ืกื™ืŸ ื”ื—ืœื” ืœื—ืกื•ื ื—ื™ื‘ื•ืจื™ HTTPS ืฉื ื•ืฆืจื• ืขื TLS 1.3 ื•-ESNI

ืกื™ืŸ ืžื•ื˜ืžืข ื ืขื™ืœื” ื›ืœ ื—ื™ื‘ื•ืจื™ HTTPS ื”ืžืฉืชืžืฉื™ื ื‘ืคืจื•ื˜ื•ืงื•ืœ TLS 1.3 ื•ื‘ืกื™ื•ืžืช ESNI (Encrypted Server Name Indication) TLS, ื”ืžืกืคืงืช ื”ืฆืคื ื” ืฉืœ ื ืชื•ื ื™ื ืขืœ ื”ืžืืจื— ื”ืžื‘ื•ืงืฉ. ื”ื—ืกื™ืžื” ืžืชื‘ืฆืขืช ืขืœ ื ืชื‘ื™ ืžืขื‘ืจ ื”ืŸ ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ืฉื ื•ืฆืจื• ืžืกื™ืŸ ืœืขื•ืœื ื”ื—ื™ืฆื•ืŸ, ื•ื”ืŸ ืžื”ืขื•ืœื ื”ื—ื™ืฆื•ืŸ ืœืกื™ืŸ.

ื”ื—ืกื™ืžื” ื ืขืฉื™ืช ืขืœ ื™ื“ื™ ื”ืคืœืช ืžื ื•ืช ืžื”ืœืงื•ื— ืœืฉืจืช, ื‘ืžืงื•ื ื”ื—ืœืคืช ืžื ื•ืช RST ืฉื‘ื•ืฆืขื” ื‘ืขื‘ืจ ืขืœ ื™ื“ื™ ื—ืกื™ืžื” ืกืœืงื˜ื™ื‘ื™ืช ืฉืœ ืชื•ื›ืŸ SNI. ืœืื—ืจ ื”ืคืขืœืช ื—ืกื™ืžืช ืžื ื” ืขื ESNI, ื›ืœ ืžื ื•ืช ื”ืจืฉืช ื”ืžืชืื™ืžื•ืช ืœืฉื™ืœื•ื‘ ืฉืœ IP ืžืงื•ืจ, IP ื™ืขื“ ื•ืžืกืคืจ ื™ืฆื™ืืช ื™ืขื“ ื ื—ืกืžื•ืช ื’ื ื”ืŸ ืœืžืฉืš 120 ืขื“ 180 ืฉื ื™ื•ืช. ื—ื™ื‘ื•ืจื™ HTTPS ื”ืžื‘ื•ืกืกื™ื ืขืœ ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ TLS ื•-TLS 1.3 ืœืœื ESNI ืžื•ืชืจื™ื ื›ืจื’ื™ืœ.

ื ื–ื›ื™ืจ ื›ื™ ืขืœ ืžื ืช ืœืืจื’ืŸ ืขื‘ื•ื“ื” ืขืœ ื›ืชื•ื‘ืช IP ืื—ืช ืฉืœ ืžืกืคืจ ืืชืจื™ HTTPS, ืคื•ืชื—ื” ืชื•ืกืฃ SNI, ืืฉืจ ืžืฉื“ืจ ืืช ืฉื ื”ืžืืจื— ื‘ื˜ืงืกื˜ ื‘ืจื•ืจ ื‘ื”ื•ื“ืขืช ClientHello ื”ืžื•ืขื‘ืจืช ืœืคื ื™ ื”ืชืงื ืช ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ. ืชื›ื•ื ื” ื–ื• ืžืืคืฉืจืช ื‘ืฆื“ ืฉืœ ืกืคืง ื”ืื™ื ื˜ืจื ื˜ ืœืกื ืŸ ื‘ืื•ืคืŸ ืกืœืงื˜ื™ื‘ื™ ืชืขื‘ื•ืจืช HTTPS ื•ืœื ืชื— ืื™ืœื• ืืชืจื™ื ื”ืžืฉืชืžืฉ ืคื•ืชื—, ืžื” ืฉืœื ืžืืคืฉืจ ื”ืฉื’ืช ืกื•ื“ื™ื•ืช ืžืœืื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-HTTPS.

