FINDING · DEFENSE

Most deployed circumvention protocols (obfs4, Shadowsocks, Trojan, VMess, etc.) still rely on pre-quantum primitives (X25519, AES-GCM, ChaCha20). Drivel is the first published treatment of how to perform this migration in the specific context of a fully-encrypted pluggable transport, providing a design template and security analysis that does not exist elsewhere in the circumvention literature.

From 2025-himmelberger-drivelDrivel: A Quantum-Safe Fully Encrypted Protocol Proxy · §2, §5 · 2025 · ETH Zurich (MSc thesis)

Implications

Tags

censors
cngeneric
techniques
fully-encrypted-detect
defenses
obfs4scramblesuitrandomization

Extracted by claude-sonnet-4-6 — review before relying.