Y
Hacker News
new
|
ask
|
show
|
jobs
by
aand16
33 days ago
During the TLS handshake, you send the domain name in clear text (Server Name Indication - SNI extension) so that the hoster can present the correct certificate for that domain.
Nothing prevents the ISP from collecting that.
1 comments
ekr____
33 days ago
Hence Encrypted Client Hello (
https://datatracker.ietf.org/doc/rfc9849/
), though deployment is still thin.
link