FINDING · DEFENSE

Amazon SQS routes client traffic through a single fixed HTTPS endpoint (https://sqs.us-east-1.amazonaws.com), making it infeasible for a censor to distinguish circumvention-bound SQS traffic from legitimate AWS service traffic; blocking this signaling channel would require blocking all Amazon SQS, imposing significant collateral damage on businesses and developers.

From 2024-pu-exploringExploring Amazon Simple Queue Service (SQS) for Censorship Circumvention · §2.2 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
ip-blockingdpi
defenses
webrtc-pluggabletunnelingbridges

Extracted by claude-sonnet-4-6 — review before relying.