Skip to content

Commit

Permalink
Update draft-ietf-tls-esni.md
Browse files Browse the repository at this point in the history
Co-authored-by: Martin Thomson <[email protected]>
  • Loading branch information
ekr and martinthomson authored Nov 24, 2024
1 parent 0eff03e commit c796c1a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion draft-ietf-tls-esni.md
Original file line number Diff line number Diff line change
Expand Up @@ -1415,7 +1415,7 @@ less useful without encryption of DNS queries in transit mechanisms.
A malicious client-facing server could distribute unique, per-client ECHConfig
structures as a way of tracking clients across subsequent connections. On-path
adversaries which know about these unique keys could also track clients in this
way by observing TLS connection attempts.
way by observing TLS connection attempts.

The cost of this type of attack scales linearly with the desired number of
target clients. Moreover, DNS caching behavior makes targeting individual users
Expand Down

0 comments on commit c796c1a

Please sign in to comment.