FINDING · EVALUATION

Combining all three active probing attacks in an Internet-wide scan of 30 million HTTPS servers identified approximately 15,000 hosts (0.05%) behaving like ShadowTLS relays; of these only 6,000 presented TLS certificates for Alexa Top 1000 domains. The scan successfully discovered all four researcher-operated ShadowTLS relays planted as ground truth.

From 2023-wang-chasingChasing Shadows: A security analysis of the ShadowTLS proxy · §3.2, Table 2 · 2023 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probingmeasurement-platform
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.