Repository navigation
DoH and ECH support #944
Description
Activity
Is there a use case for this? Currently the library doesn't plan to support this, but it does support sending TLS extensions.
Is there a use case for this? Currently the library doesn't plan to support this, but it does support sending TLS extensions.
Making DNS secure, forging SNI, bypassing traffic analysis and internet censorship.
As a library that mimics browser using boringssl, wreq is perfect for proxy, tunneling and security tools. Supporting DoH and ECH can further improve privacy and security.
Plus, some websites use DNS to find real IP behind proxies, DoH make these impossible because the IPs would be DoH service providers'.
This reason is reasonable.
cc @PACHAKUTlQ, here’s a cool example of using DoH and ECH to encrypt SNI. It’d be a solid reference if anyone’s interested in picking this up and finishing the task. It’s built on rustls, but the underlying logic is pretty much the same: https://docs.rs/crate/echw/0.1.0
May DNS-over-HTTPS and Encrypted-Client-Hello be supported?
I know you can manually perform DoH lookup and use the resolved IP for connection, but that is complex.
Also, chrome and modern browsers by default enables ECH when DoH is configured. (Currently I think there is no workaround in wreq to use ECH.) If DoH will not be supported, manually configuring ECH key is also enough.