Hacker News new | ask | show | jobs
by Anunayj 986 days ago
Yes, however it defeats one of the main point of ECH, that is encrypting the SNI. Since the domain is leaked in plaintext DNS.
1 comments

Why? You can just use DNS-over-TLS/HTTPS + dnssec + ECH + TLSv1.3 and then you should have a unblockable website(outside of IP address bans).
Ah yes, sorry I thought you meant can't we just use plaintext DNS + DNSSEC.