FINDING · DEFENSE

77% of public bridges offer only vanilla Tor, which is trivially detectable via TLS certificate pattern matching. An additional 15% offer Pluggable Transports with conflicting security properties (e.g., obfs4 + obfs3 + obfs2 co-deployed on the same bridge), allowing a censor to confirm and block the bridge via the weakest PT and thereby disable all stronger PTs on the same IP — including active-probing-resistant transports like obfs4 and ScrambleSuit.

From 2017-matic-dissectingDissecting Tor Bridges: a Security Evaluation of Their Private and Public Infrastructures · §V-C, Table I · 2017 · Network and Distributed System Security

Implications

Tags

censors
cnir
techniques
tls-fingerprintactive-probingdpi
defenses
obfs4scramblesuitpluggable-transportbridges

Extracted by claude-sonnet-4-6 — review before relying.