4 ms·
You could use DoH, which you should do anyway. No reason to leak DNS lookups to anyone.
by uup 4y ago
You could use DoH, which you should do anyway. No reason to leak DNS lookups to anyone.
- madars 4y agoDoH alone is not enough due to https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication being sent in plain text. Some day ECH (formerly, eSNI) should help with that.
- erinnh 4y agoI thought TLSv1.3 already encrypted the SNI?
- uup 4y agoIt does
- Varloom 4y agoESNI is not implemented yet on any website. And there is no software support except beta versions of Chrome/Edge and you have to manually toggle flags in dev mode. All SNIs are passed as plain text to your ISP/VPN, even with DoH/TLS secure DNS enabled.
- detaro 4y agoNo. ESNI is an later-created extension to TLS 1.3
- deleted 4y ago[deleted]
- ranger_danger 4y agoyou'll always be leaking it to whoever you are sending your query to.