FINDING · DETECTION

The Russian DPI maintains two whitelists that exempt flows from the freeze: (1) a SNI-based whitelist covering select domains (visible in the TLS ClientHello), and (2) a CIDR-based whitelist of IP subnets for trusted destination servers. The SNI whitelist can be exploited by VLESS+Reality clients using an allowed SNI value as the apparent destination; the CIDR whitelist requires routing through an IP from a whitelisted prefix, making circumvention 'extremely difficult' without an intermediate node in a whitelisted subnet.

From 2025-hyperion-cs-censor-has-newCensor has a new method of blocking · upd3, upd4 · 2025 · net4people/bbs

Implications

Tags

censors
ru
techniques
sni-blockingip-blockingdpi
defenses
realityvless

Extracted by claude-sonnet-4-6 — review before relying.