[00:00.000 --> 00:00.700] Hi. [00:01.000 --> 00:02.880] Well, welcome everyone. [00:04.340 --> 00:06.380] My name is Vinicius Fortuna. [00:08.560 --> 00:11.340] Junir is one of the great engineers at Outline. [00:11.600 --> 00:13.500] We have an Outline engineer over there. [00:14.780 --> 00:17.260] So we'll be talking about the technology we've built. [00:18.620 --> 00:21.220] This is part of Jigsaw. [00:21.880 --> 00:26.360] Jigsaw is a group at Google that works on grass local societies. [00:26.620 --> 00:38.340] We work on projects like disinformation, toxicity online, localization, and I'm the engineering lead for the Internet freedom team at Jigsaw. [00:39.580 --> 00:43.800] And our effort goes beyond Outline. [00:44.500 --> 00:48.840] Our strategy is to prevent, mitigate, and expose censorship. [00:49.900 --> 00:53.560] On the prevention side, we worked on Internet standards. [00:53.960 --> 01:06.040] For example, we chaired the working group at the IETF, the Internet standards body to advance the encrypted DNS standard. [01:06.380 --> 01:16.940] And we would start to the industry by adding support to the standard, of the standard to the Google public DNS, we added to Android, we added to Chrome. [01:17.620 --> 01:21.520] And we also released an app called Intra that was an encrypted DNS client. [01:21.720 --> 01:26.220] So that really could constructs the industry and instructs the industry and encrypted DNS. [01:26.920 --> 01:35.200] Right now, right now, is an important piece of the proxelous strategy that Juni is going to talk about later. [01:36.420 --> 01:44.700] It's also like a prerequisite for encrypted client alone that some of you know, that hides the remains in encrypted communication. [01:46.000 --> 01:55.680] And then on the exposed side, it's like about measuring and exposing censorship and also understanding so we can bypass censorship. [01:55.960 --> 02:05.260] So we've done work to make Google traffic data public in a way that is accessible and usable. [02:06.080 --> 02:13.860] So we have like libraries to use it and organizations use it to track Internet shutdowns in different countries. [02:15.780 --> 02:33.800] And we also worked with organizations in the field, like Sensory Planet and Winnie to also make their data more accessible and useful, including like building a dashboard in Sensory Planet, which is a group by the University of Michigan, and writing a paper on the methodology. [02:35.940 --> 02:38.480] So that's an exposed area. [02:38.740 --> 02:41.120] And then there's the mitigate, which is like, I don't know. [02:41.280 --> 02:43.220] I don't know. [02:43.220 --> 02:43.460] What? [02:43.960 --> 02:47.360] Yeah, the simulation tools, like we have the one happening now. [02:48.800 --> 02:49.240] Hi. [02:49.380 --> 02:55.920] And we've used the simulation tools like Intra and Alphaline and other tech. [02:56.100 --> 03:02.000] And more recently, we are working with this Alphaline SDK, which is really making the technology from Alphaline. [03:02.000 --> 03:17.300] And so I've been improving and used by leaders of people, usable, because BNF, being open-source doesn't mean it's usable, given the SDK to make it usable and make it easy to access a system like that. [03:18.220 --> 03:19.380] So I'm going to stop there. [03:19.620 --> 03:22.000] The main speaker here is going to be between you today. [03:31.340 --> 03:33.780] Cool, I will show the Jigsaw icon here. [03:35.760 --> 03:39.660] That's Jigsaw, and you can access our website through jigsaw.google.com. [03:40.680 --> 03:41.840] Let's get it started. [03:42.340 --> 03:47.000] So first, I'd like to talk about the problem we are going to solve, which is censorship. [03:48.160 --> 03:56.560] Online censorship is a global issue, so when you access something and you see the 404 page, that means probably you are getting censored. [03:57.400 --> 04:06.640] And the Internet censorship is still growing over the world, so you can see, surprisingly, most of the countries are doing the online censorship now. [04:07.060 --> 04:13.280] And that's why we provide our solution, which is UltraVPN we just talked before. [04:13.720 --> 04:34.700] It is a VPN product, but it's a decentralized VPN product, so you can create your own VPN server and use the client to access that server, and you can share access keys with your friends or your colleagues to use your VPN server. [04:34.980 --> 04:36.360] So here we have two products. [04:36.640 --> 04:39.120] One is UltraVPN manager, the other is UltraVPN client. [04:39.260 --> 04:42.120] And you can share the access keys from them. [04:42.460 --> 04:50.760] So by creating your own VPN servers, you have a fully ownership of your server, so you trust what you've done to your server. [04:51.020 --> 04:58.300] You don't need to worry about privacy, you don't need to worry about the server to services monitoring your traffic because it's all owned by itself. [04:58.540 --> 05:02.160] And you can share the access keys to any number of offline clients. [05:03.640 --> 05:06.900] Let's jump into the first demo of this talk. [05:07.420 --> 05:11.460] I will show you the UI of our client manager here. [05:11.460 --> 05:12.280] Why not? [05:12.500 --> 05:13.940] So you can see where it is. [05:14.540 --> 05:19.520] The manager UI, I have already created a server for the whole event here. [05:24.620 --> 05:27.860] And you can see you can create multiple keys. [05:28.580 --> 05:31.140] I have created a demo key and a main key. [05:31.840 --> 05:36.500] And when you click the share button here, you will be able to share the key. [05:37.740 --> 05:39.960] So here is the share dialog. [05:40.420 --> 05:43.100] You will see this is the outline access key here. [05:44.780 --> 05:47.040] And you can also send invitations. [05:48.240 --> 05:56.820] So when you click copy access key, this access key is copied to your clipboard and you can send that over secure the message or secure the email to others. [05:56.820 --> 06:01.920] And I will show you the outline client. [06:02.080 --> 06:06.160] So outline client is a cross-ed form client tool. [06:06.380 --> 06:11.560] It supports all major platforms including all desktop and all mobile platforms. [06:11.800 --> 06:14.080] You can install it from the store or from the store. [06:15.100 --> 06:19.960] Here is I will show you the Linux version. [06:19.960 --> 06:24.300] So you can download it from our website, getoutline.org. [06:24.480 --> 06:26.360] I will show you the website later in the talk. [06:27.200 --> 06:31.160] And once you download it, you will see it from the download window. [06:31.500 --> 06:35.020] And feel free to double click it to launch the outline client UI. [06:35.840 --> 06:38.360] And this is the outline tool in first download. [06:40.860 --> 06:43.180] And we will show you the information page. [06:43.180 --> 06:44.500] And you can say, got it. [06:45.900 --> 06:48.500] And we will also monitor the clipboard. [06:48.660 --> 06:53.540] So if we found the outline key there, we automatically prompt the add server thing. [06:54.000 --> 06:58.780] Once you edit your server, you can see your server is added to this outline client. [06:58.980 --> 07:00.420] You can type connect to connect. [07:00.640 --> 07:04.040] To confirm, actually, we will be doing something. [07:04.040 --> 07:13.700] So we will try to get the IP address of this environment. [07:14.540 --> 07:18.080] And then there seems we are not doing it correctly. [07:19.240 --> 07:25.620] And the one thing to troubleshoot is we can restart the machine in order to reset the network. [07:27.180 --> 07:31.860] We won't wait it for now because it took some time. [07:31.860 --> 07:33.680] We can show it later. [07:35.040 --> 07:35.420] Let's jump. [07:35.840 --> 07:36.160] Let's jump. [07:36.160 --> 07:36.840] Let's jump into the slides. [07:37.640 --> 07:39.580] The brand will show the current IP address. [07:39.880 --> 07:47.900] And once you click connect in outline client, the IP address will be changed to your own VPN server. [07:50.100 --> 07:56.240] So now, outline client and outline manager are very easy to use for end users. [07:56.520 --> 08:06.140] But for developers, they are not easy to use the features or reuse the features will be like we are building a lot of outline server connection. [08:06.140 --> 08:07.860] We are based on Shadows and Hawks. [08:08.340 --> 08:11.720] If developers would like to use that, we created outline SDK. [08:12.380 --> 08:19.540] And outline SDK is a reusable, composable, and cross-platform toolkit to empower your app against censorship. [08:19.860 --> 08:27.800] So you can easily use all these censorship circumvention tools and integrate them into your own app. [08:27.800 --> 08:32.320] Or you can even create your own VPN product using this SDK. [08:32.660 --> 08:34.700] And it's fully cross-platform. [08:34.880 --> 08:41.440] I mean, you can use it on any platform from desktop to automated platforms as well. [08:43.080 --> 08:46.960] So outline SDK consists of the following components. [08:47.160 --> 08:48.240] The first is libraries. [08:48.600 --> 08:54.140] We provided a lot of libraries for you to use to add network resilience to your own apps. [08:54.140 --> 08:59.280] For example, we provided transports with the first Shadows, TLS, and WebSocket. [08:59.660 --> 09:04.100] We also provided proxy protocols like HTTP, SOX5. [09:04.520 --> 09:07.180] We also provided some proxy-less strategies. [09:07.580 --> 09:11.380] We will show them later what are proxy strategies. [09:11.380 --> 09:14.280] For example, encrypted DNS packet manipulations. [09:15.080 --> 09:17.740] And we also provided VPN APIs. [09:17.740 --> 09:27.340] For now, we provided 10 little SOX VPN APIs based on lightweight IP, which is the C library to set up a user-based network stack. [09:27.640 --> 09:40.860] So you don't need to rely on any specific software operating system kernels in order to read, write, interpret, and forward IP packets or compare them to TCP or ADP packets. [09:40.860 --> 09:43.260] We also provided mobile proxy. [09:43.500 --> 09:48.860] So mobile proxy will let you easily integrate these features into mobile apps. [09:49.060 --> 09:52.160] Because developing mobile VPN is tricky. [09:52.600 --> 09:53.820] There are a lot of restrictions. [09:54.120 --> 09:56.700] You might need to use some VPN APIs. [09:56.880 --> 09:58.920] The mobile proxy allows you to do that easily. [10:00.780 --> 10:09.620] Outline SDK also provides some command-learning tools to experiment, measure, and prototype your own censorship circumvention strategies. [10:09.620 --> 10:13.620] We provide fetch, resolve, and HTTP transport. [10:14.020 --> 10:16.780] So we will show these command-line tools now. [10:17.620 --> 10:20.600] Today we will focus on these two areas. [10:20.860 --> 10:23.680] The proxy protocols and the proxy strategies. [10:24.160 --> 10:25.880] And the three command-line tools. [10:27.200 --> 10:29.240] Let's start with the command-line tools. [10:30.280 --> 10:37.480] First, I'd like to introduce the resolve, which is a DIG or Resolve DNS name if you are using Windows. [10:38.380 --> 10:39.820] It's similar today. [10:40.420 --> 10:47.540] For example, when you type resolve youtube.com, it will give you all the IP addresses of youtube.com. [10:48.200 --> 10:52.480] And we allow you to pass or additional some additional arguments as well. [10:52.660 --> 10:56.400] For example, you can specify resolver to 8.8.8.8. [10:56.620 --> 10:58.660] And you can force TCP here. [10:59.060 --> 11:02.420] And if you just want to get a C name, you can do that as well. [11:02.420 --> 11:05.820] And the output will be the AIS of