Encrypted Client Hello (ECH / ESNI)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/encrypted-sni/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/encrypted-sni/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/encrypted-sni/)
Use the native HTML custom element.
Encrypted Client Hello (ECH), anciennement connu sous le nom d'Encrypted SNI (ESNI), est une extension TLS qui chiffre le champ Server Name Indication (SNI) dans la poignée de main TLS. Le champ SNI révèle traditionnellement à quel domaine un client se connecte, même lorsque le trafic lui-même est chiffré. ECH comble cette lacune de confidentialité en utilisant une clé publique publiée dans le [[dns|DNS]] du domaine pour chiffrer le SNI. ECH nécessite la [[dns-privacy|confidentialité DNS]] pour être pleinement efficace.
Exemple
Without ECH, a passive observer on a CDN-hosted IP sees 'TLS ClientHello → target: example.com' even over HTTPS. With ECH, the SNI field is encrypted, revealing only the CDN's outer hostname.