FINDING · DETECTION

Proxy users who resolve DNS locally (at the client) are approximately twice as susceptible to RTTdiff fingerprinting compared to users who resolve DNS at the proxy, across all tested client/proxy location combinations. Local DNS returns IPs optimally reachable from the client's region, which may be geographically distant from the proxy, increasing the proxy-to-server path distance and thus the RTTdiff discrepancy.

From 2025-xue-discriminativeThe Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic · §VI-C-2 · 2025 · Network and Distributed System Security

Implications

Tags

censors
generic
techniques
traffic-shapedns-poisoning
defenses
shadowsocksvmessvless

Extracted by claude-sonnet-4-6 — review before relying.