FINDING · EVALUATION
82.2% of ad requests from Alexa top-500 websites are sent over HTTPS (Table 2), encrypting the HTTP Referer field. This prevents censors from correlating a user's direct-path ad request back to a censored publisher domain in the vast majority of cases; only the remaining 17.8% of HTTP ad requests are vulnerable to Referer-based traffic analysis.
From 2017-javaid-online — Online Advertising under Internet Censorship · §4.3, Table 2 · 2017 · Hot Topics in Networks
Implications
- For split-path designs, configure the direct-path channel to enforce HTTPS-only connections to ad servers, eliminating the Referer leakage surface and reducing censor-observable correlation to destination IP only.
- The ~18% of HTTP ad requests that leak Referer can be handled via IRS (route through a relay) without affecting overall ad relevance for the HTTPS majority.
Tags
Extracted by claude-sonnet-4-6 — review before relying.