Skip to content

Archive

ECH

1 articles
Cybersecurity 24 Sep 2026 6 min read

Encrypted Client Hello Keeps Sensitive TLS Metadata Inside the Inner ClientHello

TLS 1.3 encrypts most handshake messages after ServerHello, but the initial ClientHello is sent before those handshake keys exist. That leaves fields in the first flight visible to an observer on the network. Server Name Indication (SNI) is especially revealing because it can identify the requested service even when the later certificate and application traffic are encrypted. RFC 9849 defines Encrypted Client Hello (ECH) to narrow that exposure. ECH does not encrypt the entire first packet. It constructs two ClientHello messages with different roles: a private ClientHelloInner containing the connection parameters intended for the backend, and a public ClientHelloOuter that carries an encrypted representation of the inner message.