FINDING · DETECTION

The GFW's SNI inspection is a stateless single-record parser: it cannot detect the SNI extension when the ClientHello is split across multiple TLS records, even when all records are contained within the same TCP segment. In contrast, the GFW does detect SNI when it appears fully within the first TCP segment despite TCP fragmentation, indicating the reassembly gap is specific to the TLS record layer.

From 2023-niere-posterPoster: Circumventing the GFW with TLS Record Fragmentation · §3 · 2023 · ACM CCS 2023 (poster)

Implications

Tags

censors
cn
techniques
sni-blockingdpi

Extracted by claude-sonnet-4-6 — review before relying.