Closed Bug 1689249 Opened 4 years ago Closed 4 years ago

Esni does not apply in firefox.

Categories

(Core :: Networking, defect)

Firefox 85
defect

Tracking

()

RESOLVED DUPLICATE of bug 1667801

People

(Reporter: qjrzbasd, Unassigned, NeedInfo)

Details

Attachments

(2 files, 4 obsolete files)

Attached image 캡처.PNG (obsolete) (deleted) —

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0

Steps to reproduce:

network.trr.mode = 3
network.security.esni.enabled = true
network.trr.uri = https://dns.adguard.com/dns-query
network.trr.bootstrapAddress = 94.140.14.14

That bug occurred after the update. And after de-setting and resetting, I repeated the restart several times.

Actual results:

Cloudflare: Your browser did not encrypt the SNI when visiting this page.

And you can't bypass sni censorship in Korea.

Expected results:

Cloudflare: Your browser encrypt the SNI when visiting this page.

And you can bypass sni censorship in Korea.

Attached image 캡처2.PNG (obsolete) (deleted) —
Attached image 캡처3.PNG (obsolete) (deleted) —
Attached image 캡처4.PNG (obsolete) (deleted) —
Attached image sni censorship error(korean).PNG (deleted) —
Attached image setting.PNG (deleted) —
Attachment #9199693 - Attachment is obsolete: true
Attachment #9199694 - Attachment is obsolete: true
Attachment #9199695 - Attachment is obsolete: true
Attachment #9199696 - Attachment is obsolete: true

Bugbug thinks this bug should belong to this component, but please revert this change in case of error.

Component: Untriaged → Networking
Product: Firefox → Core
Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE

I want bypass SNI censorship. why I can't bypass this?

ESNI is superseded by ECH. We can do nothing about that until the server is updated to support ECH.

(In reply to Masatoshi Kimura [:emk] from comment #9)

ESNI is superseded by ECH. We can do nothing about that until the server is updated to support ECH.

ok, I got it. In summary, can I understand that ESNI cannot work until the server(such as using Cloudflare service server) supports ECH?

(In reply to Masatoshi Kimura [:emk] from comment #9)

ESNI is superseded by ECH. We can do nothing about that until the server is updated to support ECH.

Is there any reasonable explanation why Mozilla removed ESNI before the arrival of working alternative? You cannot just refer to bad Cloudflare and others that are yet to support ECH. ESNI was working and the service is still provided by Cloudflare. Many people relied on it to improve their privacy.

Why Mozilla endangered privacy of those users without even a heads-up?

Flags: needinfo?(sdeckelmann)
Flags: needinfo?(joe-bugzilla)
Flags: needinfo?(ekr)
Flags: needinfo?(joe-bugzilla)
Flags: needinfo?(sdeckelmann)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: