FINDING · DETECTION

ShadowTLS is structurally limited to TLS 1.2 because in TLS 1.3 the Finished message is sent as encrypted Application Data (record type 0x17), preventing the relay from detecting handshake completion without decrypting the session. This forces ShadowTLS to advertise TLS 1.2, which is an increasingly anomalous fingerprint as TLS 1.3 adoption grows.

From 2023-wang-chasingChasing Shadows: A security analysis of the ShadowTLS proxy · §2.2 · 2023 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
tls-fingerprintdpi
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.