This means that whenever a user visits a website on Cloudflare that has ECH enabled, no one except for the user, Cloudflare, and the website owner will be able to determine which website was visited.
It’s also important to understand that no one technology can be a panacea. ECH works alongside other security and privacy features in Firefox, including DNS-over-HTTPS (DoH). DoH encrypts DNS queries to protect the translation of website names to IP addresses, which ensures that website names aren’t visible to the network in DNS traffic and is essential for ECH to be effective.
DoH alone should prevent DNS blockages, ECH would also prevent packet inspection revealing the domain.
Some asshole is going to use this to protect a website hosting CSAM. So the governments will use that as an excuse to use more invasive filters.
Newer, stricter, powerful filter is approved unanimously by the parliament.
Once the more invasive filters are set up, they can use them to block piracy websites, soccer streams, online gambling sites (but only if they didn't pay the taxes), online trading sites, then they will think "hey this website has a lot of fake news"
, let's block that too", then "you know what? We should block porn too", then "this block is really effective, we should block violent websites", then "that page on Wikipedia is smearing the government, block that", and go on
The fun thing is, that those filters cannot work.
The request begins with a normal looking https request to a non illegal (DNS) server. Then comes the secure handshake with one of the many cloudflare IPs and then the connection goes on like that.
The only way of stopping or recognizing this traffic at this point is via the IP. So they would have to ban all cloudflare IPs to block that and no western politician will survive that.
Those filters would only work on small sites that don't use cloudflare, since then you might have a small number of static IPs.
And they way to report illegal sites is there. You just write cloudflare and they will most certainly deal with the CSAM.
Just make a law that states, in order to protect the citizenship from the dangers of CSAM, it's illegal to use protocols like this or can't operate in the country. Make a smear campaign to appease public opinion to say that cloudflare is helping hide CSAM sites.
Once this first step is done, the road to stricter filters for any other use is paved
All the filters that are used in Europe to block illegal soccer streams within 30 minutes or to block those dangerous gambling sites (just because they don't pay taxes, not because of actual concern) are all coming from a "we need to find a way to block CSAM", then "we already have the tech, we should apply them also to other stuff"
The blocking well just be pushed to cloudflare and other DNS providers. Sure there well be ways around it but for the vast majority of people just use defaults.