FINDING · DEFENSE
Server-side censorship evasion strategies require zero client-side changes: clients bypass censorship without installing software or even being aware of the evasion, and this approach has been adopted in production tools including Psiphon's packetman. The packet manipulations exploit weaknesses in how censors track or tear down TCP connections, occurring entirely at the server during the three-way handshake.
From 2023-tran-crowdsourcing — Crowdsourcing the Discovery of Server-side Censorship Evasion Strategies · §1 Introduction · 2023 · Free and Open Communications on the Internet
Implications
- Deploy server-side Geneva-discovered strategies to protect all clients on a network segment simultaneously, with no client software update required — maximizing reach in high-risk deployments.
- Prioritize server-side evasion as a complementary layer on top of existing pluggable transports, since it imposes zero friction on end-users.
Tags
Extracted by claude-sonnet-4-6 — review before relying.