Project X
学到了特朗普的秦始皇摸电线,赢麻了
那必然是赢麻了啊,任某些人再说 uTLS 不是真的浏览器,REALITY 还有一些未解决的特征啥的,是是是说得都对,然而大趋势就是 SNI 豁免/白名单,这一点我早就说过了 REALITY 是永远绕不开的解决方案,那么再往后是什么?XHTTP,XDRIVE,verifyPeerCertByName,管某些人再说是滥用什么的,能应对极端环境就是强,当某些人还在搞我几年前早就说过的 Seed 再反踩 Vision 一脚的时候我早就不 care 这些了,我发力的方向早就变了,人与人之间的差距怎么就那么大呢
👍78❤10⚡6🔥3
Forwarded from GitHub
🔨 1 new commit to Xray-core:main:
6a909b2: Proxy: Add Hysteria 2 inbound & transport (supports listening port range, Salamander finalmask) (#5679)
https://github.com/XTLS/Xray-core/pull/5679#issuecomment-3888548778
Closes https://github.com/XTLS/Xray-core/issues/5605 by LjhAUMEM
6a909b2: Proxy: Add Hysteria 2 inbound & transport (supports listening port range, Salamander finalmask) (#5679)
https://github.com/XTLS/Xray-core/pull/5679#issuecomment-3888548778
Closes https://github.com/XTLS/Xray-core/issues/5605 by LjhAUMEM
🎉49👍7⚡4❤1
Forwarded from Nikita Korotaev
The New Year is approaching, and I want to thank everyone who supports xray-core - financially, through code contributions, or in any other way.
Regardless of the size of the contribution, every single one is important and valued. It is because of you that the project continues to grow and remain alive.
Thank you for your participation, your support, and your contribution to our shared mission 🎄🐎🎇🎊
Regardless of the size of the contribution, every single one is important and valued. It is because of you that the project continues to grow and remain alive.
Thank you for your participation, your support, and your contribution to our shared mission 🎄🐎🎇🎊
❤96🎉18👍4
Forwarded from GitHub
💬 New comment on Xray-core#5645 XDRIVE transport: The first remote-storage-service-based proxy, ignoring IP whitelists
by @RPRX
> Local 不只是示例吧我觉得,网盘客户端基本上都自带“本地文件夹多端同步服务”,XDRIVE 的想法最初也是由此启发,这也意味着不一定需要 API ~~且可以“滥用”几乎所有网盘,只是延迟可能会有十秒~~
Reply to this message to post a comment on GitHub.
by @RPRX
> Local 不只是示例吧我觉得,网盘客户端基本上都自带“本地文件夹多端同步服务”,XDRIVE 的想法最初也是由此启发,这也意味着不一定需要 API ~~且可以“滥用”几乎所有网盘,只是延迟可能会有十秒~~
Reply to this message to post a comment on GitHub.
👍31⚡4👀3🔥2❤1
Project X Channel
AI 还没有看到后面我写的“不正经用法”,我再解释下: 1. 绝大多数网站支持 domain fronting(CDN 一般只支持同一个账号下的),再加上大站都有 anycast 提供了合理性,也就是说比如即使 SNI www.googleapis.com 被封,你使用 www.google.com 作为 SNI 也能连上,审查者看不到内层 HTTP host 所以无法阻断连接,除非封掉整个 IP,附带伤害拉满 2. 绝大多数网站的 TLS 配置,若 SNI 不存在于服务器上则会返回“默认证书”,也就是说你甚至可以使用…
发现很多 GUI 客户端加了 pinnedPeerCertSha256(pcs)但还没加 verifyPeerCertByName(vcn),其实我觉得后者可玩性更高一些
补充一点,这两个是可以一起用的,比如你可以用 pcs pin 一些 CA 证书,然后再用 vcn 对 leaf 证书进行验证,这比直接 pin leaf 更方便
补充一点,这两个是可以一起用的,比如你可以用 pcs pin 一些 CA 证书,然后再用 vcn 对 leaf 证书进行验证,这比直接 pin leaf 更方便
xtls.github.io
传输配置 | Project X
Xray-core
👍34😁3❤1
?不是哥们,就这?我寻思我早就把 REALITY 库的改成 32 了啥时候被改回去了 https://github.com/XTLS/REALITY/commit/dc9a7cef8e8007bce8f73fc2957e57a8b70a4f82
甚至当时还留了个 TODO https://github.com/XTLS/REALITY/blob/cd53f7d5023741301aabb5a7274ed0dd024fbd2c/tls.go#L375
甚至当时还留了个 TODO https://github.com/XTLS/REALITY/blob/cd53f7d5023741301aabb5a7274ed0dd024fbd2c/tls.go#L375
GitHub
crypto/tls: set const maxUselessRecords to 32 (the same with OpenSSL) · XTLS/REALITY@dc9a7ce
https://github.com/golang/go/pull/58913
👍79😁63❤9👀5⚡2
Project X
Photo
关于我对 REALITY、uTLS、鹦鹉已死,以及 Sukka 那些人的一些看法:
https://github.com/XTLS/BBS/issues/16
https://github.com/XTLS/BBS/issues/16
GitHub
关于我对 REALITY、uTLS、鹦鹉已死,以及 Sukka 那些人的一些看法 · Issue #16 · XTLS/BBS
更新:从双重标准到“大新闻”:浅谈代理协议设计与实现上的一些本质问题与优先级区别 https://blog.skk.moe/post/to-kill-a-parrot-detecting-xtls-vless-reality-server/ web archive 没存到,这原文就别改了吧 通篇看下来,你就会发现上述文章的核心重点并非技术,而在于“攻击 RPRX”,至于为什么这么恨我,前因是...
