2026-ahmad-more-space-less
findings extracted from this paper
-
Encrypted DNS (DoH, DoT) and Encrypted ClientHello (ECH) fully hide plaintext domain names from on-path observers but leave destination IP addresses visible, enabling IP-based fingerprinting with no protocol-level metadata required. An adversary collecting only NetFlow/IPFIX destination-IP records—without TLS fingerprints, packet timing, or port metadata—correctly identifies 72% of all 520K dual-stack websites over IPv4 and 68% over IPv6.
-
IP-based fingerprints are operationally stable: approximately 60% of domains exhibit no IP changes across the three-month measurement period for both IPv4 and IPv6. Among churning domains, per-domain churn behavior is comparable across protocols—about 28% of churning IPv4 domains rotate within one hour on average vs 35% for IPv6. Fingerprint databases of ≈100 KB per site (50–60 GB for 520K sites) can be maintained with only periodic DNS re-resolution at negligible overhead for adversaries already collecting NetFlow data.
-
IP-based website fingerprinting achieves 93–94% top-1 accuracy on dual-stack incomplete websites (those with any IPv4-only third-party dependencies) using both IPv4 and IPv6 fingerprints across 228K sites. For dual-stack complete sites (all resources reachable over IPv6), accuracy drops to 56% over IPv4 and 45% over IPv6. The discriminating signal comes almost entirely from secondary resource IPs: using only the primary domain's IP yields 5–8% accuracy regardless of protocol.
-
IPv6 does not inherently worsen fingerprinting privacy: dual-stack complete sites are measurably harder to fingerprint via IPv6 (45%) than IPv4 (56%), contrary to community fears. The key driver is not the protocol but hosting provider behavior—Cloudflare, Google, and Fastly co-locate large clusters of domains behind a small set of shared IPv6 addresses, creating structured similarity clusters that reduce classifier separability, while Amazon allocates domains across vast unique IPv6 prefixes, increasing fingerprintability.
-
Raw IPv6 address entropy is inflated by continuous discovery of previously-unseen addresses throughout the measurement period (1.04M distinct IPv6 vs 552K IPv4 addresses observed), giving a misleading impression of higher fingerprint discriminability. Realized entropy—computed per crawl-batch snapshot to exclude ephemeral addresses never seen during testing—shows more than 20% of IPv6 addresses provide less information gain than their IPv4 counterparts, explaining why dual-stack complete IPv6 fingerprinting accuracy (45%) underperforms IPv4 (56%) despite higher raw uniqueness.