Reply to post: Re: Or we finally switch to IPv6

Don't panic about domain fronting, an SNI fix is getting hacked out

Orv Silver badge

Re: Or we finally switch to IPv6

You certainly *can* pile lots of sites onto one IPv6 address and use a hack like SNI. You just don't necessarily have to. People who run privacy-conscious services will probably want to stick with an SNI-like scheme, and most other people probably will out of force of habit. (One address per server is pretty ingrained now, and it's so convenient for administration to just point a bunch of CNAME records at one A record.)

For that matter, given the large address space in even a minimum IPv6 allocation, there's no reason you can't round-robin to lots of different ones and effectively force a choice between blocking the whole prefix or not blocking at all.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon