FINDING · DEFENSE

ScrambleSuit defeats active probing by requiring clients to prove knowledge of an out-of-band shared secret before the server responds; a probing censor receives only silence. Two mechanisms are provided: session tickets (preferred for non-Tor applications) and an authenticated UniformDH handshake (optimized for Tor's shared-secret bridge distribution model), with both producing payloads computationally indistinguishable from random.

From 2013-winter-scramblesuitScrambleSuit: A Polymorphic Network Protocol to Circumvent Censorship · §4.1 · 2013 · Workshop on Privacy in the Electronic Society

Implications

Tags

censors
cnir
techniques
active-probingdpi
defenses
scramblesuitpluggable-transportobfs4

Extracted by claude-sonnet-4-6 — review before relying.