FINDING · DEFENSE

The GFW operates as an on-path censor that injects forged DNS responses faster than the real resolver but cannot suppress the legitimate response from also arriving. Waiting approximately 3 seconds and accepting the last-received UDP response circumvented GFW DNS injection for 40 of 41 tested public resolvers in China; the single exception (Cloudflare 1.1.1.1) was IP-blocked via packet dropping rather than injection racing.

From 2026-niere-dpyproxy-dnsTowards Automated DNS Censorship Circumvention · §6.2.1 · 2026 · FOCI 2026 (Free and Open Communications on the Internet)

Implications

Tags

censors
cn
techniques
dns-poisoningip-blocking

Extracted by claude-sonnet-4-6 — review before relying.