Live data from Hacker News

Tell HN: Domain fronting to be blocked on Azure

news.ycombinator.com

121–130 of 132 posts

Re: Tell HN: Domain fronting to be blocked on Azure

#121

Earlier quoted context omitted.

Maybe domain fronting was initially disabled as an unsuccessful attempt to fix that bug, that's possible and as I said I was not involved in that decision. Still, if that's the case, there was a policy decision afterwards to leave it disabled, because disabling it did not fix the bug, as you seem to agree. (Again, not elaborating on the bug publicly without permission, but I remember it turned out to have nothing to…

Quoted post unavailable.

Commenters aren't allowed to attack others like this on HN, regardless of how wrong the other person is or it feels like they are.

If you'd please review and follow the site guidelines, we'd appreciate it: https://news.ycombinator.com/newsguidelines.html.

Re: Tell HN: Domain fronting to be blocked on Azure

#122

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

I was wondering that, thanks.

What I'm wondering now is why one should use that instead of a proxy server that maps some.domain.com to something.else.com

Re: Tell HN: Domain fronting to be blocked on Azure

#123

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

It's been many years, and I am still angry and disappointed by Cloudflare's decision to block domain fronting and drop Lantern as a customer. Lantern was one of the most effective Great Firewall bypass proxies at the time, and Cloudflare was expanding in China. (I was at Cloudflare at the time, but I don't have private information on the deliberation. I strongly considered quitting over it, maybe I should have, but I…

Fascinating, Filippo. We stayed silent on it at the time primarily because we were keeping a low profile particularly as more and more Chinese were using Lantern, but there was also back channel pressure through various contacts, to be honest related to the pending Cloudflare expansion in China.

There was also a prelude to all of this that I think made things stickier and bizarrely personal. Prince and I share a mutual friend who introduced us just a few weeks prior. Prince said he supported what we were doing, but asked that I not talk about it publicly, presumably because of the pending China deal. The problem was that literally moments after our friend had introduced us via email, and before he made that request, I had a call with the WSJ where I talked about precisely this. I did everything I could to walk back the article, but Prince didn't buy it and seemed to go ballistic over it. After the WSJ piece, we pulled back from talking more publicly in general.

Oh, I forgot! We also partly stayed silent because they didn't actually shut down what we were doing at all =). They matched the SNI to the Host header, sure, but they missed a little detail: we weren't using SNI. Hehe. Lantern worked for another six months or so, and then, through a similarly bizarre sequence of events, we essentially tipped them/you off to what was happening. We remained a customer throughout, and we're a customer to this day.

Either way, though, Cloudflare does great work, and everyone has their faults, so I'm generally sympathetic over the whole thing with the one caveat that I am truly unclear how much ultimately did relate to China, most clearly in terms of any public support for these internet freedom techniques.

Oh, and I've wanted you to work on Lantern forever btw. Oooh actually if you're not aware of it, the uTLS Go TLS fork is a hugely impactful project that's in widespread use (I would guess maybe 50 million monthly active users rely on it in censored regions via various projects) but needs updating - https://github.com/refraction-networking/utls

Oh, and if you think we were effective in China then, you should see what we're doing in Russia and especially Iran now!

Re: Tell HN: Domain fronting to be blocked on Azure

#124

For anyone else wondering what domain fronting is: > Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections. https://en.wikipedia.org/wiki/Domain_fronting Cool, so we are bowing down furth…

It's been many years, and I am still angry and disappointed by Cloudflare's decision to block domain fronting and drop Lantern as a customer. Lantern was one of the most effective Great Firewall bypass proxies at the time, and Cloudflare was expanding in China. (I was at Cloudflare at the time, but I don't have private information on the deliberation. I strongly considered quitting over it, maybe I should have, but I…

Oh it's also worth noting that Cloudflare is actually more aggressive in blocking domain fronting than almost anyone else. Lots of folks match the SNI to the Host header, but Cloudflare takes it a step further and also makes sure that TLS connections without SNI have a Host header that's scoped to the IP/server they're actually visiting. That means you can't, for example (not that we would ever, ever do this hehehe), scan the whole Cloudflare IP space for IPs to front through without SNI.

Re: Tell HN: Domain fronting to be blocked on Azure

#126
post #112

Earlier quoted context omitted.

> many in other countries consider it a form of neo-colonialism where you undermine their sovreignity and self-determination. Only if by "their" you mean the ruling class, and by "self-determination" you mean their ability to control others. You can't really say their opinions represent the will of the people, especially when it's the people themselves ultimately choosing to engage in "illegal" activities. And sure,…

The will of the people is relevant only in a democracy. The neocolonialism part is when you force it in a foreign country. There is absolutley nothing superior or special about democracy. If the people of a country through whatever self-determined means acheive democracy then so be it. The thing people like you don't seem to understand is that individualism is a very western thing, this idea that the individual's wil…

> The thing people like you don't seem to understand is that individualism is a very western thing

Read my comment again - I explicitly acknowledged this.

