FINDING · DEFENSE

HTTPT achieves replay-attack immunity by tunneling over TLS, which incorporates bidirectional nonces (client and server randoms) into key agreement so each connection uses unique cryptographic keys. Censors that replay a legitimate client's observed initial bytes are therefore unable to trigger a proxy response, unlike approaches that rely only on application-layer replay caches.

From 2020-frolov-httptHTTPT: A Probe-Resistant Proxy · §1.1, §3.3 · 2020 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probing
defenses
mimicrytunneling

Extracted by claude-sonnet-4-6 — review before relying.