FINDING · DEFENSE

Dust eliminates the in-band key-exchange fingerprint surface via an out-of-band half-handshake: the server's public key, IP, port, and a single-use secret are bundled into a PBKDF-encrypted invite packet transmitted out-of-band; only the decryption password (not the server IP) appears in plaintext, defeating the email/IM IP-address blocking attacks documented against prior systems.

From 2011-wiley-dustDust: A Blocking-Resistant Internet Transport Protocol · §3, §3.1 · 2011 · University of Texas at Austin

Implications

Tags

censors
generic
techniques
dpiactive-probing
defenses
dustrandomizationbridges

Extracted by claude-sonnet-4-6 — review before relying.