FINDING · EVALUATION

Despite fully encrypted protocols existing since obfs2 in 2012, the first documented evidence of the GFW passively detecting them purely by randomness appeared only in 2021 — approximately a decade later — and was limited to certain foreign IP address ranges and a subsampled fraction of traffic. Meanwhile, the GFW had been discovering obfs2/obfs3 servers via active probing as early as 2013, indicating censors found active-probing-based address discovery cheaper and more reliable than passive statistical classifiers for this protocol family.

From 2023-fifield-commentsComments on certain past cryptographic flaws affecting fully encrypted censorship circumvention protocols · §5 · 2023

Implications

Tags

censors
cn
techniques
fully-encrypted-detectactive-probingrandom-payload-detect
defenses
obfs4pluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.