FINDING · EVALUATION

CERTainty demonstrates that state-level DNS censorship in China, Iran, and Russia operates through resolver-level injection: queries sent to in-country resolvers return IPs whose TLS certificates do not correspond to the queried domain, revealing blockpage or sinkhole destinations. This pattern is distinguishable from CDN or geographic DNS behavior precisely because blockpage servers cannot present a valid certificate for the censored hostname.

From 2023-ramesh-certaintyCERTainty: Detecting DNS Manipulation at Scale using TLS Certificates · Abstract / §5–6 · 2023 · USENIX Security Symposium

Implications

Tags

censors
cnirru
techniques
dns-poisoningip-blocking

Extracted by claude-sonnet-4-6 — review before relying.