FINDING · DETECTION

Chrome and Firefox send GREASE ECH extensions in every ClientHello message, meaning a censor that blocks all ECH-containing ClientHellos would block all Chrome and Firefox TLS traffic. Cloudflare's static outer SNI "cloudflare-ech.com" in all its ECH configurations makes real ECH connections trivially distinguishable from GREASE ECH — censors can block real ECH connections to Cloudflare without triggering GREASE collateral damage. Cloudflare rejects ECH handshakes with omitted or invalidated outer SNI values; non-Cloudflare ECH deployments accept missing and invalid outer SNIs.

From 2025-niere-encryptedEncrypted Client Hello (ECH) in Censorship Circumvention · §2.1, §4.1, §6 · 2025 · FOCI 2025 (Free and Open Communications on the Internet)

Implications

Tags

censors
cnirru
techniques
sni-blockingesni-eh-blocking
defenses
ech-esni

Extracted by claude-sonnet-4-6 — review before relying.