FINDING · DETECTION

The GFW enforces SNI-based blocking on every TCP port (not just 443), triggering TCP RST injection and a penalty box for known-censored hostnames (e.g., facebook.com, zh.wikipedia.org) in the TLS ClientHello. The SNI blocklist is separate from the HTTP keyword blocklist — keyword-derived subdomains in the SNI did not trigger censorship. No evidence was found for indiscriminate HTTPS decryption or certificate substitution.

From 2021-rambert-chineseChinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of China · §4.6 · 2021 · WWW

Implications

Tags

censors
cn
techniques
sni-blockingrst-injectiondpi
defenses
ech-esnidomain-fronting

Extracted by claude-sonnet-4-6 — review before relying.