4 ms·
JFYI: Even if you use 3rd party DNS so that ISP doesn't spoof DNS records for some domains, domains are still present in plaintext in TLS encrypted traffic due
by StrLght 5y ago
JFYI: Even if you use 3rd party DNS so that ISP doesn't spoof DNS records for some domains, domains are still present in plaintext in TLS encrypted traffic due to Server Name Identification (SNI). It seems that most of internet censorship regimes know about it.
- rfd4sgmk8u 5y agoESNI is our best hope. Every channel must be indistinguishable from random noise. https://www.cloudflare.com/learning/ssl/what-is-encrypted-sni/ https://www.cloudflare.com/learning/ssl/what-is-encrypted-sn...
- StrLght 5y agoESNI is no longer relevant since it's vulnerable to a few attacks. It's ECH now. But it seems too late: some countries have already prohibited it via laws and regulations [1]. It may help other countries making censorship/intelligence harder though. [1] https://linuxreviews.org/New_Russian_Legislation_Would_Outlaw_Tor_And_Sites_Using_Encrypted_ClientHello https://linuxreviews.org/New_Russian_Legislation_Would_Outla...