#sni

Dantali0n :arch: :i3:dantalion@fosstodon.org
2025-06-13

You know you think DNS over TLS or DNS over HTTPS is great and you no longer send the domains you visit over cleartext on the internet...

Wrong, prior to TLS 1.3 your browser would request the domain in cleartext as part of the TLS negotiation in a process called Server Name Indication (SNI).

Only with TLS 1.3 did we finally get a Encrypted Client Hello (ECH).

#DoT #DoH #TLS #SNI

2025-06-03

SniProxy

SniProxy based on dnsmasq and nginx It works like shecan.ir in Iran. SniProxy How to Run ?! Install docker and docker-compose Run with docker-compose up -d Change docker-compose.yml based on your preferences ! I try to update the dnsmasq/proxy.conf file based on the internet status of Iran It could be resource intensive task to serve this dns service to many people so bring a powerhouse I tested on a 2gigs 2 cpus vps and It is OK for me, my family, and friends Also dnsmasq […]

whalers.ir/blog/sniproxy/6612/

2025-05-31

SNI là gì? Khái niệm và vai trò quan trọng trong bảo mật web

SNI là gì? Khái niệm và vai trò quan trọng trong bảo mật web Giới thiệu chung về SNI Server Name Indication (SNI) là một phần mở rộng quan trọng của giao thức TLS/SSL, được sử dụng để chỉ định tên máy chủ mà client (ví dụ: trình duyệt web) muốn kết nối đến trong quá trình thiết lập handshake TLS.

bietduoc.io.vn/2025/05/31/sni-

FWIW: der #SNI Tunnel scheint auf der #Embraer Flotte (#WiFi by #IntelSat) nicht mehr zu funktionieren.

Ich habe nur noch nicht herausgefunden ob sie jetzt explizit IP Adressen allowlisten oder ASNs.

social.zischundweg.cloud/@wifi

DionyZack 🍉✊🏽♀️🌿dionyzack.bsky.social@bsky.brid.gy
2025-03-21

🕸glané sur le net🕸 Marcelle Berthaud (dite Alouette) 1918-2013: Institutrice, militante du SNI tendance École Émancipée) ; membre des Faucons rouges d'octobre 1934 jusqu'à la guerre, secrétaire administrative de la SFIO du Rhône de 1944 à… #MarcelleBerthaud #Alouette #Education #Militantisme #SNI

Marcelle Berthaud (dite Alouet...

#Taller Introductorio #PCR para Profesionales de la Salud 2025

Impartido por la Dra. #KarinaAcevedoWhitehouse, investigadora de la @UAQmx y #SNI III

youtube.com/watch?v=89LAgYYPj1E

2024-11-06

Как отключить ECH для вашего домена на Cloudflare

Как вы знаете, Роскомнадзор (РКН) заблокировал технологию Encrypted Client Hello (ECH), а Cloudflare неожиданно принудительно включил её для всех пользователей. Это вызвало серьезные проблемы для тех, кто использует Cloudflare, особенно для пользователей из России. Решим эту проблему! Если вам нужно отключить Encrypted Client Hello (ECH) для вашего домена на Cloudflare, выполните следующие шаги. Этот процесс включает проверку текущего статуса ECH, а затем его отключение через API Cloudflare.

habr.com/ru/articles/856602/

#TLS #SNI #ECH #РКН #роскомнадзор #cdn #cloudflare #блокировка_сайтов

2024-11-06

РКН заблокировал ECH [SNI]: пользователи Cloudflare под ударом, что дальше?

Cloudflare неожиданно включил всем своим пользователям шифрование заголовка SNI (Server Name Indication). Это значит, что теперь невозможно узнать, к какому сайту происходит подключение через HTTPS. В результате многие сайты, заблокированные в России, стали снова доступны, если они используют Cloudflare. Но не все так просто: шифрование SNI — это всего лишь один из способов маскировки данных, и его не делает подключение полностью невидимым. Роскомнадзор быстро среагировал и заблокировал эту технологию. Подобные меры уже давно применяются в таких странах, как Иран и Китай, где доступ к интернету сильно ограничен.

habr.com/ru/articles/856340/

#tls #sni #ркн #роскомнадзор #cloudflare #cdn #блокировка_сайтов

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2024-08-02

#xcb #development thoughts:

One of the features I'd like to add to #Xmoji is a "system #tray icon". I know these aren't "en vogue" any more, but I like the concept a lot for an application you'll typically leave running and only use from time to time, which is likely a usage pattern for an "#emoji #keyboard".

