Runtime
Information Resilience in the Russian Federation: A Longitudinal Study of Censorship, Circumvention, and Information Behavior
Report summary
The preservation of intellectual freedom and the human drive to seek independent information under authoritarian conditions represent a continuous, dynamic struggle between state control and civilian resilience. In the Russian Federation, the digital landscape has undergone a radical transformation.
Key topics
- Runtime
- AI
- WordPress
- GEO
- .NET
- Privacy
- Research Archive
- Strategy
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Introduction
The preservation of intellectual freedom and the human drive to seek independent information under authoritarian conditions represent a continuous, dynamic struggle between state control and civilian resilience. In the Russian Federation, the digital landscape has undergone a radical transformation. What was once a largely unregulated, pluralistic space has evolved into one of the most sophisticated, centrally managed censorship environments in the world1. As the state has escalated its efforts to isolate the domestic internet—the "Runet"—from the global communications infrastructure, Russian citizens have adapted continuously, employing a vast array of technical, social, and historical methods to preserve access to competing viewpoints1. This report provides an exhaustive examination of how individuals in Russia continue to seek, share, and evaluate independent information despite pervasive censorship and information controls. By analyzing historical precedents from the Soviet era, tracing the legal and architectural evolution of the modern Russian censorship apparatus, and dissecting contemporary evasion mechanisms, this analysis highlights the multifaceted nature of information behavior. The assessment synthesizes technical countermeasures—such as Deep Packet Inspection (DPI) evasion, decentralized proxies, alternative transmission vectors, and satellite media—with the sociological and psychological dimensions of navigating a restrictive information ecology. Ultimately, the evidence demonstrates that while state censorship can dramatically increase the friction, danger, and cost of accessing independent information, it rarely succeeds in extinguishing human curiosity or dismantling resilient communities of trust.
Historical Foundations: Soviet Information Control and Civilian Resistance
To understand the contemporary dynamics of Russian internet censorship and the behavioral responses of its citizens, it is essential to examine the historical precedents of information control in the Soviet Union. The modern technological cat-and-mouse game between the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor) and Russian internet users strongly mirrors the ideological battles fought between the KGB and Soviet dissidents.
The Mechanics of Samizdat and the Architecture of Dissent
During the Soviet era, the state maintained a total monopoly on the production and distribution of information. The destruction of pre-revolutionary and foreign literature, the establishment of restricted archival collections (spetskhran), and draconian censorship laws forced independent thought entirely underground4. In response, citizens developed samizdat (literally, "self-published"), a decentralized system of uncensored textual production and circulation that became the backbone of the Soviet human rights and dissident movements5. The production of samizdat was an arduous and highly perilous endeavor. Materials ranging from literary works, such as Boris Pasternak’s Doctor Zhivago, to human rights documentation were painstakingly reproduced using typewriters and carbon paper5. An original typed document, known as the nulevaya zakladka (zero-generation manuscript), was passed to trusted contacts who would retype it, creating a chain-letter style of distribution7. This interpersonal network relied entirely on social trust and horizontal transmission, as possession or distribution of "anti-Soviet propaganda" carried severe penalties, including lengthy sentences in labor camps or indefinite commitment to psychiatric hospitals7. The most prominent example of this era was the Chronicle of Current Events (Khronika tekushchikh sobytiy), an underground human rights bulletin launched in 1968 by Natalya Gorbanevskaya5. Unlike singular literary works, the Chronicle functioned as an alternative news agency. Operating for 15 years, it documented 424 political trials and the extrajudicial persecution of Soviet citizens, including the abuse of punitive psychiatry7. The editors maintained strict anonymity and utilized standard samizdat distribution networks to gather intelligence from across the USSR, explicitly encouraging readers to pass the information securely along horizontal social networks7. The state viewed this decentralized information sharing as a severe threat. A 1970 KGB memorandum authored by Yuri Andropov detailed the geographic spread of samizdat—noting its presence in Moscow, Leningrad, Kiev, and Novosibirsk—and explicitly recognized it as a nascent political opposition mechanism that the existing repressive apparatus struggled to contain10. The Chronicle succeeded precisely because it operated on a decentralized trust protocol: information was verified through trusted nodes and distributed via fragmented, untraceable pathways.
Tamizdat, Radizdat, and the Role of Foreign Broadcasting
The internal circulation of samizdat was fundamentally bolstered by external actors through tamizdat (publishing abroad) and radizdat (foreign radio broadcasts). Documents smuggled out of the Soviet Union were published by Western presses or broadcast back into the USSR via shortwave radio, completely bypassing terrestrial Soviet borders8. The appearance of foreign radio stations broadcasting in Russian shattered the state's internal information monopoly4. In 1968, Radio Liberty established a specialized unit in Munich under the direction of Peter Dornan, dedicated entirely to collecting, archiving, and broadcasting samizdat texts back to the Soviet populace9. This symbiotic relationship between domestic dissidents and international broadcasters effectively weaponized the airwaves against the state's jamming efforts. Shortwave radio receivers became essential tools for Soviet citizens seeking objective news14. The synergy between local documentation and international broadcasting created a feedback loop that amplified the reach of independent thought far beyond the urban intelligentsia, seeding skepticism of official state narratives10.
The Evolution of the Modern Russian Censorship Apparatus
Following the dissolution of the Soviet Union, the Russian internet experienced a period of relatively unhindered growth and pluralism1. However, following the mass political protests of 2011–2012 (the "Bolotnaya Square" protests), which were heavily organized via social media, the Russian state recognized the existential threat posed by uncontrolled, horizontal digital communication15. This realization catalyzed a decade-long legislative and technological campaign to assert "digital sovereignty," transforming the telecommunications landscape into an instrument of access control2.
Legislative Milestones: From Child Protection to the Sovereign Internet
The transition from a free digital space to a highly regulated environment was achieved through a sequence of incremental legislative restrictions. These were initially justified under the guise of public safety before expanding into overt political censorship and mass surveillance15.
| Year | Legislation / Initiative | Strategic Impact on Information Access |
|---|---|---|
| 2012 | Federal Law No. 139-FZ | Created the Unified Register of Banned Websites. Initially framed as a measure to protect children from harmful content (suicide, drugs, exploitation), it established the foundational framework for ISP-level blocking15. |
| 2013 | Lugovoy's Law (398-FZ) | Granted the Prosecutor General's Office the authority to demand extrajudicial blocking of websites within 24 hours for alleged "extremism" or calls for unauthorized protests, bypassing the judicial system entirely15. |
| 2014 | Foreign Agent & Data Laws | Accelerated political blocking following the annexation of Crimea. Independent outlets like Grani.ru and Kasparov.ru were summarily blocked15. |
| 2016-2018 | Yarovaya Law | Imposed sweeping data retention mandates (SORM-3) on telecommunications providers, requiring them to store user traffic, private chats, and metadata for up to six months. The massive financial burden of this storage was passed to consumers, driving up internet costs and severely impacting domestic IT innovation3. |
| 2019 | Sovereign Internet Law (90-FZ) | Mandated the installation of state-controlled Deep Packet Inspection (DPI) equipment (TSPU) on all ISP networks. Established a national DNS and the legal framework to physically isolate the Runet from the global internet in the event of perceived threats1. |
| 2022 | Wartime Censorship Laws | Criminalized "spreading false information" about the Russian military with up to 15 years in prison. Resulted in the mass blocking of Western social media (Facebook, Instagram, Twitter) and an exodus of independent journalists19. |
| 2024-2025 | Protocol Bans & Intimidation | Widespread blocking of standard VPN protocols via DPI signature analysis. Introduction of routine regional mobile internet shutdowns. Transition toward a "whitelist" model of internet access, and new fines for citizens caught intentionally searching for "extremist" materials2. |
The Architecture of the TSPU and Deep Packet Inspection
The technological cornerstone of modern Russian internet censorship is the "Technical Means for Countering Threats" (TSPU), mandated by the 2019 Sovereign Internet Law3. Prior to the TSPU, Roskomnadzor relied on a decentralized model of enforcement, requiring thousands of independent ISPs to manually implement IP and Domain Name System (DNS) blocks via the "Revizor" monitoring system15. This system was prone to inconsistencies and user evasion. The TSPU fundamentally altered this power dynamic. Operating as a model of "decentralized deployment, centralized control," TSPU hardware (frequently utilizing EcoSGE software) is installed directly in the routing paths of Russian ISPs, mobile carriers, and cross-border uplinks20. This equipment grants Roskomnadzor unilateral authority to track, filter, throttle, and reroute traffic without the direct involvement or consent of the host ISPs20. The primary mechanism employed by the TSPU is Deep Packet Inspection (DPI). Unlike traditional firewalls that block traffic based purely on IP addresses or port numbers, DPI systems analyze the payload and metadata of individual data packets as they transit the network20. By inspecting the Server Name Indication (SNI) field in TLS ClientHello messages, the TSPU can identify the specific domain a user is attempting to reach, even if the connection itself is encrypted23.
