Chatmail self hosted server stopped working in Russia [fingerprint prior to v2.56]

Hello, delta chat application unable to connect to Chatmail server located in Russia.

The issie looks similar to My relay stopped working, how to fix? [timeout on IMAP connection after CAPABILITY] - #24 by lnchk

It seems like russian censorship replaces the SSL certificate or blocks the connection using DPI.

Yes, Delta Chat client connections to self-hosted chatmail relays are currently blocked from Russia. Probably, it is due to Delta Chat client TLS fingerprints which DPI can easily distinguish from the latest Chrome TLS fingerprints (or another browsers). Maybe, Delta Chat need adding utls library for censorship bypass (but only for possible client in Go language).

Any plans from developers to fix this issue?

I would like to understand whether this problem will be solved?

Can you use Simplex Chat? https://simplex.chat/

I’m curious if their protocol obfuscation works in Russia for you

The latest version has solved this problem v2.56.0

How did it solve it?

It’s working on Android because of background data connection, but push notification isn’t working on Apple devices.

Version v2.56.0 working fine. Thanks!

Glad to hear that. Could you then please mark this topic as solved?

Yes , rn a bit too much fingerprintable but by adding random noise to the lengths of requests and responses, making it impossible to write firewall rules based on fixed message lengths. also varies how its traffic is presented at the byte level, masquerading as different Internet standard byte patterns to resist deep packet inspection. I still have to do proper test but usually such will always helps. You should also consider using something like hiddify which will prevent the ISP from blocking the server you are connecting to

reply regarding simpleX

I wouldn’t uses simpleX considering they cannot even maintain their website without putting user security at risk. If they cannot updates known outdated and vulnerables resources. It shows how much they are aware of their own metadata and data.
The App is so fucking noisy for anyone that would sniff or perform deep packets inspection such traffic would gather his attentions. Everything is noises until you break it down.
It also facilitates social engineering so much.

they are not even compliant with the “lowest/most basic” security standard such as owasp .