Cloudflare pays to FOSS projects to push ECH, it tracks users into cohorts and shares data with other big corpos.go chrome://flags/search ECH, disable
>ECH encrypts part of the handshake and masks the Server Name Indication (SNI) that is used to negotiate a TLS session.>This means that whenever a user visits a website on Cloudflare that has ECH enabled, intermediaries will be able to see that you are visiting a website on Cloudflare, but they will not be able to determine which one.So it encrypts the header or whatever that reveals over the wire which cloudflare website you are visiting?I can see that Cloudflare created this feature, but what exactly makes you believe Cloudflare is tracking you less if you turn this off?Do you think visiting cloudflare websites with or without this flag enabled makes any difference at all?
>>109423981>Cloudflare is tracking you less if you turn this offaa-absolutely, without ECH youre behind networks mesh, otherwise every client request is tracked.
>>109424060>meaningless words
>>109423937anon, most sites use cloudflare today. that's enough for them to track you.>>109423981OP is a tech illiterate retard. or maybe a perverse shill that is trying to get anons to disable a feature that actually makes their connections more private against other companies (not cloudflare, though).
>>109424151ama freeman, everybody knows that, but youre simply shills, cloudflare kuks or retards.i have no $$$ interest here, beside public, commonwealth interest. you think wat, good daddy from the cloud cares about yer privacy? hehehe.. its them who should prove pure and tech intension, not me. so start proving cloud-kuks, start proving. or you wat? want trust for free? are you same as free-tards?
>>109423937Without ECH, the TLS SNI header exposes the hostname/vhost you are visiting, so any router between you and the website can read the metadata of the site you're trying to visit.ECH encrypts the host header so that only the destination host can read your header (usually the CDN). If the host you are visiting cloud flare there is really nothing you can do. Just don't go to websites using cloudflare for anything sensitive. There is no such thing as private browsing on the internet anyway.HTTPS is not anonymous, host metadata is visible to the ISP/VPN or proxy you are going through.I'm not sure what OP's motive is, but you should do the opposite of what OP says, as OP may be a bad actor.
>>109424556>There is no such thing as private browsing on the internet anyway.then what is the purpose of ECH bloat for an end-user? something doesnt fit.>Without ECH, the TLS SNI header exposes the hostname/vhost you are visitingwith ECH the hostname client sends packets to is not exposed?>I'm not sure what OP's motive isexpose cloudflare spying, prevent the bloat of software
>>109424611>then what is the purpose of ECH bloat for an end-user? something doesnt fit.The purpose is to hide the host-header, which is the only part of TLS traffic that remains unencrypted. Upon implementing ECH, all HTTPS traffic is end-to-end encrypted.>with ECH the hostname client sends packets to is not exposed?With ECH, the user can rest assured that the metadata of their HTTPS traffic remains encrypted end-to-end. Neither the ISP or VPN service can harvest metadata of the user's browsing behavior through deep-packet-inspection. The first end is the browser, and the second end is the website hosting the content.Now, the DNS lookup is on the user. If the user does not use DNS-over-HTTPS, then their DNS metadata is leaking and the ISP/VPN/etc can read the metadata of their traffic.In addition, deep-packet-inspection firewalls will no longer be able to block traffic based on the SNI header, so this makes it more difficult for corporate networks or authoritarian regimes to filter traffic by SNI hostname.>Expose cloudflare spying, prevent the bloat of softwareNow if the user is visiting garbage websites that do not respect the users freedom, that is on them. Cloudflare HTTPS fronting is a giant MITM service, since Cloudflare's servers act as the HTTPS proxy fronting the backend HTTP host. If companies use it for handling confidential information, not only are knowingly exposing user information to a 3rd party (cloudflare), but they are sending, in clear text, all HTTP traffic between themselves and cloudflare if they've configured a HTTP and not HTTPS backend.That being said, if you host on cloudflare for anything confidental, you do not respect your users, or worse, you risk exposing your users secrets.
The biggest reason why this is all being implemented is to make HTTPS "censorship resistant". All these protocols and technologies are used as a Trojan horse against authoritarian regimes who censor the internet.Corporations already run malware on employee computers so corporate authoritarianism is "okay" because the employee consented to getting data-raped by billionaires by signing their employment contract.
>>109424775>Now, the DNS lookup is on the user. If the user does not use DNS-over-HTTPS, then their DNS metadata is leaking and the ISP/VPN/etc can read the metadata of their traffic.BUT with DoH now CloudFlare or Google are getting your metadata instead. Checkmate.
>whines about Cloudflare>uses Chrom*You are part of the problem.
>>109424775>The purpose is to hide the host-header, which is the only part of TLS traffic that remains unencrypted. Upon implementing ECH, all HTTPS traffic is end-to-end encrypted.so you changed the purpose from hiding hostname to hiding intial header.>Neither the ISP or VPN servicewhats so important in that initial "helo", that you want to hide it from local ISP, but rather expose it to the central entity (cloudflare)? how is a BIG brother better than SMALL brother? does he have a BIGger tracking capability?>VPNwith VPN user chooses whom to trust, with ECH user dont even know that cloudflare collects his/her metadata (with or without VPN enabled).>this makes it more difficult for corporate networksECH is pushed by a corporate network, what are you babbling about>if the user is visiting garbage websitesthats what is liberty/freedom is about. who decides that user needs a cloud-daddy and "security"? daddy decides? who is authoritarian here?>>109426576> ECH is enabled in Firefox by default since version 119.which browser you mean/want, retard?>>109424814>The biggest reason why this is all being implemented is to make HTTPS "censorship resistant".that is magical and overly political thinking. a cloud daddy who wants to bring freedoms to authoritarian state? might belive in santa-clous as well
t. OP
>>109427780