FINDING · DETECTION

ShadowTLS's TLS ClientHello fingerprint (JA3 hash ebaa863800590426) was not observed in the TLSFingerprint.io dataset collected from a university network tap, making the client fingerprint unique to the tool and trivially blockable by censors maintaining a TLS fingerprint blocklist.

From 2023-wang-chasingChasing Shadows: A security analysis of the ShadowTLS proxy · §3.2 · 2023 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
tls-fingerprint
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.