What this is

Activists and journalists routinely ask which circumvention tool actually works in a given country. The honest answer for years has been “try a few and see what survives.” The Voidly evidence table records every measured block of a known bootstrap endpoint — with the underlying probe counts embedded in upstream_claim text like “DNS blocking detected: 11/11 probes anomalous for psiphon.ca”. We aggregate those rows into a per-country per-tool success rate.

For each (country, tool) pair we sum N_blocked and N_total across every blocking-class evidence row in the last 30 days where the row's domain (or signal_type for Tor) matches the tool's bootstrap match spec. success_rate = (N_total − N_blocked) / N_total. Confidence is a sigmoid of probe count centered on n=10 so single-probe rows surface but are flagged as low confidence. Tools covered: Tor (rolled-up OONI tor test), Lantern, Psiphon, Snowflake, ProtonVPN, ExpressVPN, Mullvad, VPN Gate, plus a generic-VPN aggregate.

What the first run found

30-day rollup, 17,144 candidate evidence rows, 131 (country, tool) pairs across 34 countries where we have enough probe coverage to compute a rate. Tor is the most measurable tool (31 countries), followed by Psiphon (27), generic-VPN (25), ProtonVPN (25), Lantern (23). Snowflake has very thin direct-domain coverage and falls through to the Tor signal in v1.

The pattern that pops out is Tor. The top five best-working tool-country combos are all Tor in countries with aggressive but non-GFW-grade filtering: Venezuela (96.7% success, n=153), Indonesia (96.4%, n=584), Turkey (96.2%, n=1,223), Malaysia (96.1%, n=77), Iraq (94.3%, n=176). Even in Iran — a country routinely flagged as a Tor-hostile environment — the OONI tor test passes 54% of probes over the last 30 days. That number contains real signal (Tor over plain transports is not fully blocked) and a real caveat (the OONI test rolls up vanilla / obfs4 / Snowflake / Meek; we cannot tell from these aggregates which transport is doing the work).

The countries where even the best tool fails: Azerbaijan (best=ProtonVPN at 0% over 70 probes), Pakistan (best=Tor at 0.3% over 1,495 probes), Egypt (best=ProtonVPN at 46.3% over 41 probes), Belarus (best=Tor at 50.1% over 2,406 probes, but median across 5 tools is 0.0%). Pakistan stands out: every commercial-VPN domain we tested is at or near 100% blocked, and the Tor signal that does pass is single-digit percentage. That matches the long-running PTA Web Monitoring System pattern.

What this method cannot tell you

A “successful probe” is an OONI / Voidly / CensoredPlanet probe that did NOT trip a blocking signal. It does not prove the tool actually works for a real human user. DPI vendors increasingly pass synthetic measurement traffic (it has predictable TLS fingerprints, SNI sequencing, and known IP ranges) while blocking real clients. This index is an upper bound on real-world success.

The static-domain probing approach also systematically under-estimates tools that domain-front or rotate endpoints — Snowflake, Lantern, and Psiphon all bootstrap from a static domain but their actual tunnel traffic uses rotating endpoints the probe never touches. A country can block psiphon.ca at the DNS layer (100% probe block rate) while the Psiphon app still bootstraps fine from its bundled server list.

The generic-VPN aggregate folds ProtonVPN, ExpressVPN, Mullvad, and VPN Gate together. Self-hosted WireGuard / OpenVPN on a private IP is invisible to OONI probes — this index cannot measure it. If your VPN is a rented Linode running wg-quick, none of these numbers apply.

Finally: Tor results aggregate every transport. Per-transport breakdown (obfs4 vs. Snowflake vs. Meek vs. vanilla) requires raw OONI tor nettest measurements, not the rolled- up evidence table. That's out of scope for v1.

How to use this responsibly

Caveats summary

  1. Probe coverage uneven; confidence reflects probe count.
  2. “Probe success” ≠ “real user success.”
  3. Domain-fronted tools (Snowflake, Lantern, Psiphon) are systematically under-estimated.
  4. Self-hosted WG / OpenVPN invisible to this method.
  5. Tor rows aggregate all transports.
  6. 30-day lookback; sudden regime changes hidden.
  7. Per-row evidence may double-count probes that re-measure across days. Aggregate is a 30-day rollup, not a unique-IP count.