Encrypted ClientHello removes SNI visibility
No technical countermeasure exists at this layer. A rule that pretends to close this at the router/endpoint the trick operates on is more dangerous than no rule at all, because it can give the family a false sense of coverage. Apply enforcement at the layer that actually carries the traffic or on the device/account directly.
How common it is: child-specific prevalence is not meaningful; ECH is a protocol capability negotiated by software and services. RFC 9849 states that ECH encrypts the ClientHello and protects SNI and other sensitive fi…
Detection
A network product that previously classified HTTPS destinations by SNI may lose that hostname signal while encrypted traffic continues normally.
Fix (technical)
No universal transparent router-side method can recover a signal whose protocol purpose is to encrypt it. Do not design parental filtering around SNI visibility alone. Use endpoint policy, DNS policy …
Fix (relational)
This is primarily a technology-change issue, not evidence of deliberate child circumvention. Avoid accusing the child merely because the router can no longer identify hostnames.
Residual risk
IP-address blocking is coarse, shared hosting/CDNs reduce precision, and encrypted DNS can also remove DNS visibility.
Sources
-
rfc9849-ech
-
rfc7754-filtering