4 ms·
Worth noting that the benefits of DNS over TLS/HTTPS (with encrypted SNI) are a bit limited. For cases where a very large number of domains are hosted on a sing
by profmonocle 5y ago
Worth noting that the benefits of DNS over TLS/HTTPS (with encrypted SNI) are a bit limited. For cases where a very large number of domains are hosted on a single IP address (or pool of IPs) it's effective at masking your destination from network sniffing. (sites behind Amazon Cloudfront, Cloudflare's free plan, Google App Engine/Cloud Run, old school web hosts, etc.)
But there are still tons of sites with their own IPs, or pool of IPs, in which case seeing the destination IP will reveal what domain you're visiting with no need to observe DNS traffic or SNI. i.e. 199.232.125.140 is Reddit and only Reddit. If you visit https://199.232.125.140 https://199.232.125.140 you get an error that the cert is for *.reddit.com.
If your goal is to prevent your network operator from seeing even the domains you're accessing, encrypted DNS + encrypted SNI helps but doesn't get you all the way there. A VPN (or Tor) is the only true solution there. However I imagine this is a relatively uncommon need, at least for most people on HN.
- sneak 5y agoI think most TLS today does not use encrypted SNI; the hostname to which you are connecting is still sent in the clear in the large majority of cases even when there are many sites sharing an IP.
- pabs3 5y agoThere was a study that showed that even for the cloud hosted sites, traffic patterns to the IP address can reveal the site (so ESNI/ECH are not foolproof): https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an-ip-address/ https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an... https://news.ycombinator.com/item?id=28103770 https://news.ycombinator.com/item?id=28103770