FINDING · EVALUATION
CDN infrastructure causes 61%–92% of country-specific Alexa top-1k websites to be hosted within the client's own country across India, Iran, Saudi Arabia, Brazil, and the US, as measured by the authors' R-CBG multilateration technique achieving >89% accuracy. This traffic localization means web requests to popular sites rarely cross national borders, undermining the foundational assumption of decoy routing, domain fronting, CacheBrowser, and CovertCast.
From 2021-gosain-too — Too Close for Comfort: Morasses of (Anti-) Censorship in the Era of CDNs · §4.2, §5.2 · 2021 · Privacy Enhancing Technologies
Implications
- Decoy routing implementations must not rely on Alexa-popular sites as overt destinations without verifying out-of-country hosting — 61–92% of those sites resolve to in-country CDN front-ends, so DR packets never cross the border to reach the decoy router.
- Actively pre-screen overt-site candidates using RTT-based geolocation (not IP geolocation DBs) to confirm they are hosted outside the censor's boundary before including them in the overt-site pool.
Tags
Extracted by claude-sonnet-4-6 — review before relying.