FINDING · EVALUATION
Bridges that carry clients are highly stable: their median lifetime is 116 days (~4 months) and 84% never change IP address, with 90% having at most one IP change. This means current censor policies that remove bridge IP blocks every 25 hours are far more conservative than necessary — an adversary could sustain blocks for months without significant collateral damage.
From 2017-matic-dissecting — Dissecting Tor Bridges: a Security Evaluation of Their Private and Public Infrastructures · §V-B, Figure 3 · 2017 · Network and Distributed System Security
Implications
- Design bridge infrastructure to support faster IP rotation for high-value bridges, so the censor's window for effective blocking is reduced from months to days.
- Introduce automated bridge replacement triggers when a bridge is detected as blocked, rather than relying on bridge operators to notice and act.
Tags
Extracted by claude-sonnet-4-6 — review before relying.