FINDING · DETECTION

The GFW universally uses DNS poisoning rather than IP blocking to censor CDN-hosted content. Across all tested CDN providers (Akamai, CloudFlare, CloudFront, EdgeCast, Fastly, SoftLayer), no CDN edge server IPs were IP-filtered, because a single provider like Akamai hosts content on 170,000 shared edge servers—blocking any IP would collaterally block hundreds of thousands of unrelated publishers.

From 2015-holowczak-cachebrowserCacheBrowser: Bypassing Chinese Censorship without Proxies Using Cached Content · §3.2, §3.3 · 2015 · Computer and Communications Security

Implications

Tags

censors
cn
techniques
dns-poisoningip-blocking

Extracted by claude-sonnet-4-6 — review before relying.