Live data from Hacker News

Tell HN: Domain fronting to be blocked on Azure

news.ycombinator.com

31–40 of 132 posts

Re: Tell HN: Domain fronting to be blocked on Azure

#31
post #17
post #12

Earlier quoted context omitted.

That definition is incomplete. Threat actors also abuse this to hide their command and control infrastructure.

Threat actors use knives to stab people - we have to stop selling those.

In the UK if you're under age and you decided to buy a knife you will have a lot of difficulty unless it's a little folding (but non-locking) pocket knife, like the small Swiss Army type utility knives. Indeed legally as old as 17 you can't even buy a steak knife in England although you can in Scotland.

Once you've bought a knife, it will usually be illegal to carry it in public unless you have a good reason, and "self defence" is not a good reason.

Some particular knives, which have no apparent purpose except as weapons, are just illegal automatically except in some cases if you're a museum. In particular almost all swords (if they have a working blade) are in this category, and most things designed as concealed weapons (e.g. blade hidden in an umbrella, combs that are actually knives, push daggers)

Re: Tell HN: Domain fronting to be blocked on Azure

#32

Earlier quoted context omitted.

Sure. Might be hard for people to do certain manual labor jobs without access to sharp objects. I'm sure they'll figure it out. We'll have to ban rocks next though.

It's pretty hard to stab people with rocks, especially multiple people.

But pretty easy to cause blunt force trauma to the head

Re: Tell HN: Domain fronting to be blocked on Azure

#33

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

It's been many years, and I am still angry and disappointed by Cloudflare's decision to block domain fronting and drop Lantern as a customer. Lantern was one of the most effective Great Firewall bypass proxies at the time, and Cloudflare was expanding in China. (I was at Cloudflare at the time, but I don't have private information on the deliberation. I strongly considered quitting over it, maybe I should have, but I was junior back then.)

The CEO even came on HN to try to frame it as an abuse mitigation, accusing Lantern of exploiting Cloudflare and arguing that they were not a customer. That was obviously false because you need to have a Cloudflare zone configured for domain fronting to work. They were a customer as much as the targeted hate websites they strenuously defend.

https://news.ycombinator.com/item?id=9234367

Companies show their color in selecting who they will stand up for.

Re: Tell HN: Domain fronting to be blocked on Azure

#34
post #13

Well, that sucks. What's worse is it is wankers in the "infosec" industry that pushed MS to do this (or at least, are taking credit for it).

If you want to hide your domain name you can use eSNI. Keep in mind another name for censorship is moderation, it isn't just signal that uses it bad guys also abuse it and it was not a feature explicitly built to avoid censorship but more like a bug people were abusing.

>Keep in mind another name for censorship is moderation

No it's not, see https://news.ycombinator.com/item?id=33446064

On most social media sites they're implemented the same way (ie. posts deleted/hidden from other users), but the objectives are totally different.

Re: Tell HN: Domain fronting to be blocked on Azure

#35
Doesn't domain fronting (by definition) not cover all those who reverse proxy (with cache) their S3 bucket and other apps to reduce their egress bills?

The only part of the definition that applies is a subjective part... "for censorship circumvention".

Re: Tell HN: Domain fronting to be blocked on Azure

#36

Earlier quoted context omitted.

Sure. Might be hard for people to do certain manual labor jobs without access to sharp objects. I'm sure they'll figure it out. We'll have to ban rocks next though.

It's pretty hard to stab people with rocks, especially multiple people.

Generations of Native Americans beg to differ.

Re: Tell HN: Domain fronting to be blocked on Azure

#37
post #6

This seems to be a user-hostile move. https://en.m.wikipedia.org/wiki/Domain_fronting ”Many large cloud service providers, including Amazon and Google, now actively prohibit domain fronting, which has limited it as a censorship bypass technique. Pressure from censors in Russia and China is thought to have contributed to these prohibitions”

It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.

Can’t they use almost any read-write service for C2 though?

“Because Security” arguments like this are increasingly used in place of “think of the children”.

Re: Tell HN: Domain fronting to be blocked on Azure

#38
post #18

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

They've been waging this war for a couple years now. I guess they finally got to every cloud provider. Some related reading: "Amazon and Google bow to Russian censors in Telegram battle" https://www.fastcompany.com/40568177/amazon-and-google-bow-t... "U.S. Cloud Providers Face Backlash From China’s Censors" https://www.wsj.com/articles/u-s-cloud-providers-face-backla... https://archive.ph/qhFQ5 >China’s Internet cens…

No post body was provided.

Re: Tell HN: Domain fronting to be blocked on Azure

#39

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

We have ECH (previously known as ESNI) now, is that not just domain fronting in a new form?

Re: Tell HN: Domain fronting to be blocked on Azure

#40
post #37
post #6

Earlier quoted context omitted.

It is not just used for censorship. When I was working as a pentester and domain fronting was still allowed on AWS, it became our method of choice for establishing C2 because it camouflaged so well with regular organizational outbound that it will bypass any egress filtering and restrictions. If we were using it on a pentest, you'd best believe there are actors using it for far more nefarious purposes.

Can’t they use almost any read-write service for C2 though? “Because Security” arguments like this are increasingly used in place of “think of the children”.

How many read-write services can you use to redirect traffic to your C2 infrastructure while almost guaranteeing organizations will allow outbound connections to it and not look too closely at it?
Post reply on HN