The Strategy of Throttling and Infrastructure Degradation
Rather than relying solely on binary blocking (where a site is either fully accessible or completely inaccessible), the TSPU increasingly employs bandwidth throttling as an instrument of behavioral conditioning24. Throttling deliberately degrades the quality of service for targeted platforms, rendering them functionally unusable for high-bandwidth activities like video streaming, while technically keeping them online. This tactic was pioneered during the 2021 throttling of Twitter, where the TSPU targeted specific domains (e.g., twimg.com) in the SNI extension and dropped packets to limit bandwidth to an agonizing 130–150 kbps24. In 2024 and 2025, similar massive throttling campaigns were launched against YouTube. By targeting the googlevideo.com SNI in TLS and QUIC protocols, the state severely degraded video playback speeds, blaming "technical overloads" and Google's infrastructure wear-and-tear while implicitly pressuring users to migrate to state-approved domestic alternatives26. This approach exploits human psychology: rather than provoking the sudden outrage of an outright ban, throttling induces user frustration and gradual attrition. Users simply abandon the platform due to the high friction of use, subtly steering the populace toward state-controlled platforms where the narrative is tightly managed24. Furthermore, censorship in 2025 shifted toward targeting foundational internet infrastructure, including Content Delivery Networks (CDNs), alternative DNS systems, and Cloudflare's TLS Encrypted ClientHello (ECH) protocol2. The state actively blocks protocols that conceal the requested website, forcing traffic into the open where the TSPU can inspect and terminate it16. This infrastructure-level warfare demonstrates a transition from targeting specific dissenting voices to degrading the foundational technologies that allow a free internet to function.
Contemporary Digital Circumvention: The Technology of Access
As the Russian state has refined its censorship apparatus, a parallel ecosystem of circumvention technologies has evolved. Citizens seeking independent information rely on a spectrum of tools that systematically exploit the technical and economic constraints of the TSPU. The following sections detail these technologies conceptually, focusing on how they bypass network restrictions without compromising the integrity of remote systems or engaging in illicit network sabotage.
The Evolution of VPNs and the Shift to VLESS/REALITY
Virtual Private Networks (VPNs) have been the most common circumvention tools in Russia, heavily utilized to bypass the blocks on platforms like Instagram and independent news sites20. However, the efficacy of traditional VPN protocols—such as OpenVPN, IPSec, and WireGuard—has steadily and sharply declined2. The TSPU employs signature analysis and statistical flow detection to identify the distinctive cryptographic handshakes and packet sizes of these protocols. Consequently, the TSPU actively drops these connections even if the specific VPN server IP is not on any public blacklist2. In response to this active probing and heuristic blocking, tech-savvy users and circumvention providers have migrated to advanced proxy frameworks, most notably VLESS paired with the REALITY protocol2. Unlike traditional VPNs, which establish a recognizable encrypted tunnel that stands out against normal web traffic, VLESS+REALITY masks the proxy traffic as standard HTTPS traffic directed at a highly reputable, unblocked foreign server (e.g., a major international technology, banking, or retail website)31. When the TSPU's DPI equipment inspects the connection or actively probes the server to determine if it is a hidden proxy, REALITY ensures the server responds exactly as the legitimate target website would31. This "camouflage" strategy fundamentally alters the censorship-countermeasure dynamic. Because the censor cannot definitively distinguish the proxy traffic from legitimate encrypted web traffic, it cannot block the connection without also blocking the highly reputable target site. Doing so would cause unacceptable collateral damage to the domestic economy and essential corporate communications32.
TCP Desynchronization and DPI Evasion Strategies
For users attempting to access throttled or blocked platforms without routing their traffic through external VPN servers, specialized packet manipulation tools have emerged. Open-source utilities like GoodbyeDPI (for Windows), Zapret (for Linux and routers), and ByeDPI (for Android) operate directly on the user's local device23. These tools exploit the operational limitations of the TSPU's DPI hardware. DPI systems are typically stateful, meaning they track the sequence of TCP packets to reconstruct the data stream and read the SNI field to determine the user's destination23. Because DPI systems must process millions of packets per second at ISP choke points, they are optimized for speed and often fail to handle anomalous—but completely standards-compliant—TCP behaviors26. DPI evasion tools utilize several techniques to desynchronize the censor's state machine from the actual connection state established with the destination server:
1. TCP Segmentation: The evasion tool fragments the initial TLS ClientHello message into multiple, tiny TCP packets. The SNI (e.g., youtube.com) is physically split across these fragments. The DPI system, unable to buffer and reassemble the fragments quickly enough due to processing constraints, allows them to pass uninspected. The destination server, however, correctly reassembles the fragments and serves the website23.
2. Fake Packets and TTL Manipulation: The utility injects a forged ClientHello packet containing a benign SNI (e.g., a state-approved website) immediately before the genuine packet. Crucially, this forged packet is given a low Time-To-Live (TTL) value23. The packet survives long enough to reach the TSPU—convincing the censor that the connection is permitted—but expires in transit before reaching the actual destination server. The server only receives the genuine packet that follows it23.
3. QUIC Desynchronization: As platforms like YouTube transition to the UDP-based QUIC protocol (HTTP/3), tools like Zapret utilize kernel-level netfilter queues (nfqueue) to apply similar desynchronization, packet dropping, and fragmentation techniques to UDP streams, ensuring continued access to video content despite TSPU throttling26.
