Skip to content

Add Chrome 153 ClientHello profile - #420

Open
wywywywycloud wants to merge 1 commit into
refraction-networking:masterfrom
wywywywycloud:fix/chrome-153-clienthello
Open

wywywywycloud wants to merge 1 commit into
refraction-networking:masterfrom
wywywywycloud:fix/chrome-153-clienthello

Conversation

@wywywywycloud

Copy link
Copy Markdown

Summary

  • add HelloChrome_153 and update HelloChrome_Auto
  • match current Chrome's signature_algorithms with a leading GREASE value and ML-DSA-44/65/87
  • include the empty trust_anchors extension (0xca34) and update GREASE seed handling
  • add regression coverage for the profile, extension encoding, and signature-algorithm GREASE

Fixes #397.

Verification

  • go test ./...
  • go test -race ./...
  • go vet .
  • local loopback capture of the generated ClientHello confirmed trust_anchors on the wire as ca34 0002 0000, a randomized GREASE signature scheme, and ML-DSA schemes 0904, 0905, and 0906

Scope and limitations

This fixes a specific, measured ClientHello mismatch; it does not claim complete undetectability.

Chrome's trust_anchors behavior is feature- and platform-dependent. This profile matches captures where the feature is enabled and Chrome sends an empty RequestedTrustAnchorList.

The ML-DSA codepoints are advertised for ClientHello fingerprint parity. uTLS does not currently implement ML-DSA certificate-signature verification, so a server that selects an ML-DSA-only certificate chain can still fail the handshake.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Chrome is missing the trust_anchors ClientHello extension

1 participant