5 ms·
> So what's the plan for when IPv6 gains more adoption and we don't need SNI as much since every site can have its own public IP address Say sometimes I love t
by rqs 8y ago
> So what's the plan for when IPv6 gains more adoption and we don't need SNI as much since every site can have its own public IP address
Say sometimes I love to visit a very private website for my personal pleasure when I'm alone at night.
Without eSNI, when I type-in pornhub.com and hit enter, my buddy Bob who working for the ISP immediately knows and be very sure that I'm trying to accessing none other than pornhub.com. And then, with great confident, he greedily calling me for a live chat.
Bob is a ... special person. He might tell my mom about the pleasure thing, but not just that, he also secretly tracks my pleasure activities only to figure out the pattern using some sort of weird thing called machine learning, so he can show up in front of my door at the exact right time to share the pleasure with me.
I don't like that.
With eSNI, Bob only knows that I'm accessing 216.18.168.0. But when he tries to access the 216.18.168.0:80, he be greeted by a 403 error which says "Invalid Host".
A website may have many IP addresses, and an IP address can serve many websites. Because of that, now Bob can only know MAYBE I'm watching my little pleasure, oh wait, or maybe it's imworkingverylateatnight.com? He just can't be sure now.
- koolba 8y agoIf Bob works at your ISP, he could see the DNS queries before you even connect to the site. There’s work arounds for that as well but the average Joe isn’t going to set any of them up.
- deleted 8y ago[deleted]
- rqs 8y agoOf course. But what if DNS can also be encrypted?
- still_grokking 8y agoYou mean with DoH? Serviced for example from Googles public DNS servers?
- erinnh 8y agoIm more partial to DNS over TLS myself.
- why_only_15 8y agoI have a great new idea! DNS over TLS Co-location Open Mesh. That way, we can all be back in the DOTCOM era
- jhabdas 8y agoWhat if it already was? https://dnscrypt.info/ https://dnscrypt.info/
- bscphil 8y agoMaybe I'm misunderstanding, but isn't the point of the GP that as IPv6 takes over, eSNI becomes practically useless since it's possible for every site to have its own IP address? If I'm connecting to an IP address that only maps to one site, then Bob is going to be able to figure out what that site is. You're right that eSNI is a nice to have (though years late) for IPv4, but I and the GP would like to know what we can do to protect our anonymity with IPv6.
- why_only_15 8y agoI might be misinterpreting this, but on IPV6 do CDNs keep separate addresses for different sites? I suppose it would move things up a protocol level - instead of specifying it in HTTP we can specify it in IP. However, the key issue is CDNs here. In almost no other circumstances do different websites keep the same IPV4 address.
- rocqua 8y ago> In almost no other circumstances do different websites keep the same IPV4 address. I have multiple domains hosted on my personal site. Similarly, facebook.com and facebook.co.uk could very well point to the same IPs.
- kyleomalley 8y agoESNI doesn't solve for a future where ipv6 takes over and suddenly every site has a huge block of dedicated IPv6s for just that site/fqdn. ESNI as it has been developed to essentially require two other components to work properly: 1) a large scale cdn 2) a trusted dns infrastructure (i.e. DNS-over-HTTPs or DNS-over-TLS). So people are absolutely right that in distant future when IPv4 fronted sites go extinct, it may be possible that site hostnames can be correlated to a set of IPv6 address(s). ESNI doesn't and can't solve for that. I imagine that as the internet continues to become more and more centralized, a few large CDNs will host most (or very close to all) internet traffic through a few sets stabilized anycast addresses (thus obfuscating any individual hostname among many hundreds or thousands of other sites as they would all correlate to the same ip blocks). That being said, I still don't understand why it's so important to have the SNI on the "outside" of the tunnel. Seems like we should have another layer before the symmetric key exchange where the sni is exchanged on its own.