Hacker News new | ask | show | jobs
by justDankin 2094 days ago
TLS1.3 + ESNI is a robust solution, Firefox has the option of enabling it.

Cloudflare has a great page which allows to check this https://www.cloudflare.com/en-gb/ssl/encrypted-sni/

1 comments

A couple of problems:

1. ESNI isn't a standard yet. So, support in mainstream web-clients is lacking.

2. Unfortunately, TLS v1.3 is blocked in countries with stringent censorship already.

Wait what?? TLS 1.3 is blocked by some countries? As more and more of the Web, especially CDNs move to TLS 1.3, won't these countries be effectively crippling the Net for their citizens?

Also ESNI needs server support I believe and very few servers support it. Right now it is effective only for sites fronted by Cloudflare if I'm not mistaken, and while that isn't a small number still its by no means the wider Net.

China is now blocking all encrypted HTTPS traffic that uses TLS 1.3 and ESNI

https://www.zdnet.com/article/china-is-now-blocking-all-encr...

I would not be surprised if some countries started blocking all the known DoH resolvers as well.