Internet access is not one thing. In much of the Global South the cheap, dominant way online is a mobile carrier — a SIM card and a cellular data plan — while fixed broadband (FTTH, cable, DSL) reaches a smaller, often wealthier slice of the population. Censors know this. Mobile DPI is operationally easier to deploy and update than fixed-line interception, and blocking the mobile path hits the most people for the least effort. Several regimes block mobile-first.
The per-mobile-carrier blocking detector
(scripts/build-mobile-carrier-blocking.py) makes that
split visible. It takes a hand-curated map of 62 telco
ASNs — 34 tagged mobile, 24 tagged
broadband, 4 tagged mixed — and, per
country over the trailing 90 days, splits the evidence table's
blocking observations by access type. The headline number is
mobile_skew: how much harder HTTP-level blocking lands
on a country's mobile carriers than on its fixed broadband.
Every ASN-tagged row in the evidence table is a CensoredPlanet
blocking observation — there are no clean-measurement
rows on these ASNs, so a classic block rate (blocks ÷ all
measurements) is degenerate, always 1.0. Two facts shape the real
method. First, dns-blocking rows saturate their
signal_value at exactly 1.0, while
http-blocking rows carry a genuine intensity
in [0,1] — the fraction of probes that saw the block. Second,
CensoredPlanet typically probes a given ASN with either its
DNS satellite or its HTTP hyperquack, not both. Mixing DNS
and HTTP rows would make any “mean intensity” an artifact
of the probe-protocol mix rather than of how hard the carrier is
blocked.
So the headline mobile_skew is computed on HTTP rows
only — an apples-to-apples comparison:
mobile_skew = mobile_http_intensity / (broadband_http_intensity
+ ε). A skew above 1.15 on a trusted country
(one with at least 20 HTTP-block rows on each access type) is the
mobile-first signature. DNS blocking is reported separately as a
per-side binary side-channel — observed or not — because
DNS rows carry no usable intensity gradient. The 4 mixed
ASNs (incumbent telcos running both networks at scale) are excluded
from the skew math entirely.
Across the 90-day window, 29 countries had blocking evidence on at
least one classified telco ASN. The honest result is a thin one:
only Singapore currently has enough HTTP-block rows
on both a mobile ASN and a broadband ASN to support the
headline skew — SG comes in at mobile_skew = 0.896
(mobile HTTP intensity 0.064, broadband 0.022), i.e. roughly balanced
with a slight broadband lean. The other 28 countries are probed
DNS-only or HTTP-only on one side, so they get
mobile_skew = null and only the DNS side-channel is
populated.
That side-channel is still informative. It cleanly separates where
DNS-level blocking is observed on the mobile path
(Bahrain, India, Jordan, plus mobile-and-broadband-both in Bangladesh
and Indonesia) from where it shows up only on fixed broadband
(Azerbaijan, Belarus, Cuba, Egypt). The detector is wired as a
per-country reference surface, not a model input:
GET /v1/atlas/mobile-carrier-blocking/<cc>,
/leaderboard, and /info (which returns the
full ASN→type map).
The ASN→type map is hand-curated and incomplete
— only ASNs that actually appear in the evidence table were
worth classifying; everything else is unknown and
excluded from the math. Some incumbent telcos genuinely run both a
mobile and a fixed-broadband network; those are tagged
mixed and dropped from the skew rather than guessed at.
The headline skew needs HTTP-block rows on both access types in the
same country, and CensoredPlanet's vantage-point assignment
means that condition is met for only one country today — this
will widen as probe coverage grows, but the v1 result is honestly
one trusted data point plus a DNS side-channel. Finally, this
measures blocking severity, not prevalence: every
classified ASN here is blocked; the question the detector answers is
how hard, and on which access type. Evidence volume per ASN reflects
which vantage points CensoredPlanet happens to probe — it is
not a census of national traffic.