FINDING · EVALUATION

Testing from a VPS in Iran showed that standard DTLS handshakes are blocked at that vantage point, but Oscur0 avoids this blocking by transmitting only Application Data packets (with Connection ID extension per RFC 9146) after the initial one-shot setup packet, never completing a visible DTLS handshake. A proof-of-concept was implemented in approximately 600 lines of Go using the pion/dtls library.

From 2024-chen-extendedExtended Abstract: Oscur0: One-shot Circumvention without Registration · §3 Design / Implementation · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
ir
techniques
dpitls-fingerprint
defenses
decoy-routingconjure

Extracted by claude-sonnet-4-6 — review before relying.