3 ms·
Is there a way to force SNI by blocking ECH requests?
by fiddlerwoaroof 2y ago
Is there a way to force SNI by blocking ECH requests?
- Groxx 2y agoYou'd be looking for a "TLS / ECH downgrade attack", and... while a brief googling isn't finding anything saying explicitly "yea" or "nah", it sounds like it should generally be prevented. E.g. https://wiki.mozilla.org/Security/Encrypted_Client_Hello https://wiki.mozilla.org/Security/Encrypted_Client_Hello mentions explicit bypasses are possible with enterprise proxies (which generally require client-side certificate authorities which are an explicit opt-in to allowing a third party to decrypt your traffic). And it's a TLS 1.3 extension, and TLS 1.3 -> 1.2 downgrades are intentionally prevented as part of 1.3's design... ... and even if it wasn't, ECH works by reading public keys from DNS, so the domain owner has claimed "you can send ECH" and it's pretty easy to know "therefore you shouldn't downgrade if you are capable, it's probably an attacker". Though unencrypted DNS renders this all a bit moot of course. --- tl;dr, with the caveat that IANAWebSecuritySpecialist and I haven't found anything I'd call actually conclusive yet: I believe "no". Unless you are setting up client-side CAs, at which point you can MITM everything so it hardly matters.
- fiddlerwoaroof 2y agoWell, if you control DNS, couldn’t you just block the key records?
- ignoramous 2y agoYes, ECH assumes a trusted & secure channel between the client and the resolver. https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-22#name-unauthenticated-and-plainte https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-22...