Reply to post: Re: But how?

Don't panic about domain fronting, an SNI fix is getting hacked out

Adam 1

Re: But how?

Problematic is one way to put it. Not actually solving the elephant is another.

Censorship bypass requires that the censoring authority cannot know the private key. And if they intercept 8.8.8.8 (for example) then the public key given to the client doesn't have to be the real server's one. The terrific firewall™ can simply MitM the client hello and decide whether to drop your packets; you just used their key.

The headline implies that this is a SNI fix, whereas this solution kicks off to the never never the actual magic needed to solve it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon