echdeploy / draft-ech-deployment-considerations

IETF draft describing TLS ECH deployment considerations
Other
4 stars 1 forks source link

The I-D should include considerations why ECH is absolutely critical in some circumstances #39

Closed taddhar closed 1 year ago

taddhar commented 1 year ago

Re-reading the notes from the IETF 115 side meeting, Andrew Alston had a more specific issue:

"Andrew A – Should include considerations why ECH is absolutely critical in some circumstances?"

This reopens #12

taddhar commented 1 year ago

Further note from the IETF 115 side meeting discussion

"Andrew A, Paul V: For balance, need to consider what happens if we don’t deploy ECH. It is the only defence against some very litigious actors by saying to a court that we can’t block what we can’t see. There are very clear problems (deployment considerations) in not having something like ECH in some circumstances. The specific issue (for Andrew) being that ECH does not include the full URL but does identify that the source is from, eg, YouTube, potentially requiring him to block the YouTube site rather than the specific bit of problematic content covered by a court order. In that case he may be forced to block the whole site, which would be very problematic for the future of his business."

taddhar commented 1 year ago

We recognized there are benefits in ECH