4 ms·
This is a recent technique for censorship circumvention called "domain fronting." See https://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wik
by xfs 8y ago
This is a recent technique for censorship circumvention called "domain fronting." See https://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wiki/Domain_fronting for details.
Essentially when implementing encrypted channels with TLS, the domain name is still clear text in the SNI field, making the censorship circumvention scheme vulnerable to deep packet inspection. The technique is to modify the SNI field in TLS traffic to innocent domains. Major anticencorship efforts have all adopted this approach. Tor has it as meek.
A while ago Google has disabled such usage for Tor. This is just another cloud vendor shutting down another anticensorship vendor.
The real implications here are two things. First, domain fronting is built based on the deterrence of collateral damage, i.e. as a censor you wouldn't want to block TLS traffic with google.com SNI in it, but this deterrence viewed from the perspective of cloud providers is unwanted risks. Second, domain fronting in practice is abused by malware too much (in fact Tor is also a major malware enabler) and cloud providers can't accept this.
- snvzz 8y ago>the domain name is still clear text in the SNI field Something which could have been fixed on TLS 1.3, but didn't happen. Very unfortunately.