FINDING · DETECTION

STUN and TURN packets carry a SOFTWARE attribute that explicitly names the server implementation (e.g., 'Citrix-3.2.5.1 Marshal West' for OpenTokRTC), and the choice of STUN servers, forced-TURN usage, and STUN message-type sequence (Binding-only vs. Allocate+CreatePermission vs. send-indication) differ across applications, providing a passive censor with reliable application-level fingerprints orthogonal to the DTLS layer.

From 2016-fifield-fingerprintabilityFingerprintability of WebRTC · §2, §4.1–§4.5 · 2016 · University of California, Berkeley

Implications

Tags

censors
generic
techniques
dpitraffic-shape
defenses
webrtc-pluggable

Extracted by claude-sonnet-4-6 — review before relying.