3 ms·
The client sends SNI, so how could the server opt out?
by hsivonen 9y ago
The client sends SNI, so how could the server opt out?
- Operyl 9y agoYou just solved your own question. Cloudflare creates an opensource client that users install locally.
- majewsky 9y agoWhere's the button to install your own DNS resolver on iOS? Or non-rooted Android, for that matter.
- thisacctforreal 9y agoSomeone shared this lovely iOS app yesterday: DNSCloak • DNSCrypt DoH client by Sergey Smirnov https://itunes.apple.com/ca/app/dnscloak-dnscrypt-doh-client/id1330471557 https://itunes.apple.com/ca/app/dnscloak-dnscrypt-doh-client... It supports DNSCrypt, DNSSEC and DNS-over-HTTPS, the IAP are for tips :) It works via running a VPN server on your device. To change your normal plaintext DNS resolver just tap the circle-i on your WiFi network.
- epse 9y agoNon-rooted android, you have to set a static IP for every network and then there will be an option to enter DNS names. They default to Google DNS Static IP settings are under advanced.
- MertsA 9y agoWell with SNI the concern isn't DNS. Any TLS connection that supports SNI (basically everything that isn't ancient) would have to be fixed. Also, ANI is a pretty useful thing to have and getting rid of it doesn't exactly fix much. Without SNI the server only has the destination IP address to determine which site and thus which certificate to send to the client. Having https sites with multiple certificates hosted on one IP address only works because of SNI. You would break a large portion of the web by disabling it. Also, even if you do disable SNI, the server still sends back the certificate with the domain names in it. And even if you ignore all of that, there's still reverse DNS which will probably be accurate if they send mail from that server and you can always do a DNS lookup for every domain name there is to get a map of which domains point to a given IP. Due to DNS based geolocation that won't work for every site but the sites using that are going to be big enough to find their IP address ranges via another method. In short, there's really no good solution here but an amendment to TLS could conceivably make it to where it wouldn't be possible to narrow it down to which site that an IP address hosts the user was visiting. That could actually be good enough for traffic to e.g. cloudflare.
- dancek 9y agoThe client that sends SNI is, AFAIK, the browser or a similar piece of software. Some older browsers don't support SNI so they can only access single-vhost-per-ip over https. This means you'll have a really hard time trying to get rid of SNI system-wide, what with a lot of minor apps making their own https connections (granted, on Android or iOS they probably use a common API, but not on a computer).
- d33 9y agoServer could advertise no need to use SNI in advance. Or we could do SNI after actually establishing an encrypted session...