logoalt Hacker News

maxlohtoday at 11:01 AM2 repliesview on HN

Since most ISPs also maintain their own DNS resolver, they could always reverse lookup the IP address AFAIK.


Replies

progbitstoday at 11:20 AM

The whole idea behind ECH is one IP hosts tons of sites (eg. CDN) so you have no idea which one it is.

Also reverse lookup has nothing to do with hosting own DNS resolver.

show 1 reply
szmarczaktoday at 11:15 AM

True. ECH is useless if you're using plain DNS. DNS over TLS or HTTPS is the way to go.