home.social

#dnsoverhttps — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dnsoverhttps, aggregated by home.social.

fetched live
  1. DNS-Lösungen 2026: Mein Set & Forget Favorit

    Es ist kaum zu glauben, wie schnell die Zeit in der Technikwelt vergeht. Mein letzter großer Deep-Dive zum Thema Werbeblocker liegt nun schon fast zwei Jahre zurück. Im Oktober 2024 schrieb ich den Beitrag „Werbung effektiv blockieren – Meine Empfehlung“, in dem ich meine Reise von komplexen Eigenbau-Lösungen hin zu einer komfortablen, wartungsarmen Cloud-Lösung beschrieb. Damals fiel meine Wahl auf AdGuard-DNS – und heute, am 8. August 2026, kann ich ein fundiertes Langzeitfazit ziehen. Das Internet hat sich verändert, Tracking-Methoden sind aggressiver geworden, doch die grundlegende Frage bleibt: Setzt man auf die totale Kontrolle durch einen eigenen Server oder nutzt man die Bequemlichkeit moderner DNS-Dienste? In diesem Beitrag teile ich meine Erfahrungen der letzten zwei Jahre und erkläre, warum meine Konfiguration fast unverändert blieb. […]

    myhome.zone/dns-loesungen-2026

  2. I've been optimizing my DNS setup this week, I found out that when using @quad9dns, my DNS queries are being routed to California instead of locally in Toronto even though Quad9 has servers in Toronto. For some reason my ISP has been routing Quad9 DNS queries to Quad9's servers in California.

    Luckily, both
    @cloudflare DNS & CIRA Canadian Shield DNS routes DNS traffic within Canada. Was pleasantly surprised that Cloudflare DNS actually supports DNS over HTTPS via HTTP/3 even though not advertised. Unfortunately, CIRA CanadianShield DNS doesn't support DNS over HTTPS via HTTP/3 or DNS over QUIC, hopefully @cira will consider adding those support in the near future.

    What I really hope is that the Quad9 routing gets fixed, I know there's a good chance that there's nothing they can do about ISP routing but here's to hoping.

    #dns #dnsoverquic #dnsoverhttps #cloudflare #quad9 #cira

  3. I've been optimizing my DNS setup this week, I found out that when using @quad9dns, my DNS queries are being routed to California instead of locally in Toronto even though Quad9 has servers in Toronto. For some reason my ISP has been routing Quad9 DNS queries to Quad9's servers in California.

    Luckily, both
    @cloudflare DNS & CIRA Canadian Shield DNS routes DNS traffic within Canada. Was pleasantly surprised that Cloudflare DNS actually supports DNS over HTTPS via HTTP/3 even though not advertised. Unfortunately, CIRA CanadianShield DNS doesn't support DNS over HTTPS via HTTP/3 or DNS over QUIC, hopefully @cira will consider adding those support in the near future.

    What I really hope is that the Quad9 routing gets fixed, I know there's a good chance that there's nothing they can do about ISP routing but here's to hoping.

    #dns #dnsoverquic #dnsoverhttps #cloudflare #quad9 #cira

  4. @[email protected]
    @[email protected]

    Hello,

    I would like to know whether, in RethinkDNS, the filter lists I subscribe to are still applied when I select DNS over HTTPS (DoH) with Quad9 as the DNS server.
    Does RethinkDNS add its own blocking on top of Quad9, or is only Quad9’s filtering used in that case?

    #RethinkDNS #Quad9 #DNSoverHTTPS #DoH #Privacy #Cybersecurity

  5. One Open-source Project Daily

    Ngrok FRP Alternative • Fast • Lightweight • 0 Dependency • Pluggable • TLS interception • DNS-over-HTTPS • Poor Man's VPN • Reverse & Forward • "Proxy Server" framework • "Web Server" framework • "PubSub" framework • "Work" acceptor & executor framework

    https://github.com/abhinavsingh/proxy.py

    #1ospd #opensource #dnsoverhttps #gfw #httpproxy #httpserver #httpsproxy #maninthemiddle #mitm #mitmproxy #ngrok #ngrokalternative #ngrokreplacement #proxy #proxyserver #python3 #reverseproxy #tlsinterception #tunnel #vpn #webserver #webserver

