CENSORS
et Ethiopia
Identified as a Geedge / TSG export customer in the 2025 Geedge/MESA leak. Belt-and-Road framework deployment.
Synonyms: ET
1 paper on file
9 findings tagged here
-
Based on analysis of over 100,000 leaked Geedge Networks documents, InterSecLab (2025) found that Geedge supplied China-GFW-equivalent censorship and surveillance systems to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The systems include deep packet inspection, real-time mobile user monitoring, fine-grained traffic control, regionally customizable censorship rules, and — per WIRED's reporting — ML-based extraction of metadata from encrypted traffic to determine whether a flow is likely from a VPN or circumvention tool.
-
The largest single source of censored domains in the GNL is MESA lab's SNI monitoring dataset (E21-SNI-Top200w.txt) containing 57,362 censored domains, and E21-SNI-Top120W-20221020.txt with 36,467 domains—totaling over 93K domains from network tap data alone for a single country (E21 = Ethiopia per InterSecLab attribution). A separate Xinjiang dataset (XJ-CUCC-SNI-Top200w.txt) contains 13,604 domains. These datasets "do not seem to come from popular domain lists, and instead appear to be gathered from network taps," confirming that Geedge builds censorship target lists directly from passive traffic observation.
-
Internal Geedge documents confirm active contracts to deploy GFW-derived censorship and surveillance infrastructure in Myanmar, Pakistan, Ethiopia, Kazakhstan, and at least one additional unidentified country under the Belt and Road framework, in addition to domestic deployments in Xinjiang, Jiangsu, and Fujian. The exported product (the Tiangou Secure Gateway / TSG line) is not a stripped-down export variant — leaked TSG documentation shows DPI, active-probing, ML classifiers, and granular per-region traffic control rules that mirror the domestic GFW capability set.
-
Geedge co-founder Fang Binxing—named 'father of the Great Firewall' in company documents—explicitly linked Geedge's international expansion to China's Belt and Road Initiative in a 2024 speech, and a Geedge job advertisement sought candidates willing to travel to Pakistan, Malaysia, Bahrain, Algeria, and India. This confirms BRI as an institutional channel for GFW-derived censorship infrastructure export, not merely bilateral commercial deals.
-
Geedge's internal documents show that capabilities developed for one national deployment are explicitly documented to 'trickle down' to all the company's global clients—for example, Psiphon-blocking logic developed for Myanmar was tested for Ethiopia, though not yet fully deployed there as of the leak date. This vendor-mediated capability diffusion accelerates censorship sophistication across all client states simultaneously. The same model was framed at a July 2024 Urumqi meeting as a 'long-term struggle and technical confrontation', with anti-circumvention features developed for Xinjiang slated to roll out to Geedge clients globally.
-
Internal Geedge documentation lists nine commercial VPNs as 'resolved,' providing staff with documented methods for identifying and filtering each protocol's traffic. The leak shows employees reverse-engineering popular circumvention tools to develop blocking signatures, consistent with GFW practices that have rendered most commercial VPNs inaccessible inside China.
-
A September 2025 leak of 100,000+ internal documents from Geedge Networks—co-founded by Great Firewall architect Fang Binxing—confirms export of GFW-derived Tiangou Secure Gateway (TSG) to Myanmar, Pakistan, Ethiopia, and Kazakhstan, providing those governments with DPI-based filtering, throttling, VPN blocking, and internet-blackout capabilities previously unavailable to them. Pakistan's deployment replaced Sandvine's Web Monitoring System infrastructure after Sandvine was sanctioned and exited in 2023, with Geedge apparently utilizing existing Sandvine hardware. Kazakhstan was the first client, from 2018, and Geedge claims more than 40 global service providers as clients under the Belt and Road Initiative framework.
-
As of March 2013, Tor is documented as blocked in China, Iran, Syria, Ethiopia, the UAE, and Kazakhstan. Blocking techniques range from simple IP address blacklisting to a sophisticated hybrid consisting of deep packet inspection (DPI) and active probing.
-
Tor's TLS handshake exhibited multiple distinguishing fingerprints — including the client cipher list, server certificates, and randomly generated SNIs — that were used for TLS-based filtering in Ethiopia, China, and Iran. Inferring the exact byte-level pattern matched by DPI boxes required manual analysis and remains a difficult open problem as of 2013.