[TLS] TLS against censorship

2024-11-14 Thread evasilen
Hi Experts, I am not a strong person on encryption, but it is evident for me that "TLS Encrypted Hello" https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-22 has no value in fighting censorship. Whatever DNS name would be used for "client-facing server", it is easy for a particular country

[TLS] Re: TLS against censorship

2024-11-15 Thread evasilen
Hi Raghu, OTTs reading this statement about privacy is probably laughing. OTTs are collecting the volume of private information - they are the primary danger for privacy. ECH would not help even theoretically. Hence, I do not care about privacy. It is not possible anyway. I remember a good joke, i

[TLS] Re: TLS against censorship

2024-11-16 Thread evasilen
Hi all, * I don't think there is much ECH spec can do about this - versatility of public name construction depends on many internal operational details of the hosting service. Don’t agree. It is possible. Just introduce 2 stages for adoption: 1. Stage 1: TLS extension that makes