China starts blocking HTTPS connections with encrypted SNI: Report


San Francisco, Aug 9 (IANS): In an update to its national censorship tool, known as the Great Firewall, China has reportedly started blocking HTTPS connections with Encrypted Server Name Indication.

The ban has been in place for over a week now, three organisations tracking Chinese censorship -- iYouPort, the University of Maryland, and the Great Firewall Report - said this week in a joint report.

"We confirm that the Great Firewall (GFW) of China has recently begun blocking ESNI - one of the foundational features of TLS 1.3 and HTTPS," said the report.

TLS is the foundation of secure communication on the web (HTTPS). It provides authenticated encryption so that users can know whom they are communicating with. It also ensures that an intermediary does not read or tamper with your information.

But even though TLS hides the content of a user's communication, it does not always conceal with whom the user is communicating.

The TLS handshake (a process that kicks off a communication session) optionally contains a Server Name Indication (SNI) field that allows the user's client to inform the server which website it wishes to communicate with.

Nation-state censors have used the SNI field to block users from being able to communicate with certain destinations, said that report, adding that China has long been censoring HTTPS in this manner.

TLS 1.3 introduced Encrypted SNI (ESNI) that encrypts the SNI so that intermediaries cannot view it, said the report.

The Great Firewall of China blocks ESNI connections by dropping packets from client to server, it added.

 

 

  

Top Stories


Leave a Comment

Title: China starts blocking HTTPS connections with encrypted SNI: Report



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.