Skip to content

Pre-release TODO list #4

@aaronkaplan

Description

@aaronkaplan

TODOS for us

  • clients section -> @sebix
  • incentives --> @sebix
  • censorship & blocking --> @aaronkaplan , fallback @sebix
  • DNS and weaknesses/* -> @aaronkaplan
  • de-anonymization (attacks) --> @sebix
    • legal: klar
    • metadata: im DNS die queries
    • correlations: auf andere verweisen

feedback stephen

  • change title
  • add context: the protocols are what they are, the browser vendors want speed, etc... that's why we ended up where we are...
  • too many "mights"....
  • if you publish the priv. key then ... your own problem. Rather say "this is a known risk"
  • look at rfc 8744 considered the requiremetns for TLS and possible solutions
  • the browser implementers want faster times...
  • DNSSEC -> don't insist on it.
  • ECH does not cause correlation , but rather centralization lends to ...
  • Split mode does not match any biz model. But centralization already is a biz model :)
  • GREASE is missing!!!
  • NIS --> leave it out.
  • 7.2. ... but this is an incremental deployment, don't assume it all goes at once. But what about correlation then?
  • 7.3.1: not sure clock sync is a real threat there --> don't keep priv. keys around for very long
  • 7.3.1: I think wkech is probably correct to depend on HTTPS working --> fix it.
  • in the summary - highlight new things. Or mention that all issues were known, but we collect them.
  • convert to LaTeX from markdown (see the interop report: https://defo.ie/ech-interop-report.pdf)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions