Earlier quoted context omitted.
A contract where cloudflare receives no consideration isn't particularly comforting, as such agreements are routinely ignored by courts (or equivalently by capping damages at nothing). > Mozilla's conundrum is how to protect everyone 's privacy And exactly how does this protect user's privacy? Instead of the user's ISP being able to see where the user connects now both cloudflare AND the user's ISP (via seeing the co…
Re: the contract, let's hope you're wrong. Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages). And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.
What if ISPs block requests with eSNI for all users, in order to be able to remain compliant with legal intercept legislation (e.g. warrant for suspected child porn investigation)?
There are conflicting desires with trade-offs, and all Mozilla is doing here is escalating the war, rather than trying to reach agreement with the rest of the industry on how to satisfy two different requirements.