Skip Navigation

Firefox rolls out ECH enabled by default in 118

blog.mozilla.org Say (an encrypted) hello to a more private internet. | The Mozilla Blog

As web users, what we say and do online is subject to pervasive surveillance. Although we typically associate online tracking with ad networks and other th

Say (an encrypted) hello to a more private internet. | The Mozilla Blog

ECH (encrypted client hello) is going or get enabled by default (already existed in a hidden setting) with version 118.

This page about the version explains a bit better ECH https://support.mozilla.org/fr/kb/understand-encrypted-client-hello

Tho it is still a bit confusing.

From what I understand there is the DNS query > the dns servers sends back an IP. This DNS query can be encrypted with DoH (or DoT?, it seems only DoH from the post).

Then there is a handshake with the website where the website informations can be leaked, and that can be encrypted by ECH (if the website supports it).

Then after that there is a tls connexion established between the website and the user.

The part where I'm confused is : can ECH be used without DoH? If yes that would mean that I can use a DoH capable software and not have to configure it into Firefox? (ex: Nextdns + yogadns)

18
18 comments
You've viewed 18 comments.