Decentralized Systems: Tor and the Snowflake Network
The Tor network, which anonymizes traffic by routing it through a decentralized overlay of volunteer-operated relays, has long been a staple of Russian digital resistance. In late 2021, Roskomnadzor initiated a sweeping blockade of Tor's directory authorities, public relays, and the torproject.org domain, significantly reducing network accessibility and demonstrating the vulnerability of static infrastructure34. To circumvent this, Russian users increasingly rely on Tor "Bridges"—unlisted entry nodes—and pluggable transports that obscure the nature of the traffic36. The most resilient of these in the Russian context has proven to be the Snowflake protocol. Snowflake leverages WebRTC, a standard widely utilized for peer-to-peer browser video and audio communications37. The architecture of Snowflake relies on human solidarity. Users in uncensored regions install a lightweight browser extension that acts as an ephemeral proxy. When a user in Russia connects via Snowflake, their traffic mimics a standard WebRTC video call connecting to a random volunteer's browser in another country, which then forwards the traffic securely to the Tor network36. Because Snowflake relies on domain fronting and a constantly rotating pool of transient volunteer IP addresses, it represents a moving target that the TSPU cannot easily enumerate or block32. During the blocking events of 2021 and 2022, Tor metrics indicated a massive, sustained surge in Russian bridge users, demonstrating the critical role of peer-to-peer, decentralized circumvention architectures in highly censored environments34.
Circumvention Trade-offs: Evaluating Access vs. Risk
The selection of a circumvention tool inherently involves navigating the complex trade-offs between accessibility, anonymity, reliability, and technical complexity. No single tool solves all censorship problems; instead, users must match their technological posture to their personal threat model.
| Strategy / Tool | Primary Use Case | Advantages | Limitations / Risks |
|---|---|---|---|
| Commercial VPNs | General browsing, bypassing geo-blocks | High accessibility, low technical barrier. Widely available on app stores. | Highly prone to TSPU protocol blocks; high risk of untrustworthy providers logging data or complying with state requests2. |
| VLESS \+ REALITY | Secure, unblockable access to independent media | Extremely resilient to active probing and DPI; masks effectively as normal HTTPS traffic31. | Requires advanced technical knowledge to deploy a personal server; incurs recurring cloud infrastructure costs. |
| DPI Evasion (GoodbyeDPI, Zapret) | Defeating YouTube throttling, Discord access | No external servers required; retains native internet speeds; entirely free23. | Does not hide the user's IP address from the destination server; does not encrypt unencrypted data; may require constant, manual configuration updates to outpace ISP changes26. |
| Tor / Snowflake | High-anonymity browsing, avoiding surveillance | Exceptional anonymity; circumvents IP blocks via volunteer nodes; highly resilient36. | High latency makes it unsuitable for video streaming; frequent CAPTCHAs and platform bans on Tor exit nodes limit usability for everyday tasks39. |
The Resilience of Information Dissemination: Media, Platforms, and Networks
While the technological arms race frequently focuses on the technical means of connection, the ultimate goal of the Russian populace is the retrieval, evaluation, and dissemination of independent information. Media organizations, diaspora journalists, and ordinary citizens utilize a hybrid of digital and physical methodologies to bypass the state's narrative monopoly.
App-Based Evasion, Mirror Publications, and Alternative DNS
Independent media outlets, many forced into exile under the "foreign agent" or "undesirable organization" designations17, have adapted their distribution strategies to outmaneuver DNS and IP blocking. Outlets such as Meduza have successfully utilized custom mobile applications to maintain their readership inside Russia. In 2020, Meduza rebuilt its application from scratch using Flutter, an open-source framework41. By integrating circumvention technologies directly into the application's backend—including domain fronting, rolling IP addresses, and encrypted tunnels—the app dynamically bypasses ISP-level blocks without requiring the user to manually activate a third-party VPN. Furthermore, independent platforms frequently utilize "smart mirror" sites. Automated systems generate new, unblocked URLs for restricted content and disseminate these links via newsletters, encrypted messaging channels, and social media. By the time Roskomnadzor identifies and updates the TSPU blocklist to include the new mirror, the information has already circulated to the target audience, and a new mirror has been provisioned.
The Migration to Telegram and the Threat of the "Max" Splinternet
Social networks and messaging applications function as the primary arteries of independent information. Following the 2022 blockades of Facebook, Instagram, and Twitter, the Russian media landscape fractured dramatically19. A significant portion of the population migrated to Telegram, an application that features both encrypted person-to-person messaging and massive broadcast "channels"42. Telegram occupies a highly complex position in the Russian information ecosystem. It remains one of the few platforms where both pro-state propagandists and exiled opposition figures maintain massive, overlapping audiences, making it the de facto public square of the Runet42. However, as the state recognized its inability to control the narrative on Telegram, it began implementing targeted, intermittent throttling of the application in 2025 and 2026, signaling a willingness to degrade even highly popular platforms2. Concurrently, the state has aggressively promoted domestic alternatives, most notably the "Max" super-app developed by VK2. Modeled heavily after China's WeChat, Max is designed to integrate communications, payments, government services, and digital identity into a single ecosystem43. By subsequently banning end-to-end encrypted Western applications like WhatsApp, Signal, and Discord, the state is attempting to force the population onto Max. Max is explicitly integrated with SORM (System of Operative-Investigative Measures)—the domestic surveillance architecture operated by the FSB—allowing state authorities to monitor communications, metadata, and financial transactions in real-time16. This infrastructure shift signifies an attempt to end the private communications space for the average citizen, transforming daily communication into a heavily surveilled channel43.
Satellite Media: Bypassing the Terrestrial Chokehold
Recognizing the increasing fragility, technical barrier to entry, and cost of digital circumvention, international NGOs and exiled media have revived an updated version of Cold War-era broadcasting: satellite television. In March 2024, Reporters Without Borders (RSF) officially launched the Svoboda Satellite Package44. Utilizing the Hotbird 13 satellite operated by Eutelsat, the Svoboda package broadcasts up to 25 independent Russian-language television and radio channels directly into the Russian Federation, Belarus, and occupied Ukrainian territories44. The content includes programming from exiled outlets such as Echo, Novaya Gazeta Europe, IStories, and the Anti-Corruption Foundation's "Russia's Future" channel, which broadcasts the corruption investigations of the late Alexei Navalny and his widow Yulia Navalnaya44. The strategic brilliance of the Svoboda initiative lies in its physical properties. Satellite broadcasting is a one-to-many technology that does not rely on ISPs, undersea cables, or the TSPU. It is free-to-air, meaning it requires no subscription, leaves no digital footprint, and cannot be traced to individual users, offering ultimate privacy47. Approximately 4.5 million Russian households are already equipped with satellite dishes aligned to Hotbird 1344. Because the satellite also carries apolitical entertainment channels crucial to the Russian populace, the state cannot utilize electronic warfare to jam the independent frequencies without simultaneously disabling the entire satellite array and inciting widespread public anger among loyalist demographics46. In this regard, satellite media functions as a modern equivalent to the BBC and Radio Liberty shortwave broadcasts of the Soviet era, proving that democratic nations can still "export independent journalism, to reverse the logic of propaganda"44.
A Return to Physical Networks: Modern Samizdat
As digital surveillance tightens and algorithms monitor online speech, there is a marked resurgence in physical, offline information sharing. Activists and journalists, such as those associated with Novaya Gazeta Europe, have explicitly reintroduced samizdat methods48. Independent news, human rights reports, and anti-war literature are compiled into printable newsletters, zines, and PDF documents. These files are securely transmitted via encrypted messaging to trusted individuals inside Russia. These individuals then print and physically distribute the materials in their local communities, deposit them in residential mailboxes, or leave them in public spaces such as transport hubs48. This hybrid digital-to-physical distribution model circumvents the TSPU entirely. It limits the digital exposure of the end-consumer and relies heavily on the same horizontal networks of interpersonal trust that sustained the Chronicle of Current Events half a century ago.
The Psychological Dimension: Evaluating Information and Navigating Fear
The persistence of circumvention in Russia cannot be understood solely as a technological phenomenon; it is deeply rooted in the sociology of trust, the cognitive processing of conflicting narratives, and the psychology of living under severe authoritarian pressure.
Preference Falsification and the Illusion of Consensus
State polling and official narratives consistently portray a society unified in its support for state policies and military actions. However, sociological analysis utilizing the framework of "preference falsification"—a concept articulated by Timur Kuran—reveals a vastly different, highly nuanced reality49. Preference falsification occurs when individuals, fearful of social ostracism, job loss, or state reprisal, publicly articulate preferences that contradict their private beliefs50. In the context of the Russian Federation, traditional polling methodologies are heavily skewed by this pervasive fear. While standard polls conducted by organizations like the Levada Center may show high superficial support for the state, specialized list experiments and anonymous surveying mechanisms indicate that genuine, unwavering support is substantially lower, with a vast segment of the population masking their true opinions49. Independent survey data shows that consistent proponents and dedicated opponents of state actions each make up only about a quarter of the population. The remainder navigates a complex middle ground of anxiety, political apathy, and coerced compliance49. This psychological dichotomy drives the massive demand for independent information. Citizens who harbor private doubts rely on VPNs, Telegram channels, and satellite media to validate their internal skepticism and alleviate the profound cognitive dissonance generated by ubiquitous state propaganda. The pursuit of alternative information becomes a psychological coping mechanism—a way of maintaining a coherent grasp on objective reality and avoiding the despair of perceived ideological isolation.
