responsible for the incident ;)

est•39m ago
outage would mean a connection timeout

in this case, the connection works fine, some extra RST+ACK packets were delivered to your network on purpose

preisschild•19m ago
I mean... it got blocked by their censorship infrastructure, does it really matter if it only got misconfigured?
technics256•49m ago
How would one get around this if they found themselves in such a situation?
est•40m ago
In this exact scenario, just use ports other than :443

But GFW certainly had the capability to block all ports. So no one really knew.

molticrystal•6m ago
Well for starters recreate the situation and test out different approaches. Thanks to the detailed analysis that can be done.

If I understand right, a good next step would would be with eBPF or some type of proxy ignore the forged RST+ACK at the beginning.

Then it would come testing to see if sending a bunch of ACK packets, perhaps with sequence numbers that would when reconstructed could complete the handshake. Trying to send them alongside the SYN+ACK or even before if it can be predicted. Maybe try sending some packets with sequence id 0 as well to see what happens.

neuroelectron•48m ago
They probably had a good reason to do it if they resorted to such extreme measures.
rfoo•44m ago
Pretty sure it's an incident.
veunes•33m ago
But "good reason" depends a lot on your perspective
outworlder•30m ago
There's no good reason to do that.
preisschild•19m ago
Yeah, dont want their citizens to voice anti-CCP thoughts

Building Ultra Cheap Energy Storage for Solar PV

https://austinvernon.substack.com/p/building-ultra-cheap-energy-storage
1•simonebrunozzi•5m ago•0 comments

Why is my device a touchpad and a mouse and a keyboard?

http://who-t.blogspot.com/2025/08/why-is-my-device-touchpad-and-mouse-and.html
1•todsacerdoti•6m ago•0 comments

Accessibility Conformance Testing (Act) Rules Format 1.1

https://www.w3.org/TR/act-rules-format/
1•bryanrasmussen•10m ago•0 comments

Ask HN: Would you use an agent that migrates your stack (with benchmarks)?

https://charter-nlpt.vercel.app/
1•wsoup•13m ago•0 comments

Show HN: Spectre, a coding agent for llama.cpp servers

https://github.com/dinubs/spectre
1•gavino•14m ago•0 comments

Monad Annoyance

https://macwright.com/2025/08/19/monad-annoyance
2•Bogdanp•17m ago•0 comments

If you don't create a successful startup, it's your fault

1•cesargstn•18m ago•0 comments

In AI push, China holds the first sports event for humanoid robots

https://www.nbcnews.com/world/asia/china-holds-worlds-first-sports-event-humanoid-robots-ai-rcna225531
2•go_photon_go•19m ago•0 comments

Qwen-Image-Edit: Image Editing with Higher Quality and Efficiency

https://qwenlm.github.io/blog/qwen-image-edit/
3•vismit2000•20m ago•0 comments

Unknown object explodes in cornfield in eastern Poland

https://www.newsweek.com/nato-ukraine-poland-explosion-2116064
1•maciejw•20m ago•0 comments

The Company Who Created "Play": The Origin of Namco

https://www.gamingalexandria.com/wp/2025/08/the-company-who-created-play-the-origin-of-namco/
1•Michelangelo11•23m ago•0 comments

Show HN: Vibe Coding:I built a website that can use multiple coding AI models

https://vibecoding-ai.net/
1•jumpdong•27m ago•0 comments

Turn Ideas into Audio Books

https://storybook.baby
1•hesongworkmail•34m ago•1 comments

Echidna Enters a New Era of Symbolic Execution

https://gustavo-grieco.github.io/blog/echidna-symexec/
1•galapago•35m ago•0 comments

Show HN: Flags Quiz

https://flags-quiz.com/
1•artiomyak•38m ago•0 comments

Ask HN: How can I use AlarmKit at expo/React Native?

3•tntpreneur•44m ago•0 comments

We built an open benchmark to test GPT-5 "safe completion"

https://bench.raxit.ai/
2•agairola•46m ago•1 comments

When to Open Source

3•abdospices•48m ago•1 comments

Ask HN: How do you get your devs to understand your customers?

3•ghiculescu•53m ago•6 comments

Voice AI in Firms: A Natural Field Experiment on Automated Job Interviews

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5395709
3•JumpCrisscross•53m ago•0 comments

Ask HN: Imagine coding LLM's 1M times faster; what uses might there be?

3•wewewedxfgdf•56m ago•1 comments

OpenAI eyes largest valuation for private company in stock sale talks

https://www.theguardian.com/technology/2025/aug/19/openai-chatgpt-stock-sale-reports
5•andsoitis•1h ago•0 comments

Why scientists are rethinking the immune effects of SARS-CoV-2

https://www.bmj.com/content/390/bmj.r1733
4•atakan_gurkan•1h ago•0 comments

Einstellung Effect

https://en.wikipedia.org/wiki/Einstellung_effect
2•dijksterhuis•1h ago•0 comments

Databricks is raising a Series K Investment at >$100B valuation

https://www.databricks.com/company/newsroom/press-releases/databricks-raising-series-k-investment-100-billion-valuation
17•djhu9•1h ago•12 comments

Ask HN: Why does the US Visa application website do a port-scan of my network?

71•mbix77•1h ago•24 comments

Vibe Coding Is the Worst Idea of 2025 [video]

https://www.youtube.com/watch?v=1A6uPztchXk
27•tomwphillips•1h ago•20 comments

Ban ChatGPT

https://benn.substack.com/p/ban-chatgpt
3•kiyanwang•1h ago•0 comments

Brazil's Financial Stocks Drop on Magnitsky Sanctions Fears

https://www.bloomberg.com/news/articles/2025-08-19/brazil-s-financials-drop-on-fears-over-magnitsky-sanctions-reach
4•matheusmoreira•1h ago•3 comments

KPMG wrote 100-page prompt to build agentic TaxBot

https://www.theregister.com/2025/08/20/kpmg_giant_prompt_tax_agent/
5•ofrzeta•1h ago•5 comments