Dnscrypt also does not solve the sni problem.

Reply to this note

Please Login to reply.

Discussion

Sure, but that means we agree on that the dns methods themselves aren't a problem. I wadn't sure about that.

Have you considered the OCSP queries? Given that we all want https on all servers, now suddenly we need to query for certificate validity in every connection. 😋

Firefox allows you to use CRLite but it has to be enabled.

(As a side-note: maybe not every connection. I haven't looked into when it is exactly invoked.)