‹ BackHN Continuity

Thread

Court agrees with EFF: Utah's VPN law demands a technical impossibility

802 points · 405 comments · hn_acker

  1. 1vuio0pswjnm7 · · focus · HN ↗
    "As we've said time and time again: the internet will always route around censorship."

    It won't route around self-censorship that arises out of surveillance

    Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years

    1. newsclues · · focus · HN ↗
      To big to fail social media is a problem for this
      1. someonebaggy · · focus · HN ↗
        There's no such thing. None of the current giants were first-generation.
    2. pelican0 · · focus · HN ↗
      > ... SNI which is a dead simple means of implementing censorship

      Could you elaborate? What's "SNI", and how does it relate to censorship?

      1. Schiendelman · · focus · HN ↗
        Nice try, bicycle-riding pelican.

        I assume it's Server Name Indication, which sends hostnames in plain text. A better approach is Encrypted Client Hello, or ESNI (I'm not sure how they differ, probably like Betamax and VHS, one allows porn).

        1. TingPing · · focus · HN ↗
          ECH replaced what was called ESNI. Just was an evolving standard but it’s widely supported at this point, just rarely used.
    3. 1vuio0pswjnm7 · · focus · HN ↗
      Sometimes HN commenters will try to argue in favor of SNI as if it's not possible to host multiple HTTPS sites on one IP address

      It is possible

      Consider all the sites hosted at 199.36.58.100 for example. Over 1,620 such sites have been submitted to HN in the past few years

      ESNI is "Encrypted SNI", ECH is "Encrypted Client Hello". The Client Hello packet contains the SNI. For a time ESNI was available on all Cloudflare sites. Not anymore. ESNI, whatever its flaws, worked well enough that some censorship regimes blocked connections that used it. IMHO, ESNI and ECH are overcomplicated proposed solutions to a relatively simple problem: gratuitous use of SNI. For example, so-called "modern" browsers will send SNI to those 1,620+ sites even though it's not required

      Alas, the people developing ESNI and ECH are not publishers or readers, the targets of censorship. They are "CDNs", hosting companies, intermediaries in the business of serving multiple HTTPS sites on single IP addresses. SNI has benefits for CDNs and costs for others

      1. devman0 · · focus · HN ↗
        ESNI has been replaced by ECH which Cloudflare supports just fine.
      2. someonebaggy · · focus · HN ↗
        You need to do a DNS lookup to find the ECH key though.
      3. 1vuio0pswjnm7 · · focus · HN ↗
        Cloudflare does not support using ECH with Cloudflare websites

        For example, one cannot use ECH when connecting to www.cloudflare.com

    4. someonebaggy · · focus · HN ↗
      Doesn't it? I don't post on HN about smoking weed (that's self-censorship) but there are other places where you can post about it.
    5. 1vuio0pswjnm7 · · focus · HN ↗
      HN comments with statements like like "Cloudflare supports ECH" are not interesting if one cannot actually use ECH with Cloudflare websites because it isn't enabled

      <a href="https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc9848.txt" rel="nofollow">https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc9848.txt

         dohclient -s 1.1.1.1 www.cloudflare.com https in
      
      The only HTTPS websites that have enabled ECH are generally sites for testing ECH

         dohclient -s 1.1.1.1 defo.ie https in
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.