From North America, and I’m going on vacation in china for a few weeks. I wonder if anyone knows if I’ll be able to access any of my self-hosted services over zerotier while I’m abroad?

Edit: To be specific, I’m hoping to ssh into my machine over zerotier in case I need to fix something and back up some photos to my home NAS via rsync or something

  • zero@feddit.xyz
    link
    fedilink
    arrow-up
    1
    ·
    8 hours ago

    Mobile roaming worked but not while connected to hotel Wi-Fi. I also got a VPN before I went to China, routed through Japan. It was slow as shit.

  • socsa@piefed.social
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    15 hours ago

    At first, it will probably work. But you will likely lose access after a few days and your servers will be scanned for exploits, so make sure your shit it up to date.

    Source: hosted an XMPP server which was summarily banned after 2 days of access from China and then probed/attacked repeatedly until I took it offline.

  • Ptsf@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    16 hours ago

    Bringing non-disposable technology to China is a mistake in most circumstances.

  • Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    15 hours ago

    I would not try to access a server from China. Can’t you let someone else take care of the machine in the meantime? It’s always a good idea to have some backup admin just in case.

    • Flax@feddit.uk
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      17 hours ago

      What are the risks, if you aren’t intending on doing anything illegal?

      • YiddishMcSquidish@lemmy.today
        link
        fedilink
        English
        arrow-up
        15
        arrow-down
        1
        ·
        edit-2
        17 hours ago

        They can load in spyware that follows you outside the country. Also the whole “if you aren’t intending to do anything illegal” bit really reads like all the piece of shit bootlicking conservatives after George Floyd.

        • Flax@feddit.uk
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          6
          ·
          edit-2
          17 hours ago

          They can’t do that unless they take your devices, gain admin access and install stuff onto it. You don’t just get spyware installed your phone simply by entering a country.

          Also the whole “if you aren’t intending to do anything illegal” bit really reads like all the piece of shit bootlicking conservatives after George Floyd.

          Except that is a whole different context. The argument doesn’t work if you’re a citizen of a country and granting your government more and more powers. It would apply maybe if you were a Chinese citizen. OP isn’t talking about moving to China or installing a similar government in their home country. They are going on holiday. You can behave yourself and cooperate with their requirements for a few weeks. If you are really against a country having powers to check your phone and devices and such as a matter of principle, not because you’ve got anything to hide, then don’t go.

          George Floyd was an American citizen murdered in his own country by the powers that were supposed to protect him. Big difference.

          Although I did take precautions myself, such as deleting my memes/downloads folder just in case I saved anything that could be offensive. But it didn’t matter because they didn’t check my phone anyway for simply being there.

          China itself cares the most about public disorder and foreign influence. As long as you aren’t intending on causing foreign interference in how they do things and are just going for purposes of tourism/adventure/meeting people, then you’ll be absolutely fine. They don’t really care enough about you to give you special treatment unless you are seen as a threat like that.

          • BCsven@lemmy.ca
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            2
            ·
            13 hours ago

            People have said that is exactly what happens. Some had full phone scan, other requirement is installing a china app and keeping it on your phone for your stay

            • Flax@feddit.uk
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              2
              ·
              12 hours ago

              I have never heard of that happening. surely that’ll take ages if they had to stick an app on every foreigner’s phone

              • zero@feddit.xyz
                link
                fedilink
                arrow-up
                1
                ·
                8 hours ago

                Foreigners will most likely have Alipay at least if you want to pay for stuff and use ride share.

              • YiddishMcSquidish@lemmy.today
                link
                fedilink
                English
                arrow-up
                1
                ·
                8 hours ago

                You have no idea how small these snooping apps can be. Like less than a megabyte and all your traffic goes through a server controlled by the pla and logs everything in and out of your phone whether your on mobile or Wi-Fi.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        15 hours ago

        China isn’t exactly know for rule of law. They could simply decide you are a criminal. When traveling international it is better to play it safe.

        If you really need a service I would either bring a disk drive with you or setup limited remote access for yourself that has minimal access. Remember they can force you to hand over things like passwords.

            • Flax@feddit.uk
              link
              fedilink
              English
              arrow-up
              1
              ·
              13 hours ago

              They can, but they probably won’t in all likelihood. You could get in a car accident on the way to the airport. Your aeroplane could also crash.

