[HN Gopher] List of domains censored by German ISPs
___________________________________________________________________
List of domains censored by German ISPs
Author : elcapitan
Score : 237 points
Date : 2025-12-29 18:21 UTC (4 hours ago)
(HTM) web link (cuiiliste.de)
(TXT) w3m dump (cuiiliste.de)
| nonethewiser wrote:
| So there are only 295 domains censored? Seems like a lot of them
| of streaming sights breaking copyright/license agreements. Has to
| be a small fraction of those such sites alone.
| sccxy wrote:
| So it is a collection of the best pirate sites?
| pelagicAustral wrote:
| It is to me, faved.
| jug wrote:
| Pretty much, yeah. Those they can't get to despite efforts.
| EbNar wrote:
| Let me write those down, to be sure no to go there by
| mistake.
| blell wrote:
| We are condemned to, every time a list of blocked sites is
| posted, endure the "hahaha this is great guys a list of pirate
| sites! bookmarked!!!!" edgy comments.
| aucisson_masque wrote:
| I don't know why you think this is an edgy comment, I'm
| actually screenshotting it to take a look tomorrow at the
| links. I've seen Anna archive and SCI hub which are extremely
| useful, if it helps finding more gems I'm all for it !
| Semaphor wrote:
| For those wondering: it's DNS blocks, so _only_ affecting those
| using ISP DNS.
| wrboyce wrote:
| Worth mentioning NextDNS and ControlD under this! I migrated
| from the former to the latter about six months ago, but both
| are a solid choice.
| mctt wrote:
| Free trial then $20USD per year for ControlD. Is that what
| you use? If so, why do you use this over another service?
| cyberpunk wrote:
| Not GP, but I just run my own dns inside the network
| (unbound on a little openbsd sbc) with a cronjob that pipes
| oisd.nl into it every night, works great..
| silisili wrote:
| Not OP but I also use ControlD. I admittedly like NextDNS
| interface better, but honestly, I rarely need to login
| anyways.
|
| So why ControlD? Because I don't want to run my own piHole,
| basically. They maintain ad block lists that you can edit
| as you see fit to add things or relax things that may cause
| issues(which you can't do easily with public ad blocking
| dns servers).
|
| Why ControlD then and not NextDNS? First, because their
| support was awesome when I had an issue. AFAICT it was the
| founder actually emailing me back and forth, and it ended
| up being my ISP's fault, but I only knew that based on
| research provided to me by support. Secondly, I got a good
| deal on a 5-year subscription at one point.
|
| Happy to answer any questions, not affiliated but a fan of
| the service.
| maxloh wrote:
| I am curious why SNI-based block isn't used.
| trinix912 wrote:
| Shhh, don't give them ideas
| ronsor wrote:
| It won't be relevant in a couple years when 90% of sites
| will be using ECH, meaning the SNI will be encrypted as
| well.
| hypeatei wrote:
| Just enabling ECH doesn't stop this, firewalls can see it
| and mangle the data to force a downgrade because most
| servers need to support older protocols. It's more
| accurate to say that once sites _only_ support ECH, then
| they 'll be forced to stop downgrading or deal with angry
| users.
| ronsor wrote:
| TLS 1.3, including the ECH extension, _does not_ permit
| downgrading, unless your implementation is broken.
|
| Trying to downgrade or strip extensions from any TLS 1.3
| connection will simply break the connection.
| hypeatei wrote:
| In the wild, that's not true at all[0][1]. The corporate
| firewall at my employer actually wasn't able to block ECH
| until they updated it then it was able to block sites as
| usual.
|
| 0: https://community.fortinet.com/t5/FortiGate/Technical-
| Tip-Ho...
|
| 1: https://docs.broadcom.com/doc/symantec-ech-whitepaper
| (see page 8)
| dilyevsky wrote:
| This is literally impossible. What your corp fw likely
| does is mitm _outer_ SNI because your IT department
| installed your company CA in every client 's trust store.
| So unless you do that at national level your only other
| option is to block ECH entirely.
|
| Edit: actually totally possible but you need build
| quantum computer with sufficient cubits first =)
| dilyevsky wrote:
| I ready the FortiGate link and this is the gist:
| The DNS filter setting on the FortiGate analyzes the DoH
| traffic and strips out the ECH parameters sent by the DNS
| server in the DoH response. If the client does not
| receive those parameters, it cannot encrypt the inner
| SNI, so it will send it in clear text.
|
| So basically they mess with DoH ECH config and trigger
| fallback behavior in the clients. I don't think any
| browsers do this yet but I think this loophole is not
| gonna last.
| hsbauauvhabzb wrote:
| Is there even a push for ECH? I don't imagine big tech
| and other powerful players particularly want it.
| Reason077 wrote:
| Interesting. UK ISPs have had a similar block/filter list for
| many years (mostly covering copyright-infringing torrent
| websites and the like). But it's more robust than a simple DNS
| block. A VPN can bypass the block, but changing DNS providers
| will not.
| hsbauauvhabzb wrote:
| What / how do they do it then? SNI inspection?
| lategloriousgnu wrote:
| The ISP's blackhole the IP for some blocked domains. So
| changing your DNS to 8.8.8.8 will resolve the domain, but
| the IP won't work. A VPN avoids this, since the traffic
| goes via the VPN IP.
| hsbauauvhabzb wrote:
| How would that work with cloudflare and similar though?
| peter_d_sherman wrote:
| An excellent point!
|
| Yes, any given domain name (or as non-technical people would
| think about it, "website" -- any website) could be "blocked"
| (re-routed to a non-functioning IP, claimed to not exist, other
| DNS error or malfunction, ?, ???) at any level of DNS (ISP,
| Local, Regional, Country, ?, ???)
|
| A question your statement so excellently potentially suggests,
| is:
|
| _What 's the true extent of the block?_
|
| Is it merely a DNS failure -- or are inbound/outbound packets
| to an IP address actively suppressed and/or modified to prevent
| TCP/IP connections? (i.e., The Great Firewall Of China, etc.)
|
| You have _" Bad Faith Actors"_ (let's not call them
| "governments", "countries", "nation states" or even "deep
| states" -- those terms are _so_ 2024-ish, and as I write this,
| it 's almost 2026! :-) )
|
| Observation: Let's suppose a "Bad Faith Actor" (local or
| nationwide, foreign or domestic) attempts to block a website.
| They can accomplish this in one of 3 ways:
|
| 1) DNS Block
|
| 2) TCP/IP Block, i.e., block TCP/IP4/6 address(es), address
| ranges, etc.
|
| 3) Combination of 1 and 2.
|
| #3 is what would be used if a "Bad Faith Actor" absolutely had
| to block the "offending" website, no ifs ands or buts!
|
| But... unfortunately for them (and fortunately for us "wee
| folk"! :-) ), each of these types of blocks comes with
| _problems_ , _problems for them_ , which I shall heretofore
| enumerate!
|
| _From the perspective of a "Bad Faith Actor":_
|
| 1) DNS Block -- a mere DNS block of a single domain name is
| great for _granularity_ that is, it targets that domain name
| and that domain name alone, and something like this works great
| when a given company 's products and services are directly tied
| to their website as their brand name (i.e., google.com being
| blocked in China), but it doesn't work well for fly-by-night
| websites -- that's because a new domain name pointing to the
| old IP address can simply be registered...
|
| 2) TCP/IP Address / Address Range Block -- The problem with
| this approach is that while it is more thorough than a simple
| DNS block, _it may also_ (illegally and unlawfully, I might
| add!) _block legitimate other users, websites and services and
| businesses_ which share the same IP or IP address range!
|
| Think about it like this... A long time ago, all of the mail
| traffic for AOL (America Online), about 600,000 users or so,
| was coming from a single IP address. Block that IP address, and
| yes, you've stopped spam from the single user who is annoying
| you, but you've also (equal-and-oppositely!) blocked 599,999
| legitimate users!
|
| So "Bad Faith Actors" -- are "damned if they use the first
| method, and really damned if they use the second or third
| methods"... the first method is easily circumventable for non-
| brand name dependent websites and web services, while the
| second and third methods _risk causing harm to legitimate
| users, sometimes huge amounts of them_... which _should be
| illegal and unlawful by any country 's legal standards_...
|
| In other words, _Countries should read their own sets of laws_
| (!) before contemplating Internet blocks on their Citizens...
| :-) And not just one country either, _all of them_!!! :-)
|
| Anyway, an excellent point!
|
| Very thought stimulating -- as you can see by my ramblings! :-)
| drnick1 wrote:
| If this is the case, someone running their own recursive DNS
| server (like Bind9 or Unbound) can trivially bypass these
| restrictions. Doing this is a sensible step towards more
| privacy, regardless of censorship.
| layer8 wrote:
| They don't need to run their own DNS server, just configure a
| DNS server other than the ISP-provided one, like Quad9 or
| Google.
| JohnLocke4 wrote:
| _As a reward for freeing yourself from the de facto government
| DNS, you will now be gifted free movies for eternity_
| lifestyleguru wrote:
| Germans are mostly chill but if you start torrenting copyrighed
| content or even watching illegal streaming they will eat your
| face and drink your warm blood.
| xg15 wrote:
| German authorities, not Germans.
| nosianu wrote:
| It's mostly certain law firms employed by copyright owners.
|
| Famous (in Germany) example:
| https://de.wikipedia.org/wiki/Frommer_Legal (use auto-
| translate, it's German)
| aleph_minus_one wrote:
| > Famous (in Germany) example:
| https://de.wikipedia.org/wiki/Frommer_Legal (use auto-
| translate, it's German)
|
| For a lot of Germans who are knowledgable in this topic,
| being associated with such a company is nearly like openly
| admitting to have raped children. The hate for these
| companies and their employees is extreme.
| tirant wrote:
| I knew about torrenting, due to the problem of redistributing
| copyright material. But pure streaming? Are you sure that is
| illegal in Germany?
| p2detar wrote:
| No, it's not. Friend of mine was doing it on regular basis
| and only stopped because he got Amazon Prime subscription and
| didn't need to anymore.
| lifestyleguru wrote:
| There were attempts at legal bullying, but mostly with aim
| to humiliate the victim as the correspondence contains the
| full titles of porn videos.
| tyre wrote:
| Wait people are illegal streaming twitch?
|
| I guess that makes sense but I never thought about that.
| lionkor wrote:
| Prime includes Amazon Video or whatever
| mikigraf wrote:
| Germans yes, the gov with their over-regulation not
| lysace wrote:
| German Wikipedia was taken down twice (for "privacy", not
| piracy though). Still "illegal information". In the latter case
| about a former Stasi worker turned leftist member of
| parliament.
|
| https://www.theregister.com/2006/01/20/wikipedia_shutdown/
|
| _The German Wikipedia site was taken down by court order this
| week because it mentioned the full name of a deceased Chaos
| Computer Club hacker, known as Tron. A Berlin court ordered the
| closure of the site on Tuesday after it sided with the parents
| of the German hacker, who wanted to prevent the online
| encyclopedia from publishing the real name of their son. A
| final ruling is expected in two weeks ' time._
|
| https://web.archive.org/web/20090129160045/https://cyberlaw....
|
| _By virtue of an interim injunction ordered by the Lubeck
| state court dated November 13, 2008, upon the request of Lutz
| Heilmann (Member of Parliament - "Die Linke" party), Wikipedia
| Germany is hereby enjoined from continuing linking from the
| Internet address wikipedia.de to the Internet address
| de.wikipedia.org, as long as under the address de.wikipedia.org
| certain propositions concerning Lutz Heilmann remain visible._
| lifestyleguru wrote:
| Sometimes it feels that the only reason for German "privacy
| laws" are former Nazi and Stasi officials hiding their past.
| amarant wrote:
| Those all live in South America though
| croisillon wrote:
| and here for Magenta Austria
| https://blog.magenta.at/internet/sicherheit/netzsperre/
| jug wrote:
| Honestly makes it look like legislation with "sponsorship" from
| the film industry. I had expected much shadier stuff or those
| overrun with malware to protect users, not like 90% illicit
| streaming.
| baby_souffle wrote:
| > or those overrun with malware to protect users
|
| The anti-malware companies won't lobby government to block
| malware as that would cut into sales of their anti
| virus/malware.
| carpenecopinum wrote:
| There is no legislation here. CUII is a private organization
| that generates lists of domains that contain copyright
| violations. ISPs voluntarily choose to block those.
| like_any_other wrote:
| Voluntarily under threat of prosecution under existing
| legislation if they don't.
| leonwip wrote:
| But it is not legally required, and at least my smaller German
| ISP doesn't seem to care.
| lucb1e wrote:
| Which one is that?
|
| I would be interested in paying a bit more if the ISP is
| better. In the Netherlands we always had xs4all, nowadays sorta
| morphed into freedom internet, which was started from a hacker
| magazine and kept the spirit, fighting surveillance and
| censorship while offering regular ISP services and then some.
| I'm not aware that Germany has such a thing so any step in the
| right direction would make me switch if I can get it (should be
| fine if it's available via Telekom's public network, we're
| currently on a virtual operator as well)
| jillesvangurp wrote:
| I use an o2 DSL connection in Berlin. The domains I tested seem
| to resolve fine. And you can of course configure an alternate
| DNS. Which apparently I didn't yet on my new laptop. So, that
| is fixed now. Mostly that's just a performance fix. Operator
| DNS tends to be a bit slow to respond and it's nice to get back
| a few milliseconds. But I also don't mind my operator not
| spying on me.
|
| Of course I also use Firefox so mostly that just bypasses the
| system DNS entirely and uses dns over https.
| borlox wrote:
| My ISP doesn't care either. Why would they.
| nik282000 wrote:
| Anna's Archive and Sci-Hub. So despite their facade the German
| government is just as draconian as the US.
| crazygringo wrote:
| Despite what facade?
| easterncalculus wrote:
| The frequently repeated keystone lie that Europeans have
| equivalent or greater rights, freedoms, and protection from
| authoritarianism than Americans, which is and has always been
| objectively and completely false.
| cedilla wrote:
| Well, when fascists are in power, paper won't help anyone.
| But at this point, as a European I enjoy enumerated human
| and civil rights from multiple constitutions and several
| international treaties, which are directly enforceable by
| courts at the state, national, and European level.
|
| The human and civil rights guaranteed by the US
| constitution are a complete joke in comparison, and most of
| them are not guaranteed directly constitution, but by
| Supreme Court interpretation of vague 18th century law that
| can change at any time.
| pessimizer wrote:
| You seem to have missed the Bill of Rights. Which is odd,
| because whenever we tell you during online arguments that
| our rights are guaranteed, you all say that absolute
| rights are dumb and it's actually more sophisticated and
| European to not have them.
|
| Not that courts, legislators, and administrations haven't
| tried and succeeded in abridging them somewhat in any
| number of different ways for shorter or longer periods,
| but the text remains, and can always be referred to in
| the end. They have to abuse the language in order to
| abridge the Bill of Rights, and eventually that passes
| the point of absurdity.
|
| No such challenge in Europe. Every "right" is the right
| to do something _unless_ it is not allowed.
| oezi wrote:
| Well according to press freedom indices many European
| countries and the US are quite similarly ranked. Some
| countries better some countries worse.
|
| Some countries have stronger institutions against
| dictatorships than others but unfortunately we have seen
| that even the US isn't immune and that slides auch as in
| Poland and Hungary are possible.
|
| There is always hope that things can turn around (as in
| Poland even though the road is hard and there are setbacks)
| amarant wrote:
| Citation? Every democracy index I've ever heard of rates
| most of Europe as more democratic than the US. (Eastern
| Europe will typically be rated lower, all of the former
| USSR states seem to be struggling with various degrees of
| corruption or similar problems)
|
| The most commonly used index for example:
|
| https://en.wikipedia.org/wiki/The_Economist_Democracy_Index
| fuzzy2 wrote:
| The government or even courts are not involved with these
| blocks.
| dewey wrote:
| The main complaint about these blocks is that they are managed
| and decided on by private companies and _not_ by the government
| / law.
| almostgotcaught wrote:
| > German government is just as draconian as the US
|
| this is called "disinformation"
| trelane wrote:
| I honestly cannot tell if this is serious, or irony, or even
| meta-irony.
| oezi wrote:
| If I understand it right, then OP likely believes that
| Germany has a draconian regime when it comes to freedom of
| speech (which is objectively just ridiculous give or take
| some German nuances).
|
| OP thus wants to make fun of those (such as me) who are
| puzzled by a statement that Germany could be considered a
| draconian state with regards to freedom of speech. It is
| hard to engage OP because he likely isn't German and has no
| personal knowledge and experience at all if any of his
| speech would be censored in Germany. Calling OP disinformed
| maybe isn't quite correct, maybe misinformed would fit
| better.
| like_any_other wrote:
| They are considering banning the largest opposition party,
| are using wiretaps and informants against it [1], have banned
| (ban since lifted) a magazine [2], and opened a criminal
| investigation into someone calling a fat politician fat
| online [3]. They are openly planning even worse [4] (if you
| dislike the author, keep in mind every claim is sourced, so
| take it up with the sources).
|
| [1] https://www.aljazeera.com/news/2024/5/13/court-confirms-
| germ...
|
| [2] https://www.dw.com/en/germany-compact-press-freedom-
| right-wi...
|
| [3] https://www.foxnews.com/media/germany-started-criminal-
| inves...
|
| [4] _Germany announces wide-ranging plans to restrict the
| speech, travel and economic activity of political dissidents,
| in order to better control the "thought and speech patterns"
| of its own people_ - https://www.eugyppius.com/p/germany-
| announces-wide-ranging-p...
|
| Edit as reply to nosianu, because I am "posting too fast":
|
| > Liar. Some demand it - but it is not considered by those
| with the power to actually do it, not even close.
|
| _On Monday, the center-left Social Democratic Party (SPD),
| which is currently serving as the junior coalition partner in
| Berlin's conservative-led government, voted unanimously to
| begin efforts to outlaw [AfD]._ -
| https://edition.cnn.com/2025/07/06/europe/germany-afd-ban-
| po...
|
| _The Jewish German intelligence chief trying to ban the AfD_
| - https://www.telegraph.co.uk/world-news/2025/12/09/jewish-
| ger...
|
| I would not call the head of German intelligence and ruling
| coalition parties "not even close". Kindly save that liar
| label for yourself.
|
| > The AfD happily participates in state and federal elections
| and is in the federal parliament (Bundestag).
|
| "Considering" means they haven't done it yet. Some tried, but
| have not yet succeeded.
| amarant wrote:
| Largest opposition party?
|
| It's a neo nazi terrorist group with a political wing!
|
| There are 9 main parties in Germany, AfD doesn't even make
| top 10...
|
| Your comment is like saying the US is shooting political
| dissidents, and then referring to Al-Qaida or ISIS.
| like_any_other wrote:
| > It's a neo nazi terrorist group with a political wing!
|
| If you have a source showing AfD organized terrorist
| attacks, please present it. I could find no such thing.
|
| > There are 9 main parties in Germany, AfD doesn't even
| make top 10...
|
| In the 2025 elections, the largest party, the CDU, got
| 28.5% of the vote. The AfD came second with 20.8%: https:
| //en.wikipedia.org/wiki/Results_of_the_2025_German_fed...
|
| So you're simply lying.
| nosianu wrote:
| > _They are considering banning the largest opposition
| party_
|
| Liar. Some demand it - but it is not considered by those
| with the power to actually do it, not even close. The AfD
| happily participates in state and federal elections and is
| in the federal parliament (Bundestag).
|
| Why are you against freedom of speech??
|
| People _saying_ what they want is allowed! No action of
| that kind was or is taken. AfD and its members continues to
| participate in normal political life and getting elected,
| and they continue to participate in TV and media
| interviews.
|
| What exactly is your complaint? You complain about some
| people's speech - while claiming to be for freedom of
| speech! Very peculiar.
| pessimizer wrote:
| Will Germany be banning HN for not deleting it and sentencing
| nik282000 to a prison term then?
| oezi wrote:
| Is it draconian that piracy sites aren't resolved by some ISPs'
| DNS?
|
| Is it draconian if no Government entity is involved? And the
| penalty is unavailability?
|
| I thought draconian implies that the punishment is much too
| high in relationship to the crime.
|
| Maybe the whole affair is more dystopian rather than draconian:
| ISPs block access to media even though no law or government
| asked them to just so they have less hassle with rightholders.
| elcapitan wrote:
| 39c3 talk about this tomorrow (in German, but usually available
| with English translation)
| https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/...
| jstummbillig wrote:
| And now I am _really_ interested in what Anna might have in that
| archive of her 's
| gloxkiqcza wrote:
| For example soon to be released 300TB Spotify music library
| dump.
|
| https://news.ycombinator.com/item?id=46338339
| on_the_train wrote:
| I know a few more, for example demonoid. This list is just a
| sunset. Inb4 "actually it's not Germany censoring. It's the ISPs"
| deejaaymac wrote:
| I thought demonoid was dead dead?
| kn100 wrote:
| What a handy list the Germans have prepared
| wltr wrote:
| I have never visited these _kino_ domains, but I assume that's
| just some piracy entity. Yet it's quite impressive how many
| various domain names they bought! What for? Is it to avoid those
| blocks? Or is there any more reasons?
| Barrin92 wrote:
| mostly to avoid the blocking. Those streaming sites used to be
| extremely popular here in Germany because there was an entire
| cottage industry ( _Abmahnanwalte_ ) that used to pester
| uploaders with legal threats.
|
| Not sure what the state of it is now given that commercial
| streaming replaced a lot of both.
| zoklet-enjoyer wrote:
| This reminds me of a screenshot I saw where someone told chatgpt
| they stumbled upon a piracy website and wanted a list of other
| websites to avoid hahaha
| croisillon wrote:
| related:
|
| December 2024, 31 comments -
| https://news.ycombinator.com/item?id=42457712
| lukan wrote:
| Ah yes, we need to forcefully protect our citiziens from all the
| evils of the internet: rapists, pedophiles, terrorists ... oh
| wait, this is just about copyright stuff.
|
| Seriously, thanks for updating that list and the nice
| instructions to circumvent. (3 clicks with firefox, without the
| need to install anything or type in anything by hand)
| diego_moita wrote:
| Being German, is not surprising so many are sites with football
| games (i.e. the game Americans call "soccer").
___________________________________________________________________
(page generated 2025-12-29 23:00 UTC)