FINDING · DETECTION

Tor's vanilla TLS certificate presents a distinctive pattern (SubjectCN=www.[random].com; IssuerCN=www.[random].net using base32 random strings), which never changes across certificate rotations every 2 hours. Using this pattern against Censys and Shodan scan data without running any active scans, the authors discovered 694 private bridges and 645 private proxies, and deanonymized the IP address of 35% of public bridges with clients (23% of all active public bridges) in April 2016.

From 2017-matic-dissectingDissecting Tor Bridges: a Security Evaluation of Their Private and Public Infrastructures · §II-B, §VI-A, Table V · 2017 · Network and Distributed System Security

Implications

Tags

censors
generic
techniques
tls-fingerprintactive-probing
defenses
bridgestorobfs4pluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.