TLS MITM and Throttling to 10 Mbps: Two Distinct Network Degradation Patterns Observed in Russia
Russian users connecting through Tunnel Cat have encountered sudden slowdowns and instability on international links. Examination of logs and user reports identified two distinct mechanisms that produce overlapping symptoms yet differ fundamentally in cause and detection.
International traffic throttled after initial success
The first pattern shows connections that establish normally with TCP and TLS completing successfully. Data transfer begins at expected speeds before throughput collapses, sometimes within seconds and sometimes after several minutes, occasionally falling from roughly 80 Mbps to 8–12 Mbps. This behavior differs from outright blocking, where routes either function or fail completely. Russian operators appear to be applying graduated throttling to international traffic rather than cutting it off entirely. Two hypotheses have been proposed: deep packet inspection that initially permits a flow and later subjects it to heavier analysis, or a gradual regulatory tightening of permitted bandwidth. Both remain unconfirmed, but the observable effect is consistent degradation that begins only after the connection is already active.
TLS certificate substitution detected on Windows
The second pattern produces similar user-visible instability yet includes a clear additional indicator: affected Windows machines receive an unexpected TLS certificate. Tunnel Cat logs from dozens of Windows systems showed clients obtaining a substitute certificate instead of the legitimate server certificate. This constitutes classic man-in-the-middle interception in which an intermediary terminates the client TLS session, decrypts the traffic, and forwards it onward under its own credentials. The same connection type often functioned normally on other operating systems, pointing to a platform-specific interception mechanism.
When Tunnel Cat detects an incorrect certificate it immediately drops the session. To the end user the result appears as intermittent connectivity, slow page loads, and frequent tunnel drops—the same complaints that arise from simple route degradation. Distinguishing the two therefore requires inspection of certificate chains in addition to RTT and packet-loss metrics.
Practical diagnostic guidance
Operators and users troubleshooting similar issues should separate the scenarios: connections that start normally and then degrade point toward bandwidth throttling or DPI effects, while TLS errors that appear predominantly on Windows warrant immediate certificate validation. Tunnel Cat has released updates that mitigate some symptoms, yet the underlying network changes continue. The distinction matters because one scenario reflects capacity management while the other represents active interception of encrypted sessions.
Related articles
Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS
A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.
GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use
This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.
Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection
A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.
WhatsApp Introduces Parental Controls for Teen Privacy Settings
WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.