Encrypted ClientHello removes SNI visibility

No technical countermeasure exists at this layer. A rule that pretends to close this at the router/endpoint the trick operates on is more dangerous than no rule at all, because it can give the family a false sense of coverage. Apply enforcement at the layer that actually carries the traffic or on the device/account directly.

How common it is: child-specific prevalence is not meaningful; ECH is a protocol capability negotiated by software and services. RFC 9849 states that ECH encrypts the ClientHello and protects SNI and other sensitive fi…

Detection

A network product that previously classified HTTPS destinations by SNI may lose that hostname signal while encrypted traffic continues normally.

Fix (technical)

No universal transparent router-side method can recover a signal whose protocol purpose is to encrypt it. Do not design parental filtering around SNI visibility alone. Use endpoint policy, DNS policy …

Fix (relational)

This is primarily a technology-change issue, not evidence of deliberate child circumvention. Avoid accusing the child merely because the router can no longer identify hostnames.

Residual risk

IP-address blocking is coarse, shared hosting/CDNs reduce precision, and encrypted DNS can also remove DNS visibility.

Sources

  • rfc9849-ech

  • rfc7754-filtering