Tell HN: Domain fronting to be blocked on Azure
11–20 of 132 posts
Re: Tell HN: Domain fronting to be blocked on Azure
#12For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…
Re: Tell HN: Domain fronting to be blocked on Azure
#13Well, that sucks. What's worse is it is wankers in the "infosec" industry that pushed MS to do this (or at least, are taking credit for it).
Re: Tell HN: Domain fronting to be blocked on Azure
#14This seems to be a user-hostile move. https://en.m.wikipedia.org/wiki/Domain_fronting ”Many large cloud service providers, including Amazon and Google, now actively prohibit domain fronting, which has limited it as a censorship bypass technique. Pressure from censors in Russia and China is thought to have contributed to these prohibitions”
It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.
Morally, the question is which one is the most important?
Re: Tell HN: Domain fronting to be blocked on Azure
#15Earlier quoted context omitted.
It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.
It's not possible to block C2 without also helping censorship on the Internet. Whatever mechanism is used to hide one traffic is going to be used by the other one, and reversely. Morally, the question is which one is the most important?
Re: Tell HN: Domain fronting to be blocked on Azure
#16For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…
https://hackernoon.com/domain-fronting-101-what-is-domain-fr...
Re: Tell HN: Domain fronting to be blocked on Azure
#17For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…
That definition is incomplete. Threat actors also abuse this to hide their command and control infrastructure.
Re: Tell HN: Domain fronting to be blocked on Azure
#18For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…
"Amazon and Google bow to Russian censors in Telegram battle"
https://www.fastcompany.com/40568177/amazon-and-google-bow-t...
"U.S. Cloud Providers Face Backlash From China’s Censors"
https://www.wsj.com/articles/u-s-cloud-providers-face-backla...
>China’s Internet censors have strengthened content screening in recent months, creating difficulties for businesses and disrupting more commonly used firewall-circumvention software called virtual private networks, which connect users to the Web through a proxy server overseas. President Xi Jinping has ordered tighter control of online content that may undermine the ruling Communist Party, with bloggers facing jail for spreading what the government says are false rumors.
Re: Tell HN: Domain fronting to be blocked on Azure
#19Earlier quoted context omitted.
Fixed: "Many large cloud service providers, including Amazon, Microsoft, and Google, actively prohibit domain fronting, which has limited it as a censorship bypass technique."
sure, it was merely a coincedence that they've started doing it after russian minitrue telegram fiasco. our venerable corporations would never bend to the will of foreign dictators.