FINDING · EVALUATION
Eight Indian ASes can collectively intercept 99.14% of AS-level paths connecting all Indian ASes to DNS resolvers, including GoogleDNS and OpenDNS; 4,906 routers across these 8 ASes suffice to launch DNS injection attacks covering the entire country. The same 8 ASes also appear among the 10 key ASes identified for IP filtering.
From 2017-gosain-mending — Mending Wall: On the Implementation of Censorship in India · §4.2 · 2017 · SecureComm
Implications
- Circumvention tools bootstrapping in India must not rely on standard DNS resolution — use pre-distributed IP-literal server addresses or encrypted DNS (DoH/DoT) routed through a non-Indian resolver to avoid the 8 choke-point ASes.
- DNS-based domain-fronting discovery or bridge distribution is particularly fragile in India; prefer out-of-band or IP-literal bootstrap mechanisms for any India-facing deployment.
Tags
Extracted by claude-sonnet-4-6 — review before relying.