Encrypted Client Hello
ID: 621008a7-1225-5f0b-8544-fb3ec3bb49d5
STIX ID: report--621008a7-1225-5f0b-8544-fb3ec3bb49d5
Feed Name: WatchGuard Secplicity Blog
The report describes TLS 1.3 Encrypted Client Hello (ECH), noting that by encrypting the ClientHello/SNI, modern browsers and many hosting providers now conceal the destination domain from intermediaries—enhancing privacy but breaking SNI-based filtering used by enterprises and schools. It recommends practical responses such as toggling browser flags, blocking encrypted DNS, and preferably deploying full TLS decryption/HTTPS inspection (e.g., via SASE clients), supported by the observation that most malware arrives over encrypted channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