👍145😁14❤5🎉2🔥1👀1
Forwarded from Nikita Korotaev
Friends,
What happened today - and precisely on the eve of the Chinese New Year - was bound to happen sooner or later. And it is good that it happened without consequences and without any harm to users. Most importantly, it brought a crucial outcome: the masks have finally fallen.
The XTLS community has once again proven that the principles of a free internet are not slogans. They are the daily work of many contributors, a shared sense of responsibility, and a collective readiness to stand against censorship - regardless of the country we live in or the language we speak. For every challenge we face, our community has an answer: code, engineering solutions, and, most importantly, unity.
At the same time, it became clear that there are communities that speak about internet freedom, yet at decisive moments choose a different path - delivering information to the censor and undermining the very principles they claim to defend. The difference between words and actions revealed itself.
I am proud that the XTLS community once again stands one step ahead - technologically, strategically, and in values. This once more confirms the maturity of both the community and the solutions it builds.
May the new year bring us new victories, new technologies, and new goals. And those who chose to stand against the idea of a free internet will inevitably remain on the sidelines of history.
We move forward - together 🤝
What happened today - and precisely on the eve of the Chinese New Year - was bound to happen sooner or later. And it is good that it happened without consequences and without any harm to users. Most importantly, it brought a crucial outcome: the masks have finally fallen.
The XTLS community has once again proven that the principles of a free internet are not slogans. They are the daily work of many contributors, a shared sense of responsibility, and a collective readiness to stand against censorship - regardless of the country we live in or the language we speak. For every challenge we face, our community has an answer: code, engineering solutions, and, most importantly, unity.
At the same time, it became clear that there are communities that speak about internet freedom, yet at decisive moments choose a different path - delivering information to the censor and undermining the very principles they claim to defend. The difference between words and actions revealed itself.
I am proud that the XTLS community once again stands one step ahead - technologically, strategically, and in values. This once more confirms the maturity of both the community and the solutions it builds.
May the new year bring us new victories, new technologies, and new goals. And those who chose to stand against the idea of a free internet will inevitably remain on the sidelines of history.
We move forward - together 🤝
❤166👍38🔥11👀4⚡3🎉1
Project X Channel
关于我对 REALITY、uTLS、鹦鹉已死,以及 Sukka 那些人的一些看法: https://github.com/XTLS/BBS/issues/16
从双重标准到“大新闻”:浅谈代理协议设计与实现上的一些本质问题与优先级区别:
https://github.com/XTLS/BBS/issues/19
https://github.com/XTLS/BBS/issues/19
GitHub
从双重标准到“大新闻”:浅谈代理协议设计与实现上的一些本质问题与优先级区别 · Issue #19 · XTLS/BBS
过年期间比较忙,这文章前天写了一半,今天才写完发出来 有人说代理圈春晚 #16 比 CCTV 春晚更精彩,我不知道,不过这又是反转又是原作者现身指责 Sukka 剽窃洗稿想搞个大新闻又是原东家现身要送他二进宫的剧情也确实挺混乱的(另外 Surge 群和作者觉得被波及了,从去年你说什么 AI 支持只要几个小时什么垃圾协议啥的你群就开始政治正确了,Sukka 黑我的文章就能发、带动群内一阵高潮,...
👍96👀10😁9❤3
Project X Channel pinned «从双重标准到“大新闻”:浅谈代理协议设计与实现上的一些本质问题与优先级区别: https://github.com/XTLS/BBS/issues/19»
Project X
Photo
Telegram
Project X Channel
人家公开征求意见,我只是提出了我的意见罢了
在我看来《网络犯罪防治法》(征求意见稿)唯一的进步是“翻墙相关不入刑”,毕竟以前想判你但实际上是无法可依、法无禁止皆可为,只能安上奇奇怪怪的入刑的罪名,辩护律师找得好还能给辩个无罪释放,新法补上了这个漏洞并且专注于搞钱,辅以十几天的收留教育,但是给你来个“数罪并罚”的话也不是不能把你送进去
最大的退步是新法实质上违宪,虽然宪法也不是不能改,但是按人类社会的进步速度来说相关条款可能几十年后就会被推翻了,到时候各种翻案追责清算是少不了的,成堆的国家赔偿也是一大笔纳税人的钱…
在我看来《网络犯罪防治法》(征求意见稿)唯一的进步是“翻墙相关不入刑”,毕竟以前想判你但实际上是无法可依、法无禁止皆可为,只能安上奇奇怪怪的入刑的罪名,辩护律师找得好还能给辩个无罪释放,新法补上了这个漏洞并且专注于搞钱,辅以十几天的收留教育,但是给你来个“数罪并罚”的话也不是不能把你送进去
最大的退步是新法实质上违宪,虽然宪法也不是不能改,但是按人类社会的进步速度来说相关条款可能几十年后就会被推翻了,到时候各种翻案追责清算是少不了的,成堆的国家赔偿也是一大笔纳税人的钱…
👀41❤2😁2
鱼鱼的超级机场丨闭眼入 不后悔
经过评估,我们将在 未来三天内 将所有节点传输协议统一升级为 XHTTP,并陆续为大家下发新配置。 相比 WS,XHTTP 更贴近正常 HTTPS 流量形态,特征更自然,在当前网络环境下整体稳定性与抗干扰能力更好。简单说 —— 更稳。 ⸻ 使用上的变化请注意: • ❌ 所有基于 Mihomo 核心的软件将无法继续使用 包括 Clash Meta、Clash for Windows、Clash for Android 等 ⸻ 我们的建议: • iOS / macOS:使用 Shadowrocket…
Telegram
Nikita Korotaev in Project X
The censor blocks completely random traffic.
In Russia today, no one is willing to take the risk of using a compromised or insecure protocol, especially when better alternatives exist.
Yes, of course, there are outliers who still use Shadowsocks, but the…
In Russia today, no one is willing to take the risk of using a compromised or insecure protocol, especially when better alternatives exist.
Yes, of course, there are outliers who still use Shadowsocks, but the…
😁35👍10❤8⚡1
Project X
美国国务院即将推出“http://Freedom.gov”平台:数字自由的新武器,还是外交新战场? (罗翔——破幕推墙独家报道,2026年2月21日,纽约) 在美国特朗普第二任期内,国务卿马尔科·卢比奥(Marco Rubio)主导的一项大胆数字外交举措正进入最后冲刺阶段:名为“http://Freedom.gov”的在线平台即将正式上线。该平台旨在为中国、伊朗、俄罗斯等实施严格网络审查的国家民众,以及面临内容监管的欧洲用户,提供绕过本地封锁、访问“美国式开放互联网”的工具。这一项目被视为美国重振“数字自…
这平台不是只针对欧洲的网络审查的吗咋还把俄罗斯和伊朗扯进来了,如果要在这两个国家也能用的话。。。千万别找我哈我可不敢和美国 gov 扯上任何境外势力的关系,建议聘请你国 wkrp 教授作为首席顾问
不过如果能做到境外运营商配合的话,或许可以实现那个大胆的想法
Telegram
Nikita Korotaev in Project X
I have tried many public and private solutions - from simple ones we all know, including naive, to openly experimental ones like *overRTC (and with the rise of AI and vibe-coding, there will only be more of these).
Yes, they work. But the real question is:…
Yes, they work. But the real question is:…
😁55👀8❤3