YouTube.com. [11:06.140 --> 11:08.300] So this is a cross-platform result. [11:08.920 --> 11:14.120] And since we implemented it in Go, so you can run it directly through this Go command. [11:14.480 --> 11:15.440] You just need to run Go. [11:15.480 --> 11:16.380] You don't need to... [11:16.380 --> 11:21.640] We haven't built any pre-built fineries, because you can easily run that through the Go command. [11:21.640 --> 11:27.680] And it will be built on our own platform to be run natively. [11:29.720 --> 11:35.080] Similarly, we have fetch, which is a curl or JavaScript fetch. [11:35.460 --> 11:36.400] Those functions. [11:37.100 --> 11:45.140] When you type fetch, similarly with the ipinfo.io, you will get that ipinfo.io. [11:46.640 --> 11:48.440] The output will be a region. [11:49.400 --> 11:53.680] For example, if we are here in New York, the region will be in New York. [11:54.440 --> 11:59.820] But we allow you to specify, to accept an online server key. [12:00.080 --> 12:00.960] And we just have... [12:00.960 --> 12:04.600] I just have shown you through online manager where you copy the key. [12:04.820 --> 12:07.280] You can paste the key here in the transport. [12:07.280 --> 12:15.280] When you get the ipinfo again, it will show you the location of my VPN server, which is located in the port. [12:15.700 --> 12:21.540] And this is also what we are supposed to get when we run the curl command. [12:21.880 --> 12:22.760] So there's another network. [12:24.580 --> 12:27.620] So the third is HTTP to transport. [12:28.660 --> 12:32.440] It's a local web proxy using HTTP connect. [12:33.640 --> 12:37.880] So, for example, you can start listening on a local port. [12:38.060 --> 12:39.600] Listening on local host, if you're ready. [12:40.340 --> 12:42.800] And we also accept an online server key. [12:43.120 --> 12:48.580] So this command will start a local web proxy listening on this. [12:48.720 --> 12:50.580] I've addressed an port number. [12:50.980 --> 12:55.300] And the remote server is the online key, which is listed here. [12:56.180 --> 13:04.860] And now, if you run curl without specifying the proxy, of course, it will show your own local IP address region. [13:05.180 --> 13:13.080] And if you specify the proxy using dash x, and dash p means it will use HTTP connect. [13:13.360 --> 13:18.480] So it will show the IP address of your own server there. [13:18.840 --> 13:22.800] And that is what it's supposed to do. [13:22.800 --> 13:28.800] And you can also configure your own browser proxy to point to these local proxies. [13:29.000 --> 13:35.680] So all your traffic within the browser will be routed to this offline Shutterstock server. [13:36.520 --> 13:39.540] It doesn't have to be an offline server. [13:39.760 --> 13:44.340] We actually, we are compatible to any Shutterstock servers. [13:44.340 --> 13:52.560] So if you create a Shutterstock server, you can also generate this offline access key and to visit your Shutterstock server as well. [13:53.660 --> 13:58.960] So these are the three major command line tools we will cover today. [13:59.300 --> 14:01.420] And we also provide a lot of other tools. [14:01.420 --> 14:03.800] So you can see our code. [14:03.960 --> 14:06.100] We are fully open-sourced on GitHub. [14:06.480 --> 14:09.320] And I will show you the link later in the talk. [14:10.040 --> 14:11.320] Any questions so far? [14:14.730 --> 14:15.290] Cool. [14:16.310 --> 14:19.330] I think we can dig more into the strategies. [14:19.990 --> 14:23.370] So you have seen the outside key we've shown before. [14:23.650 --> 14:25.590] Start with SS column slash slash. [14:25.590 --> 14:28.090] That is what we call a strategy. [14:29.390 --> 14:32.990] So we will start with an MPE strategy. [14:33.370 --> 14:38.890] So we run an Autonet SQL command line without specifying that transport. [14:39.470 --> 14:40.910] That means an MPE strategy. [14:41.230 --> 14:45.490] So MPE strategy means a direct connection to the target server. [14:46.410 --> 14:51.330] I will use a fetch example to show what it is doing. [14:51.570 --> 14:54.630] So you would like to fetch the YouTube website. [14:54.630 --> 14:59.820] You will first start establishing the TCP connection onto YouTube.com. [15:00.950 --> 15:05.130] And once YouTube access that, a TCP connection will be established. [15:05.430 --> 15:07.730] And you can read or write from that connection. [15:08.550 --> 15:10.670] That's the default MPE strategy. [15:10.890 --> 15:15.350] So if you don't specify anything, you're actually connecting directly to the target destination. [15:16.910 --> 15:19.070] We also have proxy strategies. [15:19.550 --> 15:23.250] The ShadowSox key I mentioned before is a proxy strategy. [15:23.250 --> 15:26.390] And we also support other protocols like Socks5. [15:26.770 --> 15:29.630] Here I will use Socks5 as an example. [15:30.230 --> 15:31.710] So we have a strategy here. [15:32.030 --> 15:35.810] And of course you need some proxy because these are proxy strategies. [15:36.090 --> 15:37.350] So you need a Socks5 proxy. [15:38.870 --> 15:43.250] And fetch will still try to establish a TCP connection. [15:43.550 --> 15:46.490] So all these strategies are transparent to the users. [15:46.490 --> 15:51.490] And when we use our SDK libraries, they are transparent as well. [15:51.910 --> 15:56.710] So you just do a traditional reestablish TCP connection with a strategy. [15:57.070 --> 16:04.730] And our Socks5 strategy will try to establish a Socks5 handshake with the remote Socks5 proxy here. [16:05.850 --> 16:12.690] And when Socks5 sees that handshake, it will try to establish the actual TCP connection with the destination. [16:12.690 --> 16:20.390] And once all these things are established, YouTube will create a TCP connection with the Socks5 proxy. [16:20.630 --> 16:25.290] And the Socks5 proxy will return that TCP