GigaTap articles in the vpn category.
- Active Probing and Why a Server Must Stay Silent Consistently - Passive analysis only flags a suspicious address; then the censor connects itself. What gives away a server that simply does not answer, and why silence has to be consistent.
- Chains and Multihop: What They Give You and What They Cost - A second hop solves specific problems and creates new ones. What a chain actually buys, why a fallback path is not failover, and the trace multihop leaves in traffic.
- Choosing a Transport Family: Vulnerability Profiles, Not a Ranking - Transports cannot be ranked by strength — their vulnerability profiles differ in kind, not in degree. Four families across five axes, and the rule of diverse failure modes.
- Config Delivery: How a Broken Subscription Locks a User Out - The worst state a service can reach is one where restoring access requires the access you do not have. The circular trap, domain migration, and channel independence.
- DNS in Circumvention: The First Step and the First Leak - Name resolution happens before the connection and announces intent before protection starts. Three roles DNS plays, the silent fallback, and where to resolve names.
- ECH: What It Actually Solves, and What It Does Not - Encrypting the name in a TLS handshake closes one leak and leaves the rest untouched. What stays visible, why the anonymity set decides, and when it is a liability.
- Measuring Blocking Correctly - A probe must measure the quantity by which the network actually breaks. Four requirements: volume, seriality, failure classification and vantage point.
- Why Looking Random Is Not the Same as Looking Normal - A fully encrypted stream with no structure does not blend into traffic — it forms a class of its own. Why removing a signature does not deliver indistinguishability.
- Silent Failures That Look Like Blocking - Some failures happen with no error at all: the server drops the client silently, and from outside that is indistinguishable from blocking. A catalogue, and why to check it first.
- Three Axes of Traffic Shape: Why Two Mechanisms Demand Opposite Settings - One restriction demands splitting connections, another demands merging them. The contradiction dissolves once count, concurrency and volume become independent axes.
- TLS Fingerprints and the Post-Quantum Shift: How a Fake Browser Gives Itself Away - By late 2025 more than half of web traffic had gone post-quantum. A client claiming a modern browser without the matching key exchange gives itself away by that field.
- Upgrades as a Source of Failure: Why It Broke Right After the Update - An upgrade changes defaults, tightens checks and relocates parameters. Four mechanisms, each of which looks exactly like blocking, and the correct order of upgrading.
- Your VPN Check Says Timeout but the Connection Works — and Vice Versa - The built-in connection check in VPN clients measures the wrong quantity. That produces two symptoms: red-but-working, and the more dangerous green-but-broken.
- What Counts as Proof That It Works - Connected and works are different claims. The thresholds below which a check proves nothing, and the minimum set of conditions under which a result can be believed.
- Whitelists: What They Are, Why They Change, and What Splitting Them Means - A whitelist lists addresses, not services. That is why subnet neighbours inherit its protection — and why splitting those addresses into separate subnets changes so much.
- Why Blocking Hits One User and Not Another - The same config behaves differently for two people, and luck has nothing to do with it. Filtering is distributed and counts per sender-destination pair, not per service.
- VPN Subscription Safety Checklist for Mobile Networks - A safe checklist for evaluating VPN and VLESS subscription feeds before importing them into mobile clients.
- How to Use remnawave-api for Remnawave API Automation - A beginner-friendly guide to automating Remnawave tasks with Python, including setup, auth, and real-world API examples.
- ByeDPIManager on Windows: Run ByeDPI + ProxiFyre for App-Selective DPI Bypass - Beginner-friendly guide to install and use ByeDPIManager on Windows to run ByeDPI with ProxiFyre for per-app DPI bypass.
- ghostcp (GhosTCP) Beginner Guide: Hardening TCP Connections on Windows - Learn how to install and configure ghostcp (GhosTCP) on Windows to reduce TCP interference using WinDivert and simple rules.
- Psiphon How-To: Censorship Circumvention Basics for Privacy-Minded Users - Learn how to install and use Psiphon to bypass network censorship, understand what it protects (and what it doesn’t), and avoid common OPSEC mistakes.
- zapret2 (anti-DPI) Beginner Guide: Install, Intercept, and Apply Strategies Safely - A beginner-friendly zapret2 guide: install it, redirect only the right packets, and apply anti-DPI strategies on Linux/Windows.
- Xray-core Guide: Proxy Access, VLESS, REALITY, and XTLS - A practical Xray-core guide covering VLESS, REALITY, XTLS, proxy access patterns, client setup, and common network troubleshooting.