65 pointsby timbill11 hours ago3 comments
  • usernomdeguerrean hour ago
    I get the impression that much of Xray's usage is in mainland China, do many other ecosystems use it? If not, why not?

    Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected.

    But perhaps they cover for usecases one doesn't see outside the gfw.

    • amritananda6 minutes ago
      You can also use it to get around captive portals where some traffic is still allowed. Some Airline flights where messaging services are free only check the SNI, so setting the Xray domain to whatsapp.com or something similar usually works.
    • ranger_danger13 minutes ago
      There are other countries that routinely block traffic like Iran or Russia, but there are also some simple methods that go right past the GFW many times, like VPN traffic that is tunneled through regular TLS, or even just plain SSH.

      The "new hotness" is randomizing your TLS fingerprints, as well as tunnel/proxy/VPN setups that utilize multiple endpoints at once to spread out the "suspicion" of all your traffic going through a single host all the time.

      • 6 minutes ago
        undefined
    • sekisusam25 minutes ago
      [dead]
  • eriwang9154 hours ago
    Xray-core's pinnedPeerCertSha256 treated an inserted leaf as the pinned cert, and the fix commit never called it a vulnerability.
    • LoganDark24 minutes ago
      Your LLM left out the clear hypocrisy and the part where the fixed version still had a vulnerability
  • cryptolobster4 hours ago
    The reaction to Xray-core is disappointing