      • BCsven@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        13 hours ago

        You have to install an app on your phone and keep it their during your visit. Some people said they had a full phone scan done on entry. Don’t bring your regular phone bring a burner and don’t login to any of your accounts

        • Flax@feddit.uk
          link
          fedilink
          English
          arrow-up
          2
          ·
          12 hours ago

          You don’t. I went to China a few weeks ago and my phone was never of any suspicion or brought into question.

  • philpo@feddit.org
    link
    fedilink
    English
    arrow-up
    29
    ·
    2 days ago

    It depends. Very much. And this is the main problem: There isn’t “one” solution, you will need a few.

    The thing with the PRC is: Their great firewall isn’t “one big uniform block”. It’s fairly “variable”.

    For example: In Beijing,even 10 years ago, I could access google maps and Facebook without any issues(back then highly blocked) as long as my mobile phone was roaming. The second I was on wifi of course it was blocked. But even the cheapo VPN my colleague had did work out fine. Until the day the police started to prepare for the party convention - then suddenly my colleague couldn’t get out, neither could I with our company wifi and even my carefully crafted wire guard over HTTPs didn’t work - unless I was in the wifi of the hotel or our host company. There it did. Party congress over? Back to normal operations.

    If you travel through the country you will find that in one place solution A works, in another solution B. Generally the more rural (or closer to Tibet/Xinjiang/Myanmar) you get, the more restrictive it seems to be.

    Personally I would simply get there different commercial VPNs to make sure you have a choice to get out at all - there are various ones with a good PRC reputation. Most providers have trials as well. And then double tunnel through that if you can’t directly reach your usual VPN at home

  • CCMan1701A@startrek.website
    link
    fedilink
    English
    arrow-up
    19
    ·
    2 days ago

    tailscale worked some times, but seemed to depend on the location of the moon relative to the air speed of a nearby sparrow and it was really slow.

    • MysteriousSophon21@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 hours ago

      Zerotier is similiar - works sometimes but China’s firewall is constantly changing which ports/protocols it blocks, so setup a wireguard server on port 443 as backup (looks like normal https traffic) and test both before you go.

  • alcasa@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    15
    ·
    2 days ago

    Look into shadowsocks, or just normal vpn.

    Pandafan was quite reliable for me. You might also be able to diy with hk, sg or sk vps instances, but it was a lot of work and a misconfiguration will cut you off.

    • iopq@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      Normal VPN doesn’t work because they don’t mask themselves. Even Tor bridges don’t work because they are blocked.

      Shadowsocks is like 2018 advice, go directly to xray and forget about legacy software

      • alcasa@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        Yes, xray is better. Forgot about that. I think there had been a couple newer ones.

        The thing with gfw circumvention is that even older approaches work surprisingly often, as detection methods change and often detection depends on the amount of suspicious traffic. I had most success with a more conventional setup on a vps, but that was more for testing out stuff. Found commericial providers to be more reliable.

        VPNs work surprisingly often from what others tell me. They only block these occasionally. I think astrill and express often work. Just know that the ones that work, probably have chinese govt access.

        Yes, tor never works.

      • Flax@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        They worked for me most of the time. They cut off after like an hour of use. So I just switch between them.

        • iopq@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          So why not just use that just works all the time? I don’t want my internet voice call to cut in the middle and have to switch VPNs

  • TehNomad@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    As another user posted, how strict the firewall is depends on where you are (and if there are any special events). I heard that Wireguard doesn’t work because of deep packet inspeciton, but I was able to use Tailscale to my home network without problems when I was there last year. I also set up a xray vless-reality proxy on a VPS and Outline servers on Google cloud and those worked too.

    But the easiest method is to buy an HK eSIM for roaming (I used 3HK). I bought a month of LetsVPN but they booted me from the service for some random reason, so I changed to Mullvad which also worked too.

  • Flax@feddit.uk
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    2 days ago

    If you will be using roaming for mobile data in China, you won’t face any blocking.

    Accessing over cloudflare tunnels or just a normal exposed server works.

    VPNs work most of the time. But you can be cut off after like 30 minutes to an hour. I’d recommend only turning it on when you need it.

    I’ve been to China very recently.