ืชื•ืกืฃ TLS ื”ื—ื“ืฉ ECH (ืœืฉืขื‘ืจ ESNI), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ืฉื™ืœื•ื‘ ืขื TLS 1.3, ืžื‘ื˜ืœ ืืช ื”ื—ืกืจื•ืŸ ื”ื–ื” ื•ืžื‘ื˜ืœ ืœื—ืœื•ื˜ื™ืŸ ืืช ื–ืœื™ื’ืช ื”ืžื™ื“ืข ืขืœ ื”ืืชืจ ื”ืžื‘ื•ืงืฉ ื‘ืขืช ื ื™ืชื•ื— ื—ื™ื‘ื•ืจื™ HTTPS. ื‘ืฉื™ืœื•ื‘ ืขื ื’ื™ืฉื” ื“ืจืš ืจืฉืช ืžืกื™ืจืช ืชื•ื›ืŸ, ื”ืฉื™ืžื•ืฉ ื‘-ECH/ESNI ืžืืคืฉืจ ื’ื ืœื”ืกืชื™ืจ ืžื”ืกืคืง ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืฉืื‘ ื”ืžื‘ื•ืงืฉ. ืžืขืจื›ื•ืช ื‘ื“ื™ืงืช ืชื ื•ืขื” ื™ืจืื• ืจืง ื‘ืงืฉื•ืช ืœ-CDN ื•ืœื ื™ื•ื›ืœื• ืœื”ื—ื™ืœ ื—ืกื™ืžื” ืœืœื ื–ื™ื•ืฃ ื”ืคืขืœื” ืฉืœ TLS, ื•ื‘ืžืงืจื” ื–ื” ื”ื•ื“ืขื” ืžืชืื™ืžื” ืขืœ ื–ื™ื•ืฃ ืื™ืฉื•ืจื™ื ืชื•ืฆื’ ื‘ื“ืคื“ืคืŸ ืฉืœ ื”ืžืฉืชืžืฉ. DNS ื ืฉืืจ ืขืจื•ืฅ ื“ืœื™ืคื” ืืคืฉืจื™, ืืš ื”ืœืงื•ื— ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘-DNS-over-HTTPS ืื• DNS-over-TLS ื›ื“ื™ ืœื”ืกืชื™ืจ ืืช ื’ื™ืฉืช ื”-DNS ืฉืœ ื”ืœืงื•ื—.

ื—ื•ืงืจื™ื ื›ื‘ืจ ืขืฉื• ื–ืืช ื’ื™ืœื” ื™ืฉื ืŸ ืžืกืคืจ ื“ืจื›ื™ื ืœืขืงื™ืคืช ื”ื‘ืขื™ื” ืœืขืงื•ืฃ ืืช ื”ื—ืกื™ืžื” ื”ืกื™ื ื™ืช ื‘ืฆื“ ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ื”ืŸ ืขืฉื•ื™ื•ืช ืœื”ืคื•ืš ืœืœื ืจืœื•ื•ื ื˜ื™ื•ืช ื•ื™ืฉ ืœื”ืชื™ื™ื—ืก ืืœื™ื”ืŸ ื›ืืžืฆืขื™ ื–ืžื ื™ ื‘ืœื‘ื“. ืœื“ื•ื’ืžื”, ื›ืจื’ืข ืจืง ืžื ื•ืช ืขื ืžื–ื”ื” ืกื™ื•ืžืช ESNI 0xffce (ืฉื_ืฉืจืช_ืžื•ืฆืคืŸ), ืืฉืจ ื”ื™ื” ื‘ืฉื™ืžื•ืฉ ื‘- ื”ื’ืจืกื” ื”ื—ืžื™ืฉื™ืช ืฉืœ ื˜ื™ื•ื˜ืช ื”ืชืงืŸ, ืืš ืœืขืช ืขืชื” ืžื ื•ืช ืขื ื”ืžื–ื”ื” ื”ื ื•ื›ื—ื™ 0xff02 (encrypted_client_hello), ืฉื”ื•ืฆืขื• ื‘ ื˜ื™ื•ื˜ื” ืฉื‘ื™ืขื™ืช ืฉืœ ืžืคืจื˜ ECH.

ื“ืจืš ื ื•ืกืคืช ืœืขืงื™ืคืช ื”ื‘ืขื™ื” ื”ื™ื ืœื”ืฉืชืžืฉ ื‘ืชื”ืœื™ืš ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ ืœื ืกื˜ื ื“ืจื˜ื™, ืœืžืฉืœ, ื—ืกื™ืžื” ืœื ืขื•ื‘ื“ืช ืื ื ืฉืœื—ืช ืžืจืืฉ ื—ื‘ื™ืœืช SYN ื ื•ืกืคืช ืขื ืžืกืคืจ ืจืฆืฃ ืฉื’ื•ื™, ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื“ื’ืœื™ ืคื™ืฆื•ืœ ืžื ื•ืช, ืฉืœื™ื—ืช ื—ื‘ื™ืœื” ืขื ื”-FIN ื•ื’ื ืขื SYN ื”ื’ื“ืจืช ื“ื’ืœื™ื, ื”ื—ืœืคื” ืฉืœ ื—ื‘ื™ืœืช RST ืขื ื›ืžื•ืช ื‘ืงืจื” ืฉื’ื•ื™ื” ืื• ืฉืœื™ื—ื” ืœืคื ื™ ืชื—ื™ืœืช ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ ืžื ื•ืช ืขื ื“ื’ืœื™ SYN ื•-ACK. ื”ืฉื™ื˜ื•ืช ื”ืžืชื•ืืจื•ืช ื›ื‘ืจ ื™ื•ืฉืžื• ื‘ืฆื•ืจื” ืฉืœ ืชื•ืกืฃ ืขื‘ื•ืจ ืขืจื›ืช ื”ื›ืœื™ื ื–'ื ื‘ื”, ืžืคื•ืชื— ืœืขืงื•ืฃ ืฉื™ื˜ื•ืช ืฆื ื–ื•ืจื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”