I travel a lot and I don't like censored internet, in this article I'm discussing the various workarounds I put in place to circumvent restrictions.

3 points•alexfortin•9 days ago•3 comments•
As usual, all kind of feedback welcome (https://a.l3x.in/contact)

3 comments

ranger_danger9 days ago
You don't even need wireguard really, you could just use ssh -D by itself, then either your browser (or foxyproxy) or individual app can point to the local socks proxy, or you can use tun2socks to make a tun(4) network interface out of it. Optionally you can use a network namespace to only route certain apps through it.

Or ssh -w can do the tun(4) interface for you, and supports both layer 2 and layer 3.

True that it won't be using UDP (or sshuttle can fix TCP-in-TCP issues for you), but for my usecase it works out better anyway, as many places I frequent restrict UDP usage. Even China doesn't block SSH.

alexfortin9 days ago
Fair, I still have to find a place that restricts UDP but iirc WireGuard should offer TCP as well.

By the way, if you check out the repository's README it already shows the SSH use case, but why not to have WireGuard available too? with it there's no need to manually setup any application to use/not use SOCKS, it's as simple as click "Connect" in the WireGuard client and all the traffic including ICMP and what not is tunneled through the server. It can even be installed at the router level so to have all the LAN traffic tunneled automatically, can't easily do that with SSH.

Different use cases, not saying SSH isn't valid, I just prefer WireGuard UX.

alexfortin9 days ago
Meanwhile the Lobsters thread was taken down because I'm "self promoting" and I have to "get back in line with the guidelines". And they complain there's too much stuff written by LLMs nowadays...

Read the full thread on Hacker News →

Related stories