Encrypted Client Hello
41–50 of 219 posts
Re: Encrypted Client Hello
#42Earlier quoted context omitted.
> but what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS? Exfiltration has always been a problem. But it's not a good reason to make MITM possible. Network control should not give control over endpoints any degree more than is necessary to deliver packets from point A to B. We can't trust them with more. > [...] Now Edge doesn't let you. That's blatantly false for…
People own their networks when they're not out in public. Again, solving for a problem with public networks by forcing shortcomings on to all networks is shortsighted and ill conceived. "But it's not a good reason to make MITM possible" is disingenuous. Avoiding DoH doesn't make MITM possible, just as adding DoH doesn't save us from MITM. It does, though, save apps / Trojans from MITM, particularly when we're the one…
It's not just being out in public. Even when you're home, you're still at the mercy of your ISP.
> Go ahead and tell me how to remove Edge, or how to have Windows open links in other browsers
What does preventing use of Edge have to do with DoH?
> You didn't address the real meat of the issue: Why is avoiding one issue - ISPs tracking DNS - worth all the bad things that come with it?
You've yet to convincingly point out a single bad thing that actually comes from DoH.
> So instead of teaching people how and encouraging them to make their networks better, you'd rather divest some of that trust to companies like Cloudflare, and to every application / Trojan writer?
You can't make public Wi-Fi or your ISP's network better no matter how knowledgeable you are.
Re: Encrypted Client Hello
#43This is going to make it even more of a pain to do egress filtering on networks/systems we administer. I want to be able to allow list sites with dynamic IPs. The existing solutions for doing this by examining SNI are already often bypassable by forging the SNI (looking at you, AWS Network Firewall).
Re: Encrypted Client Hello
#44Earlier quoted context omitted.
You're absolutely right, Cloudflare will still see it. That doesn't make this a bad improvement though. You don't have to use Cloudflare to support it, but it helps obscure which site is being visited by the nature of Cloudflare hosting so many different sites. So what does this actually protect against? Who will this benefit? Mostly people in censored countries and companies. This removes the last piece of informati…
What is wrong with DoH?
Re: Encrypted Client Hello
#45This just sounds like a less private Tor.
Re: Encrypted Client Hello
#46Earlier quoted context omitted.
That's an incorrect oversimplification. It takes control away from the owner of networks, even when we're the owner of those networks. Should DoH start to become more common, blocking it will become a Sisyphean task. It takes control away from the owner of endpoints. Sure, you can go and change the settings in Firefox to turn off DoH after they've turned it on without asking and without telling us, but what happens w…
> It takes control away from the owner of networks, even when we're the owner of those networks. My point is that even when you are the owner of a network, you shouldn't have control of traffic on it between endpoints that you don't own either of. > what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS? The Trojans could just hardcode the IP instead, so blocking DoH…
You're suggesting that applications and Trojans have the "right" to be free from my control, on my network, on my machines. Wow. What a take!
You're saying that all programs, Trojans included, will allow us to configure DoH. Again, a pretty crazy take, and completely, unambiguously wrong.
"What freedom am I giving up? What harm does DoH do to regular people?"
You clearly don't care about freedom, since you actively want to send your DNS to some third party. But you'd have me give up my freedom to control what goes on on my network because some ISPs track DNS, and instead of addressing that, you're for the idea of normalizing a protocol that removes my freedom and puts it in the hands of application / Trojan makers.
It harms regular people because it exfiltrates private information that they don't know about. Someone installs Firefox (very common) and doesn't know about DoH (also very common). Now their DNS lookups are all going to Cloudflare. We have no reason to trust Cloudflare (we do have plenty of reasons to not trust them, though).
But the point is that these regular people DON'T KNOW and haven't agreed to have their DNS data shared with Cloudflare. This has all sorts of negative implications that I'm sure you can't see.
Re: Encrypted Client Hello
#47Earlier quoted context omitted.
I agree that this is generally a good thing, and that DoH is an absolutely shitty thing, but I think the poster here was taking exception to this statement: "no one except for the user and the website will be able to determine which website was visited" That, I think we can all agree, is patently untrue. Cloudflare shouldn't be publishing blatant deceptions.
Author here - definitely not trying to be deceptive! I've amended the sentence you mentioned to be more clear.
Re: Encrypted Client Hello
#48Earlier quoted context omitted.
> It takes control away from the owner of networks, even when we're the owner of those networks. My point is that even when you are the owner of a network, you shouldn't have control of traffic on it between endpoints that you don't own either of. > what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS? The Trojans could just hardcode the IP instead, so blocking DoH…
You're not arguing in good faith. You're suggesting that me controlling my own network, and people controlling their own networks, is bad ("even when you are the owner of a network, you shouldn't have control of traffic on it between endpoints that you don't own either of"). You're suggesting that applications and Trojans have the "right" to be free from my control, on my network, on my machines. Wow. What a take! Yo…
Should your ISP be allowed to censor what you can see on the Internet? Remember they own the network that all of your traffic flows through.
> You're suggesting that applications and Trojans have the "right" to be free from my control, on my network, on my machines. Wow. What a take!
I'm not arguing that anything on your machines should be free from your control. I'm specifically saying that traffic passing through your network but not from or to one of your machines should be free from your control.
> You're saying that all programs, Trojans included, will allow us to configure DoH. Again, a pretty crazy take, and completely, unambiguously wrong.
I meant all legitimate programs do. Trojans obviously do whatever they want, and that was the case even before DoH existed.
> You clearly don't care about freedom, since you actively want to send your DNS to some third party.
You're always sending your DNS requests to some third parties. The only question is which.
> But you'd have me give up my freedom to control what goes on on my network because some ISPs track DNS, and instead of addressing that, you're for the idea of normalizing a protocol that removes my freedom and puts it in the hands of application / Trojan makers.
I disagree that "my freedom to control what goes on on my network" is a freedom that should be protected. For an extreme example, consider that someone complaining "they took away my freedom to own slaves" is obviously in the wrong. As I've said before, you should only have any control of traffic for which one of the endpoints is yours.
> It harms regular people because it exfiltrates private information that they don't know about. Someone installs Firefox (very common) and doesn't know about DoH (also very common). Now their DNS lookups are all going to Cloudflare. We have no reason to trust Cloudflare (we do have plenty of reasons to not trust them, though).
Most American ISPs are way less trustworthy than Cloudflare, and that's where almost everyone's DNS would be going otherwise.
> But the point is that these regular people DON'T KNOW and haven't agreed to have their DNS data shared with Cloudflare. This has all sorts of negative implications that I'm sure you can't see.
Do regular people even know what DNS is? Did they agree that their ISP could see their insecure DNS?
Re: Encrypted Client Hello
#49I feel like this is only possible because Cloudflare is already so huge. If this becomes widely adopted, anyone who wants to offer "private" access to their site will have to move through Cloudflare. This can't be good.
A lot of shared hosting providers would also be able to implement this. Bringing the benefits of ECH's anti-snooping to many end-users outside of CloudFlare. Individual servers hosting one single website won't benefit much though. Unless you do encrypted split-DNS, I guess.
Re: Encrypted Client Hello
#50I see a lot of confusion here, probably Cloudflare should have included an explanation of how ECH works in TFA instead of referring to their other article[1]. The difference between ECH and SNI is that while SNI includes the hostname in the ClientHello (the first TLS record indicating connection initiation), ECH includes an encrypted section in the ClientHello called ClientHelloInner, and the hostname is moved inside…
That's exactly why I'm in favor of it: it makes effective censorship impossible.
> If we take away this last resort from governments, they would react by enforcing client side blocklisting and DRMization as suggested in France[2], or force root certificate installation using legislation[3]
Note that those plans both thankfully failed.
> or blocking large swathes of the internet as is the case with China.
No free country would tolerate that.