GFWeb discovered that the GFW's bidirectional blocking is not symmetric: certain
domains trigger blocking only when probed from inside China, not from outside. This
overturns the prior assumption that the GFW blocks the same domains symmetrically
in both directions. The paper also documents that the GFW has been upgraded to fix
previously-reported evasion techniques, including overblocking mitigation and
improved fragmented-packet reassembly, indicating active engineering iteration on
the censor side.
From 2024-hoang-gfweb — GFWeb: Measuring the Great Firewall's Web Censorship at Scale
· Abstract, §5.3, §6
· 2024
· USENIX Security Symposium
Implications
Circumvention measurement infrastructure that probes the GFW only from outside China will miss a subset of blocked domains; vantage points inside China are required to characterize the full blocklist.
Fragmented-packet evasion techniques (splitting ClientHello across TCP segments, IP fragmentation) that bypassed the GFW in earlier publications may no longer be effective; treat them as deprecated without fresh empirical validation.