[{"_id":"60503","user_id":"63563","ddc":["006"],"conference":{"end_date":"2025-07-14","location":"Washington, D.C.","start_date":"2025-07-14","name":"Free and Open Communications on the Internet"},"status":"public","has_accepted_license":"1","oa":"1","citation":{"bibtex":"@inproceedings{Niere_Lange_Heitmann_Somorovsky_2025, title={Encrypted Client Hello (ECH) in Censorship Circumvention}, author={Niere, Niklas and Lange, Felix and Heitmann, Nico and Somorovsky, Juraj}, year={2025} }","ama":"Niere N, Lange F, Heitmann N, Somorovsky J. Encrypted Client Hello (ECH) in Censorship Circumvention. In: ; 2025.","mla":"Niere, Niklas, et al. <i>Encrypted Client Hello (ECH) in Censorship Circumvention</i>. 2025.","short":"N. Niere, F. Lange, N. Heitmann, J. Somorovsky, in: 2025.","chicago":"Niere, Niklas, Felix Lange, Nico Heitmann, and Juraj Somorovsky. “Encrypted Client Hello (ECH) in Censorship Circumvention,” 2025.","ieee":"N. Niere, F. Lange, N. Heitmann, and J. Somorovsky, “Encrypted Client Hello (ECH) in Censorship Circumvention,” presented at the Free and Open Communications on the Internet, Washington, D.C., 2025.","apa":"Niere, N., Lange, F., Heitmann, N., &#38; Somorovsky, J. (2025). <i>Encrypted Client Hello (ECH) in Censorship Circumvention</i>. Free and Open Communications on the Internet, Washington, D.C."},"file_date_updated":"2026-08-17T07:40:46Z","language":[{"iso":"eng"}],"main_file_link":[{"url":"https://www.petsymposium.org/foci/2025/foci-2025-0016.pdf","open_access":"1"}],"author":[{"id":"63563","full_name":"Niere, Niklas","first_name":"Niklas","last_name":"Niere"},{"id":"67893","first_name":"Felix","last_name":"Lange","full_name":"Lange, Felix"},{"full_name":"Heitmann, Nico","last_name":"Heitmann","first_name":"Nico","orcid":"0009-0003-7687-7044","id":"74619"},{"id":"83504","full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","first_name":"Juraj"}],"year":"2025","title":"Encrypted Client Hello (ECH) in Censorship Circumvention","date_updated":"2026-08-17T07:40:46Z","date_created":"2025-07-03T07:14:00Z","file":[{"creator":"nniklas","date_created":"2025-07-03T07:11:14Z","relation":"main_file","date_updated":"2026-08-17T07:40:46Z","file_name":"foci-2025-0016.pdf","access_level":"local","file_size":755171,"file_id":"60505","content_type":"application/pdf"}],"type":"conference","keyword":["censorship","circumvention","ECH","TLS"],"abstract":[{"lang":"eng","text":"Censors have long censored Transport Layer Security (TLS) traffic by inspecting the domain name in the unencrypted Server Name Indication (SNI) extension. By encrypting the SNI extension, the Encrypted ClientHello (ECH) prevents censors from blocking TLS traffic to certain domains. Despite this promising outlook, ECH’s current capability to contest TLS censorship is unclear; for instance, Russia has started censoring ECH connections successfully. This paper clarifies ECH’s current role for TLS censorship. To this end, we evaluate servers’ support for ECH and its analysis and subsequent blocking by censors. We determine Cloudflare as the only major provider supporting ECH. Additionally, we affirm previously known ECH censorship in Russia and uncover indirect censorship of ECH through encrypted DNS censorship in China and Iran. Our findings suggest that ECH’s contribution to censorship circumvention is currently limited: we consider ECH’s dependence on encrypted DNS especially challenging for ECH’s capability to circumvent censorship. We stress the importance of censorship-resistant ECH to solve the long-known problem of SNI-based TLS censorship."