FINDING · DETECTION
Internal Jira tickets reveal that Psiphon lacked obvious protocol signatures, forcing censors to fall back to IP-based blocking of Psiphon3 client IPs combined with a 'whitelist protection mechanism' that allows traffic when the destination SNI matches a popular domain—an explicit collateral-damage tradeoff documented in the Confluence file 'GTN498 The collateral damage analysis of Psiphon3 Blocking.' A ticket from the Ethiopia (E21) deployment shows customers complaining that the VPN deny policy inadvertently blocked non-VPN applications.
From 2026-ablove-technical-analysis-geedge — Technical Analysis of the Geedge Networks Firewall Source Code Leak · §4.1.2, Figure 2, Figure 3 · 2026 · USENIX Security
Implications
- Strong protocol obfuscation that eliminates obvious signatures forces censors toward blunt IP-blocking, which causes collateral damage on popular SNIs and incentivizes operators to maintain SNI whitelists—circumvention tools that tunnel over CDN IPs or popular SNIs (domain fronting, meek) exploit this whitelist mechanism.
- The Psiphon case demonstrates that the cost of false positives constrains censor aggressiveness; circumvention tools hosted on IPs shared with high-value legitimate services gain meaningful protection from over-blocking pressure.
Tags
Extracted by claude-sonnet-4-6 — review before relying.