3 ms·
Using innocent sounding CNAMEs on abandoned domains is definitely a smart idea. I’ve definitely got some old domains kicking about, I’ll see how far off they a
by 2cb 6y ago
Using innocent sounding CNAMEs on abandoned domains is definitely a smart idea.
I’ve definitely got some old domains kicking about, I’ll see how far off they are from expiration and do something similar if they have at least a few months left in them.
The proxies themselves can also be hosted at normal sounding domains and subdomains like cdn.technology.memes or whatever.
And when you point other domains to them as CNAMEs use equally regular looking subdomains no algorithm would pick up as a proxy like webmail.abandoned.tld.
- stonesweep 6y agoThought following yours, I like the CDN idea - if you add in some dynamic DNS updates with random CNAME results it could also help - ask for cdn.example.com, get node182.example.com and 5 minutes later get a different CNAME result injected from some cron job...
- iudqnolq 6y agoIf your scheme for conveying innocent sounding proxy domains requires it's own innocent sounding domains what have you added?
- stonesweep 6y agoTo my thinking, it creates a chain of "it's really hard to block them all" - as soon as I saw (via the link) that you submit your new proxy to https://signal.tube https://signal.tube I thought "...so the Iranian gov't just has to block any and all access - DNS, HTTP - to that domain" and people can't even see what proxies are out there. So if my friendly domain name is "learned as a Signal proxy" they just block my domain (personally, I'd use two domains to double-blind it). My conceptual idea is that how you get the person the name of the proxy to use has to hide as signal amongst the noise and not get trapped in DNS/domain blocking filters - and if it's keyword blocked by the Great Firewall, you just start asking other random domains for their MX records etc. I believe it's generally referred to as steganography: https://en.wikipedia.org/wiki/Steganography https://en.wikipedia.org/wiki/Steganography
- thw0rted 6y agoRe-read the OP. No connection is actually made to `signal.tube`, it's only a placeholder domain for triggering an Android registered link handler so that it will open in their app.