Can you please elaborate on that? domain name is sent after ssl handshake, no? Why is it sent plaintext?
Can you please elaborate on that? domain name is sent after ssl handshake, no? Why is it sent plaintext?
This is distinct from the HTTP Host: header, which is sent inside the TLS session and therefore is encrypted along with the rest of the HTTP request.
This includes all sites on a free Cloudflare plan to my knowledge.
SNI also allows decoupling TLS and TCP termination, which in turn allows for shared IP addresses and load balancers without necessarily delegating TLS termination and exposing certificates to some shared host.
One day people wanted to serve multiple websites from one IP, so they had browsers tell the server which site they are looking for (Server Name Indication); that way the server would know which SSL cert to send for the handshake.
SNI is still plaintext, it's a glaring privacy hole that most people aren't aware of. Encrypted SNI needs to come sooner.
For encrypted SNI, keys are expected to be published via DNS, which GFW is happy to disrupt.
Once you get a key, you have to send the key identifier in the clear (otherwise, the service doesn't know how to decrypt; unless you want to just do trial decryption with all available keys and hope that doesn't use too much CPU); the key identifier becomes the enforcement target at this point, unless you're on a host that shares ESNI keys among the many sites it hosts and is not acceptable collateral damage.
Cloudflare can explain it much better than me.
- DNS lookup for _esni.domain CNAME _esni.cloudflare.net,
- client connect to _esni.cloudflare.net via HTTPS and negotiate TLS with SNI rejected
- HTTP Host header contains desired target
Servers can trivially support the above "new" protocol (chances are they already do), no changes to DNS clients libraries or servers, and clients can support the new "encrypted SNI" by using OpenSSL APIs that already exist. GFW can't do anything unless cloudflare give them the key for _esni.cloudflare.net.
Everyone wins except the nerds who really wanted to make a new protocol. Oh and they need to walk back this stupid shit:
https://support.cloudflare.com/hc/en-us/articles/36002977947...
And the reason this stupid shit of preventing domain fronting was put in place is the exact reason why eSNI doesn't work, i.e. because it prevents state censorship and forces the state to instead block all the IP addresses in turn forcing companies to either cooperate with the state or expose enough identifying info to not interfere with state censorship.