>>22514812Encrypted Client Hello
It's a worry now because there is new law that if you decipher from govspeak essentially implies that RKN will have the power to keep logs of any tcp ipv4 and ipv6 connections in real time. So it's like in America now, where all your connections are logged, except Russia doesn't even try to hide where you needed Snowden to tell people about it.
What does it mean? Correlation attacks. For example when I'm interacting with
sys.4chan.org and posting (like this post) this interaction can be logged IN REAL TIME now, and then looked at this PUBLICLY AVAILABLE post and its time stamp then correlate my exact identity on who posted it.
What ECH does? Makes it look like I'm interacting with
cloudflare-ech.com and nothing more (that and 104.19.142.99 IP address which belongs to cloudflare). This means any observer just sees the outer cloudflare SNI and not the inner SNI domains that come after, and there are MILLIONS of people who interaction with cloudflare IPs on daily basis as many things hosted on same IPs