Hacker News new | past | comments | ask | show | jobs | submit login

The UK is fighting a losing battle. Right now they snoop SNI headers and terminate connections to banned websites. But ECH is ready to be rolled out



ECH can't be mandatory as many enterprises (that take security seriously) will block it, so they'll also be able to. No?


Don't most enterprises already use an in house root cert to MITM all https anyway?


It will take years but I believe yes it will. SNI was a big privacy mistake.

Companies just need new solutions . SNI was never a perfect one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: