Say (an encrypted) hello to a more private internet. - eviltoast
  • Domi@lemmy.secnd.me
    link
    fedilink
    arrow-up
    8
    ·
    1 year ago

    Is there anything else that might indicate the domain name in the handshake connection?

    The SNI (Server Name Indication) happens before any HTTP communication and is done in plain text. It is needed because a single web server might host multiple websites, since each of them has their own certificate it needs to know which one to serve you.

    With the new proposal that SNI is now encrypted. It makes the difference between anyone listening in being able to tell “you visited lemmy.world” and “you visited something behind Cloudflare”.