FINDING · DETECTION

A machine-checked EasyCrypt proof demonstrates that a conjunctive SNI + traffic-profile adversary achieves a true positive rate of 1.0 against meek, with a false positive rate bounded by Pr[Game0(MeekEnc).main()=true] ≤ (1/10000) × (1/1000) ≈ 10⁻⁷, under the assumption that meek traffic follows a normal distribution centered at 512 bytes and background traffic a Poisson-like distribution centered at 1024 bytes. The proof is fully machine-checked in EasyCrypt.

From 2025-pereira-positionPosition Paper: A Case for Machine-Checked Verification of Circumvention Systems · §4.2 · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
sni-blockingtraffic-shape
defenses
meekdomain-fronting

Extracted by claude-sonnet-4-6 — review before relying.