logoalt Hacker News

ocdtrekkieyesterday at 7:36 PM4 repliesview on HN

Just be aware any reasonable network will block this.


Replies

Benderyesterday at 8:48 PM

Just be aware any reasonable network will block this.

Russia blocked it for Cloudflare because the outer SNI was obviously just for ECH but that won't stop anyone from using generic or throw-away domains as the outer SNI. As for reasonable I don't quite follow. Only censorious countries or ISP's would do such a thing.

I can foresee Firewall vendors possibly adding a category for known outer-SNI domains used for ECH but at some point that list would be quite cumbersome and may run into the same problems as blocking CDN IP addresses.

kstrauseryesterday at 9:35 PM

Once upon a time, "reasonable networks" blocked ICMP, too.

They were wrong then, of course, and they're still wrong now.

show 1 reply
quantummagicyesterday at 8:08 PM

Why is it "reasonable" to block it?

show 1 reply
hypeateiyesterday at 8:13 PM

Procrastinators. FTFY.

Eventually these blocks won't be viable when big sites only support ECH. It's a stopgap solution that's delaying the inevitable death of SNI filtering.

show 1 reply