  6. One Open-source Project Daily

    Ngrok FRP Alternative • Fast • Lightweight • 0 Dependency • Pluggable • TLS interception • DNS-over-HTTPS • Poor Man's VPN • Reverse & Forward • "Proxy Server" framework • "Web Server" framework • "PubSub" framework • "Work" acceptor & executor framework

    https://github.com/abhinavsingh/proxy.py

    #1ospd #opensource #dnsoverhttps #gfw #httpproxy #httpserver #httpsproxy #maninthemiddle #mitm #mitmproxy #ngrok #ngrokalternative #ngrokreplacement #proxy #proxyserver #python3 #reverseproxy #tlsinterception #tunnel #vpn #webserver #webserver

  7. @celenity I cannot seem to disable #DoH / #DNSoverHTTPS on the latest #IronFox release (not sure about before). Despite changing settings it ways shows a DoH server in use in about:networking#dns even after a fully restarting the app.

    Can you check that out?

    Edit: never mind. The cause was #grapheneOS adding new #VPN interfaces as "always on". 🙄 Ughhh, was almost going crazy.

  8. @celenity I cannot seem to disable #DoH / #DNSoverHTTPS on the latest #IronFox release (not sure about before). Despite changing settings it ways shows a DoH server in use in about:networking#dns even after a fully restarting the app.

    Can you check that out?

    Edit: never mind. The cause was #grapheneOS adding new #VPN interfaces as "always on". 🙄 Ughhh, was almost going crazy.

  9. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  10. Kann es sein, dass die #Telekom seit neustem #DNSoverTLS und #DNSoverHTTPS blockiert und nur irgendwie etwas wie #Mullvad da durchschlüpft?
  11. Kann es sein, dass die #Telekom seit neustem #DNSoverTLS und #DNSoverHTTPS blockiert und nur irgendwie etwas wie #Mullvad da durchschlüpft?
  12. Johannes Weber hat mit mir in seinem Podcast über DNS allgemein und DNS-over-HTTPS im Speziellen gesprochen. Das Ergebnis hört ihr hier securityasapodcast.de/podcast/

    #podcast #DNS #DoH #dnsoverhttps

  13. Johannes Weber hat mit mir in seinem Podcast über DNS allgemein und DNS-over-HTTPS im Speziellen gesprochen. Das Ergebnis hört ihr hier securityasapodcast.de/podcast/

    #podcast #DNS #DoH #dnsoverhttps

  14. Stavo leggendo qualcosa relativamente a "DNS over HTTPS".

    Da Firefox ci sono tre possibilità, Cloudflare, NextDNS e un provider custom.

    Mi piace l'idea di cifrare le richieste DNS da browser ma non vorrei cadere dalla padella alla brace, nel senso che adesso uso i DNS di un provider italiano quindi lato privacy credo di essere sufficientemente protetto e non vorrei finire in mano a un provider straniero che si prende le mie richieste e se le vende.

    Cosa ne pensate?

    #dnsoverhttps

  15. I have decided to take some #privacy back to my hands. I have implemented selfhosted #dnsoverhttps server and self provisioning profile to my iPhone. It blocks ads providers and trackers similar way as #pihole. #Docker container will be released soon. Stay tuned.

  16. Currently doing some DNS testing via my ISP (Ogi) here in Wales at it seems that at the moment @aaisp has the second fastest DNS over HTTPS resolvers available!

    'DNS over HTTPS | Min | Avg | Max |Std.Dev| Median|
    ----------------+-------+-------+-------+-------+-------+

    • Average Delay | 0.012 | 0.014 | 0.015 | 0.001 | 0.013 |
    • Cached Name | 0.012 | 0.012 | 0.012 | 0.000 | 0.012 |
    • Uncached Name | 0.013 | 0.014 | 0.014 | 0.001 | 0.013 |
    • DotCom Lookup | 0.015 | 0.015 | 0.015 | 0.000 | 0.015 |---<-------->---+-------+-------+-------+-------+-------+ dns.aa.net.uk/dns-query ANDREWS ARNOLD LTD'

    Being a smidgen faster that Quad9 and NextDNS. Not too shabby! 😉🖖

    #DNS #UK #DNSoverHTTPS #Internet #Performance #AAISP

  17. Currently doing some DNS testing via my ISP (Ogi) here in Wales at it seems that at the moment @aaisp has the second fastest DNS over HTTPS resolvers available!

