The flicker
Iran's internet flickered back on today.
NetBlocks confirmed partial restoration after 2,093 hours of near-total isolation from international networks — 88 days, the longest nationwide internet shutdown in modern history. Connectivity was measured at less than 10 percent of pre-shutdown levels.
President Masoud Pezeshkian ordered the Ministry of Communications on May 25 to restore internet access to its pre-January status. A newly established Special Task Force for the Regulation and Governance of Cyberspace, chaired by First Vice-President Mohammad Reza Aref, voted 9 to 2 in favor of restoration.
The two votes against came from Peyman Jebelli, head of Iran's state broadcaster, and Mohammad-Amin Aghamiri, Secretary of the Supreme Council of Cyberspace — a key architect of the "Barracks Internet" plan.
On May 26 — today — the Administrative Justice Court suspended enforcement of the document establishing the cyberspace body, accepting complaints seeking its annulment. The legal basis for the restoration was challenged the same day the restoration was confirmed.
The flicker is real. The architecture behind the flicker is the news.
What 88 days concealed
The shutdown began January 8 during mass protests triggered by currency collapse and inflation. The blackout coincided with the most lethal phase of the regime's crackdown. The UN Special Rapporteur estimated at least 5,000 killed. Iran International, Time, and The Guardian, citing local health officials, reported estimates between 30,000 and 36,500 protesters killed during January 8-9 under cover of the blackout.
Human Rights Watch documented that the shutdown restricted access to lifesaving information — strike locations, medical care, food and shelter — during active military operations. It severed communication with loved ones during armed conflict. It prevented documentation of evidence of killings and abuses. It reduced international scrutiny of state violence.
The economic cost ran at $35.7 million per day by the Iranian Communications Minister's own estimate. NetBlocks placed it up to $37 million per day in direct costs, and $70-80 million per day including indirect losses. Online sales fell 80 percent. The Tehran Stock Exchange lost 450,000 points in four days. Two million people lost their jobs directly or indirectly. DigiKala, Iran's largest e-commerce company, laid off 200 employees. Kamva, another e-commerce platform, declared bankruptcy. Its founder wrote: "After two wars and months of internet shutdown, we could no longer bypass the crisis."
Job search platforms recorded 318,000 resumes submitted on April 25 alone — 50 percent above the previous single-day record. Immigration agencies were overwhelmed.
The blackout was not a defensive measure. It was infrastructure for concealment.
The kill switch
On May 23, Mohammad Sarafraz — member of the Supreme Council of Cyberspace and former head of state broadcaster IRIB — told the newspaper Faraz that Chinese hardware is already in the country. The purpose: laying the groundwork for permanent throttling of the internet, with only tightly monitored access for select users among 90 million people.
Sarafraz's analogy: "It's like living in a land with abundant water, but being forced to pay a huge amount for a bottle just to quench your thirst."
The kill switch data center is located underground beneath Fanap's administrative building at Pardis IT Town, approximately 20 kilometers northeast of Tehran. Designed to be difficult to strike by missile. Capacity: approximately 400 server racks. Cost: estimated $700 million to $1 billion. Equipment: supplied by Huawei in 24 containers shipped after the twelve-day war. Huawei's name does not appear in related documentation. The facility is managed by ArvanCloud through the company Ayandeh Afzay-e Karaneh. Fanap's CEO, Shahab Javanmardi, was sanctioned by the US Treasury in August 2025 for ties to the intelligence ministry and Revolutionary Guards.
President Pezeshkian visited the construction site in March 2025.
The system uses deep packet inspection at foundational network layers to identify and block encrypted international traffic. The technical purpose is the permanent separation of Iran's domestic network from the global internet — the infrastructure for a whitelisting-only access model.
The three tiers
The architecture that emerged from the blackout is not a shutdown. It is a class system.
Tier 1 — "White Internet." Full, unfiltered access for senior officials and security-vetted elites. Approximately 16,000 people hold "white SIM cards" that have existed since at least 2013. Government ministries, banks, and critical infrastructure. Approximately 2 million in this tier. No disruption during shutdowns.
Tier 2 — "Internet Pro." Cost: 40,000 tomans per gigabyte, approximately 0.20 euros. Available to registered companies, journalists, lawyers, academics, medical professionals. Access to approximately 10 international platforms. Telegram and WhatsApp generally stable; Instagram, YouTube, and X unreliable. Approximately 5 million in this tier.
Tier 3 — Standard. The general public. Cost: 500,000 tomans per gigabyte to maintain VPN access — approximately 75 euros per month for 1 gigabyte daily. More than 12 times the cost of Internet Pro. Limited to basic text-only services. Approximately 45 million Iranians in this tier.
Government spokesperson Fatemeh Mohajerani stated access will "never return to its previous form."
The Tier 1 rollout is planned for government agencies on June 1. Tier 3 reaches the general public by end of September. The flicker today is not a return to the pre-January internet. It is the first visible operation of the tiered system.
The Russian layer
The filtering infrastructure runs on Russian deep packet inspection technology. STC Protei, headquartered in St. Petersburg with branches in Estonia and Jordan, supplies the DPI platform. Revenue approximately $43 million. Client reach: over 300 million subscribers globally across Central Asia, the Middle East, Africa, and South Asia.
In 2024, Russia's state-owned Rostelecom entered a joint venture with Protei with expectations of complete ownership acquisition — effectively making Protei a state-controlled surveillance technology firm.
Protei's platform provides identification and selective blocking of specific services and protocols, URL blacklisting and whitelisting, DNS filtering, and application-layer traffic inspection — blocking not by IP but by type of traffic. Citizen Lab in 2023 discovered Protei provided core network components to Iranian telecom operator Ariantel, including user authentication systems and DPI infrastructure.
The Russia-Iran partnership is formalized in treaty. The 2025 update established a "comprehensive strategic partnership" including provisions for "strengthening internet sovereignty through regulating international companies" and "exchange of experience in the management of national segments of the Internet."
Russian DPI helped Iranian security forces identify protesters' coordination centers, track communication patterns, and carry out targeted detentions before protests rather than after.
The wall in a box
The Chinese export model is documented.
In September 2025, a 500-gigabyte leak from Geedge Networks — a Chinese network security company — exposed over 100,000 documents containing DPI and filtering technology blueprints. The leak confirmed export destinations: Ethiopia, Myanmar, Kazakhstan, Pakistan. Job postings for overseas engineers specifically named Pakistan, Bahrain, India, Malaysia, Algeria. Chinese companies supply AI surveillance technology to at least 63 countries. Huawei alone supplies more than 50.
On April 8, a leaked Shaanxi Telecom notice ordered all IP addresses to halt connections to any external network — VPN services and proxy routing eliminated. Violations: immediate service termination, permanent IP allocation loss, no refunds. China is eliminating the technical capability for international connections at the infrastructure level.
The "Great Firewall in a Box" is not a metaphor. It is a product. The receiving countries are identified. The blueprints are documented. The technology is the same architecture Iran is deploying at Pardis IT Town.
The convergence
The whitelisted internet is being built across multiple countries simultaneously.
Russia. Whitelisting deployed across approximately 70 regions. VPN surcharges — 150 rubles per gigabyte of international traffic above 15 gigabytes per month — were postponed until after September elections because carriers could not configure billing systems and the political sensitivity was too high. Instead, the regime shifted to application-layer enforcement: major Russian platforms including Gosuslugi, Sberbank, Ozon, Wildberries, and Yandex now deny access to users with active VPNs, after the Digital Development Ministry threatened loss of whitelist status. Roskomnadzor targets 92 percent VPN blocking effectiveness by 2030, with 20 billion rubles allocated annually. Russia banned the "VPN Traffic Light" project — a site tracking which VPNs still work — on April 6-9. Censoring information about how to circumvent censorship.
Turkey. Parliament passed a social media ID verification law on April 22 requiring government ID-linked verification through the e-Devlet portal for all social media account creation. Social media banned entirely for children under 15. A separate VPN licensing bill is expected imminently. Twenty-seven VPN services already blocked. DPI used to detect and drop OpenVPN, WireGuard, and IPSec traffic.
Myanmar. The military junta operationalized Chinese-backed surveillance infrastructure. The Cybersecurity Law enacted January 1, 2025 makes VPN provision without approval punishable by one to six months imprisonment. The "Person Scrutinization and Monitoring System" deploys AI facial recognition and biometric databases. Police physically stop and search citizens on the street for VPN-enabled devices. Reports of bribery and corrupt police threatening detention for VPN use.
The pattern across all three countries plus Iran: block everything by default, allow only what is approved, verify identity before granting access, and criminalize the tools that let users bypass the architecture.
