9 ms·
I blame, in part, TLS 1.3, E-SNI, and DoH for this. Previously, a government could monitor what site a user is visiting just by looking at the TLS session star
by mdhardeman 7y ago
I blame, in part, TLS 1.3, E-SNI, and DoH for this.
Previously, a government could monitor what site a user is visiting just by looking at the TLS session startup. Even if it is hosted on a cloud provider and 100 different sites are hosted from the same IP, they could look at the TLS-SNI data in the plain text to choose to interrupt and block the connection.
A fallback would be to manipulate DNS queries and force all DNS queries to be directed to official DNS resolvers. But DoH makes that far harder to control.
This is a bluff being called. Tech said "If we make it so that they have to spend all this money and build a massive scale intercept that actively participates in each TLS session, they won't buy into the cost."
Costs keep going down for this sort of thing. Now there are large organizations and governments willing to work on this stuff.
- jedisct1 7y agoIt's probably completely unrelated. DoH is easy to block. They can look at SNI and cut DoH connections. Being able to access all the content is far more valuable than hostnames.
- mdhardeman 7y agoWe have E-SNI now, where SNI is encrypted. And you have DoH providers who'll use that. And then massive CDNs will start to support it. Some of them might even enable it, with encrypted SNI, on _every single listener on all of their IPs_. DoH was designed to evolve into something nearly unblock able. Unless you active intercept 100%. Which some people believed no one would pay up for or that it would be unscalable. This stuff only gets cheaper and easier.