Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But if SNI based blocking is the case, it should give ERR_CONNECTION_RESET, here the page appeared with apparently a (cloudflare issued) Valid SSL Certificate with the given text. Isn't that supposed to not happen?

This is what curling the output gave me earlier: https://pastebin.com/Ae5DMn04 , Now the site has mysteriously started working.

This should only be possible if the request is being intercepted somewhere between Cloudflare's server (which might have a unicast location in India) and the actual server that might be happening over HTTP, which is a serious issue! This would also explain why it works sometimes and fails the other times. But that won't explain why it shows my ISP in the blocked message.

To further support this theory, Wireshark showed nothing weird in the TLS exchange, So it either suggests my ISP has cracked encryption (unlikely) or the link between cloudflare middleboxes and the "Internet" should be treated as insecure.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: