It won't route around self-censorship that arises out of surveillance
Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years
It won't route around self-censorship that arises out of surveillance
Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years
Could you elaborate? What's "SNI", and how does it relate to censorship?
I assume it's Server Name Indication, which sends hostnames in plain text. A better approach is Encrypted Client Hello, or ESNI (I'm not sure how they differ, probably like Betamax and VHS, one allows porn).
It is possible
Consider all the sites hosted at 199.36.58.100 for example. Over 1,620 such sites have been submitted to HN in the past few years
ESNI is "Encrypted SNI", ECH is "Encrypted Client Hello". The Client Hello packet contains the SNI. For a time ESNI was available on all Cloudflare sites. Not anymore. ESNI, whatever its flaws, worked well enough that some censorship regimes blocked connections that used it. IMHO, ESNI and ECH are overcomplicated proposed solutions to a relatively simple problem: gratuitous use of SNI. For example, so-called "modern" browsers will send SNI to those 1,620+ sites even though it's not required
Alas, the people developing ESNI and ECH are not publishers or readers, the targets of censorship. They are "CDNs", hosting companies, intermediaries in the business of serving multiple HTTPS sites on single IP addresses. SNI has benefits for CDNs and costs for others
For example, one cannot use ECH when connecting to www.cloudflare.com
https://www.rfc-editor.org/rfc/rfc9848.txt
dohclient -s 1.1.1.1 www.cloudflare.com https in
The only HTTPS websites that have enabled ECH are generally sites for testing ECH dohclient -s 1.1.1.1 defo.ie https in