connection to the strategy. [16:25.510 --> 16:28.210] And the strategy will also return a TCP connection. [16:28.730 --> 16:33.410] So from fetch perspective, it has no difference with the MPD strategy. [16:33.410 --> 16:34.390] It's the same. [16:34.650 --> 16:38.270] You establish a TCP connection and you can rewrite from that connection. [16:38.470 --> 16:42.030] But under the hood, our strategy will do a bunch of these things. [16:42.310 --> 16:47.390] Try to do all these things for the fetch. [16:47.670 --> 16:49.190] But it's all transparent to fetch. [16:49.370 --> 16:52.270] The fetch will think, okay, we're just fetching something from YouTube. [16:52.730 --> 16:54.130] And we got the result. [16:55.190 --> 16:56.970] So that's proxy strategies. [16:57.710 --> 17:00.350] And we also have transport strategies. [17:00.350 --> 17:13.510] So transport strategies will marshal or un-marshal traffic over a specific network transport, for example, TLS or WebSocket. [17:13.950 --> 17:16.910] I will use the WebSocket as an example here. [17:17.250 --> 17:26.490] So for the fetch and if we are going to establish some connection to rewrite some data to that WebSocket server, echo the WebSocket.org. [17:26.490 --> 17:31.110] For fetch, we are still trying to establish a TCP connection. [17:31.670 --> 17:34.570] As I said, it's completely transparent to fetch. [17:34.830 --> 17:36.990] So for fetch, we are still trying to establish a TCP. [17:37.330 --> 17:46.750] But our strategy will encapsulate into a WebSocket upgrade protocol with that target destination. [17:47.770 --> 17:52.730] And, of course, later the fetch can send the TCP data or read TCP data from the strategy. [17:52.730 --> 17:59.730] And our strategy will also put that data into the WebSocket frame to the target server. [18:00.670 --> 18:06.750] And it will also read the WebSocket frames and try to un-marshal the TCP data and send it back to fetch. [18:07.090 --> 18:10.170] So from fetch perspective, it's still a TCP connection. [18:10.510 --> 18:18.150] But in the boot, and what our strategy is doing is actually encapsulate it into a WebSocket protocol. [18:19.430 --> 18:21.230] Transparency to fetch. [18:24.350 --> 18:24.910] Yeah. [18:25.090 --> 18:25.170] Sure. [18:26.410 --> 18:34.030] So what could be about sub-warned WebSockets is that it allows you to run a proxy entry point on a CDN. [18:35.190 --> 18:37.850] So like Cloudflare and that kind of thing. [18:41.350 --> 18:47.290] Typically, CDNs do not allow you to do HTTP connect, which is the HTTP-based kind of proxy protocol. [18:47.630 --> 18:49.370] But they allow you to do WebSockets. [18:49.370 --> 18:53.510] So that gives you a make-up point to your proxy. [18:55.270 --> 18:59.770] Which means that you are using the CDN IP pool, which makes you have to pull. [19:00.190 --> 19:06.390] So in order to block them, begin by your proxy, by IP address, they have to block them to the CDN. [19:13.630 --> 19:18.690] Okay, our next strategy is called the DNS Protection Strategies. [19:18.890 --> 19:27.610] So we provide a lot of DNS request protocols like DNS over HTTPS, DOH, which is pretty secure because it's fully encrypted. [19:27.610 --> 19:32.590] And we also provide other DNS over TCP or TLS options as well. [19:33.110 --> 19:36.990] So let's take an example of the DNS over HTTPS. [19:37.510 --> 19:39.190] So still prepare a Fetch. [19:39.410 --> 19:44.890] The Fetch trying to establish a TCP connection with the destination, youtube.com. [19:45.390 --> 19:50.830] And our strategy sees Fetch is requesting something from a domain name. [19:50.970 --> 19:55.350] So it will send a domain name request to DNS.google. [19:55.350 --> 20:06.290] And because we specify the DOH server as DNS.google, it will try to send a HTTPS-based DNS request to DNS.google. [20:06.410 --> 20:12.450] And DNS.google will return the IP address accordingly using HTTPS as well. [20:13.170 --> 20:20.710] In this case, strategy now will know the actual destination is 142.250.72.110. [20:21.730 --> 20:30.330] And then it will try to establish that TCP connection with this specific server, and it is one of the YouTube.com servers. [20:31.230 --> 20:40.210] And YouTube.com will successfully return a TCP connection, and our strategy will forward that connection back to Fetch again. [20:40.430 --> 20:45.530] So from Fetch's perspective, it's still establishing a TCP connection and redirect from that connection. [20:45.530 --> 20:49.330] But strategy is doing some more complicated things. [20:49.650 --> 20:52.510] It's trying to solve the DNS using HTTPS. [20:52.850 --> 20:54.670] So there are no leaks. [20:56.210 --> 21:01.430] Because the traditional UDP-based DNS requests are clear text. [21:01.730 --> 21:07.090] And the sensors will be able to see all your domain names, and they can easily block your domain name. [21:07.090 --> 21:12.490] But once you use HTTPS, it's all good, because it's all fully encrypted. [21:15.790 --> 21:19.610] And the next is packet manipulation strategies. [21:20.010 --> 21:29.790] So it will modify the network packets in order to bypass some deep packet inspection censorship, such as SNI-based blocking. [21:29.790 --> 21:35.670] So SNI is a concept in TOS when it is doing a TOS handshake. [21:36.210 --> 21:44.870] So sometimes the TOS client will put the server name indication into the client handshake, which is clear text. [21:45.250 --> 21:50.610] Because when we are doing the TOS handshakes, we don't have any keys established yet. [21:50.610 --> 21:52.590] So it's not improved at all. [21:52.590 --> 21:58.390] And in that case, the sensor might see that domain name in clear text, and they can block you as well. [21:58.530 --> 22:08.090] For example, when establishing a TOS connection with YouTube, sometimes the client will put YouTube.com into the TOS handshake as well. [22:09.190 --> 22:11.330] I will show an example here. [22:11.850 --> 22:13.650] So here Fetch will try to... [22:13.650 --> 22:14.990] I will skip the TCP connection. [22:15.190 --> 22:18.750] So before the TOS handshake, you need to establish the TCP connection. [22:18.890 --> 22:19.990] And I will skip that for now. [22:19.990 --> 22:27.810] But for TOS handshake, Fetch will try to send the TOS handshake record in clear text. [22:28.670 --> 22:37.790] And by the definition of the protocol, you can actually split that record into two smaller records. [22:38.410 --> 22:40.810] So for example here, we show TOS... [22:40.810 --> 22:47.410] We will put the first 60 bytes in the first record, and put the next 200 bytes in the second record. [22:47.410 --> 23:02.630] And these two records are still in clear text, but it will confuse sensors, because sensors will think, okay, typically you only send one TOS handshake, and they will try to find some sensitive domain names in that package. [23:02.630 --> 23:05.670] But what we are sending record-wide is only 60 bytes. [23:06.470 --> 23:08.730] It might not even reach the SNI, right? [23:09.330 --> 23:12.170] So the sensors will think, cool, it's a good hand shape. [23:12.310 --> 23:17.490] Or maybe it's a malfunction hand shape, because the sensors don't know we're actually splitting that. [23:17.850 --> 23:21.390] And the sensors will let all these connections go to save the resource. [23:21.390 --> 23:38.150] Of course, sensors can memorize all your records and try to reconstruct everything in their own machine, but that will increase the cost of the sensor servers, because the traffic might choose different servers, or might even choose different routes. [23:38.490 --> 23:49.850] And sensors need to synchronize all these memories with all the servers, and that's a huge effort, and it will use a lot of resources, including secure power and memory power. [23:50.110 --> 23:56.630] So the goal here is not to completely have sensorship, but to increase the cost of sensorship. [23:56.810 --> 24:00.330] And most of the sensors in the world doesn't implement that. [24:00.630 --> 24:10.710] And we will show you that later, we can use this TOS handshake fragmentation to bypass sensorship. [24:11.790 --> 24:21.050] And once the TOS connection is established, the strategy will pass that connection back to Fetch or GASO connection, and rewrite our next TOS connection. [24:23.230 --> 24:37.370] Cool, so these are all the strategies we've already supported in Autonic SDK, but it will also support some other strategies as well, but they will fall in one of the categories I mentioned before. [24:37.370 --> 24:43.710] And a more important concept of that is all these strategies are composable. [24:44.290 --> 24:55.370] So composable means you can combine different strategies to construct a more complicated and more censorship resilient strategy. [24:56.450 --> 25:04.350] So you can use, for example, you can use a pipe here to combine the DNS over HTTPS and the TOS recommendation together. [25:04.610 --> 25:14.510] And if you have three different offline servers, you can even connect the three servers into something similar to the linear routing. [25:14.510 --> 25:20.570] And you can also, if you want to have five over TOS, you can combine that two as well. [25:20.830 --> 25:22.290] So you can combine multiple strategies. [25:22.770 --> 25:28.770] Use your imagination to create new strategies based on these existing built-in strategies. [25:29.890 --> 25:32.630] I will give you the first one example. [25:33.230 --> 25:37.650] So here we have FATS and we have the destination, which is youtube.com. [25:37.870 --> 25:41.430] And we have two strategies linked together. [25:42.070 --> 25:48.070] Click note that sequence is actually reversed from what we type in to the command line. [25:48.430 --> 25:53.110] So in command line, we type in DNS NURATS DPS first and then TOS spread. [26:00.010 --> 26:09.530] So in this way, the first one will be the strategy that's facing directly to the Internet. [26:09.530 --> 26:16.370] And the last one will be the one facing your user code in this example to fetch. [26:18.450 --> 26:23.870] So fetch will soon start trying to establish HTTP connection. [26:24.810 --> 26:28.010] And the TOS recommendation doesn't care of HTTP. [26:28.190 --> 26:35.670] So it will just forward that HTTP connection to the next strategy, which is the DOS GNNs over HTTPS. [26:36.110 --> 26:39.050] And this strategy cares about the domain name. [26:39.050 --> 26:46.270] So it will try to send UU.com to TOS or Google to get the IP address using HTTPS. [26:46.990 --> 26:53.710] And then it will establish the HTTP connection with that IP address with YouTube.com. [26:55.150 --> 27:04.170] Next, once that HTTP connection is established, that will try to establish the TOS connection as well by sending the TOS hashtag. [27:04.170 --> 27:09.210] This time, the TOS recommendation strategy cares about it. [27:10.350 --> 27:14.210] It will try to split that into two records. [27:14.870 --> 27:17.930] But the DNS over HTTPS doesn't care. [27:18.090 --> 27:19.470] It only cares about my name. [27:19.710 --> 27:21.830] It will forward that hack directly to YouTube. [27:22.510 --> 27:26.290] And we will send the second one as well to YouTube. [27:26.290 --> 27:29.370] So that client, hello, it's listed in YouTube. [27:29.710 --> 27:34.050] And YouTube will return a successful TOS connection with our strategy. [27:34.410 --> 27:38.910] And we will return that all the way back to Fetch. [27:39.130 --> 27:49.970] So in this case, Fetch established a successful TOS connection with the remote web bias by patching the message using DMF over HTTPS and the TOS representation. [27:52.150 --> 27:57.190] So that's for the composal strategy question. [27:59.810 --> 