On Wed, May 02, 2018 at 12:33:00AM +0000, Nima Fatemi wrote:
I don't know if people have seen this:
https://aws.amazon.com/blogs/security/enhanced-domain-protections-for-amazon...
Yep, and did you see this post from Moxie [0]?
[0] https://signal.org/blog/looking-back-on-the-front/
Amazon is killing domain fronting too. We should probably work on a plan. Anybody knows anybody at top of the food chain in Amazon? They should probably be nudged that they're doing all the dictators and authoritarian regimes around the world the biggest favor they could ask for (but didn't have to).
Right, and this only leaves Microsoft - but considering the current trend, that may fall soon, too. How do we convince these large companies that they are helping real people, and they should help us help them? Using domain fronting wouldn't be a volation of their terms of service if they explicitly made it a service they provide.
Apparently fronting was used by malware and CnCs, and that was becoming problematic.
Difficult times ahead...