Re: [LINK] Calling time on DNSSEC?

Liste des GroupesRevenir à c misc 
Sujet : Re: [LINK] Calling time on DNSSEC?
De : gtaylor (at) *nospam* tnetconsulting.net (Grant Taylor)
Groupes : comp.misc
Date : 04. Dec 2024, 02:37:46
Autres entêtes
Organisation : TNet Consulting
Message-ID : <viobpa$s79$2@tncsrv09.home.tnetconsulting.net>
References : 1 2 3 4 5 6
User-Agent : Mozilla Thunderbird
On 12/3/24 00:14, Lawrence D'Oliveiro wrote:
Nobody uses PKI.
Um....  I think I'm one of many, Many, MANY people that will have to disagree with you on hat one.

TLS has a hole in it, in that the SNI, “Server Name Indication” (the “Host:” line in the HTTP request header) has to be sent unencrypted.
Two flags on the play:
1)  Encrypted SNI is a thing.
2)  "the "Host:" line in the HTTP request header" is *NOT* the SNI.  The Host: header is part of the HTTP request that's inside of the TLS connection.
The SNI hello message does include something similar, but it's not the Host: header.  And there's also ESNI to protect it.

This allows eavesdroppers, like authoritarian Government regimes, to determine when you are trying to access a prohibited service, and block it before the encrypted connection can be set up.
Those are examples of the very things that ESNI is designed to defend against.
Link - What is encrypted SNI? | How ESNI works | Cloudflare
  - https://www.cloudflare.com/learning/ssl/what-is-encrypted-sni/
ECH also looks promising.
--
Grant. . . .

Date Sujet#  Auteur
27 Nov 24 * [LINK] Calling time on DNSSEC?19Computer Nerd Kev
27 Nov 24 +* Re: [LINK] Calling time on DNSSEC?17Grant Taylor
27 Nov 24 i`* Re: [LINK] Calling time on DNSSEC?16Richard Kettlewell
28 Nov 24 i `* Re: [LINK] Calling time on DNSSEC?15Grant Taylor
28 Nov 24 i  `* Re: [LINK] Calling time on DNSSEC?14Richard Kettlewell
28 Nov 24 i   +* Re: [LINK] Calling time on DNSSEC?2Grant Taylor
29 Nov 24 i   i`- Re: [LINK] Calling time on DNSSEC?1Richard Kettlewell
3 Dec 24 i   `* Re: [LINK] Calling time on DNSSEC?11Lawrence D'Oliveiro
4 Dec 24 i    `* Re: [LINK] Calling time on DNSSEC?10Grant Taylor
4 Dec 24 i     +* Re: [LINK] Calling time on DNSSEC?7Lawrence D'Oliveiro
4 Dec 24 i     i`* Re: [LINK] Calling time on DNSSEC?6Grant Taylor
4 Dec 24 i     i `* Re: [LINK] Calling time on DNSSEC?5Lawrence D'Oliveiro
5 Dec 24 i     i  `* Re: [LINK] Calling time on DNSSEC?4Grant Taylor
5 Dec 24 i     i   +* Re: [LINK] Calling time on DNSSEC?2Lawrence D'Oliveiro
5 Dec 24 i     i   i`- Re: [LINK] Calling time on DNSSEC?1Grant Taylor
5 Dec 24 i     i   `- Re: [LINK] Calling time on DNSSEC?1Richard Kettlewell
4 Dec 24 i     `* Re: [LINK] Calling time on DNSSEC?2Richard Kettlewell
5 Dec 24 i      `- Re: [LINK] Calling time on DNSSEC?1Grant Taylor
27 Nov 24 `- Re: [LINK] Calling time on DNSSEC?1Marco Moock

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal