Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

“Signal” Uses Domain Fronting to Bypass Censorship

Open Whisper Systems informed users on Wednesday that the latest Android version of its secure messaging app Signal includes a feature designed to bypass censorship in some countries.

Open Whisper Systems informed users on Wednesday that the latest Android version of its secure messaging app Signal includes a feature designed to bypass censorship in some countries.

The company learned recently that ISPs in Egypt and the United Arab Emirates had started blocking the Signal service and website, likely in an effort to prevent users from communicating over channels that authorities cannot access.

In order to bypass these censorship attempts, the latest version of Signal for Android uses a technique called domain fronting, which involves disguising traffic to make it look as if it’s going to a host allowed by the censor.

Domain fronting was described last year in a paper published by researchers at the University of California – Berkeley, Psiphon Inc., and Brave New Software.

“The key idea is the use of different domain names at different layers of communication. One domain appears on the ‘outside’ of an HTTPS request—in the DNS request and TLS Server Name Indication—while another domain appears on the ‘inside’—in the HTTP Host header, invisible to the censor under HTTPS encryption,” researchers explained.

Since the technique involves the use of services from major companies such as Google, Amazon, CloudFlare, Fastly and Akamai, the censor can only block communications by banning the entire service, which can result in serious collateral damage.

In the case of Signal, messages look like regular HTTPS requests to google.com and blocking these communications would require ISPs to block Google altogether. Domain fronting is enabled for Signal users who have phone numbers with Egypt or UAE country codes.

Domain fronting via Google was used by a censorship circumvention tool called GoAgent in China, but it only worked until June 2014, when the country decided to block all Google services.

Advertisement. Scroll to continue reading.

The new censorship circumvention feature is also present in the beta channel of Signal for iOS and it will soon become generally available to iPhone and iPad users.

“Follow up releases will include detecting censorship and applying circumvention when needed (eg. so that when users with phone numbers from other countries visit places where censorship is being deployed, Signal will work without a VPN for them as well) and expanding the services that domain front for Signal,” said Open Whisper Systems founder Moxie Marlinspike.

Related: Flaw Allows Hackers to Alter “Signal” Attachments

Related: Open Whisper Systems Launches Encrypted Messaging App for Desktop

Related: Meet Matrix, an Open Standard for De-centralized Encrypted Communications

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...