2026-spiderxss-tlshello-fragmentation-not
findings extracted from this paper
-
Iran's censorship infrastructure began dropping all fragmented TLS ClientHello packets around late July 2026, rendering the tlshello fragmentation bypass technique non-functional. The blocking took effect approximately July 27, 2026, based on user-reported timelines in the net4people/bbs community report.
-
Iran's fragmentation-detection capability targets the fragmentation mechanism itself, not the SNI field content: testers report blocking occurs even when the fragmented ClientHello carries a clean, non-blocked SNI. This indicates the censor is classifying flows by structural packet properties (fragment boundary patterns) rather than by inspected SNI value.
-
Community testing in Iran following the fragmentation bypass failure confirms that REALITY and Shadowsocks remain viable circumvention mechanisms as of late July 2026. Neither protocol relies on ClientHello fragmentation for evasion, which accounts for their continued functionality under the updated Iranian filtering regime.