So the version of cURL distributed on Termuz disabled ECH support for whatever reason. Bloody awesome when you want to rely on readily-available tools for tests.

Edit: The version bundled in Windows also doesn't offer such support. Seems like it's disabled by default.

#curl #Termux #ECH #ESNI
ECH 變成 Standards Track 了

看到 ECH 變成 Standards Track 了:「RFC 9849 TLS Encrypted Client Hello (via)」。 瀏覽器都在 2023 的下半年預設啟用了 (Firefox 119 是 2023/10/24,Chromium 117 是 2023/09/12)。 ECH is enabled in Firefox by default since version 119, and is recommended by Mozilla to be used a...

Gea-Suan Lin's BLOG

Just found out that you can get #ESNI ^W #ECH #DNS queries working in #Firefox without having to run my own DNS over HTTPS server.

Just set network.dns.native_https_query to true. Bonus points for network.dns.preferIPv6 to make it stop preferring #IPv4 for some reason.

You obviously have to find a way of getting DNS traffic in and out of your network safely. I spread it out over a couple of servers that I host.

#centralization

@Seirdy @feistyduck I've been waiting for years for it to work. But if we would finally start getting to that direction.

Many also forgot the #ESNI, which didn't work either.

Cloudflare #ECH #test:
https://www.cloudflare.com/ssl/encrypted-sni/
Akkoma

We had lots of queries on why TLS ECH is not good/good, so shedding some light on why it was conceived.

(formerly called Encrypted SNI #ESNI)

https://infosec.exchange/@ChaserSystems/111323263652989467

Chaser Systems (@[email protected])

Attached: 1 image We've added more info on a use case for #TLS Encrypted ClientHello #ECH in our blog post on how to disable it for Google Chrome. The paper that studies "to prevent censors from learning the server names" is now cited 👇 https://chasersystems.com/blog/disabling-encrypted-clienthello-in-google-chrome-and-why/ Image from: china-briefing[.]com

Infosec Exchange

Google Chrome v117 turned on TLS Encrypted ClientHello by default (on 27 Sep?) This will impact the effectiveness and accuracy of outbound traffic filtering* - for those who've implemented it (regardless of vendor.) We've written a short blog post on disabling it with PowerShell, Windows Registry and Google Chrome UI for those who may need to roll this out ASAP and regain visibility. (Disclosure: we are a vendor of an outbound filtering solution and this has impacted our customers already.)

*for many websites, the domain name visibility during an HTTPS handshake will no longer be available to firewalls/proxies (unless they were terminating.)

https://chasersystems.com/blog/disabling-encrypted-clienthello-in-google-chrome-and-why/

#esni #tls #ech #encryptedclienthello

Disabling Encrypted ClientHello in Google Chrome, and Why | Chaser Systems

How to disable TLS Encrypted ClientHello in Google Chrome using PowerShell

💬 "Encrypted Client Hello, a new proposed standard that prevents networks from snooping on which websites a user is visiting, is now available on all Cloudflare plans."

❓ How does the internet like this?

Links for further reading:

The CloudFlare blog: Encrypted Client Hello - the last puzzle piece to privacy
https://blog.cloudflare.com/announcing-encrypted-client-hello/

gHacks: The End of DNS-based Site Blocking is near
https://www.ghacks.net/2023/10/07/the-end-of-dns-based-site-blocking-is-near/

#Cloudflare #ECH #EncryptedClientHello #ServerNameIndication #SNI #ESNI #Security #TLS

Encrypted Client Hello - the last puzzle piece to privacy

We're excited to announce a contribution to improving privacy for everyone on the Internet. Encrypted Client Hello, a new standard that prevents networks from snooping on which websites a user is visiting, is now available on all Cloudflare plans.

The Cloudflare Blog
Encrypted Client Hello (ECH) Effectively Defeats Pirate Site Blocking

Cloudflare has enabled Encrypted Client Hello for customers on free plans. When sites and visitors enable ECH, site-blocking is circumvented.

TF Publishing

I tidigare poddavsnitt har vi förklarat hur vikten av att använda VPN-tjänster på publika wifi-nät har minskat. I veckans podd förklarar vi varför ”krypterade hälsningar” minskar behovet ytterligare (på sikt).

https://www.youtube.com/watch?v=ng3Ug-snNYE

#blisäker #ech #esni #chrome #firefox #vpn

Podd 209: Krypterad hälsning minskar VPN-behovet

YouTube
@miyuru Your #ESNI #checker is nice, as far as I can remember, I haven't ever seen ESNI working with #Firefox either, even if enabled. Dunno why.
Akkoma