A multi-perspective view of Internet censorship in Myanmar FOCI’21, August 27, 2021, Virtual Event, USA Figure 4: Blocking of websites in Myanmar from Feb. to Apr. 2021 based on OONI measurements. The bars (left Y-axis) show the percentage of measurements with specific results on a particular day; the circles show the total measurements on that day (Log scale, right Y-axis). The size of the circles shows the number of distinct ASes that produced measurements on that day. Measurements to social media websites and circumvention tool websites faced high rates of TCP/IP and DNS blocking. these domains are hosted on the same IP address, and presented the same TCP/IP anomalies during the same time period, suggests that some of them may have temporarily been blocked unintentionally as a result of collateral damage. We observed 4 ASes that blocked this IP address during the same time period, suggesting that there was some coordination in blocking among ASes. However, other ASes did not show this blocking. (ii) Domains hosted on the IP 151.101.1.195. This address belongs to the Fastly network and includes the domains coronavirus.app and getintra.org, both of which started to present TCP/IP anomalies on Mar. 2, 2021. Reverse IP lookups indicate that the blocking of this IP may lead to the blocking of more than 10,000 websites, showing the severity of collateral damage due to IP blocking [75]. In some cases, we observe both censorship techniques being used on the same ASes. Non-deterministic censorship. OONI measurements show that IP blocks are not implemented consistently, offering additional signs that ISPs operated independently and (sometimes) arbitrarily. Within the same AS, we do not observe IP blocking for all the addresses associated with a domain. One cause of this inconsistency could potentially be the result of ISPs using incomplete addresslists for blocking. E.g.: OONI measurements collected from the testing of facebook.com on Frontiir (AS58952) show the blocking of Facebook’s IP 157.240.15.36, but not of Facebook’s IP 31.13.82.36. 3.4 Twitter hijack and collateral damage On Feb. 5th—the same day that Twitter was blocked in Myanmar— Campana Mythic (AS136168) announced the 104.244.42.0/24 prefix, belonging to Twitter. The proximity of this hijacking event in time to the blocking of Twitter in other Myanmar ISPs suggests that the original intent was to blackhole traffic to Twitter for users of this Myanmar ISP1 . However this route accidentally leaked to the global Internet, appearing as if AS136168 owned/hosted Twitter’s address space. This accidental event offers additional evidence that providers used various ways to perform IP-level blocking to censor domains (Section 3.3). Censorship variance across networks. Our findings show that different websites are blocked on different networks. Some of the blocked websites listed in Figure 4 are accessible on certain networks in Myanmar. This suggests that Internet censorship in Myanmar is not centralized and that local ISPs may implement blocking at their own discretion. We also observe variance in censorship methods across networks and over time. After the coup on Feb. 1, we primarily observe IP based blocking of websites across ASes. However, we also continue to observe DNS based interference, returning IP addresses that (previously) hosted block pages or an address in private IP space. 1 Private 31 communication corroborated that the hijack was accidental.

Select target paragraph3