(no title)
retrodaredevil | 8 months ago
With that in place, I wonder if that could ever be abused by these pirate sites. Imagine temporarily pointing your pirate site domain name at a valid IP address. When you do that, in theory ISPs (and now VPNs) would automatically block perfectly valid IPs.
This would only happen if the owners of the pirate site domains actually try to do something malicious like that, but I know there are instances in the past of ISPs blocking cloudflare IPs (which is a separate issue, but the scenario I just made up reminds me of it).
numpad0|8 months ago
Now, HTTP headers and SNI are both unencrypted, so oppressive governments abuse these. Obvious fix is to make'em encrypted by enforcing HTTPS everywhere and upgrading SNI to ESNI with DoH-obtained per-server public keys.
Some of offensive side fixes to the defensive side fix are: blocking ESNI, blocking DoH, forcing use of MITM proxy, just blaming strawman terrorist groups for having to block affected IPs. etc.
sidewndr46|8 months ago
AnthonyMouse|8 months ago