FINDING · DETECTION

Shadowsocks transmits a fixed-size AEAD-encrypted length field followed by the AEAD-encrypted payload with no support for reducing ciphertext size via fragmentation, while Obfs4 permits input-side padding but not output fragmentation. These designs impose distinct minimum output message lengths, allowing a passive adversary to distinguish between them — and identify short-message sessions — based solely on the minimum observed message length.

From 2023-fenske-securitySecurity Notions for Fully Encrypted Protocols · §2.4 · 2023 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
traffic-shapefully-encrypted-detect
defenses
shadowsocksobfs4

Extracted by claude-sonnet-4-6 — review before relying.