@inproceedings{60503,
  abstract     = {{Censors have long censored Transport Layer Security (TLS) traffic by inspecting the domain name in the unencrypted Server Name Indication (SNI) extension. By encrypting the SNI extension, the Encrypted ClientHello (ECH) prevents censors from blocking TLS traffic to certain domains. Despite this promising outlook, ECH’s current capability to contest TLS censorship is unclear; for instance, Russia has started censoring ECH connections successfully. This paper clarifies ECH’s current role for TLS censorship. To this end, we evaluate servers’ support for ECH and its analysis and subsequent blocking by censors. We determine Cloudflare as the only major provider supporting ECH. Additionally, we affirm previously known ECH censorship in Russia and uncover indirect censorship of ECH through encrypted DNS censorship in China and Iran. Our findings suggest that ECH’s contribution to censorship circumvention is currently limited: we consider ECH’s dependence on encrypted DNS especially challenging for ECH’s capability to circumvent censorship. We stress the importance of censorship-resistant ECH to solve the long-known problem of SNI-based TLS censorship.}},
  author       = {{Niere, Niklas and Lange, Felix and Heitmann, Nico and Somorovsky, Juraj}},
  keywords     = {{censorship, circumvention, ECH, TLS}},
  location     = {{Washington, D.C.}},
  title        = {{{Encrypted Client Hello (ECH) in Censorship Circumvention}}},
  year         = {{2025}},
}

@inproceedings{57816,
  abstract     = {{TLS-Attacker is an open-source framework for analyzing Transport
Layer Security (TLS) implementations. The framework allows users
to specify custom protocol flows and provides modification hooks to
manipulate message contents. Since its initial publication in 2016 by
Juraj Somorovsky, TLS-Attacker has been used in numerous studies
published at well-established conferences and helped to identify
vulnerabilities in well-known open-source TLS libraries. To enable
automated analyses, TLS-Attacker has grown into a suite of projects,
each designed as a building block that can be applied to facilitate
various analysis methodologies. The framework still undergoes
continuous improvements with feature extensions, such as DTLS
1.3 or the addition of new dialects such as QUIC, to continue its
effectiveness and relevancy as a security analysis framework.}},
  author       = {{Bäumer, Fabian and Brinkmann, Marcus and Erinola, Nurullah and Hebrok, Sven Niclas and Heitmann, Nico and Lange, Felix and Maehren, Marcel and Merget, Robert and Niere, Niklas and Radoy, Maximilian Manfred and Schmidt, Conrad and Schwenk, Jörg and Somorovsky, Juraj}},
  booktitle    = {{Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)}},
  keywords     = {{SSL, TLS, DTLS, Protocol State Fuzzing, Planning Based}},
  location     = {{Hawaii}},
  title        = {{{TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations}}},
  year         = {{2024}},
}

