Meni
SL

Cloudflare says Encrypted Client Hello might ‘solve privacy for good’. The reality is not that simple

A cutting-edge technology that is “filling the privacy gap in our existing online security infrastructure” and that, if widely adopted, “might even solve privacy for good.” Sounds promising, right? That’s how Mozilla and Cloudflare describe Encrypted Client Hello (ECH), a protocol that encrypts the entire “hello” message or the first communication between your browser and a website’s server.

We believe ECH is indeed a major element of Internet privacy, and the importance of its support by such major players as Mozilla, Chrome, and Cloudflare cannot be understated. At AdGuard, we have added ECH support in our Windows, Mac, and Android apps, because we believe in the technology’s potential to make browsing more private. AdGuard’s ECH support works across all apps and browsers that AdGuard filters. But is ECH the missing piece of the puzzle that will solve privacy and defeat censorship once and for all? As much as we would like it to, it is unlikely.

And before we pour some cold water on the excitement over ECH and its supposed invincibility to censors, copyright authorities, peeping toms, and other prying eyes, we need to take a step back and cover some basics.

What is ECH and why do we need it?

Imagine you are sending a letter to your friend. You seal the envelope and write their name and address on it. No one can open the envelope and read your letter without breaking the seal. But anyone can see who you are sending the letter to by looking at the address.

That’s kind of how HTTPS, a default protocol that is used by over 84% of websites, works. The first piece of information your browser communicates when establishing an encrypted connection to the website is known as “Client Hello.” Some information in Client Hello, such as SNI (Server Name Indication, which is a way for your browser to tell the server which website it wants to connect to), is not encrypted. This, in turn, means that network operators, including your ISP, can see it. Having received the Client Hello message, the server replies with some information known as “Server Hello” to complete the ‘handshake’ with the device.

Cloudflare illustrates how the handshake works
Source: Cloudflare

After that first greeting, the data your browser exchanges with the server is encrypted, so that only you and the website can see what’s inside it. But by that point, your internet provider already knows the name of the website you are visiting. For example, if you went to www.google.com, your internet provider couldn’t see what you were searching for, but they could see that you were using Google.

What we’ve described above is how a TLS handshake works. TLS stands for Transport Layer Security, which is a cryptographic protocol that provides end-to-end security for data sent over the Internet. To be more technical, the first “Client Hello” message that your browser sends in clear text to the website’s servers contains not only the SNI, but also the TLS version and an encryption algorithm. But the main point is it’s not encrypted, so anyone who can see the network traffic can also see the website name your browser is requesting.

The question is, how can we shield that first piece of data that is not encrypted and that exposes our browsing habits?

This is where the Encrypted Client Hello protocol comes in. In simple terms, ECH encrypts the Client Hello message containing SNI, which, as we’ve already mentioned, indicates the name of the website you are visiting. Instead of showing the website’s real domain name, like www.google.com, to any external observers, your browser only shows the name of a so-called client-facing server, behind which multiple backend servers with their own domain names are hidden. The client-facing server has a general domain name: for example, Cloudflare uses cloudflare-ech.com as its client-facing server name. But how does your browser know which information to send to it to connect to a specific website?

The client-facing server acts as a middleman that has a special decryption key with which it opens your inner letter and sees your website name. Then it forwards the request to the real domain and sends back the response. This is possible because ECH splits Client Hello into two parts: the outer part contains non-sensitive information like the name of the client-facing server, and the inner part contains the inner SNI indicating the domain name of the backend server, which is the website you want to visit. To continue with our letter analogy: it’s like having the same address written on letters to different recipients, and having to use a magic wand to break the seal to see the inner letter with an actual address.

Cloudflare illustrates how the ECH works
Source: Cloudflare

What is the situation like with ECH adoption?

In recent months, more and more industry players have begun to warm up to ECH. Google started shipping the feature in Chrome 117, while Chrome 118 became the first stable release of Google’s browser with ECH support. In Firefox, ECH is on by default as of Firefox 118, but only works if you have DNS-over-HTTPS enabled. Edge is also testing ECH, but has yet to roll it out in a stable version.

However, support for ECH from the browser side means little without being reciprocated from the server side. It only means that a browser can send encrypted ECH messages to the servers that support this protocol. So, the move by Cloudflare, the most popular CDN provider on the market, to also support the protocol has made a big difference in the ECH adoption. Cloudflare, which handles around 20% of all the traffic on the Internet, announced that it began supporting ECH for all customers on free plans at the end of September, and encouraged paid customers to apply for the feature.

The protocol, however, still has a long way to go before it is widely accepted. As of right now, many of Cloudflare’s free domains are missing information about ECH in their DNS records, so Chrome can’t use ECH for those websites. But, since the ECH rollout is still in its early stages, this issue will likely be resolved over time.

So, is privacy solved?

As much as we would like to see it happen, declaring privacy solved is wishful thinking.

On the one hand, the universal adoption of the ECH, if it happens, will render useless some of the tried-and-tested blocking techniques employed by Internet authorities around the world to tackle online piracy, incur geo-fencing, and impose censorship. For one, law enforcement authorities will find it more difficult to target specific websites based on their names, because they will be hidden by the ECH.

However, this does not mean that censors won’t be able to clear this hurdle. It may require some adjustments on their part, but blocking will still be possible.

ECH’s weak spots or potential blocking methods

Now, we’re going to play devil’s advocate and give you some concrete ways that censors can try to block websites despite the implementation of the ECH.

  • One way is to “cut” the ECH from DNS records. To establish an ECH connection with a server, your browser needs a special DNS record from that server. This record tells your browser which domain name and decryption key to use in the outer and inner part of the ECH. However, if your DNS traffic is not encrypted, which is the case for most users, then anyone who can see your DNS queries, such as your ISP or a censor, can also see the ECH record. They can use this record to identify and block your ECH connection. Of course, if users have encrypted their DNS traffic, then this method won’t work.

  • A cruder, but a fairly effective way is to block all known client-facing servers, such as clouflare-ech.com. Realistically, there shouldn’t be many of these servers, so it should not be hard for censors to identify and block them all. But this method is very risky because it could break the Internet for many users. If the censors block all the servers that support ECH, then the browsers will not be able to establish a connection with the websites that have ECH enabled. This may, in turn, prompt Cloudflare to disable ECH for countries with strict internet censorship. It remains to be seen how Cloudflare will react if their client-facing server gets blocked by censors in countries like China or Russia. They will face a difficult choice, for sure. Another pitfall that awaits those banking on ECH as the ultimate solution to all privacy-related problems is a risk that website owners will simply refuse to adopt it or will opt out of the protocol because of the very same reason. If censors target ECH and make websites that enable it unaccessible, then website owners might want to disable the ECH support rather than lose their visitors.

There’s no denying that ECH is an exciting and a very promising technology that aims to make the Internet more private. However, it is not foolproof, and should not be regarded as a panacea against surveillance. Moreover, its widespread adoption favors the use of certain CDN services, such as the one offered by Cloudflare. While these services may not be problematic in and of themselves, their promotion as a side-effect of the ECH adoption risks making the Internet even more centralized than before. Only time will tell if this is for better or worse.

Vam je bila objava všeč?
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za Windows

AdGuard za Windows ni le še en zaviralec oglasov, je večnamensko orodje, ki združuje vse potrebne funkcije za najboljšo spletno izkušnjo. Onemogoča oglase in nevarne spletne strani, pospeši nalaganje strani in ščiti vaše otroke, ko so na spletu.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za macOS

Za razliko od drugih zaviralcev oglasov je AdGuard zasnovan z upoštevanjem posebnosti macOS. Ne zagotavlja le obrambe pred oglasi v Safariju in drugih brskalnikih, ampak vas tudi ščiti pred sledenjem, lažnim predstavljanjem in goljufijami.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za Android

AdGuard za Android je idealna rešitev za mobilne naprave Android. V nasprotju z drugimi zaviralci oglasov AdGuard ne potrebuje korenskega dostopa in ponuja širok spekter funkcij: filtriranje v aplikacijah, upravljanje aplikacij in še veliko več.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za iOS

Najboljši blokator oglasov iOS za iPhone in iPad. AdGuard odstrani vse vrste oglasov v Safariju, ščiti vašo zasebnost in pospeši nalaganje strani. Tehnologija blokiranja oglasov AdGuard za iOS zagotavlja filtriranje najvišje kakovosti in omogoča uporabo več filtrov hkrati
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard VPN

