FINDING · DEFENSE

TCP segmentation — splitting DNS-over-TCP messages into 20-byte fragments — successfully circumvented DNS censorship for 40 of 41 tested resolvers in China. In Iran, TCP segmentation is inconsistently effective: it succeeds in some scan runs and fails entirely in others, suggesting the Iranian censor can reassemble TCP fragments when processing capacity permits.

From 2026-niere-dpyproxy-dnsTowards Automated DNS Censorship Circumvention · §6.2.1, §6.2.2 · 2026 · FOCI 2026 (Free and Open Communications on the Internet)

Implications

Tags

censors
cnir
techniques
dpidns-poisoning
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.