7 ms·
SNI can be encrypted in an extension of TLS 1.3 called ESNI (encrypted server name indication). With both EDNS and ESNI, there's sufficient privacy coverage. T
by manigandham 4y ago
SNI can be encrypted in an extension of TLS 1.3 called ESNI (encrypted server name indication). With both EDNS and ESNI, there's sufficient privacy coverage.
The next standard is ECH (encrypted client-hello) which secures the entire handshake: https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/
- gsich 4y agoIs it still in draft state?
- manigandham 4y agoYes: https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15 https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15