@evilemily@misskey.sindastra.net
Post #3802150
2026-07-14 06:38 UTC
@sigmasternchen@comfy.social I suppose it is like that because of conflicting interests.
Modern firewalls often have L7 scanning using Suricata or Snort.
While they won’t scan encrypted content, they do rely on reading SNI.
In the field, this does make a big difference, actually!
Of course, this opens up new vulns, yes. So I think having a plaintext SNI IS the wrong solution to a valid problem.
Replies (0)
No replies.