5 ms·
Not really. Typically the query includes much more information (the site you want to visit) than the response (an IP potentially shared by thousands or millions
by markonen 9y ago
Not really. Typically the query includes much more information (the site you want to visit) than the response (an IP potentially shared by thousands or millions of sites).
- pfg 9y agoYou're still leaking that information due to SNI.
- xioxox 9y agoEven with https, the name of the site is sent in clear when the connection to the site is established (this is SNI).
- markonen 9y agoBack when they chose this design for SNI, I’m sure someone argued that it was fine because DNS had already leaked the hostname anyway :)
- tialaramex 9y agoIt's really hard to fix this. https://datatracker.ietf.org/doc/draft-ietf-tls-sni-encryption/ https://datatracker.ietf.org/doc/draft-ietf-tls-sni-encrypti... is the state of the art -- note that's a Draft, and really, really not finished, help is doubtless welcome. If it was easy, it would have been done during the TLS 1.3 process, but after a lot of discussion we're down to basically "Here is what people expect 'SNI encryption' would do for them, here's why all the obvious stuff can't achieve that, and here are some ugly, slow things that could work, now what?"
- dfox 9y agoIt is hard because of the TLS's pre-PFS legacy and to some extent also because of (very meaningful) intention to reduce roundtrips. The way to do SNI-like stuff is obvious: negotiate unauthenticated encrypted channel (by means of some EDH variant, you need one roundtrip for that) and perform any endpoint authentication steps inside that channel. This is what SSH2 does and AFAIK Microsoft's implementation of encrypted ISO-on-TCP (eg. rdesktop) does something similar. Edit: in SSH2 the server authentication happens in the first cryptographic message from server (for the obvious efficiency reasons), and thus for doing SNI-style certificate selection there would have to be some plaintext server-ID in first clients message, but the security of the protocol does not require that as long as the in-tunnel authentication is mutual (it is for things like kerberos).
- tialaramex 9y agoSo, it feels like you're saying this is how SSH2 and rdesktop work, and then you caveat that by saying well, no, they actually don't offer this capability at all it turns out. You are correct that you can do this if you spend one round trip first to set up the channel, and both the proposals for how we might encrypt SNI in that Draft do pay a round trip. Which is why I said they're slow and ugly. And as you noticed, SSH2 and rdesktop do not, in fact, spend an extra round trip to buy this capability they just go without.
- gsich 9y agoA load balancer can chose the correct backend by using the SNI. So there is a use for being unencrypted.