Live data from Hacker News

Investigating TLS Blocking in India

ooni.org

1–10 of 136 posts

Re: Investigating TLS Blocking in India

#2
> In the absence of a publicly available official list of blocked hostnames

This is the icing on the cake right here. It's just awful that not only do websites get censored largely arbitrarily, there is no insight into the process and what is even blocked–the fact that someone had to literally check sites to see if they are being blocked (via a variety of different methods largely indistinguishable from a malicious actor :/) is just a truly horrible state to be in.

Re: Investigating TLS Blocking in India

#7
post #6

Will TLS 1.3 and ESNI support circumvent this?

I'm wondering this too. The article claims some of the connection are proxied. However if it's a big site that uses a set range if incoming IPs, I feel like blocking could still happen at the TCP level (and maybe catch a bunch of other unrelated sites if it's on a shared hosting solution).

Re: Investigating TLS Blocking in India

#9
This is a great, detailed report. I use one of these providers and see somewhat similar results (I do not use my ISPs DNS, but another one with DoH).

Am I right in concluding that these blocking methodologies can be thwarted to a greater extent by the user using Tor (or a VPN outside the country) and/or the websites in question using ESNI (and the user also using a non-ISP DoH provider that doesn’t have legal presence in the country, since the DNS providers will be the next target for these ill defined blocking orders)?

Post reply on HN