FINDING · DETECTION

The GFW does not distinguish DNS query traffic directionality, injecting forged replies for both inbound and outbound queries on monitored links. This causes collateral censorship of DNS resolvers outside China when they contact authoritative nameservers located in or whose paths transit China, even for non-Chinese clients.

From 2014-anonymous-towardsTowards a Comprehensive Picture of the Great Firewall's DNS Censorship · §2 · 2014 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.