70
anonymous
707918de34e2473336eed90ea847f19db4751b7175d893642684a6aaaf4d9cce
I am rude, because I have been treated (unjustly) like utter crap by a lot of people. If you are nice to me, I will very likely be nice to you.

I keep coming back to wondering if everyone's working very hard to trying to teach/convince me things that I have long known, while I'm waiting for something sensible. πŸ˜…

Actually, you're missing the key point. The goal is to bully me into giving up all the things I valued either in terms of knowledge/information or principle. There has been a coordinated campaign with harassment and abuse, essentially to push me to give up on choice I made based on my values and principles.

*That* is what I refuse to surrender. The curve was never an issue. It's all part of the deception of my enemies.

This isn't the point.

Replying to Avatar cryptowolf

That's pretty solid parking πŸ˜‹

Don't force your argument. Stop lying. Stop deceiving. Stop making up false, malicious excuses to be assholes.

Sure, but that means we agree on that the dns methods themselves aren't a problem. I wadn't sure about that.

Have you considered the OCSP queries? Given that we all want https on all servers, now suddenly we need to query for certificate validity in every connection. πŸ˜‹

Firefox allows you to use CRLite but it has to be enabled.

Sure, so the passive attacker knows you connect to the DoH/DoT ip address and it leaks the fact that it is "dotprovider.secret", but not the query you send.

Indeed SNI was necessary at first for webservers that serve multiple domains. ESNI solves that.

I didn't see dnscrypt discussed while scanning the article. dnscrypt is built on plain UDP/TCP packets, very similar to original DNS, but with encryption. See spec at dnscrypt.info (Note also that there are "oblivious" querying methods that obscure the exact domain name you're querying from the nameserver. Offered by dnscrypt-proxy.)

Afaict from your post, the emphasis is predominantly on the (E)SNI issue.

Also, I don't understand what you're actually commenting on with ESNI and ECH .. is it the dns query or the subsequent webserver connection?

I doubt it. I'm very bad with birthdays. πŸ˜…πŸ˜†