Domain fronting
Censorship circumvention technique
Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to connect discreetly to a different target domain from that which is discernable to third parties monitoring the requests and connections. Due to quirks in security certificates, the redirect systems of the content delivery networks (CDNs) used as 'domain fronts', and the protection provided by HTTPS, censors are typically unable to differentiate circumvention ("domain-fronted") traffic...
Nº Q28137019 ★
Common · History
Domain fronting
Censorship circumvention technique
Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to connect discreetly to a different target domain from that which is discernable to third parties monitoring the requests and connections. Due to quirks in security certificates, the redirect systems of the content delivery networks (CDNs) used as 'domain fronts', and the protection provided by HTTPS, censors are typically unable to differentiate circumvention ("domain-fronted") traffic...
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to connect discreetly to a different target domain from that which is discernable to third parties monitoring the requests and connections. Due to quirks in security certificates, the redirect systems of the content delivery networks (CDNs) used as 'domain fronts', and the protection provided by HTTPS, censors are typically unable to differentiate circumvention ("domain-fronted") traffic from overt non-fronted traffic for any given domain name. As such they are forced to either allow all traffic to the domain front—including circumvention traffic—or block the domain front entirely, which may result in expensive collateral damage and has been likened to "blocking the rest of the Internet". Domain fronting is achieved by a mismatch of the HTTP Host header and the TLS SNI extension. The standard that defines the SNI extension discourages such a mismatch but does not forbid it. Many large cloud service providers, including Amazon, Microsoft, and Google, actively prohibit domain fronting, which has limited it as a censorship bypass technique. Pressure from censors in Russia and China is thought to have contributed to these prohibitions, but domain fronting can also be used maliciously. A variant of domain fronting, domain hiding, passes an encrypted request for one resource (say, a website), concealed behind an unencrypted (plaintext) request for another resource whose DNS records are stored in the same cloud. It has much the same effect. As of August 2020, Cloudflare started refusing requests sent with both plaintext and encrypted destinations, rendering the initial implementation of the method only capable of obscuring the destination, but not bypassing firewalls. Refraction networking is an application of the broader principle.
Text: Wikipédia, CC BY-SA 4.0. · Image: Reseletti (CC0) ·
Related cards
DNS over HTTPS
Protocol to run DNS queries over HTTPS
Nº Q50826096 ★★★★
HTTP Strict Transport Security
HTTP response header field and associated policy
Nº Q2438540 ★★★★
Content delivery network
Layer in the Internet ecosystem addressing bottlenecks
Nº Q72588 ★★★
Cross-site request forgery
Type of malicious exploit of a website where unauthorized commands are transmitted from a user trusted by the web app, using image tags, hidden forms, XMLHttpRequest etc.
Nº Q15401472 ★★★★
Internet filter
Software that restricts or controls what content an Internet user can access
Nº Q13515741 ★
SIPRNet
Internetwork used by US Department of Defense (DoD) & US State Department for SECRET (Classified) Communications.
Nº Q1201480 ★★