Activists and journalists routinely ask which circumvention tool
actually works in a given country. The honest answer for years
has been “try a few and see what survives.” The
Voidly evidence table records every measured block of a known
bootstrap endpoint — with the underlying probe counts
embedded in upstream_claim text like
“DNS blocking detected: 11/11 probes anomalous for
psiphon.ca”. We aggregate those rows into a
per-country per-tool success rate.
For each (country, tool) pair we sum N_blocked and
N_total across every blocking-class evidence row
in the last 30 days where the row's domain (or
signal_type for Tor) matches the tool's bootstrap
match spec. success_rate = (N_total − N_blocked) /
N_total. Confidence is a sigmoid of probe count centered
on n=10 so single-probe rows surface but are flagged as low
confidence. Tools covered: Tor (rolled-up OONI tor
test), Lantern, Psiphon, Snowflake, ProtonVPN, ExpressVPN,
Mullvad, VPN Gate, plus a generic-VPN aggregate.
30-day rollup, 17,144 candidate evidence rows, 131 (country, tool) pairs across 34 countries where we have enough probe coverage to compute a rate. Tor is the most measurable tool (31 countries), followed by Psiphon (27), generic-VPN (25), ProtonVPN (25), Lantern (23). Snowflake has very thin direct-domain coverage and falls through to the Tor signal in v1.
The pattern that pops out is Tor. The top five
best-working tool-country combos are all Tor in countries with
aggressive but non-GFW-grade filtering: Venezuela (96.7% success,
n=153), Indonesia (96.4%, n=584), Turkey (96.2%, n=1,223),
Malaysia (96.1%, n=77), Iraq (94.3%, n=176). Even in Iran —
a country routinely flagged as a Tor-hostile environment —
the OONI tor test passes 54% of probes over the last
30 days. That number contains real signal (Tor over plain
transports is not fully blocked) and a real caveat (the OONI
test rolls up vanilla / obfs4 / Snowflake / Meek; we cannot
tell from these aggregates which transport is doing the work).
The countries where even the best tool fails: Azerbaijan (best=ProtonVPN at 0% over 70 probes), Pakistan (best=Tor at 0.3% over 1,495 probes), Egypt (best=ProtonVPN at 46.3% over 41 probes), Belarus (best=Tor at 50.1% over 2,406 probes, but median across 5 tools is 0.0%). Pakistan stands out: every commercial-VPN domain we tested is at or near 100% blocked, and the Tor signal that does pass is single-digit percentage. That matches the long-running PTA Web Monitoring System pattern.
A “successful probe” is an OONI / Voidly / CensoredPlanet probe that did NOT trip a blocking signal. It does not prove the tool actually works for a real human user. DPI vendors increasingly pass synthetic measurement traffic (it has predictable TLS fingerprints, SNI sequencing, and known IP ranges) while blocking real clients. This index is an upper bound on real-world success.
The static-domain probing approach also
systematically under-estimates tools that
domain-front or rotate endpoints — Snowflake, Lantern,
and Psiphon all bootstrap from a static domain but their
actual tunnel traffic uses rotating endpoints the probe never
touches. A country can block psiphon.ca at the
DNS layer (100% probe block rate) while the Psiphon app
still bootstraps fine from its bundled server list.
The generic-VPN aggregate folds ProtonVPN, ExpressVPN, Mullvad,
and VPN Gate together. Self-hosted WireGuard / OpenVPN on a
private IP is invisible to OONI probes — this index
cannot measure it. If your VPN is a rented Linode running
wg-quick, none of these numbers apply.
Finally: Tor results aggregate every transport. Per-transport
breakdown (obfs4 vs. Snowflake vs. Meek vs. vanilla) requires
raw OONI tor nettest measurements, not the rolled-
up evidence table. That's out of scope for v1.
confidence as a hard filter. Anything below
0.30 is “a few probes saw this” — do not cite
it in journalism without that caveat. Anything below 0.10 is
noise.
success_rate as an upper bound. Real users
see lower numbers because their traffic doesn't look like
OONI's traffic. The honest framing is “Tor probes pass
54% of the time in Iran” not “Tor works 54% of
the time in Iran.”
/v1/anomaly/dbscan/{cc} and
/v1/sentinel/movers endpoints for change
detection. The evasion index is a 30-day rollup; sudden
regime shifts won't show up until they dominate the window.
/v1/atlas/evasion/info to see the full tool
catalogue.