FINDING · DETECTION

The paper formally characterizes the censor's visibility gap: the SNI field in the TLS ClientHello and the HTTP Host header inside the tunnel are the two places that reveal destination, and CDNs that terminate TLS before forwarding HTTP requests prevent censors from correlating them. Any censor capable of correlating SNI to inner-Host (e.g., through CDN cooperation or plaintext HTTP/2 framing) can defeat domain fronting without CDN blocking.

From 2015-fifield-blocking-resistantBlocking-resistant communication through domain fronting · §3 · 2015 · PETS

Implications

Tags

censors
genericcnirru
techniques
sni-blockingdpi
defenses
domain-fronting

Extracted by claude-sonnet-4-6 — review before relying.