|
|
|
|
|
by collinmanderson
2968 days ago
|
|
> I’m not sure why this doesn’t break SNI, or exactly when or how the certificate gets switched out over to Signal’s cert and private key. They way I understand it, the connection really _is_ using amazon’s cert+key, not Signal’s cert+key. Is signal (the server side) using amazons’s cert+key? Not technically. |
|
I also found this paper on domain fronting to be a very good read - Blocking-resistant communication through domain fronting [2]
[1] - https://docs.aws.amazon.com/AmazonCloudFront/latest/Develope...
[2] - https://www.bamsoftware.com/papers/fronting/