3 ms·
It is required to send a sni in clear at every connection? In theory, after the first connection, you should be able to just fully encrypt the entire packet by
by hexmiles 4y ago
It is required to send a sni in clear at every connection? In theory, after the first connection, you should be able to just fully encrypt the entire packet by using the certificate (public key) of the website.
If that is the case, is it possible to "preload" a list of keys into the useragent to avoid having to pass the SNI in clear? I understand that is not always practical, but can it help against censorship?
- tialaramex 4y ago> you should be able to just fully encrypt the entire packet by using the certificate (public key) of the website The public key is not used (unless you are doing RSA key exchange which is terrible and you should stop, this is no longer possible in TLS 1.3) to encrypt anything. Modern schemes, including TLS 1.3 and thus HTTP/3 do ECDH key agreement and then the public key is used for signatures to authenticate your peer.