Censors Ignore Unencrypted HTTP/2 Traffic (2024)
Published on: 2025-04-29 08:23:30
*Authors in alphabetical order – all contributed equally
Abstract
Censors worldwide have long censored unencrypted HTTP traffic. In this blog post, we show that a specific HTTP version—unencrypted HTTP/2—is unaffected by censorship in China and Iran. We access otherwise censored websites in both countries over unencrypted HTTP/2. Despite no web browser implementing unencrypted HTTP/2, we detect that up to 6.28% of websites support unencrypted HTTP/2 traffic. To aid the community and ease future research, we provide a tool that evaluates the unencrypted HTTP support of a website. Finally, we discuss the limitations and potential of unencrypted HTTP/2 for censorship circumvention. We consider our finding an interesting addition to current censorship circumvention techniques.
Note: Do not send sensitive data over unencrypted HTTP/2, it can be eavesdropped!
Introduction and Background
In this section, we provide background information on HTTP and its censorship. We place special empha
... Read full article.