tl;dr:
- mostly, hosts ignore the mss sent
- most of the interesting behaviour comes from the extremes: mss=1 and mss=1440
- setting mss=(an atypical value, say 1275 or 1411) ought to spot hosts that simply reflect MSS values
- setting mss=1024 apparently will spot a bunch of (Microsoft?) hosts returning MSS=956
- passively, mss=1220, 1360, 1410 may help identify CDN/non-CDN nodes inside yahoo/edgecast, google, facebook respectively
Variation is less than I initially thought; just enough for me to notice