FINDING · DEFENSE

Configuring iptables to drop incoming Tor packets whose TCP MSS equals 1400 (the value observed on GFW scanners) prevented bridge IPs from being added to the blocklist across the entire 44-hour experiment. This technique requires changes only on the relay, unlike pluggable transports that require both client and server upgrades.

From 2018-dunna-analyzingAnalyzing China's Blocking of Unpublished Tor Bridges · §5.2 · 2018 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probing
defenses
bridges

Extracted by claude-sonnet-4-6 — review before relying.