Encrypted client hello (Solved)

gillsman

Active Member
Joined
Jan 29, 2019
Messages
151
Reaction score
61
Credits
1,192
Hi all,
This is a brave browser related question & maybe not on the right forum but having had no luck elsewhere I will try my luck here.
When using any other chromium based browser on Linux mint (Mate) 21.2 I have been able to go to chrome://flags find encrypted client hello and enable it, then when I go to https://www.cloudflare.com/en-gb/ssl/encrypted-sni/#sni those browsers will pass all four tests but in Brave browser (also Chromium based) there is no such entry in flags and hence it only passes three tests, failing the last SNI test. Now I will admit I don't really understand ECH or SNI except to say I assume it's making my browser more secure. It seems odd that Brave rated highly for privacy is the only one that doesn't allow this unless it's there's a different way to achieve it but I can't see anything in settings.

Maybe someone might tell me it's not necessary or it's achieved in a different way I don't know but I have searched the internet for answers and can't find anything specifically related to Brave.
Can anyone throw some light on this or maybe some thoughts on ECH in general (do I need it etc)

Thank you
 


Welcome to TLS 1.3 https://datatracker.ietf.org/doc/html/rfc8446 I don't know anything about brave but if you could force it to use TLS 1.3 only (I'm assuming) I think the caveat to that is if you attempt to communicate with a site using an earlier version of TLS such as TLS 1.2 which is still commonly used your communication will be broken.
 
put the following in the browser bar

chrome://flags/ or brave://flags/ (both seem to work) hit enter

Type TLS into the search bar. One of the results will be what you are looking for
 

Members online


Top