Skip to content
Permalink
master

Commits on May 11, 2021

  1. transports/meek_lite: Bump the version of the utls fork

    And add the Chrome 83 fingerprint.
    Yawning committed May 11, 2021

Commits on Dec 17, 2020

  1. Actually support unsafe logging.

    Obfs4proxy implements the -unsafeLogging switch but it's been ignored so
    far.  This patch makes it work.
    NullHypothesis committed Dec 17, 2020

Commits on Dec 7, 2020

  1. Update Azure's root CA certificate pins.

    Microsoft recently updated the root CA certificates that are served to
    Azure clients.  See the following article for more details:
    https://docs.microsoft.com/en-us/azure/security/fundamentals/tls-certificate-changes
    
    This change broke meek-lite because none of its pins work anymore.  That
    means that Tor Browser users can no longer use meek-azure or moat as
    both rely on meek-lite.
    
    This patch fixes the problem by updating the certificate pins.
    
    Signed-off-by: Yawning Angel <yawning@schwanenlied.me>
    NullHypothesis authored and Yawning committed Dec 7, 2020

Commits on Apr 10, 2020

  1. common: Replace the extra25519 import with an internal package

    I really didn't want to do this, but this should make `go get` work
    again, and maybe people will leave me alone.
    Yawning committed Apr 10, 2020

Commits on Jun 21, 2019

  1. obfs4: Alter tear down behavior to be less distinctive

    The old behavior closed the connection on handshake failure after:
     * The first N bytes (random on a per-server basis).
     * The first M seconds (random on a per-server basis).
    
    Whichever came first.  As Sergey Frolov kindly points out, depending on
    which conditions cause termination, the server will send either a FIN or
    a RST.  This change will remove the "amount read" based termination
    threshold, so that connections that cause failed handshakes will discard
    all data received until the teardown time is reached.
    
    Thanks to Sergey Frolov for bringing this issue to my attention.
    Yawning committed Jun 21, 2019

Commits on Apr 12, 2019

Commits on Mar 30, 2019

  1. transports/meek_lite: More utls related changes

     * Bump the module import to a new tag
     * Bump the rest of the dependencies while I'm here
     * Add some new fingerprints from upstream
     * Disable my fork's AES timing sidechannel defenses
    Yawning committed Mar 30, 2019

Commits on Mar 18, 2019

Commits on Feb 5, 2019

  1. transports/meeklite: Bump the tag for the utls fork

    Upstream fixed a bug, so use a tag that has the important parts
    cherry-picked.
    Yawning committed Feb 5, 2019

Commits on Feb 4, 2019

  1. transports/meek_lite: Switch to pinning MS's CA intermediary certs

    This should give me more time before I need to update this.
    Yawning committed Feb 4, 2019
  2. transports/meek_lite: Add an expiry date for HPKP entries

    Mostly since the built-in pins will likely become invalid once the
    certificates I used to generate them start to expire.
    Yawning committed Feb 4, 2019
  3. transports/meeklite: Add a lightweight HPKP implementation

    HPKP is effectively dead as far as a standard goes, but the idea has
    merit in certain use cases, this being one of them.
    
    As a TLS MITM essentially will strip whatever obfuscation that the
    transport may provide, the digests of the SubjectPublicKeyInfo fields
    of the Tor Browser Azure meek host are now hardcoded.
    
    The behavior can be disabled by passing `disableHPKP=true` on the bridge
    line, for cases where comaptibility is prefered over security.
    Yawning committed Feb 4, 2019

Commits on Feb 3, 2019

  1. transports/meeklite: Use a modified version of utls

    Changes:
     * Use a fork of utls with some compatibility improvements.
     * Switch the default ClientHello profile to `HelloFirefox_Auto`.
     * Add the `HelloChrome_71` profile.
    
    The existing `HelloFirefox_Auto` profile that points to
    `HelloFirefox_63` also matches the (common) behavior of Firefox 65,
    assuming that 3DES ciphersuites are not disabled.
    Yawning committed Feb 3, 2019

Commits on Feb 1, 2019

  1. fixup! transports/meeklite: uTLS for ClientHello camouflage

    Fix `getDialTLSAddr` to always return a integer port.  Thanks to dcf for
    reporting the issue.
    Yawning committed Feb 1, 2019

Commits on Jan 21, 2019

  1. transports/meeklite: Add utls argument to configure behavior

    Per dcf:
    > As for the TODO, my plan was was to expose a "utls" SOCKS arg
    > to make it configurable per bridge, and just reuse the utls
    > Client Hello ID names:
    >	utls=HelloChrome_Auto
    
    This adds support for all currently supported utls ClientHello IDs
    with the following caveats/differences:
    
     * `none` - Disables using utls entirely, forces `crypto/tls`.
     * `HelloGolang` - Alias of `none`, since using utls is pointless.
     * `HelloCustom` - Omitted as pointless.
    Yawning committed Jan 21, 2019
  2. transports/meeklite: uTLS for ClientHello camouflage

    There's still some interesting oddities depending on remote server and
    what fingerprint is chosen, but I can watch videos online with the
    chosen settings and the TBB Azure bridge.
    
    Note: Despite what people are claiming in the Tor Browser bug tracker
    it isn't all that hard to use the built in http client with utls.  And
    yes, the `transport.go` code does negotiate correctly in a standalone
    test case (apart from compatibility related oddities).
    Yawning committed Jan 21, 2019

Commits on Jan 20, 2019

  1. transports/meeklite: Cleanups, bugfixes and improvements

     * Properly close the response body on HTTP error.
     * Cleanup close signaling.
     * Write() should return faster on closed connections.
    Yawning committed Jan 20, 2019
  2. Bump the version to 0.0.9-dev

    Yawning committed Jan 20, 2019
  3. Fix missing field size in obfs4-spec.txt

    Thanks to @SudoHenk on github for pointing out the issue long ago.
    Yawning committed Jan 20, 2019

Commits on Jan 19, 2019

  1. Clean up static analysis warnings

    Mostly but not entirely discarding error return values of things that
    can not possibly fail despite the API returning errors.
    Yawning committed Jan 19, 2019
  2. Annotate use of deprecated net/http/httputil package

    This is to silence some of the static analysis tools used in
    development.  Despite `http.Client` and `http.Transport` being
    suggested as an alternative, there is no way to accomplish current
    functionality with either suggested replacement.
    
    See: golang/go#8285
    Yawning committed Jan 19, 2019

Commits on Jan 16, 2019

  1. Change the canonical upstream repo location to gitlab

    This commit changes the upstream repo location to:
      https://gitlab.com/yawning/obfs4.git
    
    Additionally all the non-`main` sub-packages now have an import
    comment annotation.  As a matter of courtesy, I will continue to
    push to both the existing github.com and git.torproject.org repos
    for the foreseeable future, though I reserve the right to stop
    doing so at any time.
    Yawning committed Jan 16, 2019
Older