    You will most likely face speed issues, although this may be due to the physical infrastructure itself connecting China to the outside internet isn’t really that stellar. As everything Chinese citizens typically use is hosted in China.

  • BaroqueInMind@piefed.social
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    5
    ·
    edit-2
    2 days ago

    People posting here don’t realize that CN gov IDs and allows certain traffic to get rerouted through a certain VLAN so they can do DPI and record every packet through a beefy expensive tap device to analyze the telemetry later, and potentially build a case against you. If they so choose. And they likely have the capability to trivially decrypt TLS.

    Don’t bring in any tech, don’t access your personal net back home, don’t expect any level of actual privacy or good intentions. Just do your business and keep your digital digital persona minimal while there.

    • Flax@feddit.uk
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      4
      ·
      edit-2
      18 hours ago

      Case against you for doing what exactly? Just don’t break the law. It’s not hard. They’re hardly going to care much about an average American going on holiday unless he intends on causing problems, a disruption, or potentially has useful information

      • BaroqueInMind@piefed.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        14 hours ago

        Extremely privileged of you to think that one can simply live a routine life thinking they are safe, while immigrants in the US aren’t breaking the law and still getting rounded up into concentration camps.

        China doesn’t have laws enshrined in its constitution to protect immigrants like the US does (yet the Executive Branch barely give a fuck about the law), so they (China) can do whatever they fuck they want. Not defending anyone, just illuminating it since I am ignorant af

        • Flax@feddit.uk
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          edit-2
          15 hours ago

          I actually see China and the USA as the same level now. Difference is that the USA doesn’t have cool railway infrastructure and whatever the heck is going on in Chongqing.

          I don’t really think China is going to want to cause an international incident, especially during a tourist drive. Although it can be risky if they want to take hostages.

        • Flax@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 hours ago

          Fair enough to be fair. I did make sure the passport I was using to enter China was that of a country with no political drama happening. It did allow visa free entry though as well, so that was nice.

    • BuoyantCitrus@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      they likely have the capability to trivially decrypt TLS

      Whoa. Anywhere to read more about this? Had not been paying close attention, didn’t realise that was so starkly the case.

  • yaroto98@lemmy.org
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    2 days ago

    From what I’ve read if you use a VPN it’s pretty simple to get past the great firewall of china. It’s also only technically illegal, and not really punished.

    • iopq@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Well, no, if you open a wireguard connection it well just get dropped in a minute. You need to do a lot more work than that

  • ag10n@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    15
    ·
    2 days ago

    What you’re asking is illegal where you’re going

    Best of luck to you

      • greyfox@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        18 hours ago

        Unauthorized VPNs (non government approved) are illegal in China. If a business needs their own they can get approval but they have to apply for those exceptions.

        It isn’t really enforced, probably especially so for non citizens, but if you do something they don’t like it is something they could use against you.

        You would probably be less breaking the law to just directly open up SSH and access that instead of tunneling through a VPN. Even though SSH can do tunneling of its own.

      • kristoff@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        15 hours ago

        You mean "copy the photos you have taken but you not want in your device if you would get checked on your way back out to a server in a hostile country " ?

        99.99% if the normal tourists do not have a personal server to store their photos. They use a commercial cloud. By using your personal server, you behave differently from 99.99% of the tourists.

        " Why do you keep your images to your personal server and not the cloud? What do you have to hide? "

    • iopq@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      You realize not only Google is blocked, but also Brave search, duckduckgo, everything but Russian and Chinese search engines? You can’t find anything on them except scams and SEO spam

      • ag10n@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 days ago

        Yes, I do know and realize that. Why it’s probably not a good idea to try connecting to your homelab lol

        • iopq@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          1 day ago

          Just connect, they don’t block random IPs for no reason. You need to transfer a lot of traffic to trigger something

      • Flax@feddit.uk
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        3
        ·
        2 days ago

        I found deepseek was good for using as a search engine. Lol.

    • Flax@feddit.uk
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      3
      ·
      2 days ago

      Not really. It’s a grey area. They don’t care about foreigners using vpns at all. It’s kind of expected. Foreign SIMs don’t even face blocks on mobile networks. If you’re going to a sensitive province of China, I think they’ll care slightly more, but as long as you’re not using the VPN to do something illegal, you’ll be okay.