Skip to content

Inside View · DNS injection

The firewall, measured from inside it

Every other network signal on this site observes the Great Firewall from outside and reasons inward. OONI ingests measurements other people's probes already uploaded. Bleedthrough reads the injection that leaks out of China. Inside View runs it the other way: it commands live DNS lookups on volunteer probes inside mainland China and publishes the answers those probes were handed. An answer counts as forged when it shares no address with a control arm measured outside China in the same round, so truth is fixed per round rather than read off a stale list of known forged addresses.

Outside in

A probe outside China queries inward, or reads what escaped the wall, and infers what a user inside would have received. The inference is sound. It is still an inference, and differences between one Chinese province or one Chinese network and another are largely invisible to it.

Inside out

A probe inside China asks, and reports what it was actually given. Injection happens on the path between that probe and its resolver, and that path is inside, so disagreement between Beijing and Guangzhou, or between one operator and another, is a thing this measurement can see rather than a thing it has to assume away.

Palimpsest is two instruments run as one public good: a China censorship observatory and a pre-registered, hash-chained AI eval registry whose chain roots are anchored outside the project. MIT licensed, developed in the open, never a commercial product, and never monetising the people or topics it observes. What it costs to run.

The reading

Figures on this page are read from inside-view-latest.json when the page loads. Nothing here is typed in by hand. If the numbers below do not appear, the fetch failed or JavaScript is off, and the raw file is the reading.

Block rate · censored panel

%

The denominator is censored panel domains that produced a classifiable answer from at least one in-China vantage, not the whole panel. Benign controls are excluded from it by construction: their job is to prove the classifier works, not to be counted as blocked.

Where the instrument sees from

Two views of the same round. The map places every mainland city that hosted a probe this round; the strip groups the same observations by the cloud operator whose network they sat on. No national borders are drawn, deliberately: this maps the instrument, not the territory, and the instrument sees datacentre networks in these cities — not households, and not a country.

Vantage cities, this round

inside-view-latest.json

Per-city probe positions and verdict counts are published in the raw reading, and this map draws from it when the page loads.

The same observations, by network operator

the second angle

Grouped from the same published reading when the page loads.

A domain forged inside a single operator's network is reported as a single operator, not as national filtering — the map and this strip exist to keep that distinction visible.

How the round was gated

Honesty machinery

A round can fail in a way that looks like calm

If the classifier breaks, every domain reads clean and an observatory reports quiet. So the panel carries two globally constant domains that must come back clean from inside China. If they read forged, the round is thrown away rather than published. A censorship observatory cannot report that it saw nothing unless it can also show that it would have seen something.

Control state, this round

What each state permits

Sighted
At least one censored domain read forged and every benign control read clean. Injection is visible and is not being invented. A block rate may be derived.
Blind
The controls behaved but no censored domain read forged. That is a coverage gap, not an all clear, so the round is published with no block rate at all.
Degraded
A benign control read forged, or too little answered to judge. The classifier is untrustworthy this round, so nothing is published and the previous reading stands.

The negative controls, this round

These resolve to fixed anycast addresses that are identical everywhere on earth, so they cannot geo-split and be mistaken for injection. An earlier version of this panel used a China-hosted domain as its control and tripped the gate on the first live round, which is exactly what the gate is for.

Ethics of the vantage

The probes belong to real people inside China

Globalping's China pool is mostly cloud machines, but it also holds household connections: cable subscribers, small provincial ISPs, somebody's home router. Hosting a probe is agreement to run measurements. It is not agreement to have a home connection ask the Great Firewall about WikiLeaks.

The first deployment of this collector asked Globalping for probes in China by country and took whatever answered. Household networks answered alongside the cloud ones, and those connections were made to emit DNS queries for wikileaks.org, torproject.org, rsf.org and hrw.org from inside China.

This is the one class of error the control gates could never catch, because the harm does not land on the data, it lands on a person, and no downstream check undoes a packet already sent. Every other failure mode in this signal is recoverable by discarding a round. That one is not.

Two things changed, and both narrow what the instrument is allowed to do. Every query in the panel is now pinned to datacenter networks through Globalping's country-plus-network filter, so a sensitive lookup is only ever carried by a cloud host. And a test in the suite asserts that no request may ever target China by country alone, so the loose form of the query cannot come back by accident.

The panel itself is small and fixed for the same reason. It is a short list, written out in the collector where anyone can read it, and it does not grow to whatever a probe could be made to ask. Its size is the figure printed in the reading above. What may be asked is bounded by who has to carry the question.

This costs real measurement power, and the cost is stated in the reading rather than hidden in a footnote. The feed carries the limitation in its own words, and the page prints it:

vantage_limitation, as published

The full change, including what was drawn and what it was made to ask, is in the repository: a volunteer hosting a probe did not consent to query WikiLeaks.

Vantages, and why the count decides the verdict

Networks represented this round

A forged answer proves that something on the path rewrote the reply. It does not by itself prove national filtering. Tencent and Alibaba each operate their own resolver interception, so forgery seen only inside one operator's network is that operator's behaviour as far as this measurement can tell. A blocking verdict therefore requires agreement across at least two distinct ASNs, and a unanimous single-network result is published as SINGLE_OPERATOR instead of as blocked. Disagreement between vantages is reported at any width, because disagreement is informative even when attribution is not.

attribution_caveat, as published

The panel, domain by domain

Each row is one domain measured from several in-China vantages in the same round. Counts are vantages, not queries. A silent vantage returned no A record at all, which is a measurement in its own right and is never folded into either the forged or the clean side.

Every vantage, every answer

The receipts. For each domain: what the control arm outside China resolved, then what each in-China vantage was handed, with its city and its network. Forged answers differ from vantage to vantage even when every vantage is blocked, because the injector draws from a rotating pool, so the states are compared and the addresses never are.

What each verdict means

Uniform blocked
Forged from every answering vantage, across at least two distinct networks.
Regional
Forged from some vantages and resolving correctly from others. Filtering is not uniform, and this is the finding an outside vantage cannot produce.
Single operator
Forged from every answering vantage, but only one network was represented. Not distinguishable from that operator's own resolver behaviour, so not published as blocked.
Uniform clean
Resolved correctly from every answering vantage.
Insufficient
Fewer than two vantages answered. Regional variation cannot be judged at that width.

Provenance

Measurements run on Globalping, operated by jsDelivr, on probes hosted by volunteers. The published file is rewritten only when the answer changes, so an unchanged round leaves the timestamp where it was rather than manufacturing movement.

Palimpsest

An open source observatory of information control, run as a public good. It watches the censor and never the censored: public reads only, no person inside is ever asked to act, and no state-aligned model is ever the analyst. Every finding ships its raw evidence. The same project runs a verifiable AI eval registry whose runs are pre-registered, hash-chained and anchored outside the project, so a result cannot be quietly rewritten after the fact.