4 ms·
What OP wrote seems correct: > ECH basically kills TLS fingerprinting as a bot detection signal They are not talking about fingerprinting in general. Please e
by hzwanip 7mo ago
What OP wrote seems correct:
> ECH basically kills TLS fingerprinting as a bot detection signal
They are not talking about fingerprinting in general. Please elaborate how else TLS fingerprinting can be done.
- szmarczak 7mo agoI am talking about TLS fingerprinting, not JS fingerprinting. > Please elaborate how else TLS fingerprinting can be done. By doing everything as it is right now?
- hzwanip 7mo agoHow would you (an arbitrary web server) fingerprint a TLS connection if the Client Hello is encrypted?
- conradludgate 7mo agoThe website owner (or cloudflare in this case) has the keys to decrypt the client hello. That's necessary for routing information.
- hzwanip 7mo agoYou're right, sorry! I got confused myself.
- szmarczak 7mo agoBy decrypting it? I don't think you know how TLS, or E2E works in general. ISP doesn't perform the fingerprinting, the server does.
- hzwanip 7mo agoOf course! My bad, thanks for engaging.