Hacker News new | ask | show | jobs
by DistractionRect 1558 days ago
It really doesn't, as server name indication is sent in clear text. As encrypted SNI didnt take off, you dont actually get privacy benefits from DoH and friends, just security/mild inconvenience to censors.
1 comments

> encrypted SNI didnt take off

Says who? I think your data is very old considering that ECH replaced ESNI 2 years ago. IIRC it has ~50% adoption, same as TLS 1.3. Just about every company that cares about security supported ECH for years.

Moreover, someone has to move first. If DoH wasn’t widely deployed you’d be complaining that ECH is useless because DNS is unencrypted.