{"id":91188,"date":"2020-08-09T13:42:21","date_gmt":"2020-08-09T11:42:21","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni"},"modified":"2020-08-09T13:42:21","modified_gmt":"2020-08-09T11:42:21","slug":"kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni","title":{"rendered":"China has begun blocking HTTPS connections established with TLS 1.3 and ESNI.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>China <noindex><a rel=\"nofollow\" href=\"https:\/\/mailarchive.ietf.org\/arch\/msg\/tls\/Dae-cukKMqfzmTT4Ksh1Bzlx7ws\/\">implemented<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/gfw.report\/blog\/gfw_esni_blocking\/en\/\">blocking<\/a><\/noindex>  all HTTPS connections using the TLS 1.3 protocol and the ESNI (Encrypted Server Name Indication) extension, which encrypts data about the requested host. The blocking is carried out on transit routers for connections established from China to the outside world and from the outside world to China.<\/p>\n<p>To block, the packets from the client to the server are dropped, rather than injecting packets with the RST flag, which was previously done for selective blocking based on SNI content. After the blocking of an ESNI packet is triggered, all network packets corresponding to the combination of the source IP, destination IP, and destination port are also blocked for 120 to 180 seconds. HTTPS connections based on older versions of TLS and TLS 1.3 without ESNI are allowed as usual. <\/p>\n<p>Let us recall that the SNI extension was developed to enable multiple HTTPS sites to work on a single IP address, transmitting the host name in clear text within the ClientHello message sent before establishing an encrypted communication channel. This feature allows internet providers to selectively filter HTTPS traffic and analyze which sites the user visits, making it impossible to achieve complete privacy when using HTTPS.<\/p>\n<p>The new TLS extension ECH (previously ESNI), which can be used in conjunction with TLS 1.3, eliminates this drawback and completely prevents the leakage of information about the requested site when analyzing HTTPS connections. When combined with requests through a content delivery network, the use of ECH\/ESNI also allows hiding the requested resource's IP address from the provider. Traffic inspection systems will only see requests to the CDN and won\u2019t be able to apply blocking without replacing the TLS session, in which case the user's browser will display a corresponding certificate replacement notification. A potential leakage channel remains DNS, but to conceal DNS requests, the client can use DNS-over-HTTPS or DNS-over-TLS.<\/p>\n<p>Researchers have already <noindex><a rel=\"nofollow\" href=\"https:\/\/geneva.cs.umd.edu\/posts\/china-censors-esni\/esni\/\">identified<\/a><\/noindex> There are several workarounds for bypassing the Chinese block on the client and server sides, but they may lose relevance and should be considered only as temporary measures. For instance, currently only packets with the extension identifier ESNI 0xffce (encrypted_server_name) are blocked, which was used in <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-tls-esni-05\">the fifth version of the draft standard<\/a><\/noindex>, but packets with the valid identifier 0xff02 (encrypted_client_hello), proposed in <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-tls-esni-07\">the seventh draft of the ECH specification<\/a><\/noindex>.  <\/p>\n<p>Another workaround involves using a non-standard connection negotiation process; for example, the block does not trigger when a SYN packet with an incorrect sequence number is sent in advance, manipulating packet fragmentation flags, sending a packet with both FIN and SYN flags set, injecting an RST packet with an incorrect checksum, or sending a packet with SYN and ACK flags before connection negotiation begins. The described methods have already been implemented as a plugin to the toolkit <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Kkevsterrr\/geneva\">Geneva<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52249\">being developed<\/a><\/noindex> to bypass censorship methods.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53520\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u0438\u0442\u0430\u0439 \u0432\u043d\u0435\u0434\u0440\u0438\u043b \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0443 \u0432\u0441\u0435\u0445 HTTPS-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b TLS 1.3 \u0438 TLS-\u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0435 ESNI (Encrypted Server Name Indication), \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u0435 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e \u0437\u0430\u043f\u0440\u0430\u0448\u0438\u0432\u0430\u0435\u043c\u043e\u043c \u0445\u043e\u0441\u0442\u0435. \u0411\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430 \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u044b\u0445 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u0430\u0445 \u043a\u0430\u043a \u0434\u043b\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0438\u0437 \u041a\u0438\u0442\u0430\u044f \u0432\u043e \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u043c\u0438\u0440, \u0442\u0430\u043a \u0438 \u0438\u0437 \u0432\u043d\u0435\u0448\u043d\u0435\u0433\u043e \u043c\u0438\u0440\u0430 \u0432 \u041a\u0438\u0442\u0430\u0439. \u0414\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0442\u0431\u0440\u0430\u0441\u044b\u0432\u0430\u043d\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u043e\u0442 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443, \u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-91188","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u0438\u0442\u0430\u0439 \u0432\u043d\u0435\u0434\u0440\u0438\u043b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0438\u0442\u0430\u0439 \u043d\u0430\u0447\u0430\u043b \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c HTTPS-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0435 \u0441 TLS 1.3 \u0438 ESNI | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u0438\u0442\u0430\u0439 \u0432\u043d\u0435\u0434\u0440\u0438\u043b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-09T11:42:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-09T11:42:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47China has started blocking HTTPS connections established with TLS 1.3 and ESNI | ProHoster","description":"China has implemented","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0438\u0442\u0430\u0439 \u043d\u0430\u0447\u0430\u043b \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c HTTPS-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0435 \u0441 TLS 1.3 \u0438 ESNI | ProHoster","og:description":"\u041a\u0438\u0442\u0430\u0439 \u0432\u043d\u0435\u0434\u0440\u0438\u043b","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/kitaj-nachal-blokirovat-https-soedineniya-ustanavlivaemye-s-tls-1-3-i-esni","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-09T11:42:21+00:00","article:modified_time":"2020-08-09T11:42:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"91188","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:32:23","updated":"2022-09-28 04:45:43","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/91188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=91188"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/91188\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=91188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=91188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=91188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}