Pervasive Encryption: Is the Internet Ready to Hide Everything?
Informing protocol design through crowdsourcing: the case of pervasive encryption
This paper introduces a crowdsourcing-based methodology to evaluate the feasibility of "Pervasive Encryption" across the Internet. By leveraging over 2,000 global vantage points, the authors assess the success of establishing TLS connections on 68 non-standard ports, ultimately determining the impact of network middleboxes on protocol innovation.
TL;DR
Researchers used crowdsourcing to turn thousands of global smartphones and PCs into "measurement probes." They discovered that while most of the Internet is ready for encryption everywhere, traditional web ports (like Port 80) are heavily policed by "middleboxes"—devices that kill connections if they don't see the specific type of traffic they expect.
Background: The Ossified Internet
The Internet was designed to be "end-to-end" transparent, but the reality is an obstacle course of middleboxes. Firewalls, NATs, and proxies often expect Port 80 to contain plain-text HTTP. If you try to run a secure TLS tunnel through it, these boxes might simply drop your packets. This creates Internet Ossification: a state where we can't upgrade our protocols because the network hardware "understands" too much and allows too little.
Motivation: Privacy After the Snowden Era
Following major global surveillance disclosures, the IETF and the research community pushed for "Pervasive Encryption"—the idea that all traffic should be encrypted by default. But before we flip the switch, we need to know: will the middleboxes let us?
Methodology: Crowdsourcing the Global Network
Unlike prior studies that used a handful of university servers, this paper recruited 2,120 participants via the Microworkers platform. This provided a massive, diverse set of vantage points across 53 countries and hundreds of Autonomous Systems (ASes).

The agents attempted connections across three port types:
- Well-known ports: Ports 0-1023.
- Registered ports: Ports 1024-49151.
- Ephemeral ports: Temporary ports used for short-lived connections.
The Core Challenge: Middlebox Hostility
The researchers identified a major culprit in connection failures: Proxies. In mobile networks, 25% of users were behind proxies. When these users tried to use TLS on Port 80, the failure rate skyrocketed to 70%.
Why does this happen? (Packet-Level Intuition)
Middleboxes often use "Late Binding." They don't just forward a TCP SYN packet; they wait to see the first payload (like an HTTP GET). If they see a TLS "Client Hello" instead of a GET on Port 80, they "silently kill" the connection. This explains why the study found that 90.4% of SYN packets for encrypted Port 80 traffic never even reached the server.

Experimental Insights
The data suggests a 90% conditional probability of failure: if TLS fails on Port 80 for a specific user, it is highly likely to fail on every other port for that same user. This indicates that certain network providers are systematically hostile to non-standard traffic.

Critical Analysis & Conclusion
Takeaway
If you are designing a new protocol today (like TCPCrypt or a custom TLS-based app), do not assume you can use Port 80 as a fallback. While the general success rate of 94% across other ports is encouraging, the mobile ecosystem remains highly restrictive.
Limitations
The study focuses on whether a connection can be established. It does not deeply analyze middleboxes that might let a connection start but kill it later based on traffic patterns (Deep Packet Inspection), which is a common tactic in modern state-level censorship.
Future Outlook
This work paved the way for modern protocols like QUIC (used by Google/Facebook), which encrypts almost everything—including the transport headers—to specifically hide from and bypass these nosy middleboxes. The battle between protocol innovation and network ossification continues, but crowdsourcing has proven to be an essential tool in mapping this invisible battlefield.
