The infrastructurefronting · domain hiding

Domain fronting

Hiding the real destination of a connection behind a permitted one, by presenting an allowed hostname where the network can read it while the encrypted request asks for something else on the same infrastructure.

Why it matters to you

It defeats blocking that works on names, which is most blocking. What it cannot hide is the shape of the conversation: beacon intervals, payload sizes and session durations survive the disguise, and are what a network defender should be watching once name-based control is known to be insufficient.

Where we meet it

The technique depends on shared infrastructure that the defender cannot block outright, so it follows whichever large provider currently permits it. That list changes, and the operators track it more attentively than most defenders do.

Where this term stops being vocabulary

Malveine is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.