FINDING · EVALUATION

The SNI-to-destination mapping in MITM-DomainFronting is hand-curated by inspecting CDN certificate SAN lists with no automatic discovery; the author explicitly flags that these mappings must be refreshed whenever a CDN changes its SAN list or edge topology. This maintenance burden is evidenced by 20 versioned releases published in under five months (through May 18, 2026), making the config effectively a continuously-updated snapshot of 'what CDN fronting pairs are valid from Iran this week.'

From 2026-patterniha-mitm-domainfrontingMITM-DomainFronting: client-only domain fronting via local TLS MITM with a user-installed CA · README / Limitations · 2026 · GitHub (1.5k stars; merged into XTLS/Xray-core via PR

Implications

Tags

censors
ir
defenses
domain-fronting

Extracted by claude-sonnet-4-6 — review before relying.