FINDING · DEFENSE

Telex embeds steganographic tags in TLS ClientHello nonces using elliptic-curve Diffie-Hellman, placing proxy stations at ISP level on paths between the censor's network and popular uncensored destinations. Because the cover destinations are ordinary popular HTTPS websites, the censor cannot block Telex without simultaneously blocking a large class of legitimate TLS traffic — converting the censor's own reluctance to over-block into an unblockability guarantee.

From 2011-wustrow-telexTelex: Anticensorship in the Network Infrastructure · §2, §4 · 2011 · USENIX Security Symposium

Implications

Tags

techniques
ip-blockingdpi
defenses
telexdecoy-routingsteganographymimicry

Extracted by claude-sonnet-4-6 — review before relying.