FINDING · DETECTION
Iran's number of blocked domains increases from 25 (HTTP keyword blocking) to 374 (TLS SNI-based blocking) — a 15× increase — with the newly blocked domains shifting composition to predominantly News, Human Rights, and Anonymization tools. This demonstrates that Iran maintains a distinct, more aggressive SNI blocklist for HTTPS traffic that is largely invisible to HTTP-only measurement.
From 2018-vandersloot-quack — Quack: Scalable Remote Measurement of Application-Layer Censorship · §6.4 · 2018 · USENIX Security Symposium
Implications
- Circumvention tools operating over TLS must encrypt the SNI via ECH/ESNI or use domain fronting to evade Iran's SNI blocklist, which is 15× larger than its HTTP blocklist.
- Treat HTTP keyword filtering and TLS SNI blocking as distinct threat surfaces; a tool that evades HTTP DPI may still be blocked via SNI inspection in Iran.
Tags
Extracted by claude-sonnet-4-6 — review before relying.