Comment on Movie industry demands US law requiring ISPs to block piracy websites

<- View Parent
rottingleaf@lemmy.zip ⁨7⁩ ⁨months⁩ ago

However, there is so-called “clienthello” that is not encripted and can be used to identity the resource you are trying to reach.

Yes, so how is it going to inform you that this is a VPN server and not anything else? You put your little website with kitties and family photos behind nginx on a hosting somewhere, and some resource there, like /oldphotos, you proxy to a VPN server, with basic auth before that maybe.

And about libraries: VPN protocol Openconnect, for example uses library gnutls (which almost no one else uses) instead of more common openssl. So in China it is blocked using dpi by this “marker”.

Ah. You meant fingerprinting of clients.

Banning everything using gnutls (which, eh, is not only used by openconnect) is kinda similar to whitelists.

Both applicable to situations like China or something Middle-Eastern, but not most of Europe or Northern America.

source
Sort:hotnewtop