}]},{"department":[{"_id":"632"}],"type":"conference","keyword":["censorship","censorship circumvention","http","http request smuggling"],"date_created":"2024-07-09T07:49:37Z","file":[{"creator":"flange","date_created":"2024-07-09T07:42:54Z","relation":"main_file","date_updated":"2026-08-17T07:40:56Z","file_name":"Turning Attacks into Advantages_ Evading HTTP Censorship with HTTP Request Smuggling - foci-2024-0012.pdf","file_size":189676,"access_level":"local","file_id":"55139","content_type":"application/pdf"}],"abstract":[{"lang":"eng","text":"Many countries limit their residents' access to various websites. As a substantial number of these websites do not support TLS encryption, censorship of unencrypted HTTP requests remains prevalent. Accordingly, circumvention techniques can and have been found for the HTTP protocol. In this paper, we infer novel circumvention techniques on the HTTP layer from a web security vulnerability by utilizing HTTP request smuggling (HRS). To demonstrate the viability of our techniques, we collected various test vectors from previous work about HRS and evaluated them on popular web servers and censors in China, Russia, and Iran. Our findings show that HRS can be successfully employed as a censorship circumvention technique against multiple censors and web servers. We also discover a standard-compliant circumvention technique in Russia, unusually inconsistent censorship in China, and an implementation bug in Iran. The results of this work imply that censorship circumvention techniques can successfully be constructed from existing vulnerabilities. We conjecture that this implication provides insights to the censorship circumvention community beyond the viability of specific techniques presented in this work."}],"publication":"Proceedings on Privacy Enhancing Technologies","language":[{"iso":"eng"}],"main_file_link":[{"url":"https://www.petsymposium.org/foci/2024/foci-2024-0012.pdf","open_access":"1"}],"date_updated":"2026-08-17T07:40:56Z","publication_status":"published","author":[{"last_name":"Müller","first_name":"Philipp","full_name":"Müller, Philipp"},{"id":"63563","last_name":"Niere","first_name":"Niklas","full_name":"Niere, Niklas"},{"id":"67893","full_name":"Lange, Felix","first_name":"Felix","last_name":"Lange"},{"id":"83504","full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky"}],"title":"Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling","year":"2024","oa":"1","place":"Bristol","quality_controlled":"1","citation":{"mla":"Müller, Philipp, et al. “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling.” <i>Proceedings on Privacy Enhancing Technologies</i>, 2024.","bibtex":"@inproceedings{Müller_Niere_Lange_Somorovsky_2024, place={Bristol}, title={Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling}, booktitle={Proceedings on Privacy Enhancing Technologies}, author={Müller, Philipp and Niere, Niklas and Lange, Felix and Somorovsky, Juraj}, year={2024} }","ama":"Müller P, Niere N, Lange F, Somorovsky J. Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling. In: <i>Proceedings on Privacy Enhancing Technologies</i>. ; 2024.","ieee":"P. Müller, N. Niere, F. Lange, and J. Somorovsky, “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling,” presented at the Free and Open Communications on the Internet 2024 , Bristol, 2024.","apa":"Müller, P., Niere, N., Lange, F., &#38; Somorovsky, J. (2024). Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling. <i>Proceedings on Privacy Enhancing Technologies</i>. Free and Open Communications on the Internet 2024 , Bristol.","short":"P. Müller, N. Niere, F. Lange, J. Somorovsky, in: Proceedings on Privacy Enhancing Technologies, Bristol, 2024.","chicago":"Müller, Philipp, Niklas Niere, Felix Lange, and Juraj Somorovsky. “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling.” In <i>Proceedings on Privacy Enhancing Technologies</i>. Bristol, 2024."},"file_date_updated":"2026-08-17T07:40:56Z","ddc":["006"],"user_id":"63563","_id":"55137","has_accepted_license":"1","conference":{"end_date":"2024-07-15","location":"Bristol","name":"Free and Open Communications on the Internet 2024 ","start_date":"2024-07-15"},"status":"public"}]
