FINDING · EVALUATION

Google Cloud CDN and Amazon CloudFront disabled domain fronting by 2021 by enforcing SNI/Host header consistency, causing Tor Meek, Psiphon, Lantern, and Signal to halt or migrate their domain-fronting deployments. Domain shadowing avoids this failure mode entirely because it does not rely on the SNI/Host mismatch that CDNs were able to patch with a simple header equality check.

From 2021-wei-domainDomain Shadowing: Leveraging Content Delivery Networks for Robust Blocking-Resistant Communications · §2.3 · 2021 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
sni-blocking
defenses
domain-fronting

Extracted by claude-sonnet-4-6 — review before relying.