The democratic parallels
The whitelisted internet does not only take authoritarian form.
Utah. Senate Bill 73, signed March 19, declares anyone accessing websites from within Utah is doing so "regardless of whether they use a VPN, proxy server, or other means to disguise their geographic location." Commercial entities hosting adult content cannot facilitate VPN use or even provide instructions on how to use a VPN. The EFF calls it a "liability trap" — forcing websites to either ban VPN IPs globally or mandate universal age verification. Enforcement was paused until September 3 after a legal challenge by Aylo, Pornhub's parent company. The UK Children's Commissioner has called VPNs a "loophole that needs closing." France's Minister for AI and Digital Affairs said VPNs are "the next topic on my list."
Canada. Bill C-22, the Lawful Access Act, would allow the government to secretly order companies to weaken encryption or create backdoors. Signal's VP of strategy stated the company "would rather pull out of the country than be compelled to compromise on the privacy promises we have made to our users." Windscribe, a Toronto-based VPN, said it would relocate its headquarters. NordVPN warned it would consider following suit.
United Kingdom. The Online Safety Act provisions, if implemented by regulator Ofcom, would require scanning of encrypted messages. Signal president Meredith Whittaker stated the company will leave before compromising encryption. Sweden's parliament is considering a law requiring messaging apps to store and provide access to user communications.
The mechanism differs. The effect converges. Whether by VPN criminalization, age-verification mandates, encryption backdoor laws, or identity-verified access requirements, the legislative output across democratic and authoritarian jurisdictions is structurally similar: the intermediary layer between user and destination is no longer neutral.
The institutional gap
The same Memorial Day weekend the flicker arrived from Iran, the institutional architecture responsible for defending the open internet continued its contraction.
The Cybersecurity and Infrastructure Security Agency is operating at approximately 2,300 filled positions — down from a peak of 3,400. During the February 14 DHS shutdown, 1,453 of 2,341 employees were furloughed; 888 remained — 38 percent. The Election Security Program was eliminated entirely. The Stakeholder Engagement Division — the team that coordinates critical infrastructure cybersecurity with states, local governments, and private businesses — was closed. The Multi-State Information Sharing and Analysis Center lost federal funding and transitioned to a paid model; only 24 states are participating.
Axios reported today that CISA has been pushed to a backseat role in responding to AI-fueled cybersecurity threats. Sources described the agency as not having "a big role" despite its mandate. On May 14, a public GitHub repository created by a CISA contractor was discovered to have exposed 844 megabytes of plaintext passwords, AWS GovCloud keys, and SSH certificates — open for six months.
CISA's acting director told Congress in February: "When the government shuts down, our adversaries do not."
Today NBC News and TechCrunch reported that Iranian hackers breached the Los Angeles County Metropolitan Transportation Authority in March — 700 gigabytes of emails, backups, and files stolen. The breach was discovered by an Israeli cybersecurity firm, not by US federal agencies. The attack disabled arrival screens and prevented customers from loading transit cards.
The institutional calendar takes holidays. The threat side does not.
What works inside Iran
The user-side response to 88 days of whitelisted internet is the operational evidence for the architecture that does not depend on a presidential order.
Psiphon peaked at 9.6 million daily Iranian users during the blackout. Psiphon Conduit — a bandwidth-sharing tool that lets diaspora users relay traffic — recorded 26 million daily connections from Iran. Four hundred thousand Iranians abroad shared Conduit bandwidth as volunteer relays.
Noghteha, a Bitchat fork enabling Bluetooth-based mesh communication independent of internet infrastructure, was downloaded 72,000 times within 48 hours of launch.
Starlink maintained approximately 50,000 terminals smuggled into Iran — most entering via mountain tracks linking Iraq's Kurdish region to Iran's Kurdistan province. Starlink made service free in Iran. The regime disabled approximately 40,000 terminals through GPS jamming, achieving 30-80 percent packet loss. Detection trucks trace signals from antennas for confiscation. 108 terminals were seized — an 881 percent year-over-year increase. Use carries a 10-year prison sentence. One man arrested for using Starlink died after a beating by security forces.
The arxiv technical analysis confirmed that all circumvention techniques using conventional local internet connectivity were blocked by the allowlist approach. Unlike previous shutdowns that used BGP route withdrawal, the 2026 shutdown operated at higher protocol layers — 98 percent of IPv4 prefixes remained globally routed despite near-total connectivity loss. This made traditional VPN circumvention largely ineffective.
