FINDING · DEFENSE

CloudTransport's passive-rendezvous design ensures clients never establish direct connections to bridges; consequently, even a censor in complete control of a bridge cannot enumerate client IP addresses without computationally intensive flow-correlation analysis. Blacklisting the IP address of a CloudTransport bridge has zero effect on CloudTransport connections, and when a bridge migrates to a new IP address this change is completely transparent to clients.

From 2014-brubaker-cloudtransportCloudTransport: Using Cloud Storage for Censorship-Resistant Networking · §4.3 · 2014 · Privacy Enhancing Technologies Symposium

Implications

Tags

techniques
ip-blockingactive-probingflow-correlation
defenses
tunnelingbridges

Extracted by claude-sonnet-4-6 — review before relying.