Live data from Hacker News

Tell HN: Domain fronting to be blocked on Azure

news.ycombinator.com

11–20 of 132 posts

Re: Tell HN: Domain fronting to be blocked on Azure

#12

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

That definition is incomplete. Threat actors also abuse this to hide their command and control infrastructure.

Re: Tell HN: Domain fronting to be blocked on Azure

#13

Well, that sucks. What's worse is it is wankers in the "infosec" industry that pushed MS to do this (or at least, are taking credit for it).

If you want to hide your domain name you can use eSNI. Keep in mind another name for censorship is moderation, it isn't just signal that uses it bad guys also abuse it and it was not a feature explicitly built to avoid censorship but more like a bug people were abusing.

Re: Tell HN: Domain fronting to be blocked on Azure

#14
post #6

This seems to be a user-hostile move. https://en.m.wikipedia.org/wiki/Domain_fronting ”Many large cloud service providers, including Amazon and Google, now actively prohibit domain fronting, which has limited it as a censorship bypass technique. Pressure from censors in Russia and China is thought to have contributed to these prohibitions”

It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.

It's not possible to block C2 without also helping censorship on the Internet. Whatever mechanism is used to hide one traffic is going to be used by the other one, and reversely.

Morally, the question is which one is the most important?

Re: Tell HN: Domain fronting to be blocked on Azure

#15
post #14
post #6

Earlier quoted context omitted.

It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.

It's not possible to block C2 without also helping censorship on the Internet. Whatever mechanism is used to hide one traffic is going to be used by the other one, and reversely. Morally, the question is which one is the most important?

The question for cloud providers is not which one is morally more important, but which one is better for their shareholders. It seems like creating a situation where organizations move their workloads off your public cloud because they have to blacklist your entire domain to stop an attack would be bad for their shareholders.

Re: Tell HN: Domain fronting to be blocked on Azure

#16

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

I really enjoyed this explanation

https://hackernoon.com/domain-fronting-101-what-is-domain-fr...

Re: Tell HN: Domain fronting to be blocked on Azure

#17
post #12

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

That definition is incomplete. Threat actors also abuse this to hide their command and control infrastructure.

Threat actors use knives to stab people - we have to stop selling those.

Re: Tell HN: Domain fronting to be blocked on Azure

#18

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

They've been waging this war for a couple years now. I guess they finally got to every cloud provider. Some related reading:

"Amazon and Google bow to Russian censors in Telegram battle"

https://www.fastcompany.com/40568177/amazon-and-google-bow-t...

"U.S. Cloud Providers Face Backlash From China’s Censors"

https://www.wsj.com/articles/u-s-cloud-providers-face-backla...

https://archive.ph/qhFQ5

>China’s Internet censors have strengthened content screening in recent months, creating difficulties for businesses and disrupting more commonly used firewall-circumvention software called virtual private networks, which connect users to the Web through a proxy server overseas. President Xi Jinping has ordered tighter control of online content that may undermine the ruling Communist Party, with bloggers facing jail for spreading what the government says are false rumors.

Re: Tell HN: Domain fronting to be blocked on Azure

#19

Earlier quoted context omitted.

Fixed: "Many large cloud service providers, including Amazon, Microsoft, and Google, actively prohibit domain fronting, which has limited it as a censorship bypass technique."

sure, it was merely a coincedence that they've started doing it after russian minitrue telegram fiasco. our venerable corporations would never bend to the will of foreign dictators.

Separate of whether the correlation is correct do you or anyone have info on the Telegram minitrue issue? I was unaware and don't really use Telegram.
Post reply on HN