74 lokacij svetovnega spleta

Dostop do katere koli vsebine

Močno šifriranje

Politika 'Brez dnevnikov'

Najhitrejša povezava

stalna podpora

Poskusite brezplačno
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Zaviralec vsebine

AdGuard Zaviralec oglasov bo odstranil vse vrste oglasov v mobilnih brskalnikih, ki podpirajo tehnologijo zaviralcev vsebin — in sicer Samsung Internet in Yandex.Browser. Čeprav je bolj omejen kot AdGuuard za Android, je brezplačen, preprost za namestitev in še vedno zagotavlja visoko kakovost onemogočanja oglasov.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Razširitev brskalnika

AdGuard je najhitrejša in najlažja razširitev za zaviranje oglasov, ki učinkovito onemogoča vse vrste oglasov na vseh spletnih straneh! Za brskalnik, ki ga uporabljate, izberite AdGuard in hitro ter varno brskajte brez oglasov.
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Pomočnik

Spremljevalna razširitev brskalnika za AdGuard namizno aplikacijo. Ponuja dostop do takšnih funkcij v brskalniku, kot so zaviranje elementov po meri, seznam dovoljenih spletnih strani ali pošiljanje poročila.
18.308 18308 ocen uporabnikov
Odlično!

AdGuard DNS

AdGuard DNS je brezhiben način zaviranja internetnih oglasov, ki ne zahteva nameščanja nobenih aplikacij. Je preprost za uporabo, popolnoma brezplačen, enostavno nastavljiv na kateri koli napravi in vam zagotavlja minimalne potrebne funkcije za zaviranje oglasov, števcev, zlonamernih spletnih strani in vsebine za odrasle.
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Home

AdGuard Home je omrežni program za zaviranje oglasov in sledenja. Ko ga nastavite, bo pokril VSE vaše domače naprave in za to ne potrebujete nobenih programov na strani odjemalca. Z dvigom internetnih zadev in povezanih naprav, postaja vse bolj pomembno, da lahko nadzorujete celotno omrežje.
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Pro za iOS

AdGuard Pro ima močno ponudbo odličnega onemogočanja oglasov za iOS v Safariju, ki ga uporabniki redne različice že poznajo. Z zagotavljanjem dostopa do nastavitev DNS po meri aplikacija omogoča zaviranje oglasov, zaščito vaših otrok pred vsebino za odrasle na spletu in varovanje vaših osebnih podatkov pred krajo.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za Safari

Razširitve oglasov za zaviranje oglasov za Safari imajo težave, odkar je Apple začel vsiljevati vse, da uporabljajo nov SDK. Razširitev AdGuarda naj bi vrnila visoko kakovostno onemogočanje oglasov nazaj v Safari.
18.308 18308 ocen uporabnikov
Odlično!

AdGuard Temp Mail

Brezplačen ustvarjalec začasnih elektronskih naslovov, ki vas ohranja anonimne in ščiti vašo zasebnost. Brez neželene pošte v vašem glavnem predalu!
18.308 18308 ocen uporabnikov
Odlično!

AdGuard za Android TV

AdGuard za Android TV je edina aplikacija, ki zavira oglase, varuje vašo zasebnost in deluje kot požarni zid za vaš Smart TV. Prejmite opozorila o spletnih grožnjah, uporabite varen DNS in izkoristite šifriran promet. Sprostite se in se potopite v svoje najljubše oddaje z vrhunsko varnostjo in brez oglasov!
Prenos AdGuarda Za namestitev AdGuarda kliknite gumb, označen s puščico Izberite 'Odpri' in kliknite na 'Vredu', nato pa počakajte, da se datoteka prenese. V odprtem oknu povlecite ikono AdGuarda in jo spustite v mapo 'Aplikacije'. Hvala, ker ste izbrali AdGuard! Izberite 'Odpri' in kliknite na 'Vredu', nato pa počakajte, da se datoteka prenese. V odprtem oknu kliknite na 'Namesti'. Hvala, ker ste izbrali AdGuard!
Namestite AdGuard na svojo mobilno napravo