Evaluating Information, Detecting Propaganda, and Maintaining Trust
In an environment saturated with state disinformation, aggressive censorship, and pervasive rumors, evaluating the reliability of information is a paramount cognitive challenge. As demonstrated by recent Levada Center data, trust in state television is steadily declining42. Audiences are shifting their attention to internet sources, but the internet is equally fraught with state-sponsored manipulation and algorithmic echo chambers. To navigate this, Russian citizens construct carefully curated communities of trust. Instead of relying on institutional authority, individuals verify information through interpersonal networks, long-standing parasocial relationships with independent journalists, and specialized, closely monitored Telegram channels42. Similar to the Soviet era, credibility is frequently assigned to sources that accept the risk of state persecution. Media designated as "foreign agents" or "undesirable organizations"—labels intended by the state to stigmatize and criminalize independent reporting—often experience a paradoxical increase in credibility among critical thinkers17. For this demographic, state persecution serves as a perverse guarantor of editorial independence. Conversely, state television is increasingly viewed as entertainment or official signaling rather than a source of factual news.
Navigating Risk: Legality, Anonymity, and Intimidation
The cost of seeking and sharing information has escalated from technical inconvenience to severe legal peril. The state has increasingly weaponized the legal system and public intimidation to deter circumvention. In 2025, new legislation imposed steep fines on citizens for "intentionally" searching online for "extremist" content (a heavily politicized designation), with internet providers actively reporting users who view unapproved military information to the FSB16. The act of utilizing a VPN, once a mundane tool for bypassing geo-blocks, is increasingly treated as an aggravating factor in criminal proceedings2. Furthermore, the introduction of strict SIM card verification and the restriction of virtual phone numbers aims to strip users of their anonymity, tying every digital action to a verified physical identity2. In this environment of pervasive surveillance, citizens must constantly calculate the risk matrix of their digital behavior. The decision to deploy VLESS+REALITY, to operate a Tor Snowflake bridge, or to print a samizdat newsletter is not merely a technical configuration; it is an act of calculated civil disobedience that carries tangible risks to one's freedom and livelihood.
Case Studies in Circumvention
To illustrate the practical dynamics of information seeking under censorship, examining specific case studies reveals the real-world successes and failures of these methodologies.
Case Study 1: The Success of the Svoboda Satellite Package
The launch of the Svoboda Satellite Package in 2024 by Reporters Without Borders represents a highly successful asymmetric response to digital censorship44. By recognizing that the Russian state had successfully compromised the terrestrial internet via the TSPU, RSF shifted the battlefield to space. By leveraging the Hotbird 13 satellite—which already serviced 4.5 million Russian homes with apolitical content—the initiative bypassed ISP blocks entirely44. The inability of the Russian state to jam the signal without crippling domestic entertainment access demonstrated the strategic value of co-opting existing, essential infrastructure for the delivery of independent journalism46.
Case Study 2: The Efficacy of Snowflake During the Tor Blockade
When Roskomnadzor blocked the Tor network's public directory authorities and default bridges in late 2021, the network's accessibility in Russia plummeted34. However, the Snowflake protocol proved exceptionally resilient. Because Snowflake relies on domain fronting and routes traffic through transient, volunteer-operated WebRTC proxies across the globe, the TSPU could not identify a static list of IP addresses to block36. Over the course of 2022, Snowflake usage scaled from 5,000 to 75,000 daily users, heavily driven by Russian citizens seeking a reliable off-ramp to the uncensored web, proving the viability of decentralized, peer-to-peer evasion mechanisms36.
Case Study 3: The Struggle Against Throttling and Infrastructure Bans
Conversely, the state's throttling of YouTube and its wholesale bans on standard VPN protocols (like OpenVPN and WireGuard) represent significant successes for the censorship apparatus28. By utilizing DPI signature analysis, the TSPU effectively rendered commercial VPNs useless for the average, non-technical citizen2. Similarly, by throttling YouTube rather than banning it outright, the state induced massive user frustration24. While technical users deployed tools like GoodbyeDPI to bypass the throttling, the vast majority of mobile and smart-TV users could not implement these workarounds, leading to a measurable decline in YouTube's reach and accelerating the state's goal of migrating the population to domestic, monitored platforms23.
Conclusion: The Enduring Nature of Intellectual Freedom
The contemporary landscape of the Russian internet represents a high-stakes collision between a highly sophisticated, well-funded state censorship apparatus and the decentralized ingenuity of millions of citizens. The implementation of the Sovereign Internet Law, the deployment of the TSPU, the algorithmic precision of Deep Packet Inspection, and the looming transition to the "Max" super-app have successfully erected massive barriers to information access. These actions have effectively fractured the global internet, creating a heavily surveilled domestic digital sphere2. However, as historical comparisons with the Soviet samizdat and radizdat movements elucidate, technological suppression cannot completely extinguish human curiosity. The architectural flaws of state control provide continuous vectors for evasion. The inability of DPI systems to process fragmented ClientHello packets at scale, the impossibility of blocking domain-fronted Snowflake connections without paralyzing vital commercial infrastructure, and the physical limitations of jamming satellite television all serve as critical lifelines for free thought26. When digital avenues become too constricted, the resilience of the population manifests in alternative mediums, from the revival of physical samizdat networks to the utilization of free-to-air broadcasts that bypass terrestrial chokeholds entirely47. The persistence of circumvention behavior in Russia demonstrates a fundamental truth about information controls: while censorship can dramatically increase the friction, financial cost, and personal risk of accessing alternative viewpoints, it cannot mandate belief. Supported by the psychological realities of preference falsification, citizens will consistently seek mechanisms to bypass the state's narrative monopoly, preserving communities of trust and maintaining a vital, albeit underground, sphere of intellectual freedom. As the state continues to refine its technological and legal countermeasures, the continuous evolution of evasion tools—from basic VPNs to cryptographic obfuscation, peer-to-peer networks, and extraterrestrial broadcasting—ensures that the flow of independent information remains an intractable challenge for authoritarian governance. The desire for truth remains a resilient, highly adaptive human condition that routes around censorship much as the internet itself routes around physical damage.
Works cited
1. A Comparative Analysis of Internet Regulation in Russia and China, https://youvan.ai/pdf.php?file=Navigating%20Digital%20Sovereignty%20-%20A%20Comparative%20Analysis%20of%20Internet%20Regulation%20in%20Russia%20and%20China.pdf
2. Runet 2025: Sovereignization and Degradation \- RKS Global, https://rks.global/en/research/runet-2025/
3. Russia: Freedom on the Net 2019 Country Report, https://freedomhouse.org/country/russia/freedom-net/2019
4. Censorship in the Soviet Union \- Wikipedia, https://en.wikipedia.org/wiki/Censorship\_in\_the\_Soviet\_Union
5. About Samizdat | Project for the Study of Dissidence and Samizdat, https://samizdat.library.utoronto.ca/content/about-samizdat
6. How and Why Did the Focus of Samizdat Shift Following the End of, https://museumstudiesabroad.org/samizdat-shift-khrushchev-thaw/
7. Chronicle of Current Events \- Wikipedia, https://en.wikipedia.org/wiki/Chronicle\_of\_Current\_Events
8. dissidents in soviet psychiatric hospitals, 1968-1974, https://cdr.lib.unc.edu/downloads/ks65hd618
9. The Year 1968 in the History of Samizdat \- Cold War Radio Museum, https://www.coldwarradiomuseum.com/the-year-1968-in-the-history-of-samizdat/
10. Samizdat according to Andropov, https://junglepoetry.wordpress.com/wp-content/uploads/2014/04/samizdat-according-to-andropov.pdf
11. SAMIZDAT: THE SOVIET UNDERGROUND PRESS \- CIA, https://www.cia.gov/readingroom/document/cia-rdp85t00875r001100100130-1
12. The Long History of Censorship \- Brewminate, https://brewminate.com/the-long-history-of-censorship/
13. The Year 1968 in the History of Samizdat. In memoriam Peter, https://www.academia.edu/38006888/The\_Year\_1968\_in\_the\_History\_of\_Samizdat\_In\_memoriam\_Peter\_Dornan\_Paper\_presented\_at\_a\_Conference\_organized\_by\_CSSEO\_Center\_for\_the\_Study\_of\_East\_European\_History\_in\_Levico\_Terme\_Italy\_November\_23\_24\_2018
14. Shortwave as the only way to get information, https://www.reddit.com/r/shortwave/comments/1s1vbmq/shortwave\_as\_the\_only\_way\_to\_get\_information/
15. The Ladder of Censorship (Full Version) \- OZI, https://ozi-ru.net/en/art1.html
16. Mass surveillance in Russia \- Wikipedia, https://en.wikipedia.org/wiki/Mass\_surveillance\_in\_Russia
17. Russian foreign agent law \- Wikipedia, https://en.wikipedia.org/wiki/Russian\_foreign\_agent\_law
