#esni — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #esni, aggregated by home.social.
-
Just found out that you can get #ESNI ^W #ECH #DNS queries working in #Firefox without having to run my own DNS over HTTPS server.
Just set network.dns.native_https_query to true. Bonus points for network.dns.preferIPv6 to make it stop preferring #IPv4 for some reason.
You obviously have to find a way of getting DNS traffic in and out of your network safely. I spread it out over a couple of servers that I host.
-
@Seirdy @feistyduck I've been waiting for years for it to work. But if we would finally start getting to that direction.
Many also forgot the #ESNI, which didn't work either.
Cloudflare #ECH #test:
https://www.cloudflare.com/ssl/encrypted-sni/ -
We had lots of queries on why TLS ECH is not good/good, so shedding some light on why it was conceived.
(formerly called Encrypted SNI #ESNI)
-
Google Chrome v117 turned on TLS Encrypted ClientHello by default (on 27 Sep?) This will impact the effectiveness and accuracy of outbound traffic filtering* - for those who've implemented it (regardless of vendor.) We've written a short blog post on disabling it with PowerShell, Windows Registry and Google Chrome UI for those who may need to roll this out ASAP and regain visibility. (Disclosure: we are a vendor of an outbound filtering solution and this has impacted our customers already.)
*for many websites, the domain name visibility during an HTTPS handshake will no longer be available to firewalls/proxies (unless they were terminating.)
https://chasersystems.com/blog/disabling-encrypted-clienthello-in-google-chrome-and-why/
-
💬 "Encrypted Client Hello, a new proposed standard that prevents networks from snooping on which websites a user is visiting, is now available on all Cloudflare plans."
❓ How does the internet like this?
Links for further reading:
The CloudFlare blog: Encrypted Client Hello - the last puzzle piece to privacy
https://blog.cloudflare.com/announcing-encrypted-client-hello/gHacks: The End of DNS-based Site Blocking is near
https://www.ghacks.net/2023/10/07/the-end-of-dns-based-site-blocking-is-near/#Cloudflare #ECH #EncryptedClientHello #ServerNameIndication #SNI #ESNI #Security #TLS
-
Encrypted Client Hello (ECH) Effectively Defeats Pirate Site Blocking
https://torrentfreak.com/encrypted-client-hello-ech-effectively-defeats-pirate-site-blocking-231006/
#encryptedclienthello #siteblocking #Cloudflare #Piracy #esni #ECH
-
I tidigare poddavsnitt har vi förklarat hur vikten av att använda VPN-tjänster på publika wifi-nät har minskat. I veckans podd förklarar vi varför ”krypterade hälsningar” minskar behovet ytterligare (på sikt).
-
Russia wants to ban the use of secure protocols such as #TLS 1.3, #DoH, #DoT, #ESNI
Amendment to IT law would make it illegal to use #encryption protocols that fully hide the traffic's destination. -
Минцифры хочет запретить передовые технологии шифрования #Минцифры, #Шифрование, #ESNI, #цензура, #закон, #Госдума https://www.securitylab.ru/news/512312.php https://twitter.com/SecurityLabnews/status/1308107488034779137/photo/1
-
And the beat goes on in the #security and #privacy cat-and-mouse-game:
The Internet/#IETF roll out encrypted #DNS and #ESNI to hide the web sites you're browsing: https://blog.cloudflare.com/esni/
And the #greatfirewall (and Paul Vixie) block it: https://www.zdnet.com/article/china-is-now-blocking-all-encrypted-https-traffic-using-tls-1-3-and-esni/
-
Китайские власти стали блокировать HTTPS-трафик #Китай, #цензура, #трафик, #шифрование, #HTTPS, #TLS, #ESNI https://www.securitylab.ru/news/510937.php https://twitter.com/SecurityLabnews/status/1292701519788285952/photo/1