Brave-browser: feature: support encrypted SNI

Created on 26 Oct 2018  路  26Comments  路  Source: brave/brave-browser

per slack discussion from a while ago, we should support encrypted SNI on all platforms: https://blog.mozilla.org/security/2018/10/18/encrypted-sni-comes-to-firefox-nightly/

Chromiuwaiting upstream prioritP3 privacy privacfeature security

Most helpful comment

@FireMasterK this would be fixed upstream in Chromium

It appears some good work has been done on the Chromium side since then. The issues tracking this work are:

You can login with a Google account and star those and you'll get email notifications on update

All 26 comments

https://www.cloudflare.com/ssl/encrypted-sni/ seems to emphasize having support for this alongside DNS over HTTPS (#1864)

Chromium 78 shipped this week with an optional flag to enable DNS over HTTPS, so I think it would be great to get encrypted SNI soon as well.

We are totally on board with adopting encrypted SNI as soon as we can.

According to https://bugs.chromium.org/p/chromium/issues/detail?id=908132, the state of ESNI in Chromium seems to be that Google is waiting for the IETF TLS working group to finish the draft https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ before they implement it. (The last update to the draft was yesterday, so it evidently hasn't settled yet.)

Since it is likely to involve some intimate surgery in the TLS stack in BoringSSL, we probably won't do this ourselves if Google is likely to do it soon anyway. Probably the best way to get things going is to let the IETF TLS WG finish the specification as soon as possible.

What is the status of privacy regarding ESNI?
Does the Brave Browser support encrypted SNI now?
For people living in countries filtering content by SNI this is crucial.

brave esni

What is the status of privacy regarding ESNI?
Does the Brave Browser support encrypted SNI now?
For people living in countries filtering content by SNI this is crucial.

brave esni

Use firefox for the time being....
image

Is there any progress on ESNI?

Yeah me too, also want to know. Is there any progress? Brave is great, but still using firefox because I can get full ESNI support.

Yeah, status update pllzzzz

Any update on this feature?

I would also like to know if there are any updates for this

So many people are waiting for this, hopefully brave will add it soon

Any updates on this?

+1

+1, it seems like the specification is taking forever - would be great to see support for this sooner rather than later.

+1

+1

this is the only feature that holds me off using Brave as my everyday browser

This is needed in Brave, hope this get to Brave soon.

Is this gonna be fixed by Brave or Chromium? This literally breaks censorship in many countries and at the same time, hides what you're doing from your ISP.

@FireMasterK this would be fixed upstream in Chromium

It appears some good work has been done on the Chromium side since then. The issues tracking this work are:

You can login with a Google account and star those and you'll get email notifications on update

ANy progress on how to enable this?

So this isn't coming to Linux until chromium gets it? says disabled on the platform (literally all other platforms supported by chromium are supported)

+1

+1

Was this page helpful?
0 / 5 - 0 ratings