Can someone explain how does one serve content on a domain they don't own, like in this case Souq.com? Do they shove their content to something like product reviews or what? EDIT: I realized they use souqcdn.com. Does this mean it works because their clients use "souqcdn.com" to resolve to CloudFront CDN's IP address and then they craft a different Host header (like "Host: api.signal.org"). Also how can they possibly…
TFA explains it in detail.
Amazon threatens to suspend Signal's AWS account over censorship circumvention
41–50 of 519 posts
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#42What was it that convinced Google and Amazon to no longer allow this particular censorship evasion?
Russia made it clear that they would block AWS and Google Cloud if domain fronting was allowed to continue. https://arstechnica.com/information-technology/2018/04/in-ef... As moxie says in the blog post >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. In the end, the rest of the internet didn’t like that plan.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#43The HN post that alerted Amazon: https://news.ycombinator.com/item?id=16868564
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#44You want to use the resources and influence of a large corporation to acheive your organizations goals. They don’t have to be on board with your mission, and it’s arrogant to think so IMO. Why should they let you do it, when they won’t allow it for others? Seems like you feel entitled because you think by default people should support what you’re trying to do. The flipside of free speech you’re ignoring is that peopl…
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#45Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#46Misleading headline? > Signal plans to make its traffic look like traffic from another site, (popularly known as “domain fronting”) by using a domain owned by Amazon -- Souq.com
The part you're missing is: ... to third parties. They aren't spoofing the domain, they are just making sure that outside parties to an SSL connection will have a difficult time determining where that SSL connection is going. The two parties creating the SSL connection are not lying to each other, though.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#47Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#48So they're basically asking for forgiveness instead of permission, fronting other sites until they are told to stop?
You can’t really stop someone from domain fronting on any CDN. This is like “maybe you should have not talked about this on HN”. :)
The only problem is it breaks a subset of users who are domain fronting by accident (Think a mobile app that connects to www.app.com but sends api.app.com).
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#49Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#50Sorry, I'm not on board with using an Amazon owned domain for this. That's got the potential to get Amazon itself blacklisted in some places, so they're absolutely not going to be okay with it.
Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.