China has begun blocking HTTPS connections established with TLS 1.3 and ESNI.

China implemented blocking all HTTPS connections using the TLS 1.3 protocol and the ESNI (Encrypted Server Name Indication) extension, which encrypts data about the requested host. The blocking is carried out on transit routers for connections established from China to the outside world and from the outside world to China.

To block, the packets from the client to the server are dropped, rather than injecting packets with the RST flag, which was previously done for selective blocking based on SNI content. After the blocking of an ESNI packet is triggered, all network packets corresponding to the combination of the source IP, destination IP, and destination port are also blocked for 120 to 180 seconds. HTTPS connections based on older versions of TLS and TLS 1.3 without ESNI are allowed as usual.

Let us recall that the SNI extension was developed to enable multiple HTTPS sites to work on a single IP address, transmitting the host name in clear text within the ClientHello message sent before establishing an encrypted communication channel. This feature allows internet providers to selectively filter HTTPS traffic and analyze which sites the user visits, making it impossible to achieve complete privacy when using HTTPS.

The new TLS extension ECH (previously ESNI), which can be used in conjunction with TLS 1.3, eliminates this drawback and completely prevents the leakage of information about the requested site when analyzing HTTPS connections. When combined with requests through a content delivery network, the use of ECH/ESNI also allows hiding the requested resource's IP address from the provider. Traffic inspection systems will only see requests to the CDN and won’t be able to apply blocking without replacing the TLS session, in which case the user's browser will display a corresponding certificate replacement notification. A potential leakage channel remains DNS, but to conceal DNS requests, the client can use DNS-over-HTTPS or DNS-over-TLS.

Researchers have already identified There are several workarounds for bypassing the Chinese block on the client and server sides, but they may lose relevance and should be considered only as temporary measures. For instance, currently only packets with the extension identifier ESNI 0xffce (encrypted_server_name) are blocked, which was used in the fifth version of the draft standard, but packets with the valid identifier 0xff02 (encrypted_client_hello), proposed in the seventh draft of the ECH specification.

Another workaround involves using a non-standard connection negotiation process; for example, the block does not trigger when a SYN packet with an incorrect sequence number is sent in advance, manipulating packet fragmentation flags, sending a packet with both FIN and SYN flags set, injecting an RST packet with an incorrect checksum, or sending a packet with SYN and ACK flags before connection negotiation begins. The described methods have already been implemented as a plugin to the toolkit Geneva, being developed to bypass censorship methods.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster