frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Geedge and MESA leak: Analyzing the great firewall’s largest document leak

https://gfw.report/blog/geedge_and_mesa_leak/en/
85•yourapostasy•14h ago
https://www.tomshardware.com/tech-industry/chinas-great-fire...

https://x.com/gfw_report/status/1966669581302309018

Comments

miohtama•12h ago
Some analysis and discussion here:

https://github.com/net4people/bbs/issues/519

> After its founding in 2018, one of Geedge's first clients was the government of Kazakhstan, to whom the company sold its flagship Tiangou Secure Gateway (TSG), which provides functions similar to China's own Great Firewall, monitoring and filtering all web traffic that passes through it, as well as attempts to bypass such censorship.

> The same tool has been rolled out in Ethiopia and Myanmar, where it has been instrumental in enabling that country's military junta to enforce a ban on VPNs. In many cases, Geedge works with other private companies, including internet service providers (ISPs) such as Safaricom in Ethiopia, or Frontiir and Ooredoo in Myanmar, to enact government censorship, the documents show. No ISPs that have partnered with Geedge responded to a request for comment.

> The leaks show employees at the company working to reverse-engineer many popular tools and find means of blocking them. One set of documents lists nine commercial VPNs as "resolved," and provides various means of identifying and filtering traffic to them. Similar capabilities have long been demonstrated by the Great Firewall, with most commercial VPNs inaccessible from within China and many dedicated anti-censorship tools also hard to access.

> At least one Jira support ticket shows evidence of plaintext capture of email

FridayoLeary•5h ago
My first thought was unfortunately whether the UK and other Western nations would copy this to build their own Firewalls. To be honest i still don't think it's a goal anyone is actively working towards and that's a bit of an hyperbolic take. But the truth is that we are moving more towards such a system then we are moving away.

My second thought is how badly Chinese communism must be doing that they need such a massive effort in order to prevent their citizens from accessing information and voicing dissent. We are lucky to be living in such a free society. Internet seems to be losing the battle against government interference and censorship and that is more of a bad thing then a good thing.

supriyo-biswas•1h ago
> My first thought was unfortunately whether the UK and other Western nations would copy this to build their own Firewalls

Various western networking companies already sell such products to authoritarian regimes, such as Nokia[1], Blue Coat Systems[2] and Siemens[3]. China, for reasons that are well documented elsewhere, has always wanted to build it with "their tech", the only thing that's new to me is their export of such tech to Chinese-allied nations.

> My second thought is how badly Chinese communism must be doing that they need such a massive effort in order to prevent their citizens from accessing information and voicing dissent.

This is a very controversial opinion, but the overton window has shifted in this respect and many people often like censorship/DPI when done for "altruistic reasons", and it was sad to see Europeans (presumably) asking for blocking of social media sites since Nepal[4] had done the same, disregarding the second-order effects it would have.

Of course, we live in interesting times, with a major western world power embracing economic policies that prioritize government ownership of industries[5], which is typically closer to communism than anything we've seen in the past :)

[1] https://www.wired.com/2011/08/nokia-siemens-spy-systems

[2] https://www.bis.doc.gov/index.php/about-bis/102-about-bis/ne...

[3] https://www.spiegel.de/international/business/ard-reports-si...

[4] https://news.ycombinator.com/item?id=45137363

[5] https://www.intc.com/news-events/press-releases/detail/1748/...

jychang•1h ago
> My second thought is how badly Chinese communism must be doing that they need such a massive effort in order to prevent their citizens from accessing information and voicing dissent.

Well, OpenAI and other companies training AI models have shown that the architecture of the model matters less than the quality of data fed into it. Same applies for humans.

I understand that the Great Firewall is mostly about censoring dissent, but it's also to keep Chinese citizens away from junk food media sources. The type of videos you see on Douyin vs Tiktok is a great example of the difference.

Yes, the videos on Douyin are politically censored, but they're also a lot less brainrot than Tiktok videos. The Tiktok algo is optimized for ad impressions and profit, whereas the Douyin algo is more tuned to some nebulous concept of Confucian social harmony, for better or worse.

A more nuanced take is that I don't think it's useful to measure Chinese govt behavior just mapped to "amount of suppressing political dissent". I actually think the level of censorship is above the level required for that. It's more useful to recognize that "suppressing political dissent" is actually a subset of Confucian "promote social harmony"- which is not strongly valued in the USA but is at least important enough to be paid lip service in China- and I suspect a big chunk of educated members of government may truly believe in that ideal. It explains behaviors like "why the Douyin algo is so different from Tiktok" and other overreaches of the Chinese govt, because it's not solely about suppressing dissent.

physicsguy•1h ago
I listened to a British politics podcast the other day called Not Another One and they were discussing that among western governments there is some looking at the UK’s porn block because in general politicians think that things have gone too far in children being able to access to extreme content, and that if 20 years ago it had been suggested this had been where we’d be, it wouldn’t have been seen as acceptable. They used the example that if you want to publish a very explicit book in the U.K., the Obscene Publications Acts would put limits on you doing so, but putting it online would be allowed
bboygravity•31m ago
Ah, the good old "think of the children" argument. Does anyone buy that?
userbinator•1h ago
would copy this to build their own Firewalls.

Just about every company already uses some form of this on their network, especially those in highly regulated sectors like banking and other finance-related industries.

More usefully and perhaps "on the other side", I have a proxy on my network to block and modify requests for ads and other content I want to "censor".

nromiun•1h ago
There is a big difference between a firewall on a private network and another on an entire country's traffic.
feverzsj•48m ago
The original GFW was literally built by Cisco. The west already has the technology. They only need an excuse to deploy it.

China relies heavily on export, so they can't just block everything. There are tons of proxy services to bypass GFW in China, and most of them have government background.

xyzzy123•36m ago
As I understand it the idea is not necessarily to stop all dissent / awareness, but that it's useful to be able to slow the spread of "rumours" / incendiary information when it is spreading virally. This gives authorities time to come up with a response if required.

While I personally wouldn't want to live in a country which does this, the flip side of unrestricted virality in countries that culturally might not be prepared for it are events like https://en.wikipedia.org/wiki/Indian_WhatsApp_lynchings

Given that the US controls much of what happens on the Internet, another issue for many countries (not China so much) is that without controls they become extremely vulnerable to US influence campaigns and "colour revolutions".

I predict that all countries will end up with something like the GFW eventually because there's basically no other way for governments to achieve "Internet sovereignty" (enforce laws regarding users and publishers on the web). The US might be last to do this because it is in the doubly privileged position of a) being able to exert significant pressure on other countries and b) being able to apply regulation to major US-based Internet companies using their own legal system.

ipnon•15m ago
The apparatus we call GFW is really a Chinese CDC for memes. The CDC expects novel strains of bird flu every year, it’s okay, they closely monitor the situation, research the novel strains, cull risky populations, and develop vaccines for worst case scenarios. GFW expects novel strains of anti-CCP viral memes every year, it’s okay, they closely monitor the situation, they analyze the meme for spreaders and origin, they use the new meme to gauge changes in public sentiment, they fine or jail or imprison particularly quarrelsome netizens, and in the worst case scenario they prepare narrative shifts or outright censorship to maintain a net that is deemed healthy. It’s meme epidemiology, with mind viruses instead of RNA viruses.
nromiun•1h ago
AFAIK QUIC traffic is impossible to attack using MITM techniques. So I wonder how the GFW handles it. Do they block it entirely or still filter it somehow?
xyzzy123•49m ago
According to https://gfw.report/publications/usenixsecurity25/en/#3 they sniff the SNI out of the handshake like for TLS.
jonathanlydall•44m ago
Why would QUIC be any more or less MITM attackable than say HTTP1.1 or 2?

AFAIK, the only thing that stops an MITM attack (where they respond as if they’re the remote server and then relay to the real remote server) are certificates.

If an authority requires you trust their root certificate so they can spy on you, QUIC will not make any difference.

Myocardial infarction may be an infectious disease

https://www.tuni.fi/en/news/myocardial-infarction-may-be-infectious-disease
402•DaveZale•9h ago•135 comments

Refurb Weekend: Silicon Graphics Indigo² Impact 10000

http://oldvcr.blogspot.com/2025/09/refurb-weekend-silicon-graphics-indigo.html
42•Bogdanp•1h ago•6 comments

Geedge and MESA leak: Analyzing the great firewall’s largest document leak

https://gfw.report/blog/geedge_and_mesa_leak/en/
85•yourapostasy•14h ago•15 comments

A single, 'naked' black hole confounds theories of the young cosmos

https://www.quantamagazine.org/a-single-naked-black-hole-rewrites-the-history-of-the-universe-202...
16•pykello•3h ago•5 comments

