Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SNI is sent in the clear once per tls connection, not once per http request.


While the OP had the wrong method, it still means ISP boxes end up tracking that TLS connection.


(Though this is being fixed-- both Firefox and Cloudflare implement the eSNI draft).




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: