FINDING · DETECTION
Turkey's filtering of Twitter relied overwhelmingly on DNS manipulation over IP blocking: as of April 24, 2014, only 167 IP addresses were blocked versus 40,566 domain names. Users who received valid DNS answers could browse Twitter without further interference, making foreign DNS servers (Google 8.8.8.8, OpenDNS) an effective circumvention mechanism — reportedly graffitied across Turkey in protest of the ban.
From 2014-anderson-global — Global Network Interference Detection over the RIPE Atlas Network · §4.1 · 2014 · Free and Open Communications on the Internet
Implications
- Hardcode IP addresses or use DNS-independent bootstrapping so clients can reach proxies without relying on valid DNS resolution in a censored environment.
- Treat foreign DNS resolvers as untrusted in high-censorship environments; a censor that controls upstream routing can poison responses regardless of which resolver the client queries.
Tags
Extracted by claude-sonnet-4-6 — review before relying.