The use of TLS in Censorship Circumvention
Sergey Frolov, Eric Wustrow
Abstract
TLS, the Transport Layer Security protocol, has quickly become the most popular protocol on the Internet, already used to load over 70% of web pages in Mozilla Firefox. Due to its ubiquity, TLS is also a popular protocol for censorship circumvention tools, including Tor and Signal, among others. However, the wide range of features supported in TLS makes it possible to distinguish implementations from one another by what set of cipher suites, elliptic curves, signature algorithms, and other extensions they support. Already, censors have used deep packet inspection (DPI) to identify and block popular circumvention tools based on the fingerprint of their TLS implementation. In response, many circumvention tools have attempted to mimic popular TLS implementations such as browsers, but this technique has several challenges. First, it is burdensome to keep up with the rapidly-changing browser TLS implementations, and know what fingerprints would be good candidates to mimic. Second, TLS implementations can be difficult to mimic correctly, as they offer many features that may not be supported by the relatively lightweight libraries used in typical circumvention tools. Finally, dependency changes and updates to the underlying libraries can silently impact what an application's TLS fingerprint looks like, making it difficult for tool maintainers to keep up. In this paper, we collect and analyze real-world TLS traffic from over 11.8 billion TLS connections over 9 months to identify a wide range of TLS client implementations actually used on the Internet. We use our data to analyze TLS implementations of several popular censorship circumvention tools, including Lantern, Psiphon, Signal, Outline, TapDance, and Tor (Snowflake and meek pluggable transports). We find that the many of these tools use TLS configurations that are easily distinguishable from the real-world traffic they attempt to mimic, even when these tools have put effort into parroting popular TLS implementations. To address this problem, we have developed a library, uTLS, that enables tool maintainers to automatically mimic other popular TLS implementations. Using our real-world traffic dataset, we observe many popular TLS implementations we are able to correctly mimic with uTLS, and we describe ways our tool can more flexibly adapt to the dynamic TLS ecosystem with minimal manual effort.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1192ed6-e723-46a2-825c-1a176971975eCited by top-tier papers31
- Meteor: Cryptographically Secure Steganography for Realistic DistributionsGabriel Kaptchuk, Tushar M. Jois, Matthew Green, Aviel D. RubinCCS 2021 · 50 citations
- Apophanies or Epiphanies? How Crawlers Impact Our Understanding of the WebSyed Suleman Ahmad, Muhammad Daniyal Dar, Muhammad Fareed Zaffar, Narseo Vallina-Rodriguez et al.WWW 2020 · 42 citations
- Conjure: Summoning Proxies from Unused Address SpaceSergey Frolov, Jack Wampler, Sze Chuen Tan, J. Alex Halderman et al.CCS 2019 · 28 citations
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 24 citations
- Balboa: Bobbing and Weaving around Network CensorshipMarc B. Rosen, James Parker, Alex J. MalozemoffUSENIX Security 2021 · 22 citations
Builds on4
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 180 citations
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes et al.NDSS 2017 · 161 citations
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar et al.NDSS 2016 · 117 citations
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 89 citations
Related papers
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu et al.CCS 2026
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
- Snowflake, a censorship circumvention system using temporary WebRTC proxiesCecylia Bocovich, Arlo Breault, David Fifield, Serene et al.USENIX Security 2024 · 18 citations
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 40 citations
