3 ms·
> Currently, SNI in TLS 1.2 has a flaw that allows censors to differentiate between a “real” service and a “fake” service if they are savvy enough to figure it
by rqs 8y ago
> Currently, SNI in TLS 1.2 has a flaw that allows censors to differentiate between a “real” service and a “fake” service if they are savvy enough to figure it out. Interestingly, SNI in TLS 1.3 fixes this problem by hiding all of the information about the service behind encryption.
Isn't this (Encrypted SNI) was the one been extensively discussed here: https://news.ycombinator.com/item?id=17538390 https://news.ycombinator.com/item?id=17538390 ?
This is great. I hope CDNs like Cloudflare etc deploy it ASAP. Also, deprecate previous TLS versions as ASAP so it can be more effective.
- TheCycoONE 8y agoThat was my thought reading the article. https://tools.ietf.org/html/draft-ietf-tls-sni-encryption-03 https://tools.ietf.org/html/draft-ietf-tls-sni-encryption-03 indicates this is not a solved problem for TLS 1.3, and the key in DNS solution is still in the experimental phase (though compatible with TLS 1.3) This article is premature?