Percy Wegmann

Lawrence, Kansas, United States Contact Info
677 followers 500+ connections

Join to view profile

About

- Nearly 25 years professional software development experience as consultant, developer…

Activity

Join now to see all activity

Experience & Education

  • Tailscale

View Percy’s full experience

See their title, tenure and more.

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

Publications

  • Blocking Resistant Communication through Domain Fronting

    De Gruyter Open

    We describe “domain fronting,” a versatile censorship circumvention technique that hides the remote endpoint of a communication. Domain fronting works at the application layer, using HTTPS, to communicate with a forbidden host while appearing to communicate with some other host, permitted by the censor. The key idea is the use of different domain names at different layers of communication. One domain appears on the “outside” of an HTTPS request—in the DNS request and TLS Server Name…

    We describe “domain fronting,” a versatile censorship circumvention technique that hides the remote endpoint of a communication. Domain fronting works at the application layer, using HTTPS, to communicate with a forbidden host while appearing to communicate with some other host, permitted by the censor. The key idea is the use of different domain names at different layers of communication. One domain appears on the “outside” of an HTTPS request—in the DNS request and TLS Server Name Indication—while another domain appears on the “inside”—in the HTTP Host header, invisible to the censor under HTTPS encryption. A censor, unable to distinguish fronted and nonfronted traffic to a domain, must choose between allowing circumvention traffic and blocking the domain entirely, which results in expensive collateral damage. Domain fronting is easy to deploy and use and does not require special cooperation by network intermediaries. We identify a number of hard-to-block web services, such as content delivery networks, that support domain-fronted connections and are useful for censorship circumvention. Domain fronting, in various forms, is now a circumvention workhorse. We describe several months of deployment experience in the Tor, Lantern, and Psiphon circumvention systems, whose domain-fronting transports now connect thousands of users daily and transfer many terabytes per month.

    Other authors
    • David Fifield
    • Rod Hynes
    • Chang Lan
    • Vern Paxson
    See publication

Languages

  • German

    Native or bilingual proficiency

  • English

    Native or bilingual proficiency

  • Spanish

    Limited working proficiency

Recommendations received

  • LinkedIn User

    LinkedIn User

1 person has recommended Percy

Join now to view

More activity by Percy

View Percy’s full profile

  • See who you know in common
  • Get introduced
  • Contact Percy directly
Join to view full profile

People also viewed

Explore collaborative articles

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Explore More

Add new skills with these courses