FINDING · DETECTION

BitTorrent's Message Stream Encryption (MSE), despite omitting static strings from the handshake, can be identified with 96% accuracy using packet-size analysis and direction-of-packet-flow; MSE also uses a cleartext Diffie-Hellman key exchange, leaving an additional fingerprint surface.

From 2011-wiley-dustDust: A Blocking-Resistant Internet Transport Protocol · §2.2 · 2011 · University of Texas at Austin

Implications

Tags

censors
generic
techniques
traffic-shapedpi

Extracted by claude-sonnet-4-6 — review before relying.