FINDING · DEFENSE

The authors recommend that users encrypt DNS queries (DoT or DoH) to prevent the GFW's on-path injectors from intercepting and poisoning them, and additionally block all outgoing traffic to the known pool of GFW-injected IP addresses to avoid silently connecting to potentially surveillance-oriented infrastructure.

From 2025-sheffey-extendedExtended Abstract: I’ll Shake Your Hand: What Happens After DNS Poisoning · §4 · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dns-poisoning
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.