QUIC streams with encrypted_client_hello extensions in QUIC initials are being blocked in Uzbekistan

Dropping HTTPS connections containing encrypted_client_hello extensions in ClientHello was perfectly predictable. Now it’s QUIC too. Even DNS queries for cloudflare-ech.com A record where blocked for a while.

Concerning HTTPS I dream of sweet battery power saving RSTs or false FINs.

1 month ago in Uzbekistan was blocked two protocols: QUIC and TLSv1.3. As I remember, these was posted in local news:

Were TLSv1.3 being blocked totally in Uzbekistan, I would have lost my job. :expressionless:

As I know - in December Uzbektelecom switched on new complex of DPI, but I don’t know - what kind of DPI was bought. And in December several deny rules were activated, such as partial blocking of quic/tls1.3 (looks like they activated these rules for some commercial ISPs) and, for example, blocking of GRE tunnels.