Live data from Hacker News

Tell HN: Domain fronting to be blocked on Azure

news.ycombinator.com

91–100 of 132 posts

Re: Tell HN: Domain fronting to be blocked on Azure

#91
post #64
post #40

Earlier quoted context omitted.

How many read-write services can you use to redirect traffic to your C2 infrastructure while almost guaranteeing organizations will allow outbound connections to it and not look too closely at it?

Google Docs/Forms/Sheets/etc, anything with an image proxy, probably Microsoft's Office Online stuff tho I personally haven't used it, webpush connections, the possibilities are endless.

DNS…

Re: Tell HN: Domain fronting to be blocked on Azure

#92

Earlier quoted context omitted.

Yeah, I believe China doesn't even allow TLSv1.3

Not allowing TLS 1.3 means nothing (no modern web sites) works. Modern browsers and servers both speak TLS 1.3 and if they can't they give up. Some things don't work in China, but China wouldn't have a thriving economy if nothing was working. So no, they did not block TLS 1.3 although it's interesting how this rumour seems to have self-popularised. China blocks certain popular sites, but it does not block whole proto…

They can ban tls 1.3 internally and do tls1.3 post intercept to the server.

Re: Tell HN: Domain fronting to be blocked on Azure

#93
post #90

Earlier quoted context omitted.

> You can't write tech that overrides the authority of governments Really? Tor springs to mind.

Same. What's your point? VPNs also bypass government blocks. It's a cat and mouse game, they block vpns and guards as they see fit when they have a good reason to. Look at tor, if a country tls decrypts everything and blocks connections that can't be decrypted can it still bypass their blocks? Just because not every government is doing it does not mean Tor can't be blocked. Hell, countries allow-list connections to a…

You're right; ultimately, if you have total power, you can just block the internet.

Re: Tell HN: Domain fronting to be blocked on Azure

#94

Well, that sucks. What's worse is it is wankers in the "infosec" industry that pushed MS to do this (or at least, are taking credit for it).

Could you explain to me how "nibbleshifter" would use the "feature" for good? What are you losing here "nibbleshifter"? Why do you put infosec in scare quotes? Why are they "wankers"? Why scare quote and name call a legitimate profession? Because you have qualms?

Evading censorship in less democratic countries, for a start. I've had to do this quite a number of times on my travels - and its even more important for people in the human rights field.

Tor's "meek" pluggable transport uses domain fronting for this purpose.

I work in the so called "infosec" field, and about half the field are myopic wankers who would readily sacrifice privacy wholesale to gain an ounce of so called security. Think: the kind of people who also want to cripple eSNI or DoH in the name of "network monitoring".

Re: Tell HN: Domain fronting to be blocked on Azure

#95
post #46

> will block any HTTP request that exhibits domain fronting behavior. How does the CDN detect this? The CDN only sees the encrypted domain, correct?

No, CDN is a full MiTM on the traffic.

And it has to be or it’s not a CDN.

Re: Tell HN: Domain fronting to be blocked on Azure

#96

Earlier quoted context omitted.

It absolutely does not work. Violence finds a way.

The mind is humanity's most lethal weapon. With the "right" mindset the entire universe can become a weapon. Efforts to reduce violence tend to focus on the presence of concrete weapons (because this is easier to quantify and measure etc) with much less focus on violent ideation and the root causes of the various forms of interpersonal violence. Reducing violence is a tricky thing because to a large extent it seems t…

Also ever since “driving while black/poor/not liked” became something you couldn’t arrest on they need another excuse.

Re: Tell HN: Domain fronting to be blocked on Azure

#97
post #64
post #40

Earlier quoted context omitted.

How many read-write services can you use to redirect traffic to your C2 infrastructure while almost guaranteeing organizations will allow outbound connections to it and not look too closely at it?

Google Docs/Forms/Sheets/etc, anything with an image proxy, probably Microsoft's Office Online stuff tho I personally haven't used it, webpush connections, the possibilities are endless.

Google and now Microsoft are also blocking domain fronting.

The other 'possibilities' are not necessarily guaranteed to be allowed for egress traffic out of an organization. That's why the cloud providers blocking it is a big deal - most orgs WILL allow outbound traffic on more than a few ports to these platforms

Re: Tell HN: Domain fronting to be blocked on Azure

#98

Lack of SNI encryption is the Achilles heel of modern web when it comes to oppressive regimes blocking access. Between encrypted SNI (Or domain name fronting), encrypted DNS and of course HTTPS. The biggest legitimate use case of Tor would vanish.

> Between encrypted SNI (Or domain name fronting), encrypted DNS and of course HTTPS. The biggest legitimate use case of Tor would vanish.

Your comment was on point up until this. Just because the Tor use you seemingly most identify with is access from oppressive regimes to the western web, doesn't mean that the rest should be shunned. If you want to make political points about specific other uses of Tor, do it explicitly rather than maligning the whole project.

Re: Tell HN: Domain fronting to be blocked on Azure

#99
post #71

Earlier quoted context omitted.

Domain fronting leads to collateral damage in terms of blocking. If I really want to block X and X is using domain fronting to blend in with traffic on a given CDN, that CDN is going to get blocked. CDN customers that are having their stuff blocked because of that are not going to be happy, in general.

The goal is to get people to stop wanting to block X in the first place. Alternatively, make it so they have to block the entire internet along with X.

That's your (and my) goal, not corporate America's or totalitarian regimes', which are both different flavors of authoritarianism.
Post reply on HN