Movatterモバイル変換


[0]ホーム

URL:


Skip to main content

Encryption App 'Signal' Fights Censorship With a Clever Workaround

A technique called "domain fronting" makes the app's encrypted traffic look no different from a Google search.
Encryption App 'Signal' Fights Censorship With a Clever Workaround
Getty Images

Any subversive software developer knows its app has truly caught on when repressive regimes around the world start to block it. Earlier this week theencryption app Signal, already a favorite within the security and cryptography community, unlocked that achievement. Now, it's making its countermove in the cat-and-mouse game of online censorship.

On Wednesday, Open Whisper Systems, which created and maintains Signal,announced that it's added a feature to its Android app that will allow it to sidestep censorship in Egypt and the United Arab Emirates, where it wasblocked just days ago. Android users can simply update the app to gain unfettered access to the encryption tool, according to Open Whisper Systems founder Moxie Marlinspike, and an iOS version of the update is coming soon.

Signal's new anti-censorship feature uses a trick called "domain fronting," Marlinspike explains. A country like Egypt, with only a few small internet service providers tightly controlled by the government, can block any direct request to a service on its blacklist. But clever services can circumvent that censorship by hiding their traffic inside of encrypted connections to a major internet service, like the content delivery networks (CDNs) that host content closer to users to speed up their online experience---or in Signal's case, Google's App Engine platform, designed to host apps on Google's servers.

"Now when people in Egypt or the United Arab Emirates send a Signal message, it’ll look identical to something like a Google search," Marlinspike says. "The idea is that using Signal will look like using Google; if you want to block Signal you'll have to block Google."

The trick works because Google's App Engine allows developers to redirect traffic from Google.com to their own domain. Google’s use of TLS encryption means that contents of the traffic, including that redirect request, are hidden, and the internet service provider can see only that someone has connected to Google.com. That essentially turns Google into a proxy for Signal, bouncing its traffic and fooling the censors.

That domain fronting technique has already been used by other encryption and anti-censorship tools like Tor, Psiphon, and Lantern. And it doesn't just depend on Google, but also works with CDNs like Cloudflare, Akamai, and Amazon Cloudfront. So a censor attempting to block the circumvention method would have to block not only Google, but also a long list of other major services. "All of that together represents a large chunk of internet traffic," says Marlinspike. "Eventually disabling Signal starts to resemble disabling the internet."

Blocking major services, or even blocking the entire internet, is certainly a real possibility. Egypt, after all, did block its entire internet during the Arab Spring protests in 2011. And Brazil blocked WhatsApp, which integrates Signal as its encryption protocol, after a stymied drug investigation. But in both cases, the block was short-lived---only a few countries like China, Iran, and North Korea have been willing to permanently censor large swathes of the internet wholesale.

If any other countries block Signal, Marlinspike says he'll be ready to react. "This kind of thing is a high priority," he says. (In fact, Marlinspike rushed out an Arabic language version of Signal's predecessor encryption apps Redphone and Textsecure to help Arab Spring protestors five years ago.) And at least in countries where the government isn't willing to shut down the internet altogether, he thinks the app has a strong chance of staying online. "At least in places like this, these techniques are going to be really effective," says Marlinspike. "It’s possible that these countries will respond. But the endgame is that we’ll win."

Andy Greenberg is a senior writer for WIRED covering hacking, cybersecurity, and surveillance. He’s the author of the booksTracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency andSandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers. His books ...Read More
Senior Writer
Read More
Notepad++ Users, You May Have Been Hacked by China
Suspected Chinese state-backed hackers hijacked the Notepad++ update infrastructure to deliver a backdoored version of the popular free source code editor and note-taking app for Windows.
Social Security Workers Are Being Told to Hand Over Appointment Details to ICE
The recent request goes against decades of precedent and puts noncitizens at further risk of immigration enforcement actions.
What Is Thread? We Explain the Smart Home Network Protocol
Thread is a mesh networking protocol that connects low-power smart home gadgets, and it’s one of Matter’s underlying technologies.
Thinking Machines Cofounder’s Office Relationship Preceded His Termination
Leaders at Mira Murati’s startup believe Barret Zoph engaged in an incident of “serious misconduct.” The details are now coming to light.
Salesforce Workers Circulate Open Letter Urging CEO Marc Benioff to Denounce ICE
The letter comes after Benioff joked at a company event on Monday that ICE was monitoring international employees in attendance, sparking immediate backlash.
Palantir CEO Alex Karp Recorded a Video About ICE for His Employees
In a video shared with Palantir employees, Alex Karp did not explain how ICE is utilizing the company’s products. Instead, workers were told they can sign NDAs if they want detailed information.
A Wave of Unexplained Bot Traffic Is Sweeping the Web
From small publishers to US federal agencies, websites are reporting unusual spikes in automated traffic linked to IP addresses in Lanzhou, China.
The ICE Expansion Won’t Happen in the Dark
People have a right to know who their neighbors are, especially when it’s ICE.
ICE Is Crashing the US Court System in Minnesota
Petitions demanding people get the chance to be released from ICE custody have overwhelmed courts throughout the US.
Senators Urge Top Regulator to Stay Out of Prediction Market Lawsuits
As prediction market platforms like Polymarket and Kalshi battle regulators in court, Senate Democrats are urging the CFTC to avoid weighing in, escalating a broader fight over the burgeoning industry.
How to Film ICE
Filming federal agents in public is legal, but avoiding a dangerous—even deadly—confrontation isn’t guaranteed. Here’s how to record ICE and CBP agents as safely as possible and have an impact.
Exclusive LegalZoom Promo Code for 10% Off Services for February
Save on top services at LegalZoom, like LLC registration, incorporation, estate plans, and more with coupons and deals from WIRED.

[8]ページ先頭

©2009-2026 Movatter.jp