Our website is made possible by displaying online advertisements to our visitors.
Please consider supporting us by disabling your ad blocker.

Responsive image


Domain fronting

After TLS encryption is established, the HTTP header reroutes to another domain hosted on the same CDN.

Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than that which is discernable to third parties monitoring the requests and connections.

Due to quirks in security certificates, the redirect systems of the content delivery networks (CDNs) used as 'domain fronts', and the protection provided by HTTPS, censors are typically unable to differentiate circumvention ("domain-fronted") traffic from overt non-fronted traffic for any given domain name. As such they are forced to either allow all traffic to the domain front—including circumvention traffic—or block the domain front entirely, which may result in expensive collateral damage and has been likened to "blocking the rest of the Internet".

Domain fronting is achieved by a mismatch of the HTTP Host header and the TLS SNI extension. The standard that defines the SNI extension discourages such a mismatch but does not forbid it.[1] Many large cloud service providers, including Amazon, Microsoft, and Google, actively prohibit domain fronting, which has limited it as a censorship bypass technique. Pressure from censors in Russia and China is thought to have contributed to these prohibitions,[2][3][4] but domain fronting can also be used maliciously.

A newer variant of domain fronting, domain hiding, passes an encrypted request for one resource (say, a website), concealed behind an unencrypted (plaintext) request for another resource whose DNS records are stored in the same cloud. It has much the same effect.[2] Refraction networking is an application of the broader principle.

  1. ^ Eastlake 3Rd, Donald E. (January 2011). "IETF RFC 6066 section 3".{{cite web}}: CS1 maint: numeric names: authors list (link)
  2. ^ a b Cimpanu, Catalin (August 8, 2020). "DEF CON: New tool brings back 'domain fronting' as 'domain hiding'". ZDNET.
  3. ^ Cite error: The named reference psiphon was invoked but never defined (see the help page).
  4. ^ Cite error: The named reference china was invoked but never defined (see the help page).

Previous Page Next Page






Domain fronting AZ Domain Fronting German Συγκάλυψη όνομα τομέα Greek دامنه صوری FA Domain fronting French 도메인 프론팅 Korean 域前置 Chinese

Responsive image

Responsive image