GuillaumeRossolini

joined 2 years ago
[–] GuillaumeRossolini@infosec.exchange 4 points 11 months ago* (last edited 11 months ago) (1 children)

@rikudou @voxel
ASFAIR it used to be even worse than that, because if you didn’t want SNI (for compatibility reasons or whatever), but you still wanted a certificate, you had to have one server for every hostname (because each had its own IP), assuming you could afford the additional IP space

Granted you didn’t need a physical server, but that was still a bigger cost

Some servers are more flexible on that front, but early SNI didn’t have those

[–] GuillaumeRossolini@infosec.exchange 1 points 11 months ago (1 children)

@rikudou @voxel
Wasn’t SNI happening after the handshake? Or is this completely what ECH is about.

RIP Windows XP