Skip to content

Archive

Web Privacy

2 articles
Cybersecurity 17 Sep 2026 8 min read

Encrypted ClientHello Separates Public Routing From Private TLS Identity

Encrypted ClientHello Separates Public Routing From Private TLS Identity TLS 1.3 encrypts most handshake messages, yet a conventional connection still exposes the initial ClientHello. That message can contain Server Name Indication, allowing an on-path observer to associate a connection with a requested hostname before application traffic is protected. Encrypted ClientHello, standardized in RFC 9849, changes that boundary. The client constructs a private ClientHelloInner containing the service-specific parameters and wraps it inside a public ClientHelloOuter. The outer message remains usable by the client-facing infrastructure, while sensitive inner fields are protected with Hybrid Public Key Encryption.

Cybersecurity 14 Sep 2026 6 min read

Referrer Policy Controls Navigation Metadata Exposure

Referrer Policy Controls Navigation Metadata Exposure A link from an internal account page to an external support site can carry more context than the destination needs. Depending on browser policy and request conditions, the HTTP Referer header can identify the source origin or include a fuller source address. If that address contains sensitive path structure or query data, navigation metadata becomes an unintended disclosure channel. Referrer Policy gives a document, response, or individual element control over how much source address information accompanies eligible requests. It does not encrypt traffic, authenticate destinations, or prevent navigation. Its purpose is narrower: constrain the referrer information exposed when the browser makes requests.