home.social

#esni — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #esni, aggregated by home.social.

  1. So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

    Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

    #curl #Termux #ECH #ESNI

  2. So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

    Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

    #curl #Termux #ECH #ESNI

  3. So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

    Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

    #curl #Termux #ECH #ESNI

  4. So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

    Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

    #curl #Termux #ECH #ESNI

  5. So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

    Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

    #curl #Termux #ECH #ESNI

  6. Just found out that you can get #ESNI ^W #ECH #DNS queries working in #Firefox without having to run my own DNS over HTTPS server.

    Just set network.dns.native_https_query to true. Bonus points for network.dns.preferIPv6 to make it stop preferring #IPv4 for some reason.

    You obviously have to find a way of getting DNS traffic in and out of your network safely. I spread it out over a couple of servers that I host.

    #centralization

  7. @Seirdy @feistyduck I've been waiting for years for it to work. But if we would finally start getting to that direction.

    Many also forgot the #ESNI, which didn't work either.

    Cloudflare #ECH #test:
    https://www.cloudflare.com/ssl/encrypted-sni/
  8. We had lots of queries on why TLS ECH is not good/good, so shedding some light on why it was conceived.

    (formerly called Encrypted SNI #ESNI)

    infosec.exchange/@ChaserSystem

  9. Google Chrome v117 turned on TLS Encrypted ClientHello by default (on 27 Sep?) This will impact the effectiveness and accuracy of outbound traffic filtering* - for those who've implemented it (regardless of vendor.) We've written a short blog post on disabling it with PowerShell, Windows Registry and Google Chrome UI for those who may need to roll this out ASAP and regain visibility. (Disclosure: we are a vendor of an outbound filtering solution and this has impacted our customers already.)

    *for many websites, the domain name visibility during an HTTPS handshake will no longer be available to firewalls/proxies (unless they were terminating.)

    chasersystems.com/blog/disabli

    #esni #tls #ech #encryptedclienthello

  10. 💬 "Encrypted Client Hello, a new proposed standard that prevents networks from snooping on which websites a user is visiting, is now available on all Cloudflare plans."

    ❓ How does the internet like this?

    Links for further reading:

    The CloudFlare blog: Encrypted Client Hello - the last puzzle piece to privacy
    blog.cloudflare.com/announcing

    gHacks: The End of DNS-based Site Blocking is near
    ghacks.net/2023/10/07/the-end-

  11. I tidigare poddavsnitt har vi förklarat hur vikten av att använda VPN-tjänster på publika wifi-nät har minskat. I veckans podd förklarar vi varför ”krypterade hälsningar” minskar behovet ytterligare (på sikt).

    youtube.com/watch?v=ng3Ug-snNY

    #blisäker #ech #esni #chrome #firefox #vpn

  12. @miyuru Your #ESNI #checker is nice, as far as I can remember, I haven't ever seen ESNI working with #Firefox either, even if enabled. Dunno why.
  13. Russia wants to ban the use of secure protocols such as #TLS 1.3, #DoH, #DoT, #ESNI
    Amendment to IT law would make it illegal to use #encryption protocols that fully hide the traffic's destination.

    zdnet.com/article/russia-wants

    #privacyMatters

  14. And the beat goes on in the and cat-and-mouse-game:

    The Internet/#IETF roll out encrypted and to hide the web sites you're browsing: blog.cloudflare.com/esni/

    And the (and Paul Vixie) block it: zdnet.com/article/china-is-now

  15. NEW: #China's Great Firewall is now blocking all encrypted #HTTPS traffic using #TLS 1.3 and #ESNI

    -Block put in place last week, at the end of July
    -HTTPS+TLS1.3+ESNI prevents the GFW from determining the destination of an HTTPS connection, hence the ban

    zdnet.com/article/china-is-now

    #privacyMatters