Anticensorship in the Internet's Infrastructure
freedom-to-tinker.com
freedom-to-tinker.com
But somehow the telex station does, without initially decrypting every packet. So I guess the arms race will be a short one as whatever telex uses as a decrypt me signal will be replicated.
Unfortunately, and rather ironically, my client's proxy is blocking telex.cc so I cannot read any details on the steganography.
How does the client tag connections?
When establishing a normal HTTPS connection, the client sends a random number (called the ClientHello nonce). To create a Telex connection, the client replaces this number with what we call a tag — essentially, an encrypted value that looks random until it's decrypted. Decrypting Telex tags requires a private key contained in Telex stations. Since the censor doesn't have this key, it can't tell the difference between tags and the random numbers used in normal connections.
In addition to marking connections that are requests for anticensorship service, Telex tags convey information that allows Telex stations to decrypt the secure HTTPS connection that the client establishes with the non-blacklisted destination website. This lets the Telex station replace the contents of the connection with data from a blacklisted site.
No no, this isn't security by obscurity. By your definition, every encryption scheme provides security by obscurity of encryption keys (kept a secret) and data (that looks "random"). :-)
The details of this implementation are public so that anyone can review it. Does http://viewtext.org work behind your proxy? If not, have you tried Tor http://torproject.org?