5 ms·
"It can even \"spoof\" the TLS SNI string to avoid HTTPS firewalls..." Are you confirming SNI is being used for censorship?
by textmode 10y ago
"It can even \"spoof\" the TLS SNI string to avoid HTTPS firewalls..."
Are you confirming SNI is being used for censorship?
- clinta 10y agoPlenty of content blockers support blocking domains based on SNI. Here's just a couple of examples from a quick google search. https://wiki.untangle.com/index.php/Web_Filter#HTTPS_Options https://wiki.untangle.com/index.php/Web_Filter#HTTPS_Options http://www.watchguard.com/help/docs/wsm/xtm_11/en-us/content/en-us/proxies/https/https_domain_names_c.html http://www.watchguard.com/help/docs/wsm/xtm_11/en-us/content...
- NetStrikeForce 10y agoIf someone is doing DPI their best bet to know where are you connecting to is to look at the host in SNI, but if you're in a corporate environment with an explicit proxy, your computer would be sending a "CONNECT hostname.tld" in plain text anyway :)