Say (an encrypted) hello to a more private internet. | The Mozilla Blog

kixik@lemmy.ml to Firefox@lemmy.ml – 298 points –
Say (an encrypted) hello to a more private internet. | The Mozilla Blog
blog.mozilla.org
22

You are viewing a single comment

This makes it so that your ISP doesn't see the actual name of the server/site you're communicating with, only the IP address. Without Encrypted Hello they're able to see both.

I would think that an IP address tells you the domain name by doing a simple DNS lookup.

In many cases you can, but there's never a guarantee that a given IP address will have reverse DNS records configured for resolve it into. On top of that, if it's a major site it's likely hosted behind a content delivery network that may a share a single IP address across thousands or even millions of completely unrelated servers. Cloudflare does some pretty interesting stuff with that approach: https://blog.cloudflare.com/cloudflare-servers-dont-own-ips-anymore/ edit: bad at typing