FINDING · DEFENSE

Domain fronting exploits the fact that major CDN providers (Google, Amazon CloudFront, Akamai, Microsoft Azure) terminate TLS at the edge before inspecting the Host header, so the SNI visible to a censor names a permitted CDN domain (e.g., www.google.com) while the inner HTTP Host header routes the request to a blocked destination. Blocking the fronted service requires blocking the entire CDN, creating collateral damage that most censors are unwilling to accept for major providers.

From 2015-fifield-blocking-resistantBlocking-resistant communication through domain fronting · §2 · 2015 · PETS

Implications

Tags

censors
cnirrugeneric
techniques
sni-blockingdpi
defenses
domain-frontingmeektunneling

Extracted by claude-sonnet-4-6 — review before relying.