DOH and it's effectiveness against ISPs

ESNI or as they call it now ECH is not just a matter of the client but must also be handled on the other side, at the moment ECH is probably not even an officially published and approved RFC.

Firefox supports ESNI/ECH since version 85 (don’t quote me). And now I think it’s even turned on right away, although I’m not sure. But so what if not every hosted resource supports it. Similarly with solutions like Pi-Hole, the devs do not touch the subject seriously until the RFC is approved.

You have three urls to check, among others…
Just even if ECH works for you, it doesn’t mean other sites support your ECH calls, probably not.

Currently, the situation is somewhat similar to a few years ago with https vs http, slowly some people are starting to support ECH, but currently the overwhelming majority still do not.

Just keep in mind that DoH/DoT doesn’t work wonders at hiding the domain names we visit from our ISP. A little worm like SNI sometimes spoils this anonymity. :slight_smile:

https://defo.ie/ech-check.php

https://crypto.cloudflare.com/cdn-cgi/trace

https://www.cloudflare.com/ssl/encrypted-sni/
1 Like