I'd say that most of your comment is attacking a top-down "exporting democracy" whether covertly, led by the State Department, outright invasion, etc. I agree that these things are evil, especially when "democracy" is used as the marketing for the primary concern of implementing USD-denominated markets.

So where we differ is the bottom up emergent behavior of people making their own choices.

> historically people worry about the well being of their children and society which means not getting killed/raped, having economic and academic opportunities,etc... and beyonf that also, the will of their god being implemented.

And yet, those are the same exact people choosing to use technology that provides things like (very imperfect) communications privacy. Your argument implies that their choices are wrong, so what you're really saying is that the larger population needs to be paternalistically protected from themselves. Which brings us to the huge unstated assumption of your comment that for every society we should respect some ambient "values" of the society, with some more powerful in-group protecting those values against the larger population.

I agree that's a descriptive statement about the power structure of basically every society. But I don't agree that it's a prescriptive model with inherent moral value.

And yes, I do know this viewpoint is a very "western" philosophy. I put "western" in quotes because it seems like a strong general attractor, as communications technology enables human-to-human communication unmediated by traditional top-down power structures. I'm also learning not to handicap myself by getting stuck in the doldrums of relativism. To the extent that it may be inherently western, spreading our own culture through arms length communication and voluntary buy in is a hell of a lot more defensible than the traditional ways of spreading culture - violent conquest and subjugation.

Re: Tell HN: Domain fronting to be blocked on Azure

#127

Earlier quoted context omitted.

Just for the record, there are very few people on the Internet I would trust more about this kind of stuff than Filippo.

Quoted post unavailable.

I'm extraordinarily comfortable with how my comments here reflect on my judgement.

Re: Tell HN: Domain fronting to be blocked on Azure

#128

Earlier quoted context omitted.

Could you explain to me how "nibbleshifter" would use the "feature" for good? What are you losing here "nibbleshifter"? Why do you put infosec in scare quotes? Why are they "wankers"? Why scare quote and name call a legitimate profession? Because you have qualms?

Evading censorship in less democratic countries, for a start. I've had to do this quite a number of times on my travels - and its even more important for people in the human rights field. Tor's "meek" pluggable transport uses domain fronting for this purpose. I work in the so called "infosec" field, and about half the field are myopic wankers who would readily sacrifice privacy wholesale to gain an ounce of so called…

> even more important for people in the human rights field.

Historically these people and even journalists are targeted by Nation States utilizing Israeli made offense tools like Pegasus.

Domain fronting would not help in these cases to avoid censorship, maybe but you are attempting to circumvent a Nation State with almost unlimited money and resources the target would never be able to have.

Does it suck that domain fronting is gone? Yes. Is it a good thing it's gone? Yes.

The fact is the people that used domain fronting for your use case is heavily heavily outweighed by malicious actors.

One could argue that domain fronting and guns are the same. Why should I have my gun taken away when I am using it for legal purposes? Just because bad people use a gun for bad things I shouldn't be scrutinized for my legal use. I shouldn't have access taken away due to bad actors leveraging them for ill gotten gains.

Re: Tell HN: Domain fronting to be blocked on Azure

#129

Lack of SNI encryption is the Achilles heel of modern web when it comes to oppressive regimes blocking access. Between encrypted SNI (Or domain name fronting), encrypted DNS and of course HTTPS. The biggest legitimate use case of Tor would vanish.

Is it 'illegitimate' that I read all of my preferred news content and chat on the internet using Tor?

It's not really why I've run a relay for nearly a decade. But it's better than filesharing I suppose.

Re: Tell HN: Domain fronting to be blocked on Azure

#130
post #109

Earlier quoted context omitted.

Unfortunately much like every nice thing on the internet, once it is being abused, it gets axed... Domain fronting (having Host header differ to SNI in TLS) is a powerful way a malware author could send payload into organisations.. imagine seeing seemingly legitimate traffic to azure.com but end up with malwaredomain.com/lulz.exe... Unless organisations are peeking into TLS, check Host header, response with MZ file h…

Security teams should be doing DPI, using a corporate controlled CA to decrypt the traffic and then feed it into a SIEM which should start screaming bloody murder when it detects a mismatch between SNI and the requested host

big corporation with everyone working in a building, 100% achievable but with everyone working from home these days, it's a big challenge to have all users' internet traffic through a single gateway in some sort of VPN is not scalable. Most corp has to support split tunnel to make it work-able...

Lots of IoC base on DNS as well so that is out of the windows since the malicious traffic is inside TLS...:-/

Post reply on HN