ECH Support news?

Is there some information about ECH support? I could've sworn I saw an ech entry in my domain's TYPE65 record, but not any more. For context, with crypto.cloudflare.com , I see the pubkey:
$ dig +short crypto.cloudflare.com TYPE65
1 . alpn="http/1.1,h2" ipv4hint=162.159.137.85,162.159.138.85 ech=AEX+DQBB3QAgACDOmEpEI4A86cQw7uF31OiFpi7ZiXqX9ABfFO1gQktKNgAEAAEAAQASY2xvdWRmbGFyZS1lY2guY29tAAA= ipv6hint=2606:4700:7::a29f:8955,2606:4700:7::a29f:8a55
$ dig +short crypto.cloudflare.com TYPE65
1 . alpn="http/1.1,h2" ipv4hint=162.159.137.85,162.159.138.85 ech=AEX+DQBB3QAgACDOmEpEI4A86cQw7uF31OiFpi7ZiXqX9ABfFO1gQktKNgAEAAEAAQASY2xvdWRmbGFyZS1lY2guY29tAAA= ipv6hint=2606:4700:7::a29f:8955,2606:4700:7::a29f:8a55
But not for other domains (including my own on Cloudflare).
3 Replies
Chaika
Chaika•16mo ago
It's just really slowly rolling out, it's by plan level. Most of my free domains have it, but none of my Pro/Biz/Ent There's probably no rush because I don't think a single browser has it by default still, all behind flags or not implemented
Chaika
Chaika•16mo ago
The Cloudflare Blog
Handshake Encryption: Endgame (an ECH update)
In this post, we’ll dig into ECH details and describe what this protocol does to move the needle to help build a better Internet.
poiasd
poiasdOP•16mo ago
Yeah that was the one I looked at as well, but already 1.5 years old 😄 I get that ECH isnt even official yet iirc (still draft) Just wondering since ESNI for some time provided mitigations against SNI (even if behind extra flags), just unfortunate to have lost that
Want results from more Discord servers?
Add your server