Hi everyone,

I’m currently facing some frustrating restrictions with the public Wi-Fi at my school. It’s an open Wi-Fi network without a password, but the school has implemented a firewall (Fortinet) that blocks access to certain websites and services, including VPNs like Mullvad and ProtonVPN. This makes it difficult for me to maintain my privacy online, especially since I don’t want the school to monitor me excessively.

After uninstalling Mullvad, I tried to download it again, but I found that even a search engine (Startpage) is blocked, which is incredibly frustrating! Here’s what happened:

  • The Wi-Fi stopped working when I had the VPN enabled.
  • I disabled the VPN, but still couldn’t connect.
  • I forgot the Wi-Fi network and reset the driver, but still no luck.
  • I uninstalled the Mullvad, and then the Wi-Fi worked again.
  • I tried to access Startpage to search for an up-to-date package for Mullvad, but it was blocked.
  • I used my phone to get the software file and sent it over, but couldn’t connect.
  • I searched for different VPNs using DuckDuckGo, but the whole site was blocked.
  • I tried searching for Mullvad, but that was blocked too.
  • I attempted to use Tor with various bridges, but couldn’t connect for some unknown reason.
  • I finally settled for Onionfruit Connect, but it doesn’t have a kill switch, which makes me uneasy.

Ironically, websites that could be considered harmful, like adult content, gambling sites and online gaming sites, are still accessible, while privacy-tools are blocked.

I’m looking for advice on how to bypass these firewall restrictions while ensuring my online safety and privacy. Any suggestions or alternative methods would be greatly appreciated! (If any advice is something about Linux, it could be a Problem, since my school enforces Windows 11 only PC’s which is really really igngamblingThanks in advance for your help

edit: did some formatting

edit2: It is my device, which I own and bought with my own money. I also have gotten in trouble for connecting to tor and searching for tor, but I stated that I only used it to protect my privacy. Honestly I will do everything to protect my privacy so I don’t care if I will get in trouble.

edit 3: Thanks for the suggestions, if I haven’t responded yet, that’s because I don’t know what will happen.

Airvpn, then use their advanced config to create a 443 tcp tunnel out to a single server. Then use that server’s IP in your OpenVPN config file. Route all traffic including dns inside the tunnel.

Traffic will look like all other web traffic - encrypted on standard web ports. You won’t even need to do a DNS lookup to start with and airvpn uses generic rDNS so it’s not super easy to figure out from their perspective.

Melody Fwygon
link
fedilink
324d

Typically, using your own VPN should suffice. Depending on your situation you can do other things as well. If you are unable to download these tools on the school network in question; do not attempt to do so again. Use a public or other network connection elsewhere to obtain the tools you need to bypass their crap.

For example, NextDNS could be helpful. By running their client app; ( https://github.com/nextdns/nextdns/wiki/Windows ) you can make sure all your DNS requests are encrypted. Similarly you could simply set up a local DNS server that you point Windows at which can redirect those requests over DNS-Over-(HTTPS or TLS) to a DNS provider of your choosing.

DNS over HTTPS is your best bet because they can’t Man In The Middle and replace it (DNS Poison) like good old DNS. They will still be able to see the IP addresses you are connecting to unless you proxy those connections. nativeproxy uses Chromium’s stack so it is much harder to detect. There are UI frontends for it if you prefer but I’ve never used them. ProtonVPN also has a stealth protocol that I’ve heard is good, though I don’t know too much about it.

Good on you for trying to get around it. That kind of curiosity is a great way to develop your lateral thinking skills. You didn’t ask for a lecture and people giving you one should go back to stack overflow comments. If you want to take the risks of it, that is up to you and you are likely to fuck up. That being said, you aren’t the only person likely go get in trouble if you fuck up and, unlike you, IT will depend on their job financially. If you do it well enough and make sure you don’t get caught by someone seeing your screen or blagging around the school that you did it, that won’t be an issue.

IT departments also read comments in threads like this to find the current trends of how students are trying to get around their web blockers so keep in mind that you will need to keep your skills up to date.

Seems like Tor snowflake is a proxy that makes your internet traffic appear as a video call. Its purpose is to circumvent censorship, but it may get around firewalls as well. I have no experience bypassing firewalls using snowflake, but it may be a viable option (someone correct me if I’m wrong) https://snowflake.torproject.org/

Don’t use the school’s wi-fi? I’m sure there are other options to you.

You’re going to get in trouble and it’s not worth it.

Don’t do personal stuff on their network. What are you even trying to look at via the school network?

If you’re concerned about privacy while doing school stuff, use another device, or maybe a VM. Do they provide computers for students?

You might get off with a warning because you’re young (I assume you’re like 16), but bypassing network security stuff as an adult at work will often get you fired.

Mubelotix
link
fedilink
825d

I beg to differ. Everyone should have a right to access a free Internet. The censorship they are taking about is so broad that it cannot be accepted. In France the school could get highly punished if they dared to make comments on their harmless Internet activity

The rights everyone should have is irrelevant to the reality. You can’t steal a sandwich and be like “everyone should have the right to food!”. I mean you can, but you’ll still be punished.

Is this the hill for this kid to die on? Probably not. If they were trying to change the system for everyone to be more just, maybe.

