FINDING · DEFENSE

Ultrasurf confirmed to the researcher that its protocol has no forward secrecy and uses RC4 without any integrity check (no MAC or HMAC). This means all recorded ciphertext can be retrospectively decrypted once a session key is recovered, and the stream is trivially malleable — both properties confirmed by the UltraReach team during disclosure.

From 2012-appelbaum-technicalTechnical analysis of the Ultrasurf proxying software · §8.1, §5.15 · 2012 · The Tor Project

Implications

Tags

techniques
dpi

Extracted by claude-sonnet-4-6 — review before relying.