FINDING · EVALUATION

Scanning a 1% sample of the IPv4 address space and the Alexa top-1-million domains, the authors found that over half of all TLS hosts will leave an incomplete HTTP request connection open for at least 60 seconds before sending data or closing the connection; many had timeouts exceeding 5 minutes. The 16-core TapDance station prototype processes over 12,000 tag verifications per second per core, with approximately 90% of CPU time consumed by a single ECC point multiplication on Curve25519. The station adds a median latency of 270 milliseconds to page downloads versus direct connections, and a single station instance can be overwhelmed by approximately 1.2 Gbps of TLS application-layer traffic.

From 2014-wustrow-tapdanceTapDance: End-to-Middle Anticensorship without Flow Blocking · §7.3, §8, Figure 5 · 2014 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpitraffic-shape
defenses
tapdance

Extracted by claude-sonnet-4-6 — review before relying.