FINDING · DETECTION

Balboa currently supports only TLS 1.2 stream cipher suites, covering approximately 81% of TLS connections; an active censor can force non-stream cipher suite negotiation, causing Balboa to silently enter pass-through mode—a potential denial-of-service vector. Separately, if the server's traffic model deviates from the local baseline (e.g., the same audio file streamed repeatedly), a sufficiently powerful censor can detect the anomaly independently of whether Balboa is running.

From 2021-rosen-balboaBalboa: Bobbing and Weaving around Network Censorship · §5, §2.5.1 · 2021 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
active-probingtraffic-shapedpi
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.