    'DNS over HTTPS | Min | Avg | Max |Std.Dev| Median|
    ----------------+-------+-------+-------+-------+-------+

    • Average Delay | 0.012 | 0.014 | 0.015 | 0.001 | 0.013 |
    • Cached Name | 0.012 | 0.012 | 0.012 | 0.000 | 0.012 |
    • Uncached Name | 0.013 | 0.014 | 0.014 | 0.001 | 0.013 |
    • DotCom Lookup | 0.015 | 0.015 | 0.015 | 0.000 | 0.015 |---<-------->---+-------+-------+-------+-------+-------+ dns.aa.net.uk/dns-query ANDREWS ARNOLD LTD'

    Being a smidgen faster that Quad9 and NextDNS. Not too shabby! 😉🖖

    #DNS #UK #DNSoverHTTPS #Internet #Performance #AAISP

  18. @tarnkappeinfo
    Hallo,
    schöner Artikel - ich habe jedoch ein paar Nachfragen dazu:

    * Warum hat Ihr in Eurem Artikel den neuen europäischen DNS-Resolver DNS4EU nicht erwähnt? Gib es bei dem irgendwelche Gründe, die gegen eine Nutzung sprechen?

    * Ihr habt hier die Verwendung von DNS over HTTPS beschrieben - gibt es einen Grund DNS over TLS (DoT) _nicht_ zu verwenden?

    * Ihr beschreibt nur die Einstellungen für einen Windows 11-Rechner? Keine Beschreibung für das Smart-Phone - egal ob Android oder IOS - für den Betrieb außerhalb des Heimnetzes ... Spricht etwas gegen die Eintragung auf dem Home-Router (z.B. FRITZ!Box) für alle Geräte im Heimnetz?

    #DNSoverHTTPS #DNSoverTransportLayerSecurity
    #Fritzbox
    #Android #IOS

  19. 🔍😂 Behold the latest tech "innovation": DNS over HTTPS, aka DoH, which promises to hide your browsing secrets. Except, surprise! 🎉 Now, instead of many peepers, only one gets to see all your queries. Truly, a monumental win for privacy—if you're a fan of monopolies. 🙄 #TechLogic #PrivacyFail
    bsdhowto.ch/doh.html #TechInnovation #PrivacyMonopoly #DNSoverHTTPS #BrowsingSecrets #PrivacyConcerns #HackerNews #ngated

  20. 🔍😂 Behold the latest tech "innovation": DNS over HTTPS, aka DoH, which promises to hide your browsing secrets. Except, surprise! 🎉 Now, instead of many peepers, only one gets to see all your queries. Truly, a monumental win for privacy—if you're a fan of monopolies. 🙄 #TechLogic #PrivacyFail
    bsdhowto.ch/doh.html #TechInnovation #PrivacyMonopoly #DNSoverHTTPS #BrowsingSecrets #PrivacyConcerns #HackerNews #ngated

  21. Как HTTP(S) используется для DNS: DNS-over-HTTPS на практике

    HTTPS позволяет реализовать защищённую работу с интерфейсом DNS-резолвера, скрыв состав DNS-трафика, который иначе передавался бы в открытом виде. Это достаточно специальная технология, но она уже стала типовой функцией распространённых веб-браузеров и широко используется. Посмотрим, как это всё работает на практике, но не из браузера, а из консоли, попутно разобрав простейшее DNS-сообщение.

    habr.com/ru/articles/898138/

    #dns #dnsoverhttps #tls #ssl #https #http

  22. Bruh I'm still so confused about this - can any #networking people or anyone with #PiHole/#Pi-hole experience chime in and tell if my goal is privacy, and if I were to prioritise one, it'd be better privacy against my ISP, what should I use on my Pi-hole DNS server?

    -
    #Unbound as a recursive DNS server (my interpretation of this route is, it's the best privacy vs 3rd party DNS - but I'm assuming it's the worst privacy vs ISP?)
    - Enable
    #DNS-Over-TLS (#DoT) using Unbound and upstream DNS provider set to something like #Cloudflare
    - or Enable
    #DNS-Over-HTTPS (#DoH) using #Cloudflared

    I initially thought you could have Pi-hole run with all three (I have a feeling this a really stupid noob networking moment right here) but I don't think so, no?

  23. Bruh I'm still so confused about this - can any #networking people or anyone with #PiHole/#Pi-hole experience chime in and tell if my goal is privacy, and if I were to prioritise one, it'd be better privacy against my ISP, what should I use on my Pi-hole DNS server?

    -
    #Unbound as a recursive DNS server (my interpretation of this route is, it's the best privacy vs 3rd party DNS - but I'm assuming it's the worst privacy vs ISP?)
    - Enable
    #DNS-Over-TLS (#DoT) using Unbound and upstream DNS provider set to something like #Cloudflare
    - or Enable
    #DNS-Over-HTTPS (#DoH) using #Cloudflared

    I initially thought you could have Pi-hole run with all three (I have a feeling this a really stupid noob networking moment right here) but I don't think so, no?

  24. Anyway this kind of shit is why we're getting horrible ideas like #DNSoverHTTPS, I really hate ISPs and governments for forcing this into existence ​:koishtare:​

  25. Anyway this kind of shit is why we're getting horrible ideas like #DNSoverHTTPS, I really hate ISPs and governments for forcing this into existence ​:koishtare:​

  26. Man I want to get rid of #HTTP2 from my #nginx, but then it will break #DNSoverHTTPS for #Windows ​:TenshMelt:​

  27. Man I want to get rid of #HTTP2 from my #nginx, but then it will break #DNSoverHTTPS for #Windows ​:TenshMelt:​

  28. Man, if #DNSoverHTTPS is just this simple... ​:sagume_think:​

    http://mima.localghost.org/dns/chaotic.ninja/AAAA

    #!/bin/sh
    if [ $REQUEST_METHOD == "GET" ]
    then
        DNS_DOMAIN=$(echo "$QUERY_STRING" |
                     sed -n 's/^.*domain=\([^&]*\).*$/\1/p' |
                     sed "s/%20/ /g")
        DNS_TYPE=$(echo "$QUERY_STRING" |
                   sed -n 's/^.*type=\([^&]*\).*$/\1/p' |
                   sed "s/%20/ /g")
        [ -z $DNS_TYPE ] && DNS_TYPE=A
        if [ -d "$DNS_DOMAIN" ]
        then
            DNS_STATUS="NOERROR"
            LOCAL_REC="$DNS_DOMAIN/$DNS_TYPE"
            [ -e "$LOCAL_REC" ] && DNS_REC=$(cat "$LOCAL_REC")
        else
            DIG_RESPONSE=$(dig +noall +answer +comments "$DNS_DOMAIN" "$DNS_TYPE")
            DNS_STATUS=$(echo "$DIG_RESPONSE" | grep status | cut -d ':' -f 3 | cut -w -f 2 | cut -d ',' -f 1)
            if [ $DNS_STATUS == "NOERROR" ]
            then
                DNS_ANSWER=$(echo "$DIG_RESPONSE" | grep IN)
                DNS_REC=$(echo "$DNS_ANSWER" | cut -w -f 5-)
                DNS_TTL=$(echo "$DNS_ANSWER" | cut -w -f 2)
            fi
        fi
    fi
    
    httpstatus()
    {
        case $1 in
            200) httpsemantic="OK";;
            404) httpsemantic="Not Found";;
        esac
        printf "HTTP/1.0 $1 $httpsemantic\r\n"
        echo "Status: $1 $httpsemantic"
    }
    case $DNS_STATUS in
        "NOERROR")
            if [ ! -z "$DNS_REC" ]
            then
                httpstatus 200
                echo "Cache-Control: private, max-age=$DNS_TTL"
                ANSWER="$DNS_REC"
            else
                httpstatus 404
                ANSWER="NOERROR, but no $DNS_TYPE record"
            fi
            ;;
        "NXDOMAIN")
            httpstatus 404
            ANSWER="$DNS_STATUS"
            ;;
    esac
    
    echo "Content-Type: text/plain"
    echo
    echo "$ANSWER"

