$ docker logs shadowsocks 2>&1| grep "AEAD: repeat salt detected" | wc -l
16468
times total. The last 6 happened less than 10 minutes ago. My expectation is, TLS will be probed even more, because the handshake parameters (the order of CipherSuite for example) itself could leak a lots of info about the client&server.It's not easy to build a protocol that is cryptographically safe all while keep the traffic characterless/innocent. Could be a "World Changing Event" if somebody discovered a way through.
Although, if only Signal is making nice sized packets, that could be suspicous.
If the censor already knows about your proxy they would have no reason to test it... The whole point is that there isn't a central list of proxies for them to easily block.
YET. I wonder if someone will find a simple way to map these with shodan.
If it's trivial to figure out (by doing a nice handshake) whether something is a certain kind of proxy, then the cat-and-mouse game is reduced from finding lots of mice to updating the cat system to test whether passing animals are mice and instantly wiping out the mice population.