FINDING · DEFENSE

TLS record fragmentation is implementable entirely in userspace at the application layer and requires no elevated privileges, unlike TCP segmentation which requires raw socket access. The authors' DPYProxy tool demonstrates a MITM approach that wraps TLS messages into smaller records before transmission without breaking the TLS handshake, since TLS records are unprotected during the handshake phase.

From 2023-niere-posterPoster: Circumventing the GFW with TLS Record Fragmentation · §2, §5 · 2023 · ACM CCS 2023 (poster)

Implications

Tags

censors
cn
techniques
sni-blocking
defenses
pluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.