HN Hall of Fame Weekly email

GoodbyeDPI: Deep Packet Inspection circumvention utility

Screenshot of github.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 4 calendar years, with breakout response in 2 of them.

submissions
5
submitters
5
observed span
2019–2024
peak thread · 118 comments
297 pts
latest 20+ return · 2022-07-23
297 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

Worth reading Deep Packet Inspection is Dead: https://security.ias.edu/deep-packet-inspection-dead-and-her... This tool is great, but I religiously route all my traffic through a VPN that I own and control. I’ve hardened the box I use to have zero logs and I don’t need to blindly trust a commercial provider whether they’ve been audited or not. There’s no way of really knowing they’re not logging in some capacity bar from being physically in their server room and inspecting their setup. Add to the…

liberia·297-point thread·

So... this is basically fragrouter? [1] If so, this is a very old idea (I, uh, co-invented it?). A lot of DPI gear isn't built for serious security, but rather best effort, and I'm sure basic TCP tricks like this will bypass those. But you should be aware that serious, modern middleboxes were very definitely built with knowledge of fragrouter-type tricks (and of evasion more generally), and you're better off using a VPN than relying on stuff like this if…

tptacek·112-point thread·

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
2

100+ points or 50+ comments

Total points
418

reference only — not used in Hall rules or ranking

Total comments
161

reference only — not used in Hall rules or ranking

Every submission