4 ms·
Working in a school I block QUIC traffic so my web filter can (attempt to) keep kids off porn. Such filtering is required by law for schools. I haven't found a
by discreditable 8y ago
Working in a school I block QUIC traffic so my web filter can (attempt to) keep kids off porn. Such filtering is required by law for schools. I haven't found a passive filter that handles QUIC. I don't want to install invasive client software or MITM connections.
- tialaramex 8y agoThere won't ever be a passive filter. The QUIC traffic is deliberately opaque. If you control the clients you may be able to retain your status quo for some time (by just refusing to upgrade) but the direction is away from having anything filterable. So client software or MITM are your only options.
- discreditable 8y agoI've seen it coming for a while. I'll have to decide which is the lesser evil: blocking QUIC/HTTP3 or using MITM.
- comex 8y agoHow do you handle regular old HTTPS?
- discreditable 8y agoThe filter looks at the SNI header during the TLS handshake. If it doesn't like the host it will reset the connection.
- cesarb 8y agoDoes this mean you block all of Wikipedia? And what will you do once encrypted SNI becomes popular?
- discreditable 8y agoI don't block Wikipedia. I looked at some wire traffic and I can see the SNI header as normal in Firefox 67 and Chrome 72. I found a about:config flag to enable esni, toggled it, restarted the browser, and I still see the SNI. Using Cloudflare's ESNI checker it says my browser isn't using it. Ignoring ESNI will probably work fine for a good length of time. If pornhub implements it or something I'd probably have to revisit. Or, since I control the clients I might disable it in their browsers. If enough people bark up the filter vendor's tree I'm sure they'll add a checkbox to drop esni traffic. They added one for QUIC recently.