tlswg / draft-ietf-tls-esni

TLS Encrypted Client Hello
https://tlswg.github.io/draft-ietf-tls-esni/#go.draft-ietf-tls-esni.html
Other
229 stars 56 forks source link

Use Session ID in Client Hello to transfer enctypred SNI #541

Closed 0x391F closed 1 year ago

0x391F commented 1 year ago

Is it possible to use Session ID in Client Hello to transfer enctypred SNI? If it looks random enough, attacker could't distinguish Session ID is encrypted SNI or not.

By the way, how to join the mailing list?

0x391F commented 1 year ago

It may have some restrictions, for example, the SNI maybe couldn't longer than Session ID (32 bytes).

chris-wood commented 1 year ago

Hi @0x391F -- you may join the mailing list here. I recommend you propose your idea there for further discussion.