FINDING · DEFENSE
DNS-sly requires out-of-band distribution of a 2.3 MB compressed bootstrap package (user profile map) before covert communication begins. The authors explicitly reject automated in-band bootstrapping to preserve deniability, accepting a hard scalability constraint as the cost; the particular censored environment tested did not interfere with DNS traffic at all, enabling successful censored-site retrieval at the same throughput rates as uncensored tests.
From 2016-akbar-dns-sly — DNS-sly: Avoiding Censorship through Network Complexity · §3.2, §4.2 · 2016 · Free and Open Communications on the Internet
Implications
- DNS covert channels requiring a pre-shared user profile must plan a secure out-of-band bootstrap delivery mechanism (app installer, QR code, steganographic image) as a first-run step — this is a fundamental UX and scalability bottleneck to address in any production deployment.
- The 2.3 MB bootstrap size is compressible; consider incremental or streaming profile delivery to reduce the initial distribution barrier without sacrificing per-user deniability guarantees.
Tags
Extracted by claude-sonnet-4-6 — review before relying.