FINDING · DEFENSE

Filtering candidate decoy sites by a minimum 15 KB TCP window eliminated 24% of the initial ~5,500 HTTPS hosts; a 30-second HTTP-timeout floor eliminated a further 11%; and AES-128-GCM cipher-suite support requirements eliminated an average of 32%—together reducing the viable decoy-site pool by approximately 55% before any live reachability tests.

From 2017-frolov-isp-scaleAn ISP-Scale Deployment of TapDance · §3.3, Figures 2–3 · 2017 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
tls-fingerprint
defenses
tapdancedecoy-routing

Extracted by claude-sonnet-4-6 — review before relying.