FINDING · DETECTION

Chinese browsers transmit GPS coordinates alongside persistent user IDs (IMEI, GAID, CUID) and client IPs to vendor servers with poor transport security; an attacker with access to this stream can trivially detect VPN use without any DPI—GPS coordinates placing a user inside China combined with a non-Chinese client IP is an unambiguous VPN-use signal. This correlation attack succeeds against VPNs with perfect traffic obfuscation because the detection side-channel is entirely outside the encrypted tunnel.

From 2025-rodriguez-revisitingRevisiting BAT Browsers: Protecting At-Risk Populations from Surveillance, Censorship, and Targeted Attacks · §5, §6 · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
ip-blockingtraffic-shape
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.