# A letter from Amazon

DevFeed: [A letter from Amazon](<https://devfeed.tech/articles/a-letter-from-amazon-1790.md>)

Original publisher: [Read original article](<https://signal.org/blog/looking-back-on-the-front/>)

Published: 2018-05-01T00:00:00Z

Content type: article

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [github](<https://devfeed.tech/tags/github.md>), [policy](<https://devfeed.tech/tags/policy.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tls](<https://devfeed.tech/tags/tls.md>)

## AI overview

Signal describes its use of domain fronting to help users access the service in countries where direct connections are censored. The article explains how cloud load balancing and separated TLS termination and request processing can obscure the destination from network censors, and recounts Amazon's warning that using Souq.com without permission violated AWS terms.

## Source excerpt

Last week, we received the following email from Amazon: From: [redacted], [redacted] <[redacted]@amazon.com> Subject: Notification of potential account suspension regarding AWS Service Terms Moxie, Yesterday AWS became aware of your GitHub and Hacker News/ycombinator posts describing how Signal plans to make its traffic look like traffic from another site, (popularly known as "domain fronting") by using a domain owned by Amazon -- Souq.com. You do not have permission from Amazon to use Souq.com for any purpose. Any use of Souq.com or any other domain to masquerade as another entity without express permission of the domain owner is in clear violation of the AWS Service Terms (Amazon CloudFront, Sec. 2.1: "You must own or have all necessary rights to use any domain name or SSL certificate that you use in conjunction with Amazon CloudFront"). It is also a violation of our Acceptable Use Policy by falsifying the origin of traffic and the unauthorized use of a domain. We are happy for you to use AWS Services, but you must comply with our Service Terms. We will immediately suspend your use of CloudFront if you use third party domains without their permission to masquerade as that third party. Thank you, [redacted] General Manager, Amazon CloudFront Read more...