2026-gohoski-russia-possible-tun

[Russia] Possible TUN detection on DPI level?

Abstract

A user reports that enabling TUN mode with VLESS+REALITY proxy configuration on Russian mobile ISP Beeline (AS16345) causes systemic connection degradation after 5–15 minutes, restricting access to only the government MAX messenger service. The phenomenon occurs system-wide across devices, is specific to Windows TUN mode (not occurring on Android or with system proxy), and is consistently reproducible. Commenters hypothesize DNS anomalies or connection-pattern detection as the DPI-level vector.

Team notes

Auto-ingested via corpus-crawl. Tags proposed by Claude Haiku 4.5; review and tighten before relying. Documents a novel Russian DPI detection capability targeting TUN mode traffic; relevant for Lantern's defense strategy against connection-state analysis.

Tags

censors
ru
techniques
dpithrottling
defenses
vlessreality

findings extracted from this paper