Hacker News new | past | comments | ask | show | jobs | submit login

That's much easier to fix (by using DoH or DoT) than getting ECH widely deployed, though. Importantly, it can be done unilaterally by each user and doesn't need cooperation on both sides of the connection.

Many browsers these days support using DoH without changing any OS settings.




That's not actually a fix. As long as some other subscriber does the DNS lookup, then the ip address will be associated with the name that was looked up. If you happen to use a different resolver and get the same address, there's no difference.


If the IP address belongs to a cloud load balancer or CDN, that’s still much better than hostname-level detail. Even for subdomains it helps (think somebody.bloghoster.tld).

And ECH will still reveal the outer SNI, apparently.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: