ื”ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช ืžืชื›ื•ื•ื ืช ืœืืกื•ืจ ืคืจื•ื˜ื•ืงื•ืœื™ื ื”ืžืืคืฉืจื™ื ืœื”ืกืชื™ืจ ืืช ื”ืฉื ืฉืœ ืืชืจ ืื™ื ื˜ืจื ื˜

ื”ืชื—ื™ืœ ื“ื™ื•ืŸ ืฆื™ื‘ื•ืจื™ ื˜ื™ื•ื˜ืช ื—ื•ืง ืžืฉืคื˜ื™ ืขืœ ืชื™ืงื•ื ื™ื ืœื—ื•ืง ื”ืคื“ืจืœื™ "ืขืœ ืžื™ื“ืข, ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืžื™ื“ืข ื•ื”ื’ื ืช ืžื™ื“ืข", ืฉืคื•ืชื—ื” ืขืœ ื™ื“ื™ ื”ืžืฉืจื“ ืœืคื™ืชื•ื— ื“ื™ื’ื™ื˜ืœื™, ืชืงืฉื•ืจืช ื•ืชืงืฉื•ืจืช ื”ืžื•ื ื™ื. ื”ื—ื•ืง ืžืฆื™ืข ืœื”ื ื”ื™ื’ ืื™ืกื•ืจ ืขืœ ืฉื™ืžื•ืฉ ื‘ืฉื˜ื— ื”ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช ื‘"ืคืจื•ื˜ื•ืงื•ืœื™ ื”ืฆืคื ื” ื”ืžืืคืฉืจื™ื ืœื”ืกืชื™ืจ ืืช ื”ืฉื (ืžื–ื”ื”) ืฉืœ ื“ืฃ ืื™ื ื˜ืจื ื˜ ืื• ืืชืจ ื‘ืื™ื ื˜ืจื ื˜, ืœืžืขื˜ ืžืงืจื™ื ืฉื ืงื‘ืขื• ืขืœ ื™ื“ื™ ื—ืงื™ืงื” ืฉืœ ื”ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช".

ื‘ื’ื™ืŸ ื”ืคืจืช ื”ืื™ืกื•ืจ ืขืœ ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœื™ ื”ืฆืคื ื” ื”ืžืืคืฉืจื™ื ืœื”ืกืชื™ืจ ืืช ืฉื ื”ืืชืจ, ืžื•ืฆืข ืœื”ืฉืขื•ืช ืืช ืคืขื•ืœืช ื”ืžืฉืื‘ ื”ืื™ื ื˜ืจื ื˜ื™ ืœื ื™ืื•ื—ืจ ืžื™ื•ื ืขืกืงื™ื 1 (ืื—ื“) ืžืžื•ืขื“ ื’ื™ืœื•ื™ ื”ืคืจื” ื–ื• ืขืœ ื™ื“ื™ ื”ื’ื•ืฃ ื”ืคื“ืจืœื™ ื”ืžื•ืกืžืš. ื”ืžื˜ืจื” ื”ืขื™ืงืจื™ืช ืฉืœ ื”ื—ืกื™ืžื” ื”ื™ื ืกื™ื•ืžืช TLS ืื™ื›ืก (ืฉื ื•ื“ืข ื‘ืขื‘ืจ ื›-ESNI), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ืฉื™ืœื•ื‘ ืขื TLS 1.3 ื•ื›ื‘ืจ ื—ึธืกื•ึผื ื‘ืกื™ืŸ. ืžื›ื™ื•ื•ืŸ ืฉื”ื ื•ืกื— ื‘ื”ืฆืขืช ื”ื—ื•ืง ืžืขื•ืจืคืœ ื•ืื™ืŸ ืกืคืฆื™ืคื™ื•ืช, ืœืžืขื˜ ECH/ESNI, ื‘ืื•ืคืŸ ืคื•ืจืžืœื™, ื›ืžืขื˜ ื›ืœ ืคืจื•ื˜ื•ืงื•ืœ ื”ืžืกืคืง ื”ืฆืคื ื” ืžืœืื” ืฉืœ ืขืจื•ืฅ ื”ืชืงืฉื•ืจืช, ื•ื›ืŸ ืคืจื•ื˜ื•ืงื•ืœื™ื. DNS ื“ืจืš HTTPS (DoH) ื• DNS ืขืœ TLS (ื ึฐืงื•ึผื“ึธื”).

ื ื–ื›ื™ืจ ืฉื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ืขื‘ื•ื“ื” ืฉืœ ืžืกืคืจ ืืชืจื™ HTTPS ืขืœ ื›ืชื•ื‘ืช IP ืื—ืช, ืคื•ืชื—ื” ื‘ื‘ืช ืื—ืช ืกื™ื•ืžืช SNI, ื”ืžืฉื“ืจืช ืืช ืฉื ื”ืžืืจื— ื‘ื˜ืงืกื˜ ื‘ืจื•ืจ ื‘ื”ื•ื“ืขืช ClientHello ื”ืžื•ืขื‘ืจืช ืœืคื ื™ ื”ืชืงื ืช ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ. ืชื›ื•ื ื” ื–ื• ืžืืคืฉืจืช ื‘ืฆื“ ืฉืœ ืกืคืง ื”ืื™ื ื˜ืจื ื˜ ืœืกื ืŸ ื‘ืื•ืคืŸ ืกืœืงื˜ื™ื‘ื™ ืชืขื‘ื•ืจืช HTTPS ื•ืœื ืชื— ืื™ืœื• ืืชืจื™ื ื”ืžืฉืชืžืฉ ืคื•ืชื—, ืžื” ืฉืœื ืžืืคืฉืจ ื”ืฉื’ืช ืกื•ื“ื™ื•ืช ืžืœืื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-HTTPS.

ECH/ESNI ืžื‘ื˜ืœ ืœื—ืœื•ื˜ื™ืŸ ืืช ื“ืœื™ืคืช ื”ืžื™ื“ืข ืขืœ ื”ืืชืจ ื”ืžื‘ื•ืงืฉ ื‘ืขืช ื ื™ืชื•ื— ื—ื™ื‘ื•ืจื™ HTTPS. ื‘ืฉื™ืœื•ื‘ ืขื ื’ื™ืฉื” ื“ืจืš ืจืฉืช ืžืกื™ืจืช ืชื•ื›ืŸ, ื”ืฉื™ืžื•ืฉ ื‘-ECH/ESNI ืžืืคืฉืจ ื’ื ืœื”ืกืชื™ืจ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืฉืื‘ ื”ืžื‘ื•ืงืฉ ืžื”ืกืคืง - ืžืขืจื›ื•ืช ื‘ื“ื™ืงืช ืชืขื‘ื•ืจื” ืจื•ืื•ืช ืจืง ื‘ืงืฉื•ืช ืœ-CDN ื•ืื™ื ืŸ ื™ื›ื•ืœื•ืช ืœื”ื—ื™ืœ ื—ืกื™ืžื” ืžื‘ืœื™ ืœื–ื™ื™ืฃ ืืช ื”-TLS ื”ืคืขืœื”, ื•ื‘ืžืงืจื” ื–ื” ืชื•ืฆื’ ื”ื•ื“ืขื” ืžืชืื™ืžื” ื‘ื“ืคื“ืคืŸ ื”ืžืฉืชืžืฉ ืขืœ ื”ื—ืœืคืช ื”ืื™ืฉื•ืจ. ืื ื™ื•ื›ื ืก ืื™ืกื•ืจ ECH/ESNI, ื”ื“ืจืš ื”ื™ื—ื™ื“ื” ืœื”ื™ืœื—ื ื‘ืืคืฉืจื•ืช ื–ื• ื”ื™ื ืœื”ื’ื‘ื™ืœ ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ื’ื™ืฉื” ืœืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ (CDNs) ื”ืชื•ืžื›ื•ืช ื‘-ECH/ESNI, ืื—ืจืช ื”ืื™ืกื•ืจ ืœื ื™ื”ื™ื” ื™ืขื™ืœ ื•ื ื™ืชืŸ ื‘ืงืœื•ืช ืœืขืงื•ืฃ ืื•ืชื• ืขืœ ื™ื“ื™ CDNs.

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-ECH/ESNI, ืฉื ื”ืžืืจื—, ื›ืžื• ื‘-SNI, ืžื•ืขื‘ืจ ื‘ื”ื•ื“ืขืช ClientHello, ืืš ืชื•ื›ืŸ ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ื”ื•ื“ืขื” ื–ื• ืžื•ืฆืคืŸ. ื”ื”ืฆืคื ื” ืžืฉืชืžืฉืช ื‘ืกื•ื“ ื”ืžื—ื•ืฉื‘ ืžืžืคืชื—ื•ืช ื”ืฉืจืช ื•ื”ืœืงื•ื—. ื›ื“ื™ ืœืคืขื ื— ืขืจืš ืฉื“ื” ECH/ESNI ืฉื™ื™ืจื˜ ืื• ื”ืชืงื‘ืœ, ืขืœื™ืš ืœื“ืขืช ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™ ืฉืœ ื”ืœืงื•ื— ืื• ื”ืฉืจืช (ื‘ืชื•ืกืคืช ื”ืžืคืชื—ื•ืช ื”ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ ื”ืฉืจืช ืื• ื”ืœืงื•ื—). ืžื™ื“ืข ืขืœ ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ืžื•ืขื‘ืจ ืขื‘ื•ืจ ืžืคืชื— ื”ืฉืจืช ื‘-DNS, ื•ืขื‘ื•ืจ ืžืคืชื— ื”ืœืงื•ื— ื‘ื”ื•ื“ืขืช ClientHello. ืคืขื ื•ื— ืืคืฉืจื™ ื’ื ื‘ืืžืฆืขื•ืช ืกื•ื“ ืžืฉื•ืชืฃ ืฉื”ื•ืกื›ื ืขืœื™ื• ื‘ืžื”ืœืš ื”ื’ื“ืจืช ื—ื™ื‘ื•ืจ TLS, ื”ื™ื“ื•ืข ืจืง ืœืœืงื•ื— ื•ืœืฉืจืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”