18. Peering into the Future of Sino-Russian Cyber Security Cooperation, https://warontherocks.com/peering-into-the-future-of-sino-russian-cyber-security-cooperation/
19. Russia: Freedom on the Net 2022 Country Report, https://freedomhouse.org/country/russia/freedom-net/2022
20. Disrupted, Throttled, and Blocked: State Censorship, Control, and, https://www.hrw.org/report/2025/07/30/disrupted-throttled-and-blocked/state-censorship-control-and-increasing-isolation
21. Decentralized Control: A Case Study of Russia \- ResearchGate, https://www.researchgate.net/publication/339495942\_Decentralized\_Control\_A\_Case\_Study\_of\_Russia
22. Russia: Freedom on the Net 2023 Country Report, https://freedomhouse.org/country/russia/freedom-net/2023
23. How to Bypass YouTube Blocking in 2026 \- BypassCore, https://bypasscore.com/blog/bypass-youtube-blocking-russia-2026
24. Throttling Twitter: An Emerging Censorship Technique in Russia, https://censoredplanet.org/assets/throttling-imc-paper.pdf
25. 2026-03.pdf \- CERIAS \- Purdue, https://www.cerias.purdue.edu/assets/pdf/bibtex\_archive/2026-03.pdf
26. Zapret vs GoodbyeDPI vs ByeDPI — DPI Bypass Comparison 2026, https://bypasscore.com/blog/zapret-vs-goodbyedpi-vs-byedpi-comparison
27. Runet 2025: Sovereignization and Degradation \- RKS Global, https://rks.global/files/research/censorship\_review\_2025\_en.pdf?v=2
28. Throttling→blocking of YouTube in Russia, 2024-07-12 \#382 \- GitHub, https://github.com/net4people/bbs/issues/382
29. Why VPNs Stop Working in Russia: DPI and Routing | MosVPN, https://mosvpn.com/en/blog/why-vpns-stop-working-in-russia/
30. SoK: Towards Grounding Censorship Circumvention in Empiricism, https://www.researchgate.net/publication/306301919\_SoK\_Towards\_Grounding\_Censorship\_Circumvention\_in\_Empiricism
31. REALITY Protocol: The Ultimate Evasion Against Active Probing, https://vpnymous.com/reality-protocol-the-ultimate-evasion-against-active-probing/
32. The Sustainability Frontier of Moving-Target Censorship Resistance, https://arxiv.org/pdf/2606.08886
33. GoodbyeDPI — Deep Packet Inspection circumvention utility \- GitHub, https://github.com/DarMorar/GoodbyeDPI-YouTube-
34. Users \- Tor Metrics, https://metrics.torproject.org/userstats-bridge-country.html?start=2021-02-20\&end=2022-02-28\&country=ru
35. Users \- Tor Metrics, https://metrics.torproject.org/userstats-relay-country.html
36. Sustaining Snowflake operations | The Tor Project, https://blog.torproject.org/snowflake-daily-operations/
37. Tor Snowflake: Help Ukrainians and Russians fight censorship and, https://www.reddit.com/r/TOR/comments/td6b5f/tor\_snowflake\_help\_ukrainians\_and\_russians\_fight/
38. What we've learned from fighting censorship in Iran and Russia, https://blog.torproject.org/staying-ahead-of-censors-2025/
39. \[tor-project\] User Support Report for May 2026, https://forum.torproject.org/t/tor-project-user-support-report-for-may-2026/21802
40. \[tor-project\] User Support Report for July 2026, https://forum.torproject.org/t/tor-project-user-support-report-for-july-2026/21960
41. The tech stack behind Meduza's efforts to bypass Russian censorship, https://thefix.media/2024/08/15/the-tech-stack-behind-meduzas-efforts-to-bypass-russian-censorship/
42. A Breakdown of The Equilibrium: A sharp deterioration in public, https://re-russia.net/en/analytics/0446/
43. Russia's WhatsApp Ban: Digital Sovereignty and the Splintering of, https://bisi.org.uk/reports/russia-whatsapp-ban-digital-sovereignty-and-the-splintering-of-the-global-internet
44. The Svoboda Satellite Package \- Independent Russian information, https://www.denisdiderot.net/svoboda-package
45. Reporters Without Borders launches Svoboda Satellite Package to, https://theins.press/en/news/269858
46. A new satellite TV channel allows Alexei Navalny's videos to reach, https://www.btpm.org/2025-06-04/a-new-satellite-tv-channel-allows-alexei-navalnys-videos-to-reach-russian-audiences
47. Thibaut Bruttin (RSF): “With our satellite package Svoboda, Russia, https://mediaconnect.com/thibaut-bruttin-rsf-with-our-satellite-package-svoboda-russia-has-no-control
48. Piter's People \- Katya Kotlyar \- Russian Life, https://www.russianlife.com/the-russia-file/piters-people-katya-kotlyar/
49. Opponents and proponents of the war in Ukraine in Russian social, https://arxiv.org/html/2308.04473v1
50. Correcting misinformation about the Russia-Ukraine War reduces, https://pmc.ncbi.nlm.nih.gov/articles/PMC11419341/
51. Want to be heard: survey participation in Russia before and during, https://www.tandfonline.com/doi/full/10.1080/1060586X.2025.2548622
52. The reluctant consensus: war and Russia's public opinion, https://www.atlanticcouncil.org/wp-content/uploads/2024/12/RussiaTomorrow\_The-reluctant-consensus-War-and-Russias-public-opinion.pdf
53. media \- Левада-Центр, https://www.levada.ru/en/tag/media/