@12 every ISP is required to install a "black box" for network filtering. When it sees encrypted TLS traffic, it uses Server Name Indication (SNI) to check against an extensive list of domain blocks.
ECH doesn't let them see SNI, and they decided to break all sites using CloudFlare, because apparently censorship matters more than having Internet that works.
@12 every ISP is required to install a "black box" for network filtering. When it sees encrypted TLS traffic, it uses Server Name Indication (SNI) to check against an extensive list of domain blocks.
ECH doesn't let them see SNI, and they decided to break all sites using CloudFlare, because apparently censorship matters more than having Internet that works.