FINDING · EVALUATION
Open DNS resolvers, widely available across the internet as public services, make DNS poisoning trivially detectable globally: a researcher can connect to a resolver in a target country and compare responses against a trusted reference resolver, without requiring volunteer proxies or in-country infrastructure.
From 2011-wright-fine-grained — Fine-Grained Censorship Mapping: Information Sources, Legality and Ethics · §4.2 · 2011 · Free and Open Communications on the Internet
Implications
- DNS poisoning remains one of the cheapest and easiest censor techniques to detect and bypass — circumvention clients should treat DNS responses from within censored networks as untrusted and always use an encrypted, out-of-band resolver (DoH/DoT).
- Use open-resolver divergence as a fast, low-cost signal to detect new DNS-based blocking before investing in full active probing campaigns.
Tags
Extracted by claude-sonnet-4-6 — review before relying.