So, I found a spec based on #XEMBED, X selections and client messages (therefore, pure X inter-client communication), I think I can implement that! 👍
specifications.freedesktop.org

Digging deeper, I found there's a successor called #SNI and the spec above is considered "legacy" (after only 20 years, hehe) 🤨. SNI is based on #dbus. Oh damn ... it's not that I particularly hate dbus, it probably makes a lot of sense for complex desktop environments, but I really want to keep #Xmoji "plain #X11". I'll just use the old spec. At least I found #KDE seems to have a compatibility service: xembed-sni-proxy. No idea about Gnome. But then, screw it.

2024-07-15

Web development term of the week:

→ Server Name Indication (SNI)

webglossary.info/terms/server-

#webdev #webdevglossary #sni

Su • 最后一代 🏴‍☠️su@0ne.day
2023-11-21

Desync - 维基教科书,自由的教学读本
zh.wikibooks.org/wiki/Desync

#SNI #GFW #desync

Su • 最后一代 🏴‍☠️su@0ne.day
2023-11-11

自从反诈以来,中国互联网上有越来越多的网友分享自己刚打开某个网站,正准备网上冲浪的时候,突然来了“您正在浏览境外小众网站,请谨慎浏览”或者是“xx网警提醒您,您访问的网站xxx存在用户举报”之类的短信,甚至有的是直接跳脸的闪信,还有的直接就是反诈民警直接电话呼过来,甚至还边响铃边带着这是反诈中心电话,请放心接听之类的闪信,给了不少网友一点小小的反诈震撼,被诈骗之余,网友们可能会好奇他们是怎么知道你在访问什么网站的?诸位网友稍安勿燥,接下来我们将揭开反诈的骗…啊不对,是DNS的面纱,并且帮助大家学习如何保护自己的隐私。

我的网站访问记录是怎么泄露的之用 MosDNS 防止 DNS 泄露并实现分流
blog.0ne.day/i/mosdns-dns-c-0K

#DNS #SNI #反诈 #MosDNS #分流 #GFW

:mima_rule: Mima-samamima@makai.chaotic.ninja
2023-10-15

You've got to be kidding me #Mozilla

Why does
#Firefox need #HTTP2 for #EncryptedClientHello? Where in the goddamn spec does it say that #ECH needs HTTP/2?! First #DNSoverHTTPS or #DoH is required, and now HTTP/2? Really?

Why can't you just let me disable HTTP/2 in peace and use HTTP/1.1 as all web servers should be using. Why does it have to be a choice on whether I can get additional
#privacy based on whether I'm using an arbitrary and useless update to the #HTTP protocol. It's just fucking full of politics. First you require TLS if one wants to use HTTP/2, and now HTTP/2 is required if one wants to encrypt their #SNI and the whole #ClientHello. No technical fucking reason at all other than to force people in their crusade against plain text and their obsession with chopping down latency (which didn't work btw which is why they're now pushing #HTTP3 which is just not HTTP anymore with its #UDP bullshit)

This is what happens when you let politician-wannabes dictate your development

2023-10-14

I even checked in dnscheck.tools and it told me I'm only using the upstream #Contabo recursive #DNS so I should've been fine

Is my university's network doing some
#SNI blocking shit right now?

But then the
#DoH should've failed if that's the case!

[moved] Floppy 💾floppy@fosstodon.org
2023-10-09

💬 "Encrypted Client Hello, a new proposed standard that prevents networks from snooping on which websites a user is visiting, is now available on all Cloudflare plans."

❓ How does the internet like this?

Links for further reading:

The CloudFlare blog: Encrypted Client Hello - the last puzzle piece to privacy
blog.cloudflare.com/announcing

gHacks: The End of DNS-based Site Blocking is near
ghacks.net/2023/10/07/the-end-

#Cloudflare #ECH #EncryptedClientHello #ServerNameIndication #SNI #ESNI #Security #TLS

Gonçalo Valériodethos@s.ovalerio.net
2023-10-03

"Say (an encrypted) hello to a more private internet."

blog.mozilla.org/en/products/f

"ECH uses a public key fetched over the Domain Name System (DNS) to encrypt the first message between a browser and a website, protecting the name of the visited website from prying eyes and dramatically improving user privacy."

#security #tls #sni #firefox

2023-09-11

стоит ли такую отдельную хрень на go использовать?
github.com #прокси #https #SNI #обратный

Jerry Lundström :catjam:jelu
2023-06-15

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst