Live data from Hacker News

Encrypted Client Hello

blog.cloudflare.com

191–200 of 219 posts

Re: Encrypted Client Hello

#191
post #175

Earlier quoted context omitted.

> The second way is to return a “no error no answer” or an NXDOMAIN response to queries made to the use-application-dns.net. This misfeature can't be removed from browsers soon enough. Its existence is totally contrary to DoH's threat model, since the people DoH is designed to protect you from are exactly the ones who can manipulate insecure DNS results for that domain.

It's just a network hint. Browsers are free to ignore (and I think Firefox has a toggle to ignore it).

and I think Firefox has a toggle to ignore it

They do. It used to be one had to modify modes in about:config but now there is a GUI for it in the settings.

[1] - https://support.mozilla.org/en-US/kb/dns-over-https

Re: Encrypted Client Hello

#192

I see a lot of confusion here, probably Cloudflare should have included an explanation of how ECH works in TFA instead of referring to their other article[1]. The difference between ECH and SNI is that while SNI includes the hostname in the ClientHello (the first TLS record indicating connection initiation), ECH includes an encrypted section in the ClientHello called ClientHelloInner, and the hostname is moved inside…

I disagree vehemently about this:

> If we take away this last resort from governments, they would react by enforcing client side blocklisting and DRMization as suggested in France[2], or force root certificate installation using legislation[3], or blocking large swathes of the internet as is the case with China.

You left out the fourth option, which is give up on their censorship aspirations. For most countries, censorship isn't important, and making it too hard will simply make it not worth it. China is of course different.

Most countries made entirely ineffective laws and didn't bother following up.

Re: Encrypted Client Hello

#193

Earlier quoted context omitted.

"Even when you're home, you're still at the mercy of your ISP." No, I'm not. If you think I am, then you don't understand networking. "What does preventing use of Edge have to do with DoH?" If you can't have basic control of programs on your own computer, tell me how you're going to control programs' use of DoH. "You've yet to convincingly point out a single bad thing that actually comes from DoH." I've named many: w…

> "Even when you're home, you're still at the mercy of your ISP." No, I'm not. If you think I am, then you don't understand networking. If your ISP dropped all packets on port 53 that contained a response for example.com, how would you circumvent that and learn its IP otherwise? > "What does preventing use of Edge have to do with DoH?" If you can't have basic control of programs on your own computer, tell me how you'…

You answer questions by answering what you feel like and diverting, not by addressing what's relevant to the discussion. I'm not going to answer things in good faith when you're just playing dumb.

I'm fairly certain you're trolling. Do you do this with friends and family, too? Just so you know, people aren't agreeing with you just because they decide to stop engaging with you.

I like the fact that your attempts to derail are all here, plain as day, for anyone to see, because people knowing that DoH is a big scam to grab private data about them is important.

Re: Encrypted Client Hello

#194

Earlier quoted context omitted.

Trust is hard, yes. Cloudflare might not be going for the low hanging fruit such as injecting ads, but they clearly want to be a monopoly around whom the Internet recentralizes. Moving DNS from an ISP, who we pay and with whom we have legal contracts, to a company that does things, supposedly, for altruistic reasons, with whom we do NOT have contracts, doesn't fix anything. It makes things worse. The solution is to r…

> I want to run my own DNS and block DNS to the rest of the Internet. Your private recursive DNS server, of course, has to send requests to the rest of the internet; you don't want to block those. They don't have to be plaintext, unless the authoritative server in question only talks plaintext.

Of course, and it's obviously easier to configure a single recursive resolver to prefer encryption wherever possible than it is to try to configure each client (or in the case of DoH, each program) to do opportunistic encryption.

The point is that these requests don't go to my ISP's DNS servers.

And for the other people who're making up unrealistic scenarios such as the ISP trying to MITM all DNS, not just queries they answer, there are many forms of tunneling that can be used such as VPNs. It's still easier to do one solution for the whole network than individual solutions for each client (or each application, for DoH).

Re: Encrypted Client Hello

#196

I see a lot of confusion here, probably Cloudflare should have included an explanation of how ECH works in TFA instead of referring to their other article[1]. The difference between ECH and SNI is that while SNI includes the hostname in the ClientHello (the first TLS record indicating connection initiation), ECH includes an encrypted section in the ClientHello called ClientHelloInner, and the hostname is moved inside…

> Doing so prevents ISPs and governments from analyzing your traffic. However, a CDN operator such as Cloudflare terminates TLS for your website, and thus traffic would be visible to them either way. Cloudflare adopts the similar predatory Google posture of "we really really care about your privacy - nobody else should spy on you but us". Creepy!!

Well, not exactly. They are making privacy improvements in open standard protocols that you are free to use without using their service.

Re: Encrypted Client Hello

#197
post #179

Earlier quoted context omitted.

If it's really a corporate network, then the company will own the endpoints and can do the inspection there.

Not meaningfully so with ECH, the whole point of this subthread.

ECH only makes network-level monitoring harder. Monitoring on the endpoint is still just as easy.

Re: Encrypted Client Hello

#198

Earlier quoted context omitted.

Narrator: they didn't relent. Do you think for a second anyone in power in China, Russia, or North Korea care if some random 20-year-old kid can access English-language sites or not?

I know North Korea is happy to cut off the entire rest of the world, but even China and Russia are not.

For China your 'entire rest of the world' ie US + Europe is less than China population.

Re: Encrypted Client Hello

#199

Earlier quoted context omitted.

Is it a fair conjecture that in some sense there's an issue with cryptographer's trying to push the field in terms of the efficacy and robustness of encryption forward while "the government"s continually work all manner of trickery to hamper these efforts in subtle and not-so-subtle but gag-ordered-enforced ways? I feel like there's this constant ridiculous pushback on any digital product or protocol or service being…

>Like, it always comes across as they feel that their entire case is lost if they can only prove something 5 different ways instead of 6. There are a lot of crimes these days without a complainant. The sale and consumption of illegal drugs for instance. Surveillance can be very important in discovering the crime in the first place. It's like asking someone to help you with your diet and then becoming upset when they…

Did anybody ask governments to “help with diet” though? It feels more like governments in their ever expanding power struggle decided diets needed to be fixed even though nobody complained about them and then decided that the ends justify any means.

Re: Encrypted Client Hello

#200

I see a lot of confusion here, probably Cloudflare should have included an explanation of how ECH works in TFA instead of referring to their other article[1]. The difference between ECH and SNI is that while SNI includes the hostname in the ClientHello (the first TLS record indicating connection initiation), ECH includes an encrypted section in the ClientHello called ClientHelloInner, and the hostname is moved inside…

> Doing so prevents ISPs and governments from analyzing your traffic. However, a CDN operator such as Cloudflare terminates TLS for your website, and thus traffic would be visible to them either way. Cloudflare adopts the similar predatory Google posture of "we really really care about your privacy - nobody else should spy on you but us". Creepy!!

[deleted]
Post reply on HN