3 ms·
I live in Spain and can still enjoy access to this site. This is enforced by major ISPs (Vodafone among others), so anyone sane just opts for a local ISP (if th
by alkyon 12d ago
I live in Spain and can still enjoy access to this site. This is enforced by major ISPs (Vodafone among others), so anyone sane just opts for a local ISP (if they have a choice)
- apexalpha 12d agoHow is it enforced? IP or DNS?
- alkyon 12d agoAccording to this site https://bandaancha.eu/articulos/gobierno-tiene-lista-web-oficial-11138 https://bandaancha.eu/articulos/gobierno-tiene-lista-web-ofi..., they use SNI (https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication)
- alkyon 12d agoEnabling ESNI in Firefox should be a countermeasure (encrypted SNI extension of the TLS so that hostname is no longer sent in plain text) https://superuser.com/questions/1346634/modern-browser-with-a-feature-to-disable-sni https://superuser.com/questions/1346634/modern-browser-with-...
- deleted 12d ago[deleted]
- mitxela 12d agoIt's not magic. archive.is has no HTTPS record, so ESNI cannot be used.
- 1vuio0pswjnm7 12d agoThat superuser thread from 2018 (it's ECH now not ESNI) isn't much help Although I do like the comment at the bottom that states the problem as disabling SNI not encrypting it. Encrypting SNI/ClientHello is over complicated, which is why ESNI was flawed and (allegedly) why Cloudflare disabled it. The solution to the plaintext SNI problem is to not send SNI (I don't send it unless necessary) There is an alternative non-TLS method of encrypting traffic, per packet, that allows hosting multiple websites on the same IP. I use it in the homelab. It proves that TLS and SNI is not the only way There's also a popular archive of www content that does not require SNI. It's older and larger than Cloudflare The problem with software like Firefox is that it automatically sends SNI to every website no matter if SNI is required or not. The superuser thread mentions a Firefox add-on that no longer works. If Firefox is open source then why not just edit the code and recompile Clearly, Mozilla is not going to provide a solution. It would rather add support for ESNI and then ECH as opposed to giving users an option to diable sending SNI Mozilla is pro-surveillance advertising, Cloudflare is pro-surveillance advertising Fortunately, not every HTTPS website is hosted on a shared IP, not every HTTPS website requires SNI. And popular web browsers derived from Mozilla and Google are not the only user agents A couple of ways to not send SNI 1. Use an SSL client, e.g., openssl s_client, bssl client, etc. 2. Use a local forward proxy, e.g., stunnel, haproxy, etc. Even if Cloudflare enables ECH across all the websites it controls, and we have been waiting for years, there is still the issue of SSL termination by Cloudflare. For many of those sites, all the TLS traffic, not just the SNI, is available as plaintext to Cloudflare and to whomever Cloudflare, a US corporation, may or must share it with
- 1vuio0pswjnm7 12d ago*disable
- mitxela 11d agoWhy not put the IP address in your hosts file under a different name so that'll be the SNI?
- 1vuio0pswjnm7 11d agoIt seems there are HN commenters who mistakenly believe SNI values can be controlled via the HOSTS file
- embedding-shape 12d agoDiffers by the ISP you have, I've seen DNS manipulation, IP filtering, hostname filtering, and HTTPS interception so far. Obviously most websites use TLS today so it mostly "fails" so people see certificate errors rather than their scary "You're contributing to breaking the law blah blah blah". Sometimes just straight up timeouts, resets, or generic connection failures.
- mitxela 11d agoBrowsers should change that page to say "someone is hacking your internet" with red background and giant warning sign, when certain certificates are received.
- swiftcoder 12d agoIt also doesn't seem to be enforced on my Movistar connection, which means the single biggest ISP is opting out?
- embedding-shape 12d agoNor on Vodafone for me, 3rd biggest ISP in the country. Guess that leaves us with Orange or possibly Digi as the second one that maybe actually has implemented the block?
- welwala 12d agoOrange is not blocking it on my fiber yet but it is on my mobile connection. The strange thing is I use the same DNS on both (which exits on my fiber connection, even when I'm on mobile), so they must be blocking it another way.
- gorbypark 11d agoDigi is not blocking archive.today on fiber or mobile, I just tried it (Sept 21 ~11AM). However they do block a bunch of the libgen URLs, so I assume they'll eventually block this too, it's just a matter of time.
- schnitzelstoat 11d agoIt was blocked for me on O2, which is part of Movistar - have you tried it now?
- welwala 12d agoThe order only went through on Friday so presumably the ISPs will take some time to catch up.
- Al-Khwarizmi 11d agoI have a major ISP and cannot access directly, but in the last few years an VPN has become part of my routine (otherwise I wouldn't even be able to work normally during football matches) so I just click some random country and it's fixed.
- schnitzelstoat 11d agoYeah, I'm on O2, which I think is part of Movistar? And it's blocked. Fortunately, I already have a VPN anyway :)