FINDING · DEFENSE
Traffic splitting across N TURN proxies (1 ≤ N ≤ M) is hypothesized to resist active probing because each TURN server responds to probing requests identically to a regular TURN server, providing no distinguishing signal. Additionally, proxy ephemerality combined with splitting allows on-the-fly migration to new proxies when existing ones are blocked, maintaining connectivity even under partial blocking.
From 2025-vilalonga-extended — Extended Abstract: Using TURN Servers for Censorship Evasion · §3.3 Censorship Evasion · 2025 · Free and Open Communications on the Internet
Implications
- Design the client to connect through multiple TURN proxies simultaneously so that blocking a subset does not interrupt service — require M > N headroom in the proxy pool.
- Ensure the TURN proxy tier returns stock TURN protocol responses to unsolicited probes rather than custom error codes, making active probing indistinguishable from probing any regular TURN endpoint.
Tags
Extracted by claude-sonnet-4-6 — review before relying.