2 ms·
If I'm reading this right, blocking this would result in a denial of service rather than a security downgrade. And Cloudflare is so large that blocking all of i
by profmonocle 3y ago
If I'm reading this right, blocking this would result in a denial of service rather than a security downgrade. And Cloudflare is so large that blocking all of its hosted sites would effectively look like a partial internet outage. That might not bother state actors, but any ISP in a free country that willingly did this would be so overwhelmed by customer service requests that it wouldn't be worth it.
Any legitimate network operator who wants to avoid this for securiity reasons (i.e. for corporate managed devices) can just disable it by policy, assuming they aren't already using a decrypting TLS proxy.
Plus, there's an easier loophole than blocking ECH - block encrypted DNS. AFAIK most DNS over HTTPS/TLS implementations fall back to plaintext DNS if they can't make an encrypted connection. ECH's reliance on DNS privacy is its weak point; one that can't really be avoided right now.
- jeroenhd 3y agoIn many cases you don't even need to block DoH. Many implementations (Chrome/Edge/I believe Windows itself) will try to use the ISPs DoH servers by default if available, and switch to an alternative if the user chooses to do so. Because very few websites bother to implement things like DNSSEC (and even fewer clients bother to validate it), the ISP DNS server can then fake all the ECH data it wants,