FINDING · DETECTION

Tor's TLS handshake exhibited multiple distinguishing fingerprints — including the client cipher list, server certificates, and randomly generated SNIs — that were used for TLS-based filtering in Ethiopia, China, and Iran. Inferring the exact byte-level pattern matched by DPI boxes required manual analysis and remains a difficult open problem as of 2013.

From 2013-winter-towardsTowards a Censorship Analyser for Tor · §3.1.5, §5 · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
cniret
techniques
tls-fingerprintdpisni-blocking

Extracted by claude-sonnet-4-6 — review before relying.