Pass: Unix Password Manager

https://www.passwordstore.org/
161•Bogdanp•8h ago•85 comments

Models of European Metro Stations

http://stations.albertguillaumes.cat/
6•tcumulus•38m ago•0 comments

Show HN: A store that generates products from anything you type in search

https://anycrap.shop/
860•kafked•19h ago•269 comments

Why you’d issue a branded stablecoin

https://text-incubation.com/Why+you%27d+issue+a+branded+stablecoin+like+McDonaldsCoin
31•krrishd•4h ago•32 comments

The Socratic Journal Method: A Simple Journaling Method That Works

https://mindthenerd.com/the-socratic-journal-method-a-simple-journaling-method-that-actually-works/
67•surprisetalk•3d ago•17 comments

Two Slice, a font that's only 2px tall

https://joefatula.com/twoslice.html
174•JdeBP•7h ago•48 comments

AMD’s RDNA4 GPU architecture

https://chipsandcheese.com/p/amds-rdna4-gpu-architecture-at-hot
97•rbanffy•10h ago•7 comments

High Altitude Living – 8,000 ft and above (2021)

https://studioq.com/blog/2021/5/30/high-altitude-living-8000-ft-and-above-2450-meters
30•walterbell•4h ago•22 comments

Will AI be the basis of many future industrial fortunes, or a net loser?

https://joincolossus.com/article/ai-will-not-make-you-rich/
97•saucymew•9h ago•114 comments

Recreating the US/* time zone situation

https://rachelbythebay.com/w/2025/09/12/tz/
75•move-on-by•15h ago•39 comments

RIP pthread_cancel

https://eissing.org/icing/posts/rip_pthread_cancel/
188•robin_reala•14h ago•83 comments

How the restoration of ancient Babylon is drawing tourists back to Iraq

https://www.theartnewspaper.com/2025/09/12/how-the-restoration-of-ancient-babylon-is-helping-to-d...
37•leoh•7h ago•17 comments

486Tang – 486 on a credit-card-sized FPGA board

https://nand2mario.github.io/posts/2025/486tang_486_on_a_credit_card_size_fpga_board/
173•bitbrewer•16h ago•47 comments

Lexy: A parser combinator library for C++17

https://github.com/foonathan/lexy
45•klaussilveira•3d ago•5 comments

The case against social media is stronger than you think

https://arachnemag.substack.com/p/the-case-against-social-media-is
209•ingve•13h ago•173 comments

The unreasonable effectiveness of modern sort algorithms

https://github.com/Voultapher/sort-research-rs/blob/main/writeup/unreasonable/text.md
4•Voultapher•3d ago•0 comments

Safe C++ proposal is not being continued

https://sibellavia.lol/posts/2025/09/safe-c-proposal-is-not-being-continued/
146•charles_irl•12h ago•121 comments

Visual programming is stuck on the form

https://interjectedfuture.com/visual-programming-is-stuck-on-the-form/
21•iamwil•5h ago•11 comments

How Ruby executes JIT code

https://railsatscale.com/2025-09-08-how-ruby-executes-jit-code-the-hidden-mechanics-behind-the-ma...
123•ciconia•4d ago•18 comments

My first impressions of Gleam

https://mtlynch.io/notes/gleam-first-impressions/
187•AlexeyBrin•18h ago•64 comments

Four-year wedding crasher mystery solved

https://www.theguardian.com/uk-news/2025/sep/12/wedding-crasher-mystery-solved-four-years-bride-s...
293•wallflower•16h ago•89 comments

Orange rivers signal toxic shift in Arctic wilderness

https://news.ucr.edu/articles/2025/09/08/orange-rivers-signal-toxic-shift-arctic-wilderness
83•hbcondo714•2d ago•1 comments

Show HN: UltraPlot. A Succinct Wrapper for Matplotlib

https://github.com/Ultraplot/UltraPlot
10•cvanelteren•3d ago•2 comments

AI fabricates 21 out of 23 citations lawyer sanctioned reported to state bar [pdf]

https://www4.courts.ca.gov/opinions/documents/B331918.PDF
12•1vuio0pswjnm7•5h ago•2 comments

Show HN: CLAVIER-36 – A programming environment for generative music

https://clavier36.com/p/LtZDdcRP3haTWHErgvdM
119•river_dillon•17h ago•23 comments

Open Source SDR Ham Transceiver Prototype

https://m17project.org/2025/08/18/first-linht-tests/
100•crcastle•4d ago•10 comments