Pervasive Encryption: Is the Internet Ready to Hide Everything?

Informing protocol design through crowdsourcing: the case of pervasive encryption

2015-01-01
Anna Maria Mandalari, Marcelo Bagnulo, Andra Lutu
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a crowdsourcing-based methodology to evaluate the feasibility of "Pervasive Encryption" across the Internet. By leveraging over 2,000 global vantage points, the authors assess the success of establishing TLS connections on 68 non-standard ports, ultimately determining the impact of network middleboxes on protocol innovation.

TL;DR

Researchers used crowdsourcing to turn thousands of global smartphones and PCs into "measurement probes." They discovered that while most of the Internet is ready for encryption everywhere, traditional web ports (like Port 80) are heavily policed by "middleboxes"—devices that kill connections if they don't see the specific type of traffic they expect.

Background: The Ossified Internet

The Internet was designed to be "end-to-end" transparent, but the reality is an obstacle course of middleboxes. Firewalls, NATs, and proxies often expect Port 80 to contain plain-text HTTP. If you try to run a secure TLS tunnel through it, these boxes might simply drop your packets. This creates Internet Ossification: a state where we can't upgrade our protocols because the network hardware "understands" too much and allows too little.

Motivation: Privacy After the Snowden Era

Following major global surveillance disclosures, the IETF and the research community pushed for "Pervasive Encryption"—the idea that all traffic should be encrypted by default. But before we flip the switch, we need to know: will the middleboxes let us?

Methodology: Crowdsourcing the Global Network

Unlike prior studies that used a handful of university servers, this paper recruited 2,120 participants via the Microworkers platform. This provided a massive, diverse set of vantage points across 53 countries and hundreds of Autonomous Systems (ASes).

Overall Measurement Methodology

The agents attempted connections across three port types:

  • Well-known ports: Ports 0-1023.
  • Registered ports: Ports 1024-49151.
  • Ephemeral ports: Temporary ports used for short-lived connections.

The Core Challenge: Middlebox Hostility

The researchers identified a major culprit in connection failures: Proxies. In mobile networks, 25% of users were behind proxies. When these users tried to use TLS on Port 80, the failure rate skyrocketed to 70%.

Why does this happen? (Packet-Level Intuition)

Middleboxes often use "Late Binding." They don't just forward a TCP SYN packet; they wait to see the first payload (like an HTTP GET). If they see a TLS "Client Hello" instead of a GET on Port 80, they "silently kill" the connection. This explains why the study found that 90.4% of SYN packets for encrypted Port 80 traffic never even reached the server.

Error Rate vs Port Number

Experimental Insights

The data suggests a 90% conditional probability of failure: if TLS fails on Port 80 for a specific user, it is highly likely to fail on every other port for that same user. This indicates that certain network providers are systematically hostile to non-standard traffic.

Fixed vs Mobile Results

Critical Analysis & Conclusion

Takeaway

If you are designing a new protocol today (like TCPCrypt or a custom TLS-based app), do not assume you can use Port 80 as a fallback. While the general success rate of 94% across other ports is encouraging, the mobile ecosystem remains highly restrictive.

Limitations

The study focuses on whether a connection can be established. It does not deeply analyze middleboxes that might let a connection start but kill it later based on traffic patterns (Deep Packet Inspection), which is a common tactic in modern state-level censorship.

Future Outlook

This work paved the way for modern protocols like QUIC (used by Google/Facebook), which encrypts almost everything—including the transport headers—to specifically hide from and bypass these nosy middleboxes. The battle between protocol innovation and network ossification continues, but crowdsourcing has proven to be an essential tool in mapping this invisible battlefield.

Find Similar Papers

Try Our Examples

  • Search for recent studies after 2015 that analyze the impact of QUIC or TLS 1.3 deployment on Internet ossification and middlebox interference.
  • Which paper first formally defined "Internet Ossification" in the context of middleboxes, and how have subsequent works like TCP Fast Open addressed these challenges?
  • Have there been recent research efforts applying crowdsourced measurement techniques to evaluate the performance and reachability of Starlink or other Satellite-based Internet providers?
Contents
Pervasive Encryption: Is the Internet Ready to Hide Everything?
1. TL;DR
2. Background: The Ossified Internet
3. Motivation: Privacy After the Snowden Era
4. Methodology: Crowdsourcing the Global Network
5. The Core Challenge: Middlebox Hostility
5.1. Why does this happen? (Packet-Level Intuition)
6. Experimental Insights
7. Critical Analysis & Conclusion
7.1. Takeaway
7.2. Limitations
7.3. Future Outlook