Hacker News new | ask | show | jobs
by sammy2255 1373 days ago
The UK is fighting a losing battle. Right now they snoop SNI headers and terminate connections to banned websites. But ECH is ready to be rolled out
1 comments

ECH can't be mandatory as many enterprises (that take security seriously) will block it, so they'll also be able to. No?
Don't most enterprises already use an in house root cert to MITM all https anyway?
It will take years but I believe yes it will. SNI was a big privacy mistake.

Companies just need new solutions . SNI was never a perfect one.