FINDING · DETECTION

In AS45090 (China), the Cloudflare CDN IP 104.16.248.249 succeeds 100% of the time with SNI 'cloudflare-dns.com' but triggers TLS handshake resets 93% of the time with SNI 'mozilla.cloudflare-dns.com'. Follow-up measurements using those same SNIs against unrelated HTTPS servers (example.org, hbl.fi) reproduced the same resets, confirming that the GFW performs SNI-keyed TLS blocking independent of the destination IP.

From 2021-basso-measuringMeasuring DoT/DoH blocking using OONI Probe: a preliminary study · §V-E, Table VI · 2021 · DNS Privacy Workshop

Implications

Tags

censors
cn
techniques
sni-blockingrst-injection

Extracted by claude-sonnet-4-6 — review before relying.