What worked: satellite (Starlink), mesh (Noghteha, Briar), relay-based circumvention (Psiphon Conduit), and V2Ray with custom configurations purchased through informal markets. What did not work: any circumvention that depends on the carrier layer the regime controls.
The structural lesson: when the internet is whitelisted, only transports that do not traverse the intermediary layer reach the open network.
The primitive stack that ships through the flicker
The same week Iran's internet flickered, the user-side primitive stack continued shipping.
Anthropic's Project Glasswing reported first results May 22: Claude Mythos Preview flagged 23,019 vulnerabilities across 1,000 open-source projects, of which 90.6 percent were confirmed true positives. Mozilla patched 271 vulnerabilities in Firefox 150 from a single Mythos audit — a 10x increase over the prior model. wolfSSL CVE-2026-5194, a certificate forgery flaw in the TLS library embedded in approximately 5 billion devices, was discovered by an Anthropic researcher and patched April 8.
Signal shipped anti-phishing features May 12 — in-app warnings for suspicious links, local processing only, zero-knowledge architecture preserved. Proton VPN announced post-quantum encryption groundwork and Stealth protocol for Linux. Mullvad deployed GotaTun, its own Rust-based WireGuard engine. Tails 7.8 released May 21. Tor Browser 15.0.14 released May 19.
The open-source stack is being hardened at a pace the pre-AI era could not match. The circumvention tools are being built to operate outside the intermediary layer. The peer-to-peer overlay does not appear in any whitelist or blacklist because it does not route through the infrastructure the whitelist controls.
The flicker is the architecture
The flicker from Tehran today is not a restoration. It is the moment the new architecture becomes visible.
The kill switch data center exists. The three-tier pricing operates. The Chinese equipment is installed. The Russian DPI filters. The court challenged the presidential order the same day it was issued. The IRGC-aligned secretary voted against restoration. The whitelisted internet is the plan, not the shutdown.
The same architecture is being exported. Geedge Networks' 500-gigabyte leak documented the blueprints. Myanmar, Ethiopia, Kazakhstan, Pakistan are receiving the technology. Russia is deploying it in 70 regions. Turkey is mandating identity-verified access. In democracies, the same architectural pattern takes legislative form: encrypt and we leave, verify and we comply, circumvent and we prohibit.
The structural conclusion is simple. The internet is splitting. One half whitelists. The other half ships.
The user-side primitive stack — open clients with user-held keys, open firmware on user-inspectable chips, FIDO2 hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity with selective disclosure, self-hosted services, mesh and satellite at the carrier layer, post-quantum cryptographic agility — runs on the shipping half. It does not require a presidential order. It does not depend on a court ruling. It does not traverse the intermediary layer the whitelist controls.
The flicker is 10 percent of what was. The architecture is 100 percent of what will be. The choice is the transport layer.
URnetwork is a peer-to-peer overlay for censorship-resistant transport. The URnetwork overlay does not appear in the whitelist infrastructure of any of the regimes named in this article because it does not route through the carrier layer those whitelists control.
https://ur.io
References (19 sources)
References
- UPI: Iran's Internet restored for some after 88 days
- Iran International: Iran internet partly restored after 88-day blackout despite court challenge
- Euronews: Iran's internet flickers back on despite judicial halt
- RFE/RL: Limited Internet Restoration In Iran After 88-Day Blackout
- HRW: Iran Internet Shutdown Violates Rights
- Filterwatch: Iran Enters a New Age of Digital Isolation
- Rest of World: Iran is building a two-tier internet
- Global Voices: Iran's digital prison was built with the help of Russians
- TechRadar: Great Firewall in a Box leak
- Meduza: Russia delays VPN surcharges
- EFF: Utah VPN law
- MobileSyrup: Signal threatens Canada exit over Bill C-22
- Axios: CISA takes backseat in AI cyber response
- NBC News: Iranian hackers breach LA Metro
- Anthropic: Project Glasswing update
- arxiv: Iran's January 2026 Internet Shutdown
- TechRadar: Roskomnadzor 92% VPN blocking target
- Iran International: Could Iran be building a Chinese-style internet system?
- RFE/RL: Iran Chinese Technology Internet Throttling