Light

Episode #942 Quiz

Encrypting Client Hello
Date: 2023-10-03 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Exim’s SMTP service contains unauthenticated out-of-bounds write flaws enabling remote code execution on Internet-exposed servers, with patch delays worsening risk. Windows 11 now supports passkeys, custom app control, and stronger firewalling. ECH encrypts TLS ClientHello/SNI via DNS-published keys, using ClientHelloOuter/Inner fallback retries to hide hostnames and reduce metadata leakage.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key practical improvement ECH made over ESNI in the face of stale or incorrect DNS-distributed keys?
Question 2: What does the episode identify as the structure of the ECH handshake that allows the encrypted ClientHello to coexist with a visible fallback message?
Question 3: Why did the episode say the original ESNI approach was insufficient even aside from its dependence on DNS key distribution?
Question 4: Which deployment concern did the episode say might be affected by ECH because the hostname is no longer visible in cleartext?
Question 5: What did the episode say was the reason the ECH rollout was expected to be operationally messy on the Internet?
Cancel