Mubelotix
link
fedilink
024d

You will not be punished for stealing a sandwich where I live. The judge would laugh at the plaintiff

That’s not the point? The school provides a service and is (probably) not obliged to do so. If the school sets rules on this services, it’s OPs choice to either use or not use that service. 🤔

Mubelotix
link
fedilink
0
edit-2
24d

Shall we be content to obey them, or shall we endeavor to amend them, and obey them until we have succeeded, or shall we transgress them at once?

Noli equi dentes inspicere donati.

Mubelotix
link
fedilink
124d

If this is public school and you are a citizen, you should

Sounds like DNS blocking. Use DoH, won’t be as good as a VPN but it will stop the sniffing which allows them to block domains

Whats DoH? Department of health?

DNS over HTTPS

If you try to browse to the tailscale website does it work?

If it does you could setup tailscale with an exit node at your house and tunnel your connection that way? Everything would then be coming from your home internet. I have had good success with tailscale being able to punch a hole through some pretty filtered firewalls.

Possibly linux
link
fedilink
925d

Don’t use the WiFi if you don’t like the rules

Thank you, Supernintendo Chalmers

Please read Charger8283’s reply. It’s the best one. You’re thinking small, how do I break out of their system, that will only land you in trouble. You should think big like how Charger8283 thought and break the system altogether.

If you first find vulnerabilities and report them to your school, later when you find another one you don’t tell them about it until they ask. Keep it a secret and use it for a while. Just pretend like you weren’t ready to tell them because you didn’t understand it yet.

Sometimes it pays off to play nice and stupid.

Well it certainly would be cool to break the system but I honestly don’t have the skills for that. I don’t even know how I could possibly do that.

@InputZero@lemmy.ml
link
fedilink
2
edit-2
24d

Yeah you already do. I’m assuming that you’re in a public highschool. This advice becomes bad advice when there is any money on “the table”. NEVER do this at a university, private, chartered school, and absolutely NEVER do this to the person who will be giving you a paycheck.

I’ll repeat this to be clear to everyone reading this. Do not do anything on a computer or network someone else owns that they don’t allow when money you have, or money you could have gotten could be taken away.

When I said break the system I didn’t mean become so smart at computers that you can just walk past any barrier in any code. That’s impossible. Breaking the system means learning to understand the people who enforce it and working with them to get yourself around it. It means talking to the IT person, getting them to like you, then getting them to show you how to get around a firewall or tunnel out of a network or at least letting you try without getting into huge trouble.

Here are some good rule of thumbs for work and schools:

  • do not connect to their networks with your personal devices, ever.

  • Only use work/ school devices on their own network.

  • Do not do anything personal on those networks. only do work/school related tasks. This means don’t log into any non school/work accounts.

  • If for some reason they don’t have a device for you but require you to use their network, then leave your personal devices at home claiming you don’t own one and make them accommodate you.

You cannot expect privacy in these situations, and by going to the extreme lengths to try to get it then you will ironically just paint a bigger target on your back if any network admin cares. In some cases this can cost you your job or get you in trouble with the school.

Asudox
link
fedilink
1
edit-2
25d

Use Tor with bridges, or orbot if you want to use apps.

I’m assuming you probably have a smartphone. In which case, I would just use your Wi-Fi hotspot instead.

I tried this but my signal isn’t strong enough to get thorugh the walls. In some classrooms it works, but it’s more like a 50/50 chance to stay connected.

Why does it need to go though walls?

Also if the signal is a problem just use a physical cable

Physical cable to the nearest cell tower?

Possibly linux
link
fedilink
124d

What? WiFi doesn’t use a tower. Your phone is the access point.

Yeah, fair enough

Which means the mobile data plan, which doesn’t sound that easy anymore. Where I live (EU) mobile data plans are either quite limited in data cap or expensive, and for a lot of years now they are just shutting it down when yours ran out, instead of slowing it down.

At the risk of sounding contrarian/lame, you should probably not be doing any of this especially if you don’t own the hardware you’re using (as mentioned by another commenter).

You don’t specify if this is university or middle/high school, but either way you are not entitled to and should not expect any privacy on a network you don’t control. Even if you are able to set up a VPN to mask your internet activity, your school’s network administrators almost certainly can tell that you are using a VPN, which itself sounds like it would be a violation of your school’s network policy and will most likely land you in trouble. Indeed, your repeated attempts to access blocked sites have likely already raised some flags.

Even the workarounds that others here have mentioned (like routing VPN traffic over port 443) are inadequate for a network that is being actively monitored. Believe me, it is very easy to tell when someone is connecting to a VPN this way.

I would quit while you’re ahead until you can afford your own hardware/internet connection, and then maybe worry about any notion of privacy. Use your school’s internet for what it was intended.

I have gotten in trouble for using a VPN I’m the past but it was just a little talk and then they were cool with it. The thing is, that it is my device and at the school I don’t have a strong enough signal for my phone. So I can’t just make a hotspot and use that as WiFi. I need to use the WiFi to get my things done but I will not use the WiFi if I can’t protect my privacy. I know that this sounds pretty stupid but I won’t comply with my school.

lnxtx
link
fedilink
41M

If you don’t need a speed and full functionality of the Internet.
Try bridges for the Tor Browser.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.82K Posts
  • 70.8K Comments
  • Modlog