30

hello,

TLDR: just enable DoH

Today, my friend and I were talking about SNI and deep packet analysis shit done by the government. I insisted that since they do this kind of shit they can block access to certain sites like TPB and other freedom websites. he suggested that I just enable DoH in firefox and see the magic happen. I didn't believe him until I enabled DoH and magic. I can access every censored website.

so just saying that sometimes the bypass is much simpler than we think!

also I am thinking that even if the DNS request is encrypted cant they see the TLS client hello message and block it? or is it impossible?

you are viewing a single comment's thread
view the rest of the comments
[-] anon5621@lemmy.ml 11 points 1 week ago* (last edited 1 week ago)

You have weak dpi system in ur country then. the gfw and dpi aint just playing with ip blocks no more—they straight up dropping any ech packets on sight and nuking quic udp 443 to force that tcp fallback so they can sniff your sni while using active probing and ja3 fingerprinting to instant-kill any encrypted stream that dont look like a regular chrome handshake 1:1 and now they even doin alcpn hijacking and timing analysis

this post was submitted on 26 Apr 2026
30 points (96.9% liked)

Privacy

48348 readers
767 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS