FINDING · DETECTION

Seven of the 220 banned apps (Tier 1, including TikTok, Likee, Kwai, UC Browser, FaceU, Hago, and V-Fly) used the Android TelephonyManager.getSimCountryISO() API to read the primary SIM's country code and embed a carrier_region=IN parameter in HTTP requests, enabling server-side identification and blocking of Indian users regardless of source IP or VPN state. A dual-SIM phone with an Indian SIM in the secondary slot only (primary empty or non-Indian) bypassed the check.

From 2024-gosain-outOut in the Open: On the Implementation of Mobile App Filtering in India · §4.3 · 2024 · Passive and Active Measurement Conference

Implications

Tags

censors
in
techniques
ip-blockingkeyword-filtering

Extracted by claude-sonnet-4-6 — review before relying.