FINDING · DEFENSE

Evaluation of the top 10,000 Alexa websites finds that 3,916 (39%) support HTTPS, of which 1,976 (50%) perform HTTP 3XX redirects that echo the requested path in the Location header and 812 (20%) replay the URL in HTTP 404 error responses — both usable as upstream covert channels readable by downstream-only decoy routers without intercepting upstream traffic.

From 2017-nasr-waterfallThe Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks · §7.1.1 · 2017 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpi
defenses
decoy-routingsteganographytunneling

Extracted by claude-sonnet-4-6 — review before relying.