implementing enhanced protections against so-called “Domain Fronting”. Domain Fronting is when a non-standard client makes a TLS/SSL connection to a certain name, but then makes a HTTPS request for an unrelated name. For example, the TLS connection may connect to “www.example.com” but then issue a request for “www.example.org”.
In certain circumstances this is normal and expected. For example, browsers can re-use persistent connections for any domain that is listed in the same SSL Certificate, and these are considered related domains. But in other cases, tools including malware can use this technique between completely unrelated domains to evade restrictions and blocks that can be imposed at the TLS/SSL layer.
https://aws.amazon.com/blogs/security/enhanced-domain-protections-for-amazon-cloudfront-requests/
Пропустил уточнение о том, что желтуха в смешивании в кучу гугла, который как бы Outline запускает для фронтинга, и амазона, и связывание этого ещё и с блокировками, которые отношения к гуглу уж точно тут не имели.
Обсуждают сегодня