SkyF2F's friend-to-friend service model, where a server publishes its appid only to trusted contacts rather than publicly, provides significant resistance to both sybil attacks (malicious censor-controlled servers) and DoS exhaustion attacks. A censor posing as a client can establish many tunnels to exhaust a public server's resources; restricting service to a trusted friend list eliminates most of this attack surface.
From 2009-cao-skyf2f — SkyF2F: Censorship Resistant via Skype Overlay Network
· §V.A
· 2009
· International Conference on Information Engineering
Implications
Trust-restricted bridge distribution (friend-to-friend or invitation-only) substantially reduces censor infiltration and DoS attack surface versus publicly advertised proxies; pair with per-client connection/bandwidth limits as a secondary defense.
Identifier rotation is much cheaper in overlay networks than in IP space — designing circumvention systems around rotatable application-layer IDs rather than IP addresses dramatically lowers recovery cost after a server is burned.