Buy commercial curl support. We
help you work out your issues, debug your libcurl applications, use the API,
port to new platforms, add new features and more. With a team lead by the
curl founder Daniel himself.
Re: HTTPS-RR and ECH
- Contemporary messages sorted: [ by date ] [ by thread ] [ by subject ] [ by author ] [ by messages with attachments ]
From: Daniel Stenberg via curl-library <curl-library_at_lists.haxx.se>
Date: Thu, 30 Jul 2026 13:11:33 +0200 (CEST)
On Thu, 30 Jul 2026, Michael wrote:
>> We want ECH enabled to push online privacy forward.
> Their proposal assumes that relocating network visibility translates to
> eliminating it. In reality, Encrypted Client Hello (ECH) merely shifts
> domain-name exposure from a local internet service provider to a centralized
> CDN edge—such as Cloudflare.
It's more than a proposal. ECH is defined in RFC 9849. It's live and in use.
It hides the SNI from passive network snoopers. I think that's a good step
forward.
> i do not agree with c-ares project, so will see imploding it only as a net
> negative event.
I don't know what that means, but to me that is irrelevant here. c-ares is the
only way curl can resolve HTTPS records until someone adds support for another
DNS library, but then I would also love to learn why that other library is
better for this purpose.
It is up to everyone who builds curl to decide wether to use c-ares or not.
Date: Thu, 30 Jul 2026 13:11:33 +0200 (CEST)
On Thu, 30 Jul 2026, Michael wrote:
>> We want ECH enabled to push online privacy forward.
> Their proposal assumes that relocating network visibility translates to
> eliminating it. In reality, Encrypted Client Hello (ECH) merely shifts
> domain-name exposure from a local internet service provider to a centralized
> CDN edge—such as Cloudflare.
It's more than a proposal. ECH is defined in RFC 9849. It's live and in use.
It hides the SNI from passive network snoopers. I think that's a good step
forward.
> i do not agree with c-ares project, so will see imploding it only as a net
> negative event.
I don't know what that means, but to me that is irrelevant here. c-ares is the
only way curl can resolve HTTPS records until someone adds support for another
DNS library, but then I would also love to learn why that other library is
better for this purpose.
It is up to everyone who builds curl to decide wether to use c-ares or not.
-- / daniel.haxx.se || https://rock-solid.curl.dev
-- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-library Etiquette: https://curl.se/mail/etiquette.htmlReceived on 2026-07-30