3 ms·
Your ISP can still see the IPs that you are talking to... What are you talking about? They can even see the url even if you dont use them as your DNS
by OrgNet 7y ago
Your ISP can still see the IPs that you are talking to... What are you talking about? They can even see the url even if you dont use them as your DNS
- e12e 7y ago> They can even see the url Only for plaintext http. For ssl/https - the hostname/ip can leak with SNI, but should be safe with ESNI (encrypted SNI). The URL should be in the request, which comes after the TLS handshake (hence SNI, so that the server can pick a certificate before knowing the HTTP HOST header). SNI is a problem - but not much worse than the fact that a mitm can see who talks to who (IP) - IMNHO.
- nullc 7y agoESNI is not in use yet (or just doesn't work). Start up tcpdump and check yourself. At best even it were currently use it only provides protection for sites which are hosted behind DOS mitigation services. (usually cloudflare...)
- badrabbit 7y agoYou need the right TLS lib for it to work, browsers support it. I've seen big sites like facebook and cloudflare use it.
- TheGrassyKnoll 7y agoYou can check it here: https://encryptedsni.com/ -> https://www.cloudflare.com/ssl/encrypted-sni/
- gsich 7y agoESNI is still in draft.
- e12e 7y agoQuite. I didn't mean to imply a host/ip header wouldn't leak today - but I see how my comment can be read that way. In fact, siblings point about cf (cloud flare) is relevant - as cf eats the world, SNI will potentially be more of a problem; if you connect to site A via IP a, and B via ip b - not much is revealed if host headers A and B leaks, given that traffic to a and b is already obvious. But when you connect to cf on a "nearby" IP c, it suddenly becomes more of a problem that host headers for A, B, D and E are leaking. Not necessarily worse than when your ISP could see you talking to IP a and b - but worse in the sense that you reveal some information to your ISP that would otherwise only be known to cf.
- OrgNet 7y agoso we agree the ESNI is not in used?