FINDING · DETECTION
Registration-dependent Refraction Networking schemes such as Conjure create multiple single points of failure: censors can block registration channels independently of phantom connections. Domain fronting, a primary registration channel, has been progressively banned by major CDNs — Microsoft Azure in 2021 and Fastly in early 2024 — reducing its viability as a covert registration mechanism.
From 2024-chen-extended — Extended Abstract: Oscur0: One-shot Circumvention without Registration · §1 Introduction · 2024 · Free and Open Communications on the Internet
Implications
- Do not rely on a single out-of-band registration channel; any registration step is an independently-blockable attack surface that can neutralize the circumvention scheme without touching the phantom connection.
- Prefer registration-free designs or distribute registration across multiple channels (DNS, DHT) to eliminate single-point-of-failure exposure.
Tags
Extracted by claude-sonnet-4-6 — review before relying.