Signal · Bleedthrough
Not what the firewall blocks. What the firewall is.
Every other China observatory answers the policy question: which sites are blocked. Bleedthrough asks the apparatus question. How many injectors are running, which forged address pools they hold, whether a province has begun answering differently from the national baseline, and when any of that changes. It is reconstructed from outside China by making the censor's own injectors answer benign queries. The censor is the sensor.
Palimpsest is a free public good. MIT licensed, developed in the open, never a commercial product, and every finding on it ships the raw file it was computed from.
What funding buys Source on GitHubSignal status
Awaiting the first live round.
Bleedthrough is the one signal on this site that measures actively rather than reading somebody else's published data. That changes what it is allowed to do and where it is allowed to run, so it publishes nothing until a controlled prober is standing.
There is no reading here yet, and no estimate, no cached figure and no illustrative shape standing in for one. When the prober publishes its first round, this panel is replaced by the reading and by the raw file behind it.
Reading could not be loaded
A round appears to have been published, but the file could not be read. Nothing is shown in its place. There is no cached figure here, because a plausible looking number would be worse than a blank panel.
The current round
The reading
A floor on the fleet, never a census
Each injector answers a given query at most once, so parallel answers to a single query put a floor under how many injector processes are running on that path.
A silent injector is undercounted. The true fleet is at least this large and may be larger, which is why the figure is always written with a greater than or equal sign and never quoted as a count.
Apparatus events this round
Provenance of this round
How this reads the machine, not the policy
- A benign, stateless UDP DNS query for a censored domain is sent toward China. The on-path firewall is bidirectional, so its own injector answers with a forgery. No node inside China is needed, and nobody inside China is asked to do anything.
- Fleet size comes from how many parallel injectors answer one query, and from the order in which they cycle their forged address pool. That ordering is not a bug and cannot be patched away without degrading the thing itself.
- Regional divergence. A province whose forged address pool disagrees with the national baseline is a candidate autonomous provincial firewall, the wall behind the wall.
- An open resolver fallback rides Chinese resolvers' outbound recursion, so the signal survives the decay of the inbound injection channel.
Stated by the collector itself
- Method
- The collector states its scope and method inside each published round. No round has been published yet, so nothing is quoted here. The code is open and linked below, and it is the authority in the meantime.
Scope and safety, held
- Benign, stateless UDP DNS only. The same packet a normal resolver sends. It triggers no residual censorship, so probing is polite by construction and no real connection is harmed.
- Dark address targets. Curated sink addresses inside Chinese prefixes, not live services, so no third party carries the traffic or the risk.
- No exploitation. No memory disclosure attempt, no packet dropping, no availability effect, no third party reflector.
- Governance gated. Active probing runs only behind the kill switch and the rate ceiling. The halt is armed per probe rather than checked once at startup.
- Never a circumvention service. Palimpsest measures the censor. It does not route anyone around it.
Take the evidence with you
- bleedthrough-latest.json Not published yet. The first round from the prober appears at this path, and this page renders that file and nothing else.
- collectors/bleedthrough.py The collector. Fleet size, pool hashing, regional divergence and the two transports.
- scripts/bleedthrough_pull.py The round runner. Where the burst, the rate ceiling and the published fields are set.
- docs/BLEEDTHROUGH.md Method and safety in full, including what the signal deliberately does not do.
- Observatory China censorship observatory Signals across the network, content and model layers, each publishing its own raw file. This page is one of them.
- Registry Verifiable eval registry Pre-registered suites, hash chained, anchored outside our own infrastructure. A peer of the observatory, not a side feature.
- Funding A funded public good MIT licensed and open from the first commit. Grants and donations pay for the collectors, the storage and the anchoring.
Watch the censor, never the censored. Bleedthrough reads the machine that does the censoring. It never observes a person, never asks anyone inside China to act, and never operates a circumvention service.