28:01.810] Okay, we can do a question at the end. [28:01.930 --> 28:02.670] Cool, Professor. [28:04.090 --> 28:07.710] And next, I'd like to talk about remote environment. [28:08.050 --> 28:09.770] So we will talk about a strategy. [28:10.210 --> 28:12.710] And we'll talk about all the mainline tools. [28:13.250 --> 28:25.670] But we, as a developer, we are going to investigate what we can use in the specific region of the censored area to bypass censorship. [28:26.430 --> 28:30.750] Typically, when you measure censorship, it requires three sets. [28:31.230 --> 28:33.550] First, you need to access a remote access. [28:36.190 --> 28:42.550] In order to test your strategy or test what is blocked and why it is blocked. [28:43.490 --> 28:45.270] You can use the outline of HTTPS as well. [28:45.270 --> 28:50.530] For example, you can set in an outside server in the region and use that shared doc. [28:51.390 --> 28:54.530] You can also use Foxpy Red SSH. [28:54.990 --> 28:56.610] You can create a local... [28:57.670 --> 29:03.530] Create and Foxpy properly locally and connected to the target server using SSH. [29:03.530 --> 29:09.790] And then you can use the about five transferable strategy in the client as well. [29:09.990 --> 29:14.490] So all the packets and all the packets will be routed through the server. [29:15.970 --> 29:19.710] And a third option is some third-party providers. [29:20.030 --> 29:27.810] We were using SOF, which is pretty easy because it supports most of the region inside the world. [29:29.310 --> 29:31.110] But it's not free. [29:31.410 --> 29:36.150] You need to pay about $100 per month in order to use the server. [29:36.590 --> 29:38.750] But they are easy to use. [29:39.750 --> 29:45.010] And in the demo net, we wait for that to show you how they can enter. [29:45.290 --> 29:50.010] And once you set out the remote hatchet, you need to detect the ship. [29:50.010 --> 29:53.970] You need to know what is entered, what you can access, and what you cannot. [29:55.010 --> 29:59.870] For example, you might detect an in-end blocking with your .com. [30:00.150 --> 30:07.870] Or you might detect the TLS client allow server name indication blocking as well, as I mentioned before. [30:07.870 --> 30:18.610] And once you detect this censorship and bypass censorship, you will need to figure out a way to bypass all this censorship. [30:18.950 --> 30:23.250] Using either a building strategy or you can create your own strategies. [30:23.790 --> 30:31.230] Or you can compose different strategies, combine them together to construct a more powerful strategy to bypass censorship. [30:31.230 --> 30:36.110] Like here, you can use DNS over HTTPS to bypass DNS. [30:36.610 --> 30:40.750] And you can use the TLS fragmentation to bypass an eye-blocking. [30:40.950 --> 30:42.810] And you can combine them together. [30:45.510 --> 30:46.230] Cool. [30:47.230 --> 30:51.050] We'd like to show a demo here if we have time. [30:55.250 --> 31:02.330] So I will launch the terminal here and try to run the code command again. [31:02.770 --> 31:04.370] And it seems it's working now. [31:04.630 --> 31:06.070] We're in New York City. [31:06.270 --> 31:10.730] And as I said, we can connect to our authorized server. [31:10.930 --> 31:12.110] We just placed it here. [31:12.630 --> 31:16.030] Once you click connect, it will show a data connected. [31:16.930 --> 31:22.610] And when you run the code again, it should show the IP address of the server. [31:22.610 --> 31:23.970] Which is Singapore. [31:24.410 --> 31:26.930] And we host the server in DigitalOcean. [31:27.730 --> 31:29.530] So you can see all this information here. [31:30.410 --> 31:36.070] And of course, we can disconnect from the VPN server. [31:36.510 --> 31:42.870] And once it's disconnected and you run it again, it's going back to our local IP address. [31:43.590 --> 31:47.090] It's a typical behavior of VPN server as people expect it. [31:47.790 --> 31:55.250] And what I'd also like to show is you can actually share more than one key. [31:55.510 --> 31:56.390] There are a lot of keys. [31:56.610 --> 31:58.990] You can create a lot of keys of your own server. [31:59.170 --> 32:01.350] And you can even change the port numbers. [32:01.670 --> 32:07.790] So when you click the settings, it allows you to configure the host name and even port. [32:07.930 --> 32:09.450] For example, we don't like this. [32:09.450 --> 32:15.650] We want to create a port at 8080 or 80, whatever you like. [32:16.050 --> 32:20.070] When you click save and you go back to your server management. [32:20.610 --> 32:24.270] You can add a new key with that port. [32:24.670 --> 32:25.610] You can name your key. [32:25.830 --> 32:27.450] Maybe another key here. [32:28.210 --> 32:32.730] And you can also share that key with your customer. [32:32.730 --> 32:37.550] And in the key you can see the port has been changed to 8080. [32:37.990 --> 32:41.590] So you can set up the port to be any number. [32:41.830 --> 32:43.650] Changing the port is useful sometimes. [32:44.090 --> 32:47.830] Because most of the sensors might block unknown ports. [32:48.110 --> 32:50.390] But they will last for three or 80s. [32:50.670 --> 32:53.850] Because they are HTTP and HTTP ports. [32:54.190 --> 32:56.050] So changing the port is sometimes useful. [32:56.050 --> 33:00.770] And you can also add your name, like my service here. [33:01.190 --> 33:06.330] And you can copy that key and share that with your friends. [33:06.630 --> 33:11.050] And your friend will be able to add multiple keys to the client as well. [33:11.250 --> 33:18.810] So once they add that server, it will show your own service name with the correct port number, which is AAB. [33:19.150 --> 33:23.570] And of course, your friend can connect to that server as well. [33:23.570 --> 33:26.110] And to show we actually connect it. [33:26.850 --> 