Theoretically every web application you visit can be snooped by your ISP OR WORST if it uses TLS1.2 ... 🤗
1) TLS 1.3 with encrypted SNI to your rescue
3) custom DNS (cloudflare 126.96.36.199)
“The client adds the SNI extension containing the hostname of the site it’s connecting to to the ClientHello message. It sends the ClientHello to the server during the TLS handshake. Unfortunately the ClientHello message is sent unencrypted, due to the fact that client and server don’t share an encryption key at that point.
TLS 1.3 with Unencrypted SNI
This means that an on-path observer (say, an ISP, coffee shop owner, or a firewall) can intercept the plaintext ClientHello message, and determine which website the client is trying to connect to. That allows the observer to track which sites a user is visiting.” #Security #cyberdefense #cyberawareness #attacks #webapplicationsecurity #firewall #networksecurity #network #DNS #dnssecurity