Encrypted Client Hello, balancing privacy enhancements with security implications
2024 (English)Independent thesis Basic level (degree of Bachelor), 20 credits / 30 HE credits
Student thesis
Abstract [en]
With the addition of Transport Layer Security (TLS) 1.3 extension Encrypted Client Hello (ECH), new challenges are present for network- and system administrators in relation to web content moderation. Notable concerns have been issued for ECH circumventing content filtering efforts as ECH introduces new functionality to cover up previous metadata leaks. Core Information Technology (IT) security implementations used these metadata leaks to perform necessary evaluations of client network traffic. Encryption of metadata such as Server Name Indication (SNI), Application-Layer Protocol Negotiation (ALPN) and more, requires a new outlook for how to safely adapt to current day privacy improvements. Authors present current day issues observed with ECH, a general outlook on protocol improvement areas and how to adapt to new challenges ahead in organisational environments. IT-security solutions are presented for their intended ability of securing IT-infrastructure and evaluated if they can continue operational functionality in relation to ECH. Authors present a simple and open source solution for content filtering, and examining the solution in various environments. The solution is deemed to be primarily applicable for organisations as supporting implementations are required for the solution to be deemed as effective. The report addresses concerns issued by researchers on how to safely incorporate DNS over HTTPS (DoH) and ECH-enabled websites to foster the adoption process.
Place, publisher, year, edition, pages
2024. , p. 68
Keywords [en]
Encrypted Client Hello, ECH, encrypted server name indication, ESNI, TLS 1.3, privacy, privacy enhancements, security implementations, content blocking, TLS extensions, RPZ, response policy zone, DNS filtering
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-24188OAI: oai:DiVA.org:his-24188DiVA, id: diva2:1882070
Subject / course
Informationsteknologi
Educational program
Network and Systems Administration
Supervisors
Examiners
2024-07-042024-07-042024-07-04Bibliographically approved