On Russia's Early Introduction of QUIC SNI Censorship (FOCI 2026)

On Russia’s Early Introduction of QUIC SNI Censorship
Nico Heitmann, Niklas Niere, Felix Graf Lange, Juraj Somorovsky
https://www.petsymposium.org/foci/2026/foci-2026-0010.php
PDF
Data

The paper is a detailed timeline of QUIC censorship in Russia since 2022. Its biggest single finding is that TSPU devices in Russia had deployed SNI-based QUIC filtering no later than July 2023—at least 9 months earlier than the documented onset of QUIC SNI filtering in China in April 2024. The fact of QUIC SNI filtering in Russia was discussed on Russian-language forums like NTC, but was not widely known. The paper includes a detailed description of how QUIC censorship currently works in Russia, which is somewhat different from when it was first introduced.

QUIC uses TLS, so it inherits TLS’s weakness to flow classification based on the Server Name Indication extension (SNI). The packet that contains the SNI in QUIC (an Initial packet) is technically encrypted; however the encryption key is derived from public information, so it is possible for a middlebox to decrypt the packet to read the SNI. When we refer to SNI-based QUIC filtering, this is what we mean: making classification decisions based on the SNI contained in a QUIC Initial packet.

The authors delimit three periods of different QUIC blocking behavior.

Period A (until February 2022)

At the beginning of the invasion of Ukraine by Russia in February 2022, there was no blocking of QUIC.

Period B (until sometime between May 2022 and July 2023)

International QUIC traffic was blocked entirely—irrespective of SNI. If the first packet in a UDP flow destined to port 443 was at least 1001 bytes long and contained the QUIC v1 version number, all packets for the same 4-tuple would be dropped for the next 420 seconds, which is called residual censorship. There was also an effect of residual clearance: if the first UDP packet in a flow did not satisfy the QUIC check, the remainder of the flow was allowed to pass.

The broad QUIC filtering only affected international traffic that originated in Russia. QUIC traffic entering Russia was not affected. QUIC traffic that was fully domestic, on the other hand, was subject to SNI-dependent filtering. Previous discussion of the beginning of Period B is at https://github.com/net4people/bbs/issues/108 and https://ntc.party/t/1823.

Period C (starting sometime between May 2022 and July 2023)

At some point between May 2022 and July 2023, the wholesale blocking of QUIC was replaced by SNI-based filtering. Now the filter decrypted QUIC Initial packets and only blocked connections whose SNI was on a blocklist. As in Period B, only UDP traffic to port 443 was affected. During this time, the SNI of QUIC packets was also used to throttle traffic to YouTube.

Today, QUIC SNI filtering still exists in Russia. Blocking works by packet dropping. A blocked packet causes residual censorship for the same 4-tuple for 420 seconds; sending another Initial packet with a blocked SNI during residual censorship restarts the timer. Only traffic exiting the country is affected. Filtering is no longer limited to port 443, but affects all UDP ports. Only QUIC v1 is affected, not the newer QUIC v2. The QUIC SNI blocklist has almost perfect correspondence with the TSPU blocklist for TCP/TLS SNI. That and other network evidence suggests that QUIC SNI filtering happens at the same TSPU devices that are responsible for other kinds of censorship. Some SNI values get special treatment; see Appendix C. In particular, residual clearance is still present, but only for a small number of domains.

Thanks to the authors for reviewing a draft of this summary.