FINDING · EVALUATION

The bulk-transfer mode requires both the censored client and the cooperating proxy to accept incoming TCP connections, rendering it unusable for clients behind NAT without port-forwarding capability. Rendezvous mode is unaffected because it only requires the client to send a single outbound request. The authors note that many real-world residential users are behind NAT, limiting practical deployment of the bidirectional channel.

From 2013-fifield-ossOSS: Using Online Scanning Services for Censorship Circumvention · §6 · 2013 · Privacy Enhancing Technologies Symposium

Implications

Tags

defenses
tunnelingpluggable-transportbridges

Extracted by claude-sonnet-4-6 — review before relying.