FINDING · DEFENSE
MassBrowser proxies operate on NATed IP addresses shared with other users and services, meaning blocking them imposes collateral damage on unrelated parties. The proxy IP pool scales linearly with user count via client-to-client proxying, and IPs rotate as volunteers move between networks, making enumeration-and-block strategies progressively more costly for censors.
From 2020-nasr-massbrowser — MassBrowser: Unblocking the Censored Web for the Masses, by the Masses · §III-E, §IV-A · 2020 · Network and Distributed System Security
Implications
- Prefer residential or NATed IPs for relay deployment to maximize collateral-damage cost of IP blocking; dedicated datacenter IPs can be enumerated and blocked with no collateral damage.
- Tie proxy pool growth to user growth (via client-to-client proxying) so that as adoption increases, the cost of complete enumeration rises proportionally.
Tags
Extracted by claude-sonnet-4-6 — review before relying.