Live data from Hacker News

New standards for a faster and more private Internet

blog.cloudflare.com

1–10 of 87 posts

Re: New standards for a faster and more private Internet

#3
post #2

> New standards for a faster and more private Internet > Zstandard I get "faster" but how does it make the internet "more private". The word "private" only shows up exactly once on that page, in the title.

They also talk about Encrypted Client Hello (ECH).

Re: New standards for a faster and more private Internet

#4
post #2

> New standards for a faster and more private Internet > Zstandard I get "faster" but how does it make the internet "more private". The word "private" only shows up exactly once on that page, in the title.

I believe that the "more private" part is referencing the "Encrypted Client Hello (ECH)" section in the later part of the post.

Re: New standards for a faster and more private Internet

#6
post #5

Does it mean ECH works only with the Cloudflare since their example ECH contains unencrypted outer layer client hello?

No, it's am emerging standard. We are just pushing its adoption as fast as we can. Hence, we've rolled this out to all free customers.

Re: New standards for a faster and more private Internet

#7
post #2

> New standards for a faster and more private Internet > Zstandard I get "faster" but how does it make the internet "more private". The word "private" only shows up exactly once on that page, in the title.

>The word "private" only shows up exactly once on that page, in the title.

However, the word "privacy" shows up 10 times in the article.

Re: New standards for a faster and more private Internet

#9
ECH - if I understand correctly it's effective for sites hosted on big providers like Cloudflare, AWS, etc, but doesn't add much value when it comes to self-hosted domains or those on a dedicated server, as you'd still see traffic going to whatever IP and be able to infer from that which domain the user's browswer is talking to. I'm hoping someone can explain that I missed something.

And while we're explaining things... ODoH (indirectly mentioned in the article via the Encrypted DNS link) comes with a big bold warning it's based on the fundamental premise that the proxy and the target servers do not collude. When both are operated by the same company, how can you know they aren't colluding? Is there some mechanic in the protocol to help protect users from colluding servers?

Re: New standards for a faster and more private Internet

#10
re: ECH

let the cat and mice game between deep packet inspection (DPI) vendors and the rest of the encrypted internet continue. it’ll be amusing to see what they come up with (inaccurate guessing game ai/ml “statistical analysis” is about all they’ve got left, especially against the large umbrella that is cloudflare).

game on, grab your popcorn, it will be fun to watch.

Post reply on HN