Encrypted Client Hello: Ready for Prime Time?, (Mon, Mar 9th)
ID: e03fe129-3166-5572-a8ad-4e28cce4c5bc
STIX ID: report--e03fe129-3166-5572-a8ad-4e28cce4c5bc
Feed Name: SANS ISC Diary
The report outlines RFCs 9848 and 9849 introducing Encrypted Client Hello (ECH) for TLS to hide sensitive ClientHello contents (notably SNI) by using public keys published in HTTPS DNS records; it describes Cloudflare’s implementation, how to test ECH support (e.g., checking the ech= field with dig or visiting cloudflare-ech.com), and highlights that blocking HTTPS records will also prevent QUIC—an operational consideration for network defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
