Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The website operator has to use it, too. Many HTTP servers still do not support TLS1.3 let alone ECH (Draft 13). ECH is still experimental. Cloudflare disabled their ESNI trial a while back (ESNI worked great for me outside the browser), so unless they have now got ECH working (I still have not seen any announcement), currently there are even fewer sites offering encrypted SNI. You could probably count them on one hand. And Firefox (nightly), Chromium (105+) and Brave (nightly) are probably the only browsers that would support ECH and it is not enabled by default. I would be pleased to learn I am wrong here, because I would love to again start using sites that do not return requested pages unless a servername is sent.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: