FINDING · DEFENSE

The paper introduces the uTLS library, which allows a Go TLS client to impersonate a specific browser's TLS fingerprint by replaying a recorded ClientHello template (including exact cipher suites, extensions, and GREASE bytes) rather than constructing one from Go's crypto/tls. Using a Chrome 70 uTLS template reduces fingerprint-distinctiveness to near zero against a passive classifier trained on real Chrome traffic.

From 2015-frolov-the-use-of-tlsThe use of TLS in censorship circumvention · §5 · 2019 · NDSS

Implications

Tags

censors
cnirru
techniques
tls-fingerprint
defenses
mimicrypluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.