Russia intends to ban protocols that conceal website names.

Started Public discussion of the draft legal act proposing amendments to the Federal Law 'On Information, Information Technologies, and Information Protection', developed by the Ministry of Digital Development, Communications, and Mass Media. The law proposes to introduce a ban on the use of 'encryption protocols that allow the name (identifier) of a web page or website on the Internet to be concealed in the territory of the Russian Federation, except in cases established by the legislation of the Russian Federation.'

For violations of the ban on the use of encryption protocols that allow concealing the name of a website, it is proposed to suspend the operation of the Internet resource no later than 1 (one) business day from the day the violation is detected by the authorized federal executive authority. The main goal of blocking is the TLS extension ECH (previously known as ESNI), which can be used in conjunction with TLS 1.3 and is already blocked in China. Since the wording in the bill is vague and lacks specifics, in addition to ECH/ESNI, practically any protocols that provide complete encryption of the communication channel could formally fall under the ban, as well as the protocols DNS over HTTPS (DoH) and DNS over TLS (DoT).

Let us remind you that to organize the work of multiple HTTPS sites on a single IP address, the SNI extension was developed, which transmits the host name in clear text in the ClientHello message, sent before establishing a secure communication channel. This feature allows the Internet service provider to selectively filter HTTPS traffic and analyze which sites the user visits, which does not allow for complete confidentiality when using HTTPS.

ECH/ESNI completely eliminates the leakage of information about the requested site when analyzing HTTPS connections. Combined with access through a content delivery network, the use of ECH/ESNI also allows concealing the IP address of the requested resource from the provider — traffic inspection systems only see requests to the CDN and cannot apply blocking without replacing the TLS session, in which case a corresponding certificate replacement notification will be shown in the user's browser. If ECH/ESNI is banned to counter this possibility, only a complete restriction on access to content delivery networks (CDNs) that support ECH/ESNI can help; otherwise, the blocking will be ineffective and easily bypassed using a CDN.

When using ECH/ESNI, the hostname is transmitted in the ClientHello message just like in SNI, but the contents of the transmitted data in this message are encrypted. A secret, computed based on the server and client keys, is used for encryption. To decrypt the intercepted or obtained value of the ECH/ESNI field, it is necessary to know the private key of the client or server (plus the public keys of the server or client). Information about the public keys is transmitted for the server key in DNS, and for the client key in the ClientHello message. Decryption is also possible using the shared secret agreed upon during the establishment of the TLS connection, known only to the client and server.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster