| ▲ | hypeatei 3 hours ago | |
In the wild, that's not true at all[0][1]. The corporate firewall at my employer actually wasn't able to block ECH until they updated it then it was able to block sites as usual. 0: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Ho... 1: https://docs.broadcom.com/doc/symantec-ech-whitepaper (see page 8) | ||
| ▲ | dilyevsky 2 hours ago | parent | next [-] | |
I ready the FortiGate link and this is the gist:
So basically they mess with DoH ECH config and trigger fallback behavior in the clients. I don't think any browsers do this yet but I think this loophole is not gonna last. | ||
| ▲ | dilyevsky 2 hours ago | parent | prev [-] | |
This is literally impossible. What your corp fw likely does is mitm outer SNI because your IT department installed your company CA in every client's trust store. So unless you do that at national level your only other option is to block ECH entirely. Edit: actually totally possible but you need build quantum computer with sufficient cubits first =) | ||