We really should not have let the majority of internet traffic be served by a small handful of giant companies without some legal protections as to what they're allowed to do.
But I would be 100% against any law that required them to allow domain fronting. It's fine if they want to, but requiring them to basically open up/leave open a hole in their systems is not right.
I'm really bothered by blanket policies that prevent beneficial uses of a tool because it can also be used to cause harm. Google and Amazon need to figure out how to disambiguate the two.
So it was not an act by google and amazon to activly harm Signal, but rather canceling ongoing support of Signal, that could put their buisness to harm, which is something different.
In the grand scheme of things, I don't like how much infrastructure technology giants control.
In this specific case, however, domain fronting is basically saying "if you want to ban me, you have to ban all of us", without asking if the rest of "us" consent to be put on the same boat.
It would be cool if they are, but it's perfectly understandable for them to disagree.
Just set one up myself took 15 minutes and that includes setting up a fresh VPS.
Just thinking what the best way to share it is.
The best idea I've had so far is using a CNAME response to a very common DNS query which would pass a basic filter, like I'd ask for "mail.mydomain.com" and it would respond with a CNAME pointing to the actual proxy. I have dead domains which I have configured with null records for MX and stuff (so spammers can't abuse them), I could hide the name of my proxies in the MX records a CNAMEs and nobody would be the wiser...
The trick is getting the word out on how to do it - like "hey everyone, just ask random domains for "mx.domain.com" and use the 30 level MX" or something which would pass as legit traffic. Maybe...
I’ve definitely got some old domains kicking about, I’ll see how far off they are from expiration and do something similar if they have at least a few months left in them.
The proxies themselves can also be hosted at normal sounding domains and subdomains like cdn.technology.memes or whatever.
And when you point other domains to them as CNAMEs use equally regular looking subdomains no algorithm would pick up as a proxy like webmail.abandoned.tld.
My conceptual idea is that how you get the person the name of the proxy to use has to hide as signal amongst the noise and not get trapped in DNS/domain blocking filters - and if it's keyword blocked by the Great Firewall, you just start asking other random domains for their MX records etc. I believe it's generally referred to as steganography: https://en.wikipedia.org/wiki/Steganography