ECH encrypts the hostname during the handshake. From outside the connection looks like it is going to a shared address, not to your domain.
- On 14 August Vercel announced support for Encrypted Client Hello on its delivery network.
- Until now the site name travelled unencrypted even over HTTPS.
- It switches on automatically in supporting browsers, with no configuration.
A small detail few people know: even over HTTPS, the name of the site you are opening travels in the open. The content is hidden. The address is not.
Who gains. The person on a public network whose provider no longer sees which sites they open. And the site operator who does not want to be easy to filter by name.
Who loses. Anyone who until now blocked or counted by domain name. Including networks that do it for good reasons.
There is no CVE number here either, because there is no vulnerability. There is a change in what shows from outside.