Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Section 6.8 of the PDF deals with those pesky encrypted packets.


Only insofar as it talks about 1) partially encrypted traffic, 2) using local copies of the keys for decryption, or 3) flow identification of IPSEC. Properly done I don't see an IPSEC/L2TP VPN being vulnerable to DPI - although you will want a constant stream of "filler" packets going back and forward to thwart traffic analysis.

Otherwise, the whole thing is a disgrace and the engineers responsible for working on it need to take a long look at themselves. Dressing it up with examples of "Detection of Malware" is disingenuous, it's abundantly clear what the use case is here.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: