[TLS] Encrypted Client Hello - SNI leaks via public name?

2023-10-06 Thread Raghu Saxena
Hello All, I've been a huge proponent of ESNI (as a consumer, not developer) back when it was introduced as a draft, with firefox support (albeit behind a flag), and it being enabled for Cloudflare customers. For me (and people I introduced it to), the purpose was to bypass SNI based blocking

Re: [TLS] Encrypted Client Hello - SNI leaks via public name?

2023-10-06 Thread Dennis Jackson
Hi Raghu, On 06/10/2023 10:45, Raghu Saxena wrote: Specifically, I am concerned about the "public name" field in the ECHConfig. For services such as cloudflare, they can "hide" everything behind a single domain (e.g. "cloudflare-ech.com"). However, for someone who just owns a single domain (e.