FINDING · DETECTION
HTTP censorship blockpages in Iran fell into two distinct clusters distinguished by IP TTL values: type NTL1 (TTL 53–55) and type NTE1 (TTL 186–188); TCP RST injections targeting TLS and DNS-over-TCP exhibited the same two TTL ranges. The NTL1 injector was absent on June 11 but present on other days, leading the authors to conclude that an entire injector went offline rather than that a single injection pattern was selectively disabled.
From 2026-anon-insights-into-iranian — Insights into an Iranian Internet Shutdown · §2.2.5 · 2026 · Free and Open Communications on the Internet (FOCI)
Implications
- Two independent injector infrastructures with different TTL signatures mean a circumvention probe that succeeds when one injector is offline may fail when both are active — test resilience against both TTL clusters, not just one.
- The transient absence of one injector (NTL1 on June 11) represents a narrow evasion window; however, this is likely maintenance-driven and unpredictable, so it should not be relied upon as a circumvention strategy.
Tags
Extracted by claude-sonnet-4-6 — review before relying.