‹ BackHN Continuity

Thread

Spain orders blocks on Archive.today and its mirrors

555 points · 436 comments · latein

  1. peri-cl · · focus · HN ↗
    <a href="https:&#x2F;&#x2F;archive.is&#x2F;2YdN9" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;2YdN9
    1. alkyon · · focus · HN ↗
      I live in Spain and can still enjoy access to this site. This is enforced by major ISPs (Vodafone among others), so anyone sane just opts for a local ISP (if they have a choice)
      1. apexalpha · · focus · HN ↗
        How is it enforced? IP or DNS?
        1. alkyon · · focus · HN ↗
          According to this site <a href="https:&#x2F;&#x2F;bandaancha.eu&#x2F;articulos&#x2F;gobierno-tiene-lista-web-oficial-11138" rel="nofollow">https:&#x2F;&#x2F;bandaancha.eu&#x2F;articulos&#x2F;gobierno-tiene-lista-web-ofi..., they use SNI (<a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Server_Name_Indication" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Server_Name_Indication)
          1. alkyon · · focus · HN ↗
            Enabling ESNI in Firefox should be a countermeasure (encrypted SNI extension of the TLS so that hostname is no longer sent in plain text)

            <a href="https:&#x2F;&#x2F;superuser.com&#x2F;questions&#x2F;1346634&#x2F;modern-browser-with-a-feature-to-disable-sni" rel="nofollow">https:&#x2F;&#x2F;superuser.com&#x2F;questions&#x2F;1346634&#x2F;modern-browser-with-...

            1. [deleted] · · focus · HN ↗

              [deleted]

            2. mitxela · · focus · HN ↗
              It&#x27;s not magic. archive.is has no HTTPS record, so ESNI cannot be used.
            3. 1vuio0pswjnm7 · · focus · HN ↗
              That superuser thread from 2018 (it&#x27;s ECH now not ESNI) isn&#x27;t much help

              Although I do like the comment at the bottom that states the problem as disabling SNI not encrypting it. Encrypting SNI&#x2F;ClientHello is over complicated, which is why ESNI was flawed and (allegedly) why Cloudflare disabled it. The solution to the plaintext SNI problem is to not send SNI (I don&#x27;t send it unless necessary)

              There is an alternative non-TLS method of encrypting traffic, per packet, that allows hosting multiple websites on the same IP. I use it in the homelab. It proves that TLS and SNI is not the only way

              There&#x27;s also a popular archive of www content that does not require SNI. It&#x27;s older and larger than Cloudflare

              The problem with software like Firefox is that it automatically sends SNI to every website no matter if SNI is required or not. The superuser thread mentions a Firefox add-on that no longer works. If Firefox is open source then why not just edit the code and recompile

              Clearly, Mozilla is not going to provide a solution. It would rather add support for ESNI and then ECH as opposed to giving users an option to diable sending SNI

              Mozilla is pro-surveillance advertising, Cloudflare is pro-surveillance advertising

              Fortunately, not every HTTPS website is hosted on a shared IP, not every HTTPS website requires SNI. And popular web browsers derived from Mozilla and Google are not the only user agents

              A couple of ways to not send SNI

              1. Use an SSL client, e.g., openssl s_client, bssl client, etc.

              2. Use a local forward proxy, e.g., stunnel, haproxy, etc.

              Even if Cloudflare enables ECH across all the websites it controls, and we have been waiting for years, there is still the issue of SSL termination by Cloudflare. For many of those sites, all the TLS traffic, not just the SNI, is available as plaintext to Cloudflare and to whomever Cloudflare, a US corporation, may or must share it with

              1. 1vuio0pswjnm7 · · focus · HN ↗
                *disable
              2. mitxela · · focus · HN ↗
                Why not put the IP address in your hosts file under a different name so that&#x27;ll be the SNI?
              3. 1vuio0pswjnm7 · · focus · HN ↗
                It seems there are HN commenters who mistakenly believe SNI values can be controlled via the HOSTS file
        2. embedding-shape · · focus · HN ↗
          Differs by the ISP you have, I&#x27;ve seen DNS manipulation, IP filtering, hostname filtering, and HTTPS interception so far. Obviously most websites use TLS today so it mostly &quot;fails&quot; so people see certificate errors rather than their scary &quot;You&#x27;re contributing to breaking the law blah blah blah&quot;. Sometimes just straight up timeouts, resets, or generic connection failures.
          1. mitxela · · focus · HN ↗
            Browsers should change that page to say &quot;someone is hacking your internet&quot; with red background and giant warning sign, when certain certificates are received.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.