Longitudinal GFWeb data spanning 20 months shows the GFW actively patched
previously-published evasion findings during the measurement period: overblocking
bugs reported in academic papers were fixed, and fragmented-packet reassembly
failures that researchers used to bypass blocking were corrected. This demonstrates
that the GFW operator monitors published research and iterates on the system in
response to disclosed vulnerabilities.
From 2024-hoang-gfweb — GFWeb: Measuring the Great Firewall's Web Censorship at Scale
· Abstract, §5.4, §6
· 2024
· USENIX Security Symposium
Implications
Published evasion techniques have a limited operational lifetime once disclosed; circumvention tools should not rely on a single known GFW bug and must have layered fallback strategies that remain effective after the bug is patched.
Coordinated disclosure or embargo of evasion techniques (delaying publication until a fix is deployed in tools and propagated to users) is especially important given the GFW's demonstrated ability to patch quickly after public disclosure.