My preparations for the WeChat ban...

BMEWS

Junior Member
Registered Member
I'm getting a dedicated android device (in my case a tablet) that doesn't have any 3G/4G/5G functionality, it is wifi only... (this makes it impossible to get Stingray'ed etc etc etc)

In my case its a Samsung tablet, which I root it and put the custom TWRP on it for more control as it also allows me to easily make forensic backups that I can simply revert to almost like a previous snapshot if anything goes wrong:

Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

On the Android tablet I install the NetGuard app so I can block all traffic and its basically a fine tuned firewall with application level granularity:
Please, Log in or Register to view URLs content!

I also put a VPN on it, there any many different VPN, but right now I'm using NordVPN:
Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

To get the .apk manual installers for WeChat, TikTok, DJI or any other Chinese app there are many ways, but typically many of them are hosted on the likes of APKPURE, APTOIDE, F-DROID, etc...

Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

I also download the latest version of Google Play services, and keep a history of previous versions in case I need to go back to earlier versions. Its likely when the US bans WeChat/TikTok/DJI/etc that it will order Google to rig future versions of Google Play Services to not allow the aforementioned named Chinese apps to even start or open up at all!

Please, Log in or Register to view URLs content!

After I download my collection of .apk, I hash them for integrity using the free MultiHasher, and then digitally sign the hashes with my own PGP key using Gpg4Win. To protect against bit rot and tampering I use MultiPar to create 100% redundancy and parity files. I burn it to a M-Disc for safekeeping and supposedly it should last 1000 years.

Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

Once I have my tablet set up exactly the way I like it, I then boot to TWRP and create a full backup, later on if anything goes wrong, as last resort I can just simply restore that backup and I'm good to go again...

Since I cannot take the battery out of the Samsung tablet, I get a large faraday bag that I put it in when its not in use.

Please, Log in or Register to view URLs content!
 

BMEWS

Junior Member
Registered Member
WeChat has a Windows Desktop application version in addition to the app for phones and tablets...

So I use VMWare Workstation as a hypervisor and get me a Windows 10 LSTC/LSTB (Windows 7 also works) .iso file and spin up a dedicated Windows based VM (virtual machine) taking incremental snapshots along the way. If anything goes wrong, I just revert to a snapshot in time...

After installing this Windows 10 OS to the virtual machine, I go into gpedit.msc to disable its ability to do any updates whatsoever...
A free tool called ShutUp10 is also great to quickly enhance the privacy and security posture of the Windows 10 out of the box

(for those on Home version of Windows 10 that cannot stop updates, you can go to C:\Windows\System32, under MusNotificationUx.exe and MusNotification.exe, UsoClient.exe, usoapi.dll, usocore.dll, take ownership of the files, and then deny rights to the SYSTEM )

On this VM, I disable the ipv6 in NCPA.CPL and only enable ipv4; I also install TOR on it plus the Windows version of the NORDVPN

It is possible that when the US gov bans TikTok, WeChat, DJI, etc that they will order all the VPN providers to also ban these Chinese ip/servers... in that case one thing can try is to run a VPN over TOR or TOR over VPN

Please, Log in or Register to view URLs content!

Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

Please, Log in or Register to view URLs content!
Please, Log in or Register to view URLs content!

On your host computer (the physical one, not the VM) I recommend to be using always some full disk encryption like TrueCrypt or VeraCrypt... use a long password at least 64 characters (or augment it with a yubikey static key that can store 38 characters around your neck etc)




1596403304101.png
 
Last edited:

KYli

Brigadier
Banning Wechat would make many overseas Chinese very inconvenience. It would force many American businesses to use emails for communicate with their suppliers.
 

BMEWS

Junior Member
Registered Member
I made this video on security Windows 7 back in the day, but some of it still applies to Windows 10

 

BMEWS

Junior Member
Registered Member
Banning Wechat would make many overseas Chinese very inconvenience. It would force many American businesses to use emails for communicate with their suppliers.

Well everyone is using gmail (NSA) these days anyway including CGTN and Houston Consulate!
 

horse

Major
Registered Member
Banning Wechat would make many overseas Chinese very inconvenience. It would force many American businesses to use emails for communicate with their suppliers.
But how would they do it?

The Americans would have to build another Wall to keep out WeChat, besides that other Wall that Trump is building to keep out Mexicans.

Imagine that, another Chinese internet related idea that the Americans adopt. Then they will feel so proud when they put up that Chinese Wall.

:D
 

BMEWS

Junior Member
Registered Member
But how would they do it?

The Americans would have to build another Wall to keep out WeChat, besides that other Wall that Trump is building to keep out Mexicans.

Imagine that, another Chinese internet related idea that the Americans adopt. Then they will feel so proud when they put up that Chinese Wall.

:D

It is actually quite simple, they tell Google and Apple to delist the WeChat/TikTok etc apps.. they can also force Apple and Google to remotely uninstall remove it from everyone's devices. So they block it at the endpoint and distribution level....

But they will also block it at the network/transport level by getting all the US ISP to block all traffic to these servers or based on dns/ip or whatnot... a lot of international internet traffic routes through the US... they can also stop it for that as well...

Back in 2010 they did the same thing to megaupload, even though megaupload was a new zealand company that never set foot in the US, megaupload used a .com (TLD Top level domain) under the US jurisdiction so they got the DOJ to hijack megaupload.com and if you went to it you got redirected to the FBI website. Then using MLAT they raided Kim Dot Com (the Mega upload CEO living in NZ) in the middle of the night Seals Team Six style
 
Last edited:

Hadoren

Junior Member
Registered Member
Its likely when the US bans WeChat/TikTok/DJI/etc that it will order Google to rig future versions of Google Play Services to not allow the aforementioned named Chinese apps to even start or open up at all!
Is this actually possible? How exactly would Google Play do this? Any other SDF members care to comment?
 
Top