alt.hn

4/9/2026 at 12:32:48 PM

Encrypted Client Hello: How it was blocked in Russia and next steps

https://cdt.org/insights/do-not-stick-out-the-dynamics-of-the-ech-rollout/

by grittygrease

4/9/2026 at 2:56:31 PM

Can't you just drop the ECH signals, no matter what site it is? Don't you then mostly disable sites you don't want people to see anyway? Maybe like, you can't download Chrome anymore, but I bet there would be a Russian fork suuuuper fast.

by camgunz

4/9/2026 at 5:25:42 PM

Yes, Russia can shut off its Internet and computers. Know that super useful AI model out of Russia? Its name slips my tongue. Imagine how much better it will get.

by esbranson

4/10/2026 at 7:09:44 AM

That doesn't matter if you can't easily leave Russia, or you don't want to because you've been propagandized, etc.

I guess my broader point is we might need something for regimes that are willing to instate varying degrees of isolation. Like, "so your Internet is controlled by authoritarians; now what?" Not to imply there definitively is a thing--that xkcd about the wrench is the dominant principle ofc.

by camgunz

4/9/2026 at 1:14:28 PM

i use an extension called OhMyECH to show whether a website used ECH, and it is currently very rare that i encounter one that does.

at least none of the major websites on the internet do.

by thousand_nights

4/9/2026 at 1:48:24 PM

adding, one can test it here [1] though I think it also depends on the client using DoH [2] For people already using Cloudflare or Google DoH DNS it should just work.

To get ECH to work for me I had to enable DoH in my local Unbound DNS daemon and point Firefox to it rather than using unencrypted DNS on my LAN. I had to force a refresh (shift-F5 on tls-ech.dev). I only use my own recursive DNS so I get query logs and can block some ad/malware sites.

[1] - https://crypto.cloudflare.com/cdn-cgi/trace

[2] - https://tls-ech.dev/

by Bender