反贼网
Machine translation · the Chinese original is authoritative · View original

Teacher Li: Safe VPN Guide

1# · OP Author:反賊文摘 Published:2025-09-29 22:22 Replies:0 Views:100 Permalink:fanzei.net/d_2222tq

With the recent tightening of China's GFW (Great Firewall), various "airports" (VPN/shadowsocks providers) being affected one after another, and the establishment of "walls within the wall" in some provinces, how domestic netizens can safely bypass the firewall to access the internet is becoming increasingly important. In addition, as many people have recently been "invited to tea" (interrogated by police) for bypassing the firewall, we have decided to produce a safe circumvention guide to provide some reference for everyone. This guide will provide corresponding internet safety risk points and safety measure recommendations based on different user personas (such as ordinary users, political commentators/keyboard politicians, and activists) and usage scenarios.

Basic Section: Essential Safety Common Sense No matter what type of user you are, the following are the most fundamental points to ensure safe internet access:

  1. Device Selection Currently, the vast majority of newly manufactured domestic Chinese Android phones are required to have a built-in Anti-Fraud Center app or services with similar monitoring functions. This will greatly increase the probability of your circumvention behavior being detected, and you may even be unable to install circumvention tools. Therefore, it is recommended to use an iPhone or Google Pixel dedicated solely to bypassing the firewall.

Avoid using domestic Chinese input methods: Input methods such as Baidu, iFlytek, and Sogou basically upload your daily usage data. If possible, please use Google's Gboard or Apple's built-in input method.

Avoid using domestic Chinese browsers and ecosystem software: For example, UC Browser, QQ Browser, 360 Browser, 360 Safeguard, etc. Please use international mainstream browsers such as Chrome, Firefox, and Safari.

Avoid using domestic Chinese email addresses and phone numbers to register for overseas software: Since domestic phone numbers and email services can directly detect and block login verification codes from overseas apps, please use foreign email services such as Protonmail, Gmail, and Outlook, and consider using virtual numbers generated by SMS receiving platforms for registration, especially for Telegram and X.

  1. VPN and Network Environment Choose circumvention tools carefully: Stick to well-known tools listed on overseas app stores, such as Shadowrocket, Clash, etc. Never download any so-called "VPN" or "accelerator" from domestic Chinese Android/Apple app markets.

Avoid using domestic payment methods to purchase as much as possible: Purchasing VPN services using domestic payment methods (such as Alipay, WeChat Pay) will leave clear digital footprints. If you do not have an overseas SIM card, you can consider paying with cryptocurrency or gift cards.

Avoid bypassing the firewall under public or monitored networks: Campus networks and corporate networks usually deploy behavior management/logging equipment. Previously, some universities have explicitly publicized that campus networks detect circumvention behavior. Although they may not necessarily be able to decrypt your traffic content, they can easily record "who connected to a suspicious overseas server at what time."

  1. Clarify Concepts What we need to understand is that any preventive action only reduces the risk of exposure, rather than achieving "complete concealment." Anonymity does not equal invisibility—rather than obsessing over "making sure the police have absolutely no idea who you are," it is better to focus on reducing "whether others can recognize that you and your account are the same person."

Based on our observations over the past few years, what actually tends to expose users is often their behavioral characteristics (sharing their lives across all social media simultaneously, using the same profile picture/username/tone of voice as on domestic software, device fingerprints, online payments, fixed online schedules, etc.).

Since the vast majority of users who bypass the firewall do not initially realize the need to deliberately conceal their identity, identifying who you are through social engineering is far simpler than through other technological means.

User Scenarios and Safety Recommendations

I. Ordinary Surfing Users The main purpose of these users bypassing the firewall is to browse information, watch videos, and look up materials, without involving the posting and discussion of sensitive political content.

Risk Points: Personal privacy leakage (browsing history, account information being tracked); passive identity association (linking domestic and overseas identities); encountering phishing and scams.

Safety Measure Recommendations:

  1. Isolate the browsing environment: Use a dedicated phone for bypassing the firewall as much as possible; or use an independent browser (such as Firefox) on your computer and create a dedicated profile for it. Under this environment, do not log into any accounts related to your real identity (such as domestic social media accounts, Taobao, work WeChat, etc.).

  2. Minimize permissions and tracking: Deny all unnecessary permissions by default for websites or apps, such as photo library, contacts, location, microphone, camera, Bluetooth, notifications, etc. Disable third-party cookies and cross-site tracking in browser settings, and prohibit web pages from automatically downloading files.

  3. Independent account system: Do not register for software if you don't have to. If registration is necessary, please use an independent overseas email (such as Gmail, Protonmail) and a unique strong password. It is recommended to let a password manager generate it and then manually add a few characters yourself, and enable two-factor authentication (2FA)—this is crucial.

  4. Guard against phishing: Stay vigilant against messages like "account anomaly" or "winning a prize/subsidy," and do not click links directly. Some phishing emails will disguise themselves as official emails or your friends' emails; when viewing emails, be sure to confirm the source.

Be wary of direct messages from strangers on platforms like X (Twitter), especially those involving money or pornography (for example, never believe that a beautiful woman would actively want to have a naked video chat with you).

  1. Regularly clean up traces: Try to clean up browser history, cookies, cache, and download directories once a week if possible.

If you really don't have the energy, doing at least three things can protect your safety: do not log in on dedicated devices or browsers, minimize all permissions, do not click unknown links, turn off synchronization, and keep account identities independent. Doing these three things can significantly reduce the risk of exposure.

II. Users Participating in Online Discussions (Keyboard Politicians/Political Commentators, Content Creators) In addition to browsing, these users also speak on overseas platforms, participate in political discussions, or publish content. Their risk level is much higher than that of ordinary users.

Risk Points: Identity being uncovered through social engineering methods. Online speech being tracked and associated with real-world identity. Digital footprints (device fingerprints, IP addresses, behavioral patterns) being used for identity positioning.

Safety Measure Recommendations:

  1. Establish a completely independent digital identity: Physical isolation: Be sure to use independent and secure devices (phones, computers) that are completely separated from your domestic identity and devices.

Identity isolation: Use an independent nickname, profile picture, email, and phone number. This set of identity information should not have any association with any information you use domestically.

Network isolation: [Special Reminder] Try not to use the same Wi-Fi network for devices with domestic apps installed and devices used for safe internet access, to prevent passive identification at the network level.

  1. Cut off all association channels: Turn off all cloud synchronization functions for history, bookmarks, and passwords. Never share clipboards, cloud drives, input methods, or screenshot directories with your primary device.

  2. De-characterize content creation: Text: Control your habitual catchphrases, punctuation frequency, and sentence rhythm. It is recommended to complete complex content offline first and rewrite it before publishing.

Images/Videos: Be sure to check and clear metadata before publishing. An effective method is to save the image/video and then crop it, which will generate new image/video metadata, avoiding being tracked through the original image/video's metadata.

When publishing images/videos you took yourself, avoid showing any details that might expose your geographical location, living environment, or personal appearance. Information about yourself must be redacted, and it must be completely redacted. For example, with your courier information, some people only hide their delivery address, phone number, and name, but do not hide the tracking number and the time on the shipping label, which allows direct tracking to you through the tracking number, or they only apply partial mosaic, which still allows you to be found through time-node comparisons.

Audio: If you must participate in voice conversations, please use a voice changer to prevent voiceprints from being collected and compared.

  1. De-characterize behavioral patterns: Randomize your online periods and posting intervals to avoid forming a stable pattern synchronized with your real-life daily routine.

  2. Strengthen account security: Adhere to the "one account, one password, one email" principle as much as possible, and enable two-factor authentication for all accounts. Disable all third-party one-click login functions.

Since netizens who want to participate in political discussions face a much higher risk of exposure than those who only want to browse, any detail of life can become a clue for exposure. Therefore, the safety mindset must be elevated from reducing traces to cutting off the association between the network and real-world identity.

III. High-Risk Activity Users (Activists intending to participate in overseas activities) If you are already a hardcore veteran of bypassing the firewall, or even plan to engage in substantive anti-communist activities overseas, then you need to think of yourself as being in the "highest risk position," because any single instance of carelessness or mistake could lead to your identity being leaked and put you at risk.

Risk Points: Becoming a target of key focus, search, and analysis. Any single mistake can

can lead to complete identity exposure and bring severe consequences. Security vulnerabilities in team collaboration can lead to the entire team being implicated.

Recommended Security Measures:

  1. Conduct Threat Modeling: As an activist, you should calmly assess: What level of police force might be paying attention to you? What resources do they possess? What is the worst-case scenario you can endure? If exposed, do you have an emergency plan (such as a strategy in case you are arrested, leaving personal information behind in advance, and whether you are willing to receive international solidarity support, etc.).

  2. Higher Physical and Network Isolation:
    Triple Isolation: In addition to a domestic mobile phone and daily circumvention devices, there should also be a device dedicated exclusively to sensitive activities, achieving dedicated-device-for-dedicated-use. Physical Isolation: When conducting highly sensitive audio/video conferences, it is strongly recommended to put all mobile phones with domestic apps installed into Faraday bags (or completely power them off and seal them away) to prevent passive monitoring via microphones and cameras. Self-built VPN: If you have already reached this level and extent, try not to rely on commercial VPNs; learn to build your own dedicated circumvention channel.

  3. Strengthen Device and Data Security: Perform full-disk encryption on all devices and set strong screen lock passwords. Perform off-site encrypted backups of important materials, and set an "expire/destroy/rotate" policy. Keep the system and software updated to the latest versions, reducing persistent high-privilege software and startup items.

  4. Team Collaboration Security Guidelines: Least-to-Know Principle: Insist on the principle of "the minimum information necessary to complete the task" among team members. Process Standardization: Agree upon fixed devices, time windows, content templates, and publishing processes. Adopt a one-way workflow of "whoever produces it uploads it" to avoid account profiling confusion caused by frequent logins by multiple people. Two-Person Review: Establish a two-person review process before content goes live, and agree on reliable secondary verification code phrases and emergency contact channels.

  5. Zero Trust Principle: Maintain a "Zero Trust" attitude toward all external links and files. Do not click on short links, do not run scripts of unknown origin, and do not directly open compressed archives or Office macro files. If file transmission is indeed necessary, it should first be locally encrypted and packaged, with the password sent through another secure channel. Currently, Google supports online previews for commonly used document types on the market. You can put the file on Google to preview and view it. If it cannot be previewed, you need to conduct a deep check on whether the file is normal. Moreover, for documents like Office, WPS must never be used. The computer does not necessarily have to be completely free of WPS, but try as much as possible to view via online preview and avoid opening them directly locally.

  6. Emergency Response Plan: Once suspicious private messages, abnormal logins, abnormal device heating/power consumption, etc., occur, immediately stop updating and disconnect from the network. Use a clean device to change all related passwords, increase verification strength, and thoroughly review third-party application authorizations. If necessary, reinstall the operating system or replace devices after backing up data, and issue risk alerts to people who might be affected.

Lastly Beyond the technical level mentioned above, another greater risk remains personal information exposure at the "social engineering" level, such as being phished or boasting about things you participated in with friends on domestic social media. This kind of behavior is almost equivalent to turning yourself in.

In short, do not let a casual copy-paste, an erroneous login, or an unintentional conversation wipe out all the security redundancies you have accumulated over a long time.

Related topics Teacher Li Circumventing the Great Firewall VPN
Replies (0)

No replies yet — be the first to comment

Post a reply