FINDING · DEFENSE

TLS record fragmentation successfully circumvents the GFW in all tested configurations: splitting the ClientHello across multiple TLS records — whether the split falls before or after the SNI extension — bypasses GFW SNI-based blocking in every case (Table 1). TCP fragmentation after the SNI extension fails, but any TLS-layer fragmentation succeeds.

From 2023-niere-posterPoster: Circumventing the GFW with TLS Record Fragmentation · §3, Table 1 · 2023 · ACM CCS 2023 (poster)

Implications

Tags

censors
cn
techniques
sni-blockingdpi
defenses
pluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.