    With the following
    #nginx directives too assuming you got a #fastcgi set up already:
    upstream dohexperiment {
        server 127.0.0.1:80;
    }
    
    [...]
    
    location ~ /dns/(.*)/(.*)$ {
            proxy_pass http://dohexperiment/dns/index.cgi?domain=$1&type=$2;
    }
    location ~ /dns/(.*[^\/])$ {
            proxy_pass http://dohexperiment/dns/index.cgi?domain=$1;
    }

    #DNS #HTTP #REST

    RE:
    https://makai.chaotic.ninja/notes/9vyxx3nwty

  29. Man, if #DNSoverHTTPS is just this simple... ​:sagume_think:​

    http://mima.localghost.org/dns/chaotic.ninja/AAAA

    #!/bin/sh
    if [ $REQUEST_METHOD == "GET" ]
    then
        DNS_DOMAIN=$(echo "$QUERY_STRING" |
                     sed -n 's/^.*domain=\([^&]*\).*$/\1/p' |
                     sed "s/%20/ /g")
        DNS_TYPE=$(echo "$QUERY_STRING" |
                   sed -n 's/^.*type=\([^&]*\).*$/\1/p' |
                   sed "s/%20/ /g")
        [ -z $DNS_TYPE ] && DNS_TYPE=A
        if [ -d "$DNS_DOMAIN" ]
        then
            DNS_STATUS="NOERROR"
            LOCAL_REC="$DNS_DOMAIN/$DNS_TYPE"
            [ -e "$LOCAL_REC" ] && DNS_REC=$(cat "$LOCAL_REC")
        else
            DIG_RESPONSE=$(dig +noall +answer +comments "$DNS_DOMAIN" "$DNS_TYPE")
            DNS_STATUS=$(echo "$DIG_RESPONSE" | grep status | cut -d ':' -f 3 | cut -w -f 2 | cut -d ',' -f 1)
            if [ $DNS_STATUS == "NOERROR" ]
            then
                DNS_ANSWER=$(echo "$DIG_RESPONSE" | grep IN)
                DNS_REC=$(echo "$DNS_ANSWER" | cut -w -f 5-)
                DNS_TTL=$(echo "$DNS_ANSWER" | cut -w -f 2)
            fi
        fi
    fi
    
    httpstatus()
    {
        case $1 in
            200) httpsemantic="OK";;
            404) httpsemantic="Not Found";;
        esac
        printf "HTTP/1.0 $1 $httpsemantic\r\n"
        echo "Status: $1 $httpsemantic"
    }
    case $DNS_STATUS in
        "NOERROR")
            if [ ! -z "$DNS_REC" ]
            then
                httpstatus 200
                echo "Cache-Control: private, max-age=$DNS_TTL"
                ANSWER="$DNS_REC"
            else
                httpstatus 404
                ANSWER="NOERROR, but no $DNS_TYPE record"
            fi
            ;;
        "NXDOMAIN")
            httpstatus 404
            ANSWER="$DNS_STATUS"
            ;;
    esac
    
    echo "Content-Type: text/plain"
    echo
    echo "$ANSWER"

    With the following
    #nginx directives too assuming you got a #fastcgi set up already:
    upstream dohexperiment {
        server 127.0.0.1:80;
    }
    
    [...]
    
    location ~ /dns/(.*)/(.*)$ {
            proxy_pass http://dohexperiment/dns/index.cgi?domain=$1&type=$2;
    }
    location ~ /dns/(.*[^\/])$ {
            proxy_pass http://dohexperiment/dns/index.cgi?domain=$1;
    }

    #DNS #HTTP #REST

    RE:
    https://makai.chaotic.ninja/notes/9vyxx3nwty

  30. I feel like #DNSoverHTTPS would make a lot more sense if you can do #CRUD with it, kinda like #REST. So for example to get the IPv4 of www.example.com, you'd do a GET /www.example.com/A instead of the current /dns-query?dns= with GET, or god forbid, POST to /dns-query for what's clearly a query (it's in the damn name). The POST should only be used for creating custom #DNS records. And you can DELETE them so the server can return back to querying its upstream when it receives a GET for that domain and record type again.

    This would give
    #DoH an actually useful purpose other than just being a controversial circumvention method marketed as a "privacy feature" that security admins hate. If you somehow got stuck in a terminal which doesn't have dig and UDP is blocked then you can still do DNS queries. And if you have authorization you don't even have to ssh to change some /etc/hosts; just telnet to port 80 or openssl s_client to port 443 and do the editing there!

  31. I feel like #DNSoverHTTPS would make a lot more sense if you can do #CRUD with it, kinda like #REST. So for example to get the IPv4 of www.example.com, you'd do a GET /www.example.com/A instead of the current /dns-query?dns= with GET, or god forbid, POST to /dns-query for what's clearly a query (it's in the damn name). The POST should only be used for creating custom #DNS records. And you can DELETE them so the server can return back to querying its upstream when it receives a GET for that domain and record type again.

    This would give
    #DoH an actually useful purpose other than just being a controversial circumvention method marketed as a "privacy feature" that security admins hate. If you somehow got stuck in a terminal which doesn't have dig and UDP is blocked then you can still do DNS queries. And if you have authorization you don't even have to ssh to change some /etc/hosts; just telnet to port 80 or openssl s_client to port 443 and do the editing there!

  32. If any unethical network operator (or government) can disable DoH on clients with a simple DNS flag, then what problem does DoH solve?

    It stops you from blocking ads on the DNS level. That's all it was ever supposed to solve.

    Disable DoH. Reject DoH.

    #dns #adblock #pihole #networking #doh #dnsoverhttps

  33. If any unethical network operator (or government) can disable DoH on clients with a simple DNS flag, then what problem does DoH solve?

    It stops you from blocking ads on the DNS level. That's all it was ever supposed to solve.

    Disable DoH. Reject DoH.

    #dns #adblock #pihole #networking #doh #dnsoverhttps

  34. Man I am regretting not bringing more of my IT infrastructure from my old home with me in the RV.....

    Just had to buy another
    #Synology #RT2600ac (the 6600 was too expensive and way overkill) just so I can put the #Starlink into #BypassMode and have #DNSoverHTTPS/ #DNSoverTLS for all my wireless devices in the trailer. Specifically, to take advantage of @[email protected]'s DNS servers to block ads and malware.

    (I already subscribe to
    #MullvadVPN on several of my devices.)

    #RVlife

  35. I wrote a very basic #Ansible playbook to help people set up #PiHole with #DNSOverHTTPS (#DoH) directly installed on a Debian-based host (Raspberry Pi or small VM). It's available on my GitHub repo. I hope you find it useful! #HomeLab #SelfHosted
    github.com/badnetmask/miscelan

  36. Days since DNS-over-HTTPS (DoH) silently screwed with me and caused me irritation: 0

    (Obviously, days since it was DNS is also now also 0.)

    My Windows machines all disable DoH in Firefox by policy, but apparently my Linux machine started to silently start using it and broke my stuff.

    #doh #dnsoverhttps

  37. You've got to be kidding me #Mozilla

    Why does
    #Firefox need #HTTP2 for #EncryptedClientHello? Where in the goddamn spec does it say that #ECH needs HTTP/2?! First #DNSoverHTTPS or #DoH is required, and now HTTP/2? Really?

    Why can't you just let me disable HTTP/2 in peace and use HTTP/1.1 as all web servers should be using. Why does it have to be a choice on whether I can get additional
    #privacy based on whether I'm using an arbitrary and useless update to the #HTTP protocol. It's just fucking full of politics. First you require TLS if one wants to use HTTP/2, and now HTTP/2 is required if one wants to encrypt their #SNI and the whole #ClientHello. No technical fucking reason at all other than to force people in their crusade against plain text and their obsession with chopping down latency (which didn't work btw which is why they're now pushing #HTTP3 which is just not HTTP anymore with its #UDP bullshit)

    This is what happens when you let politician-wannabes dictate your development