FINDING · DEFENSE

A pre-shared key enables encrypting the entire GoHop packet—header, payload, and padding bytes—achieving true randomness in the full byte stream. Standard VPN protocols such as OpenVPN encrypt only the payload while leaving headers in plaintext, exposing protocol-identifying fields to DPI without payload inspection. This design choice is a prerequisite for defeating header-based fingerprinting.

From 2014-wang-gohopGoHop: Personal VPN to Defend from Censorship · §III.A · 2014 · International Conference on Advanced Communication Technology

Implications

Tags

censors
cn
techniques
dpirandom-payload-detect
defenses
randomization

Extracted by claude-sonnet-4-6 — review before relying.