FINDING · EVALUATION
CERTainty measured DNS manipulation across thousands of resolvers in 102 countries, identifying state-level censorship in China, Iran, and Russia, among others. The breadth of coverage — both resolver count and country count — demonstrates that TLS certificate validation scales to Internet-wide vantage-point studies.
From 2023-ramesh-certainty — CERTainty: Detecting DNS Manipulation at Scale using TLS Certificates · Abstract / §5 · 2023 · USENIX Security Symposium
Implications
- The Internet-wide resolver coverage confirms that DNS poisoning is not confined to a small set of ISPs; circumvention clients must assume any in-path resolver in CN/IR/RU is potentially compromised and default to encrypted or pinned resolution.
- Measurement infrastructure using cert validation can serve as a canary for circumvention operators to detect when their own domain's DNS records have been hijacked by a censor.
Tags
Extracted by claude-sonnet-4-6 — review before relying.