FINDING · DEFENSE

Geneva discovered 6 client-side and 4 server-side TCP-layer evasion strategies against GFW ESNI blocking within 48 hours of training, all achieving near 100% reliability. Effective strategies include desynchronization attacks (triple SYN with corrupt sequence number, FIN+SYN flag confusion, TCB turnaround via pre-handshake SYN+ACK) and TCB teardown via corrupted-checksum RST injection. All strategies operate at the TCP layer and require no changes to the application sending ESNI.

From 2020-gfw-esni-blockingExposing and Circumventing China's Censorship of ESNI · Evasion strategies / Summary on Circumvention Strategies · 2020 · gfw.report

Implications

Tags

censors
cn
techniques
esni-eh-blocking
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.