4 ms·
I really like this even though I think it only makes for a minimal increase in privacy due to either SNI[1] or quickly grabbing the cert of an IP revealing the
by NaliSauce 9y ago
I really like this even though I think it only makes for a minimal increase in privacy due to either SNI[1] or quickly grabbing the cert of an IP revealing the hostname if no SNI is supported.
[1] https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- richardjennings 9y agoSNI will show the hostname of the "DNS over TLS" server the TLS connection is made with but not the DNS queries made.
- Ajedi32 9y agoDNS isn't very useful unless you're actually planning to visit the IPs you just looked up. And as soon as you do that, you'll send the domain name in plaintext via SNI.
- LogicX 9y agoI don't think so. The purpose of SNI is to pass the domain name to the final destination server, so it can serve up the correct SSL cert where there are multiple domains hosted on the same IP
- johannes1234321 9y agoIt will also show the hostname of the server I access after doing the DNS lookup.
- knorker 9y agoDoesn't TLS 1.3 fix this SNI hostname leak though?
- deleted 9y ago[deleted]
- aaomidi 9y agoNope, they kept it because there weren't better alternatives.
- jedisct1 9y agoDNS-over-TLS and DNSCrypt are more about authentication than privacy. They are useful against the guy sitting behind you at Starbucks doing DNS injection. They don't replace a VPN.