Tor – Snowflake Makes It Easy for Anyone to Fight Censorship
eff.org
eff.org
> ... domain fronting lets the client make a request that looks like an ordinary web request for google.com ... To block Snowflake, a network or country would have to block all of Google
But Google disabled domain fronting in 2018. Amazon did as well[0]. Cloudflare disabled it in 2015.
The article even links to this Wikipedia page[1] on domain fronting, which states that all three of these providers have disabled domain fronting.
So... how does it work?
Prior to this, they were fronting via Azure, using ajax.aspnetcdn.com as the front for target snowflake-broker.azureedge.net. But they switched to Fastly after Microsoft announced they'd be changing their policy to explicitly block domain fronting: https://www.microsoft.com/security/blog/2021/03/26/securing-...
Snowflake and anything else relying on domain fronting are quickly becoming non-viable. I wonder what the next stage in the rat race will be?
Isn't this a little sugarcoated? Your IP will now be known/knowable as a target to people you may consider bad. Running a Tor browser is between you, your ISP, and the bridge/entry.
I peeked at the failed AJAX calls and I saw that the site was denying my traffic because I was classified as a high risk endpoint. The name of their WAF/filtering vendor was in the error responses or headers, so I found a free way to query that company's threat database for my home IP. There it was, my IP was marked high risk because it was associated with a tor relay. It's a silly threat correlation, in my opinion, but it was enough of an annoyance that I stopped running the relay so I didn't have to worry about flaky firewalls.
The ironic thing was, I could have probably fired up Tor Browser and tried new exit nodes until I found a fresh one their system didn't know about, just to finish updating my claim! I actually just tethered my laptop to my phone, I think.
PS I forgot to ask: does anyone know if Snowflake is as detectable as a normal bridge or relay node? If so, there's the risk that your home connection gets a risk/reputation strike against like mine did.
I've got a spare laptop and started a TOR relay (no exit) recently - I'll be on the look out for these kind of errors
Something like nyx (for tor) but for snowflake.