FINDING · EVALUATION
Encrypted DNS (DoH, DoT) and Encrypted ClientHello (ECH) fully hide plaintext domain names from on-path observers but leave destination IP addresses visible, enabling IP-based fingerprinting with no protocol-level metadata required. An adversary collecting only NetFlow/IPFIX destination-IP records—without TLS fingerprints, packet timing, or port metadata—correctly identifies 72% of all 520K dual-stack websites over IPv4 and 68% over IPv6.
From 2026-ahmad-more-space-less — More Space, Less Privacy? Measuring the Effectiveness of IP-based Website Fingerprinting in IPv6 · §1, §3, §6.1 · 2026 · PoPETs 2026
Implications
- ECH/DoH/DoT alone are insufficient privacy protections against a passive ISP-level adversary; circumvention tools must also prevent destination IP attribution, not merely hide the SNI.
- Any transport that reveals the true destination IP (including after ECH negotiation) remains fingerprintable; full tunneling through a shared proxy or decoy-routing is required to defeat this attack class.
Tags
Extracted by claude-sonnet-4-6 — review before relying.