China now blocking TLS 1.3 say Great-Firewall-watchers
(2020/08/11)
- Reference: 1597125187
- News link: https://www.theregister.co.uk/2020/08/11/china_blocking_tls_1_3/
- Source link:
China is now blocking all encrypted HTTPS traffic that uses TLS 1.3, according to observers at the Great Firewall Report (GFR).
TLS is the foundation of secure online communication and hides content users wish to access or have generated so it can pass over the internet without being observed by unrelated parties.
While TLS hides the content of a user's communication, it cannot always hide the server they are communicating with because its handshake optionally contains a Server Name Indication (SNI) field designed to explain where traffic is going. China and other nation-states have used this info to block their users from accessing particular websites.
To address that privacy gap TLS introduced Encrypted SNI (ESNI). ENSI encrypts the SNI so that intermediaries cannot view it and thus, in theory at least, prevent overzealous censors from sniffing and blocking traffic headed to and from places they don't like.
But according to [1]report from the GFR , China has found one way around this: block all TLS 1.3 connections outright.
The new block on ESNI connections is blunter than many of China's previous content-control strategies, which relied on sending forged TCP reset commands to both server and client to close a connection.
By comparison, the great firewall just blocks TLS 1.3 outright when China feels the need to do so, meaning that any website or server that uses the protocol cannot not be accessed in any form from the Middle Kingdom.
The GFWR team found that the block on ESNI connections works both ways, meaning Chinese users may struggle to get some traffic out of the country.
The team also found that any time an ESNI connection block was triggered, any connection with the same 3-tuple of source IP, destination, and destination port would continue to be blocked for up to 180 seconds. The block also happens on all ports, not just port 443 as is usually the case.
The GFWR found that it could circumvent the new blocks using Geneva, a genetic algorithm developed by the University of Maryland that manipulates packet streams without impacting the original connection. Using Geneva, the GFWR team discovering six strategies that work from the client side and four that work from the server side with 100 per cent reliability. ®
Get our [2]Tech Resources
[1] https://gfw.report/blog/gfw_esni_blocking/en/
[2] https://whitepapers.theregister.com/
TLS is the foundation of secure online communication and hides content users wish to access or have generated so it can pass over the internet without being observed by unrelated parties.
While TLS hides the content of a user's communication, it cannot always hide the server they are communicating with because its handshake optionally contains a Server Name Indication (SNI) field designed to explain where traffic is going. China and other nation-states have used this info to block their users from accessing particular websites.
To address that privacy gap TLS introduced Encrypted SNI (ESNI). ENSI encrypts the SNI so that intermediaries cannot view it and thus, in theory at least, prevent overzealous censors from sniffing and blocking traffic headed to and from places they don't like.
But according to [1]report from the GFR , China has found one way around this: block all TLS 1.3 connections outright.
The new block on ESNI connections is blunter than many of China's previous content-control strategies, which relied on sending forged TCP reset commands to both server and client to close a connection.
By comparison, the great firewall just blocks TLS 1.3 outright when China feels the need to do so, meaning that any website or server that uses the protocol cannot not be accessed in any form from the Middle Kingdom.
The GFWR team found that the block on ESNI connections works both ways, meaning Chinese users may struggle to get some traffic out of the country.
The team also found that any time an ESNI connection block was triggered, any connection with the same 3-tuple of source IP, destination, and destination port would continue to be blocked for up to 180 seconds. The block also happens on all ports, not just port 443 as is usually the case.
The GFWR found that it could circumvent the new blocks using Geneva, a genetic algorithm developed by the University of Maryland that manipulates packet streams without impacting the original connection. Using Geneva, the GFWR team discovering six strategies that work from the client side and four that work from the server side with 100 per cent reliability. ®
Get our [2]Tech Resources
[1] https://gfw.report/blog/gfw_esni_blocking/en/
[2] https://whitepapers.theregister.com/