Encrypted Client Hello (ECH / ESNI)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/encrypted-sni/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/encrypted-sni/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/encrypted-sni/)
Use the native HTML custom element.
Encrypted Client Hello (ECH), sebelumnya dikenal sebagai Encrypted SNI (ESNI), adalah ekstensi TLS yang mengenkripsi kolom Server Name Indication (SNI) dalam handshake TLS. Kolom SNI secara tradisional mengungkapkan domain mana yang dihubungi klien bahkan ketika lalu lintas itu sendiri dienkripsi. ECH menutup kesenjangan privasi ini dengan menggunakan kunci publik yang diterbitkan dalam [[dns|DNS]] domain untuk mengenkripsi SNI. ECH memerlukan [[dns-privacy|privasi DNS]] agar sepenuhnya efektif.
Contoh
Without ECH, a passive observer on a CDN-hosted IP sees 'TLS ClientHello → target: example.com' even over HTTPS. With ECH, the SNI field is encrypted, revealing only the CDN's outer hostname.