China is now blocking all encrypted HTTPS traffic using TLS 1.3 and ESNI
zdnet.com
zdnet.com
The capability described in this article sounds more like a full layer-7 MITM.
That's terrifying. Is any HTTPS secure within mainlan China's networks?
Or am I misunderstanding, and it's just the government websites that are blocking incoming TLS 1.3 connections?
Looks like it's L4?
HTTPS is somewhat secure, but subject to MITM. Most Chinese forks of browsers ignore certificate errors and allow everything through.
But remember with SNI they know exactly what website you're visiting.