AWS starts blocking domain-fronting, a technique used by services to evade state-level internet blocks, following a similar move by Google's App Engine
A week after Google shut down a method for app developers to skirt internet censorship, Amazon is doing the same.
Context & Ripple Effects
This closes a two-week arc: on April 20, Google quietly disabled domain-fronting on App Engine, ending developers' ability to route traffic through its network to slip past state-level blocks. Within days, AWS followed, and by May 2 Amazon had warned Signal directly that continuing the technique would cost it its AWS account.
The move matters because domain-fronting was one of the few censorship workarounds that required no local infrastructure — it borrowed the reputational cover of the biggest cloud domains. With both Google and Amazon closing it, the technique's viability now depends entirely on which smaller hosts still permit it.
First-order effects
- Signal and other services using AWS for domain-fronting must stop the practice immediately or lose their hosting, forcing an emergency migration of their censorship-evasion traffic.
Second-order effects
- With the two largest cloud platforms closed, demand shifts to smaller providers willing to host fronting traffic — concentrating risk on hosts with less leverage against state pressure, as China's earlier blocking of VPN services showed states will pursue whatever channel remains.
Third-order effects
- Cloud terms of service are becoming a de facto enforcement layer for national internet controls: when Amazon and Google align their policies, the effective reach of a state block extends to every customer on their networks, without any regulator acting.
The trend: Anti-censorship tooling is being squeezed out of mainstream cloud infrastructure, leaving circumvention dependent on a shrinking set of providers whose policies — not governments' — now define where state blocks end.