看到 ECH 變成 Standards Track 了:「RFC 9849 TLS Encrypted Client Hello (via)」。
瀏覽器都在 2023 的下半年預設啟用了 (Firefox 119 是 2023/10/24,Chromium 117 是 2023/09/12)。
ECH is enabled in Firefox by default since version 119, and is recommended by Mozilla to be used along with DNS over HTTPS. In September 2023, Chromium version 117 (used in Google Chrome, Microsoft Edge, Samsung Internet, and Opera) enabled it by default, also requiring keys to be deployed in HTTPS resource records in DNS.
而 server 端看起來最近也都支援了:nginx 的「Encrypted Client Hello Comes to NGINX」、Caddy 的「Automatic HTTPS」。
這個算是基礎建設,再降低可被偵測到的部分。從 ESNI 走到 ECH 這樣也五六年了:




