FINDING · DEFENSE
An experimental 'random-and-mimic' option in snowflake-proxy produced a DTLS ClientHello fingerprint distinct from any observed standard fingerprint and was not blocked by the Russian filter. The covert-dtls library under development by the Tor Anti-Censorship team systematically randomizes the DTLS ClientHello handshake to defeat JA3/JA4-based classification.
From 2026-wkrp-snowflake-targeted-dtls-filtering — Snowflake-targeted DTLS filtering in Russia, starting 2026-03-30 · kad09 report + abstract team notes · 2026 · net4people/bbs
Implications
- Merge and ship covert-dtls into the default Snowflake client and proxy path as the highest-priority unblocking action; the defense is already validated by in-field PCAP evidence.
- Design the randomization so that the resulting fingerprint does not converge on a new detectable constant — rotate or generate per-session to stay ahead of a fingerprint-update arms race.
Tags
Extracted by claude-sonnet-4-6 — review before relying.