Comment by qmarchi
3 years ago
Not a little snitch user, however I do happen to agree with the author that they should disclose this somewhere.
A quick Google search and some viewing of Objective Development's help center doesn't show any related results. Amusingly, it's the author's post and the other article mentioned that take top slot.
As for remediations, the difficult but proper implementation would be to intercept, but handle the TCP handshake and emulate the responses in order to get the SNI. The easy way is to just add a behavior toggle with an explanation of the caveats.
No comments yet
Contribute on Hacker News ↗