I was reading about a whizzy new internet technology called Encrypted Client Hello (ECH). It has been implemented already in many internet browsers but also needs participation from websites to make it all work. This weeks news is that websites using
hosting at a company called Cloudflare will use this new tech. The importance of this is that the internet routing from a browser to the website will be pretty much all encrypted, so that Thai ISPs will no longer be able to detect which web
sites are being accessed, so can't easily block them. Anyway I decided to have poke around and see what is currently being implemented, at least by my Thai ISP, True. I was rather surprised to note that a couple of porn tube sites I tried
were unblocked. However things were not so good for my favourite bookie which was indeed blocked with nothing more than a blank page appearing when I typed the URL. Another sneaky piece of censorship is that Google Search is locked into
'safe search' regardless of what setting you select. So a search for porn tube returns no actual porn tubes. Not to worry though, the alternative privacy-based search engine DuckDuckGo.com still works fine. Actually there are existing
elements of Encrypted Client Hello (ECH) that are already available. These already clear a way through the current Thai blocking tech without needing to bother with a VPN. Recent versions of Firefox (from version 118) Chrome and Edge have already
added support for ECH. The first thing to select is in the browser network settings and is called DNS over HTTPS (DoH). This needs to be enabled and then select the Cloudflare DNS provider. Note that computers on a network outside of your control,
eg on a company network or a hotel network, can stop you setting this. This was enough on Chrome to get the internet unblocked, but on Firefox I had to one more step. In the Windows Network & internet WiFi settings for the network I am using I
replaced the ISP DNS server with Google's DNS server 8.8.8.8 (Encrypted preferred) for the first of the two IPv4 DNS Server selections. And as a bonus Google.com no longer forced safe mode searches. |