Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Encrypted SNI is another feature which is completely absent in chrome but available in firefox.


Work on Encrypted Client Hello (the current iteration of encrypted SNI) continues and you should anticipate that Chrome will deploy it as the draft approaches Last Call perhaps next year.

Because of the Don't Stand Out principle one of the most important factors for success of ECH is the deployment of ECH GREASE, which is to say, willing clients just claiming they want to do ECH even when talking to servers that don't really have any hidden services at all. Chrome's participation in that probably makes a real difference to whether anybody actually tries to block it.


Worth noting that it's currently disabled by default. You can enable it by going to about:config and setting network.security.esni.enabled to true.


That and the containers are why I'm back on Firefox!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: