从ESNI到ECH - 加密的Client Hello - 火狐ESNI未来之路 重要的是,ECH 还添加了重试机制,以提高服务器密钥轮换和 DNS 缓存的可靠性。 在从 DNS 接收到陈旧密钥后 ESNI 当前可能会失败的情况下,ECH 可以安全地恢复,因为客户端直接从服务器接收更新的密钥。 ECH in Firefox 85
什么是SNI、ESNI、ECH? ESNI and ECH: A long overdue overhaul ESNI 和 ECH:姗姗来迟的大修 TLS 1 3 sends the server certificate later on in the conversation, no longer exposing the endpoint a user is visiting in the plaintext portion of its response This signaled that it was time to reevaluate SNI, and Encrypted SNI (ESNI) was born
ESNI:未走的路 ECH had been proposed by the very same researchers behind the ESNI draft as a natural evolution of the ESNI standard 简而言之,顾名思义,ECH 尝试在 TLS 1 3 Handshake 中加密整个 Client Hello,而不仅仅是 SNI。 它保护 TLS 参数并防止握手元数据(如 ALPN 扩展和密钥共享)落入坏人之手的可能性。