4 ms·
The ISP could just block the IP address (they're an ISP, they can just figure it out), or inspect he presented certificate.
by staticassertion 4y ago
The ISP could just block the IP address (they're an ISP, they can just figure it out), or inspect he presented certificate.
- ignoramous 4y agoNot if you share the IP space with many other web properties. For an extreme case of this, see Ao1: https://blog.cloudflare.com/addressing-agility/ https://blog.cloudflare.com/addressing-agility/
- asabla 4y agoIt's not that hard setting up your own relay on any cheap vps out there. Good luck blocking all those addresses
- staticassertion 4y agoIf you're doing that DoH doesn't change anything
- yakubin 4y agoIt doesn't change compared to DoT, but it does compared to raw DNS, since raw DNS is trivial for ISP to intercept, regardless of IPs involved.
- tialaramex 4y agoThe ISP can indeed block arbitrary IP addresses. As well as the risk of overblocking (and consequent negative consumer experience, oops, we forgot WikiMedia's controversial project X is also on the same servers as their famous encyclopedia so when we blocked the ~1 in a million customers looking at project X we also broke Wikipedia for all our customers) this is a serious administrative hassle. ISPs are for-profit entities so "We can spend $$$ doing this" is only justified if you can show why it increased revenue more than $$$. You can't see "the presented certificate" on a modern web browser visiting most web sites. In TLS 1.3 (offered by > 55% of 135,000 surveyed web sites) every step after Client Hello is encrypted, so the certificate isn't available to snoops. For now, you can see the SNI in that client Hello, telling the server who they wanted to talk to. However ECH (Encrypted Client Hello) is intended to get rid of that too.
- staticassertion 4y agoYes, I should not have said the certificate, I'd meant SNI. Thank you for correcting.
- tialaramex 4y agoHowever, the SNI (prior to ECH) just tells us who the Client said they wanted to talk to when connecting. Suppose the client calls 10.20.30.40, and they announce they want to talk to legit.example which is fine. The server sends a certificate (which the ISP doesn't see) and that certificate says it's valid for legit.example and for naughty.example. Now the client is allowed, in HTTP/2 and HTTP/3 to say "Actually I want https://naughty.example/stuff https://naughty.example/stuff" and although the server isn't obligated to have that answer because the client said it originally wanted to talk to legit.example not naughty.example it often can answer and will. The client has a certificate showing this server is entitled to answer this question, and now it has an answer, so it's done. [If the HTTPS server can't answer or doesn't want to for any reason, the HTTP error code for this scenario, where somebody asked you about a name for which you have a certificate but aren't actually able to answer questions, is 421 Misdirected].
- staticassertion 4y agoInteresting, I'd never considered such a scenario. Thank you.
- darkhorn 4y agoThere was ESNI. Hopefully they will introduse it again.
- arbitrage 4y ago> they can just figure it out Yes, but that is computationally expensive at the ISP level. Turning on deep packet inspection for one user is way overkill. Doing it for everyone? Congrats, you've just completely trashed out your core. Performance tanks. You lose customers. It is opportunistically expensive, as well. Tracking down users on a case-by-case basis costs a lot in real time, as well as human work hours. It is almost never worth it to an ISP do to this type of inspection -- ie, 'just figure it out' -- unless they are being compelled to.
- staticassertion 4y agoAll you have to do is do reverse DNS resolution, which an ISP is in an excellent position to do.
- darkhorn 4y agoI remember one case where Russia was blocking a web site's IP address automatically. Whenever the owner of the site changed IP address of his own web site it was blocked in minutes. Then he has changed to, I don't remember exactly but if I'm not mistaken to bank's IP address. And as you have guessed that bank was blocked :D