5 ms·
I guess the encrypted SNI draft is what's meant here.
by ameshkov 8y ago
I guess the encrypted SNI draft is what's meant here.
- xyzzy123 8y agoThanks, sorry, you are totally right and I should be more specific. Yes. It’s a metadata leak and generally I am pro the end-to-end principle but encrypted SNI actually forces everyone to MITM. Whether that is good or bad is a value judgement but for people who have been doing “light touch” egress filtering it is a huge PITA. It is actually going to force more invasive surveillance in basically any regulated workplace.
- pilif 8y agoPersonally, I think it's a good thing it forces MITM. Either you monitor your users browsing habits or you don't. If you do, it's only fair if they have a chance to know that you do and seeing an SSL connection be "protected" by a company-internal cert makes that totally clear.
- amaccuish 8y agoThe thing is, most users won't look for that. I like what Android does, where if you switch on a VPN or install an extra CA, you get a "your network use may be being monitored". That should appear in the browser.
- icebraining 8y agoHow could you rely on SNI for filtering? How did you know they weren't just domain fronting? Or was it about blocking access to regular sites?
- deleted 8y ago[deleted]