Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNS over HTTPS is the solution here.


SNI is still in the plaintext.


It it still an improvement; you need to DPI the traffic then, which is more demanding than just logging 53/udp queries.


Anyone who is trying to invade your privacy is going to do DPI.

My prosumer grade harder does DPI without any issue.


Doesn't change the fact that the SNI is sent in clear text.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: