FINDING · DEFENSE

Browsers cannot independently set the HTTP Host header or TLS SNI field, blocking the standard censorship-trigger methods used in Geneva training. The paper proposes two workarounds: (1) keyword-based HTTP censorship triggers using forbidden strings in URL parameters, limited to censors that employ keyword filtering; and (2) registering domains whose strings contain a censored substring to exploit censor overblocking via overbroad regular expressions (e.g., registering a domain matching torproject.org's regex to also catch mentorproject.org).

From 2023-tran-crowdsourcingCrowdsourcing the Discovery of Server-side Censorship Evasion Strategies · §3 Design — Triggering Censorship · 2023 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
keyword-filteringsni-blockingdpi
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.