
DEF CON 33 - TSPU: Russia's Firewall and Defending Against Digital Repression - Benjamin Mixon-Baca
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 41:24
Russia's Internet Censorship: Technical Analysis and Circumvention Methods
Summary
Russia's sovereign internet law (federal law number 90-FZ) has established a sophisticated censorship system implemented by Roskomnadzor (RKN) through TSPU devices equipped with EcoFilter DPI technology. Unlike China's Great Firewall, Russia's system operates "in-path" and closer to users (approximately 5 hops away), allowing it to directly throttle connections rather than using reset injections. This makes Russia's censorship harder to detect as intentional blocking. The TSPU devices, manufactured by RDP.r, are technically impressive as they can process over 100 Gbps of traffic—significantly more than similar systems. The censorship primarily targets political content deemed destabilizing to the government, including sites like CNN, X (Twitter), Google, and Voice of America.
Key Technical Details
- Deployment Strategy: Russia's censorship system must be deployed "in-path" and closer to users due to the country's ISP ecosystem, which has an order of magnitude more autonomous system numbers than China and more regionally distributed ISPs.
- Blocking Method: The TSPU devices can throttle connections directly because they're in the traffic path, making censorship appear like legitimate network disruption rather than intentional blocking.
- Regional Specificity: This deployment approach allows Russia to implement more targeted, region-specific censorship compared to China's system.
Circumvention Techniques
- Server-side Bypass: Researchers discovered that "simultaneous open" exploits can bypass censorship by exploiting ambiguities in TCP connection tracking. This technique involves coordinating an internal client with an external server to establish a connection that confuses the TSPU's state tracking.
- Client-side Bypass: A "5-ACK" strategy was accidentally discovered that appears to disrupt the TSPU's internal state during TLS handshakes. This method
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
We have a real treat for you today. It's uh Russia's firewall and defending against the future of digital repression uh with Benjamin Mixon Baka. Have a great talk. >> Yeah, thank you. [Music] >> Hi. Um thank you for coming to my talk today. I hope you are excited to learn about Russia's fancy new firewall. So to sort of motivate this discussion, uh I'm going to start with an example. So imagine you want to surprise your grandmother for her birthday. Uh she absolutely loves cherry peach and eggplant cobbler. And so you being the good grandson or granddaughter that you are, you go online and you're searching for recipes and you expect to see images like what uh what you see here right on your phone and to your horror, your dismay, your disgust, you see these uh block pages, right? And then …