FINDING · EVALUATION
Of 72 PlanetLab vantage points, 7 (~10%) automatically stripped or replaced TCP options (Multipath TCP, MD5, and Window Scale) with NOPs at the very first hop, and 2 VPs always altered TCP sequence numbers. These modifications occurred without any corresponding update to dependent fields, corrupting the TCP stream for higher-layer protocols.
From 2013-detal-revealing — Revealing Middlebox Interference with Tracebox · §3.1 · 2013 · Internet Measurement Conference
Implications
- Do not rely on TCP options (MPTCP, Window Scale, MD5) being preserved end-to-end; ~10% of paths strip them at the access edge, making option-dependent handshake or signaling mechanisms unreliable for circumvention transports.
- Test for first-hop TCP option stripping before deploying transports that use non-standard TCP options as covert signaling channels.
Tags
Extracted by claude-sonnet-4-6 — review before relying.