4 ms·
Couldn't the Government ban Signal relatively easily? A simple dns ban should suffice, no?
by thepete2 5y ago
Couldn't the Government ban Signal relatively easily? A simple dns ban should suffice, no?
- viraptor 5y agoSignal responds to dns banning with their own tricks. Previously it was domain fronting https://signal.org/blog/looking-back-on-the-front/ https://signal.org/blog/looking-back-on-the-front/ I'm sure they wouldn't leave India without a similar fight.
- Anunayj 5y agoDNS injection can be relatively easily bypassed by using DNS over HTTPS/TLS. ISPs usually block websites by terminating the connection on seeing a blacklisted SNI which is part of the TLS handshake (So the server can respond with the appropriate TLS certificate). The only way to bypass is either to use domain-fronting (aka using different SNI/Host, not standard-compliant, doesn't work with most CDNs), or use a different protocol. (Not that practical) ECH/eSNI plan [1] to make the SNI encrypted, and therefore uncensorable in future. (The draft is now in it's later stages). Ofcourse this can end up with government potentially blocking all ECH traffic. [1] https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni