Submitted via IRC for Fnord666
The team behind secure messaging app Signal says Amazon has threatened to drop the app if it doesn't stop using an anti-censorship practice known as domain-fronting. Google recently banned the practice, which lets developers disguise web traffic to look like it's coming from a different source, allowing apps like Signal to evade country-level bans. As a result, Signal moved from Google to the Amazon-owned Souq content delivery network. But Amazon implemented its own ban on Friday. In an email that Moxie Marlinspike — founder of Signal developer Open Whisper Systems — posted today, Amazon orders the organization to immediately stop using domain-fronting or find another web services provider.
Amazon has said that it's banning domain-fronting so malware purveyors can't disguise themselves as innocent web traffic. But Signal used the system to provide service in Egypt, Oman, and the United Arab Emirates (UAE), where it's officially banned. It got around filters by making traffic appear to come from a huge platform, since countries weren't willing to ban the entirety of a site like Google to shut down Signal.
Source: https://www.theverge.com/2018/5/1/17308508/amazon-web-services-signal-domain-fronting-ban-response
Also at TechCrunch and TechRepublic.
See also: A Google update just created a big problem for anti-censorship tools
APT29 Domain Fronting With TOR
Previously: Encrypted Messaging App Signal Uses Google to Bypass Censorship
Related: Open Whisper Systems Releases Standalone "Signal" Desktop App
(Score: 1) by nitehawk214 on Wednesday May 02 2018, @08:26PM (1 child)
Why not both?
"Don't you ever miss the days when you used to be nostalgic?" -Loiosh
(Score: 0) by Anonymous Coward on Wednesday May 02 2018, @08:31PM
You can try to kill all the cold viruses in the world, but it's a much better idea to figure out how to make one's own immune system thwart infection.
While malware authors should be despised, their success should be interpreted as one's own failure; if retaliation is not allowed by one's philosophical view of the matter, then one has no choice but to pour his energy into making it always un-profitable to write malware.