FINDING · DEPLOYMENT
Russia's TSPU ("Средства противодействия угрозам") system is deployed inline at individual ISP edges rather than at centralized internet exchange points, producing substantial per-ISP heterogeneity: some providers apply layer-7 SNI/Host filtering while others rely primarily on IP-prefix blocklists, and QUIC/HTTP3 is blocked at several major providers. Rollout timing and enforcement depth vary measurably across autonomous systems, meaning a single "Russia passes/fails" test fixture systematically underestimates blocking coverage.
From 2024-xue-tspu-russia — Tspu: Russia's decentralized censorship system · §4–§5 · 2024 · IMC
Implications
- Segment Russia measurements and bandit dimensions by ASN, not by country — a circumvention technique that survives Rostelecom may fail at MTS or Beeline.
- Protocols relying on QUIC for obfuscation (e.g. Hysteria2) must account for QUIC being blocked outright at a meaningful fraction of Russian ISPs.
- SNI-based blocking means ECH/ESNI and domain-fronting remain the primary defenses for TLS-based transports; IP-prefix approaches alone are insufficient.
Tags
Extracted by claude-sonnet-4-6 — review before relying.