33:29.310] And we query this IP address. [33:29.650 --> 33:31.330] It will show the Singapore thing. [33:32.050 --> 33:34.250] And move sometimes. [33:35.550 --> 33:36.910] Maybe the... [33:38.370 --> 33:40.470] Yeah, the Mipshine service though. [33:41.210 --> 33:43.330] But we can show that here. [33:43.670 --> 33:45.270] It's from Singapore. [33:46.990 --> 33:49.150] And disconnect from the key. [33:49.590 --> 33:51.430] And the older key is also working. [33:51.430 --> 33:54.430] You can connect using the older key as well. [33:54.670 --> 34:03.170] But you can also revoke the access for the key in your Outline Manager in order to, for example, remove people there. [34:03.390 --> 34:07.910] And you can also set other data limits and other things. [34:08.290 --> 34:13.690] So Outline Manager is pretty useful here when you try to create your own server and share key. [34:13.690 --> 34:18.030] And we support a lot of service creation methods as well. [34:18.250 --> 34:21.870] For example, we will expand that and try to add a server. [34:22.150 --> 34:24.970] We support DigitalOcean, Google Cloud, and Amazon. [34:25.450 --> 34:30.610] And you just, with a single click, an Outline Server will be set up. [34:30.830 --> 34:33.970] I will not click that, because that charges go up. [34:34.270 --> 34:34.830] Not a lot. [34:35.150 --> 34:36.990] About $6 a month. [34:37.750 --> 34:38.750] But yeah. [34:38.930 --> 34:39.950] Just show it, but it's slow. [34:40.790 --> 34:41.350] Cool. [34:41.590 --> 34:43.810] So that's supposed to be the first demo. [34:44.310 --> 34:47.790] I'm heading to the second, which is measuring YouTube in Iraq. [34:54.370 --> 34:58.630] For a second demo, I will not use Outline or Outline Manager. [34:58.630 --> 35:04.090] I will switch to a new desktop here. [35:04.670 --> 35:11.310] And you see the part that you think is wrong, that's the part of that endpoint there. [35:14.270 --> 35:17.430] It's so sad when we have those here. [35:17.570 --> 35:17.950] Yeah. [35:17.950 --> 35:23.530] And you choose to block, and you can put it in there. [35:24.330 --> 35:25.570] And I'll move the process. [35:26.610 --> 35:28.090] I would like to do that in one. [35:29.610 --> 35:30.590] Right, right. [35:30.710 --> 35:33.510] So the first command line will show it live. [35:33.930 --> 35:34.210] Oh, okay. [35:34.310 --> 35:35.010] Can you get that in here? [35:36.050 --> 35:36.390] Cool. [35:36.770 --> 35:38.990] So this command line is a fetch tool. [35:39.410 --> 35:43.870] You can write directly from command line using Go, but you need to go. [35:43.870 --> 35:49.190] And then you can pass that IP input from this goal. [35:49.650 --> 35:55.570] And I will formate it in the JSON using the JQ command. [35:57.170 --> 35:59.090] And Go will... [35:59.090 --> 36:05.330] If you write for the time, Go will try to download everything here and try to build it. [36:05.710 --> 36:07.850] And then it will run the binary. [36:08.130 --> 36:11.210] And you can see we passed the same jobs. [36:11.490 --> 36:12.630] And we'll see the IP here. [36:12.630 --> 36:15.150] So that's for the fetch man. [36:15.350 --> 36:16.990] Any man can be working in this way. [36:17.170 --> 36:20.450] We don't need to install anything from any platform. [36:20.710 --> 36:26.270] So I'm using MacGear to write it from all desktop environments in automobile. [36:26.850 --> 36:29.810] But if you use that as I'm sharing mobile, you might. [36:31.910 --> 36:36.730] Next, I'd like to show how to use that remote connection here. [36:37.750 --> 36:41.390] So, for example, we are using the stock center. [36:42.070 --> 36:46.490] And this is the transport we are going to use. [36:46.810 --> 36:48.130] I'll go for the smoke pad. [36:48.430 --> 36:53.650] Because we need to add that to the previous fetch command. [37:07.000 --> 37:10.860] So this is the fetch man here. [37:11.500 --> 37:16.220] And you can add the transport command line here. [37:26.280 --> 37:29.700] You can see we set the time out to be 10 seconds. [37:30.140 --> 37:31.760] Because it's pretty far over. [37:32.480 --> 37:35.760] And you can support .5 here. [37:36.080 --> 37:40.980] And either way, we hide the credentials in .5. [37:41.780 --> 37:45.720] And you can specify a specific country. [37:56.220 --> 38:06.870] So, for example, here I will paste in the correct Iran section. [38:06.870 --> 38:12.050] So, the higher part is the wrong dating. [38:12.610 --> 38:14.010] We have the wrong decimal section. [38:14.390 --> 38:18.970] And in the country, we use the title, character, country name IR. [38:19.350 --> 38:23.750] And also, we specify the IR, PN, and TN, the wrong setup. [38:24.590 --> 38:26.390] So, let's run that. [38:26.870 --> 38:29.190] And it will take a longer time. [38:29.190 --> 38:33.190] Because we are actually going all the way to the wrong. [38:33.710 --> 38:34.230] And... [38:34.230 --> 38:38.250] But, luckily, it's all successfully returned. [38:38.510 --> 38:41.170] And if I want to get that to us, which is by one-to-one. [38:41.570 --> 38:44.950] And you can see the IRC is . [38:45.810 --> 38:48.610] And the city is . [38:49.270 --> 38:51.490] And, of course, the country is . [38:52.130 --> 38:55.850] So, we successfully support the remote access in the wrong here. [38:55.850 --> 39:00.430] And, the export is pretty long. [39:01.290 --> 39:09.050] So, in that case, I want to save some typings by exporting any wrong software. [39:09.990 --> 39:17.990] And we will try to fetch YouTube from groundhogs. [39:18.770 --> 39:21.830] And we expect it to fail. [39:22.210 --> 39:27.810] Because, most of the time, YouTube is blocked in Iran. [39:28.370 --> 39:33.290] And we use the same fetch with Iran's software transport. [39:33.410 --> 39:35.170] Try to fetch . [39:36.830 --> 39:39.570] And, yes, it shouldn't fail. [39:39.930 --> 39:40.970] That should be affected. [39:41.330 --> 39:43.850] Because we haven't added anything to it. [39:43.850 --> 39:47.370] And it will pretend that it needs to be blocked. [39:47.710 --> 39:49.510] So, hang out. [39:49.930 --> 39:50.590] Because it's blocked. [39:52.070 --> 40:00.530] What we suspect is maybe Iran is doing a DNS blocking. [40:00.890 --> 40:05.870] In that case, let's go back to the previous command. [40:05.870 --> 40:09.610] And then, let's pipe ping the DNS request here. [40:10.090 --> 40:11.730] The DNS for HTTPS. [40:11.830 --> 40:15.670] We use CloudFair as a DNS request. [40:16.050 --> 40:18.090] And try to fetch YouTube again. [40:18.410 --> 40:20.470] It should also fail, as expected. [40:21.970 --> 40:23.590] And this is a rumor. [40:24.250 --> 40:28.510] That failure is not expected because I typed two pipes there. [40:28.510 --> 40:31.830] You only need to type one. [40:33.070 --> 40:34.430] Let me remove that. [40:35.210 --> 40:36.090] And write again. [40:36.510 --> 40:39.430] But still, you might see the errors in this case. [40:39.730 --> 40:40.790] You might see timeout. [40:41.010 --> 40:43.310] You might see handshake failed. [40:43.870 --> 40:46.110] It will happen during my test. [40:47.030 --> 40:47.890] But, no, no. [40:47.930 --> 40:50.250] Today, we're in timeout. [40:51.850 --> 40:57.690] So, what I'm going to do is we think there might be some TLS. [40:57.690 --> 41:00.850] And then I'm blocking happening there. [41:01.110 --> 41:02.290] So, I will try. [41:02.670 --> 41:06.890] Go back to the server with the sync command. [41:07.650 --> 41:14.650] But, we will add the DLS fragmentation before the DNS over HTTPS. [41:14.950 --> 41:16.750] This is important. [41:17.230 --> 41:20.810] And you can think of why this is important. [41:21.150 --> 41:27.370] And what's the difference between putting it before the DLS and what's the difference between putting it after the DLS. [41:27.370 --> 41:32.730] But, at this time, when I try to run that, it will be pretty slow. [41:33.250 --> 41:35.810] Because we are querying DNS servers. [41:36.190 --> 41:37.910] We are doing TLS fragmentation. [41:38.650 --> 41:42.430] We try to run out things to timeout. [41:42.990 --> 41:43.010] Okay. [41:43.010 --> 41:43.210] Let's change. [41:51.600 --> 41:55.880] Let's say, hopefully, it will be working this time. [41:56.200 --> 42:00.980] But, if not, I will try to see whether or not. [42:02.580 --> 42:03.720] Backexample.com. [42:05.240 --> 42:10.960] I'm going to try to really ensure the SOAP session is good. [42:11.840 --> 42:17.160] I will try to affect the IP info from the SOAP session. [42:17.160 --> 42:19.620] So, come to Enrico. [42:20.080 --> 42:21.740] So, basically, the SOAP session, I think. [42:22.000 --> 42:22.280] Yeah. [42:22.480 --> 42:23.520] So, the DLS timeout. [42:23.840 --> 42:27.300] Or, we need to refresh the SOAP session. [42:28.640 --> 42:29.180] Sure. [42:29.840 --> 42:31.000] But, yeah. [42:31.100 --> 42:32.220] I can talk to that. [42:32.460 --> 42:35.260] And people feel free to ask any questions. [42:39.540 --> 42:40.420] Yeah. [42:41.180 --> 42:42.700] Some final insights here. [42:45.300 --> 42:47.480] For the . [42:49.660 --> 42:52.140] We have an app called Enrico. [42:52.760 --> 42:54.220] And it's pretty useful. [42:54.620 --> 42:59.260] You can use that to find apps without needing a process. [43:00.940 --> 43:02.760] And let's recap. [43:03.060 --> 43:04.480] So, we talked about . [43:04.480 --> 43:06.500] We talked about apps. [43:06.500 --> 43:07.540] Some apps. [43:07.840 --> 43:09.520] And there are a lot of third-party apps. [43:10.020 --> 43:10.140] There. [43:10.400 --> 43:11.380] And you can... [43:11.380 --> 43:12.140] You all have . [43:12.780 --> 43:16.240] And here are our own open-source resources. [43:16.520 --> 43:16.920] You can use. [43:17.260 --> 43:20.660] We publish or are called on GitHub.com. [43:20.940 --> 43:22.480] So, it's all public. [43:23.460 --> 43:24.080] Thanks. [43:24.400 --> 43:25.560] And any questions? [43:27.420 --> 43:27.860] Yeah. [43:28.360 --> 43:29.220] Thank you. [43:29.220 --> 43:30.220] Thank you. [43:36.770 --> 43:39.770] You're funding from Google, right? [43:40.550 --> 43:41.230] Yeah. [43:41.430 --> 43:41.830] For funding. [43:42.750 --> 43:44.350] By Google, . [43:45.170 --> 44:03.090] In spite of Google's, like, social responsibility efforts, Google wants to give back to the community, So, it's been a fascinating meeting in this area, and we have both done that, but it's really always a rule to use that to the society. [44:03.710 --> 44:08.610] How would you be sure that you're in the actual world? [44:08.930 --> 44:09.930] I'm sure I'm sure I'm sorry. [44:11.170 --> 44:11.650] I'm great. [44:13.990 --> 44:16.070] Yeah, I hear that. [44:17.690 --> 44:22.610] And we've been married in this community for like eight years, right? [44:23.130 --> 44:28.610] And the way we address those problems is by making the code fully authors works. [44:29.350 --> 44:35.950] They can go and back and we also have screen audits by recognizing the digital rights community. [44:37.030 --> 44:43.710] And if you're running on nerves, you can expect the federal original push. [44:43.870 --> 44:45.130] We don't see that. [44:45.130 --> 44:48.990] And you can more view of all the traffic, like off-by-use and off-to-google traffic. [44:52.550 --> 44:55.130] But you can see any more problems. [44:56.910 --> 44:58.030] Okay, cool. [45:00.230 --> 45:07.030] Yeah, well, it is on time, but if you have any questions, you can try more things. [45:07.350 --> 45:10.830] Feel free to join us at workshop at VPN today. [45:10.830 --> 45:15.490] And you can see the enchanted photography, I guess, in the week. [45:16.130 --> 45:16.850] Thank you. [45:17.430 --> 45:18.150] Thank you. [45:18.150 --> 45:18.270] Thank you.