Post B8nSnQBM6ntL2rOYYi by privateger@plasmatrap.com
 (DIR) More posts by privateger@plasmatrap.com
 (DIR) Post #B8nSnPxWwCpgLyvW0e by zaki@plasmatrap.com
       0 likes, 0 repeats
       
       i mean, there shouldn't really be much stopping one from having their outer/unencrypted sni set to something like ip.isp.tld now, no?
       
 (DIR) Post #B8nSnQBM6ntL2rOYYi by privateger@plasmatrap.com
       0 likes, 0 repeats
       
       @zaki basically nothing, nothe client does not get to pick the outer SNI typically though. It gets an ECHConfig, where public_name tells it what outer SNI to usethe requirements are:- ip.isp.tld must a valid DNS-style hostname- the ECH frontend must be authoritative for it- the frontend should have a valid TLS certificate for ip.isp.tld, because rejection makes it fall back to that to update the ECH configCloudflare, for example, uses cloudflare-ech.com for every outer SNI, across all ECH capable sites