Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is somewhat the case as SNI is unencrypted.


Could you expand on that please? SNI is not the full URL or am I missing something?


But there's eSNI.


Which is a very new technology, and not widely deployed yet.


I get about 5k unique visitors from my websites, additional 20k visitors from a community project I'm in. We see about 30 - 40% eSNI Adoption.


And that is just client support. For eSNI to work, both client and server must support it.


Adoption, not support, meaning the clients and server both support it.

I bet most of the non-supporting clients are simply either a bit outdated or had it disabled (probably by the client local AV engine).


Unlikely. Since OpenSSL has no support for it (by extension this includes Apache and Nginx) because it's not a standard yet, adoption is very low. Also Chromium and by extension Chrome has no support for it.

Firefox does support a draft, but since Firefox usage numbers are somewhat low depending on what statistic you believe, this amounts to not much.


Well, again, we see about 20-40% eSNI activity based on our connection data, of about 60k monthly users.


Not plausible unless you have a very specific userbase, ie Firefox users mostly.


A draft. OpenSSL devs wait for it to be finished.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: