6 ms·
There's still TLS Server Name Indication leaking the hostname.
by TurningCanadian 4y ago
There's still TLS Server Name Indication leaking the hostname.
- manigandham 4y agoSNI can be encrypted in an extension of TLS 1.3 called ESNI (encrypted server name indication). With both EDNS and ESNI, there's sufficient privacy coverage. The next standard is ECH (encrypted client-hello) which secures the entire handshake: https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/
- gsich 4y agoIs it still in draft state?
- manigandham 4y agoYes: https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15 https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15