FakeTLS noise size is detectable due to mismatch with real certificate chain sizes
FakeTLS noise size is detectable due to mismatch with real certificate chain sizes: a task in LegoFlow-SWE (Harbor dataset). After the ServerHello + ChangeCipherSpec , the proxy sends an ApplicationData record with random noise intended to simulate the encrypted handshake (EncryptedExtensions…
The task
After the `ServerHello` + `ChangeCipherSpec`, the proxy sends an `ApplicationData` record with random noise intended to simulate the encrypted handshake (EncryptedExtensions, Certificate, CertificateVerify, Finished). Currently the noise length is always drawn from the hardcoded `range` 2500–4700 bytes, but actual…
Part of Lego-X/LegoFlow-SWE.