@buh to [email protected] • 1 year agoSay (an encrypted) hello to a more private internet.blog.mozilla.orgexternal-linkmessage-square62arrow-up1664arrow-down17cross-posted to: [email protected][email protected][email protected]technology
arrow-up1657arrow-down1external-linkSay (an encrypted) hello to a more private internet.blog.mozilla.org@buh to [email protected] • 1 year agomessage-square62cross-posted to: [email protected][email protected][email protected]technology
minus-square@[email protected]linkfedilink1•1 year agoWouldn’t it be better if reverse proxies simply had a “default key” meant to encrypt the SNI after an unencrypted “hello” is received? Including DNS in this seems weird.
minus-square@[email protected]linkfedilink1•1 year agoWhat would stop a MITM attacker from replacing the key? The server can’t sign the key if it doesn’t know which domain the client is trusting.
Wouldn’t it be better if reverse proxies simply had a “default key” meant to encrypt the SNI after an unencrypted “hello” is received?
Including DNS in this seems weird.
What would stop a MITM attacker from replacing the key? The server can’t sign the key if it doesn’t know which domain the client is trusting.