Knowledge Commons
HomeAboutGuidesPopularContact

How Does Blocking Work, Technically?

From the T24 Ruling to Bandwidth Throttling, from the Judge's Pen to the Cable: The Technical Anatomy of Censorship and Surveillance in Turkey

Author: Oğuz Demirkapı
How Does Blocking Work, Technically?

How Does Blocking Work, Technically?

From the T24 ruling to bandwidth throttling, from the judge's pen to the cable: the technical anatomy of censorship and surveillance in Turkey

Dear Young Comrades,

Those of you who tried to open T24 last night met a warning page, or an empty screen that never loaded. In the previous piece, under the title They Shut Down What They Cannot Buy, we talked about why this ban came, about the class roots of censorship. This piece's question is different: how?

How does a paper a judge signs turn, on the screens of eighty-five million people, into the sentence "this site cannot be reached"? Who emails whom, which company changes which setting, why does the application on your phone sometimes work and sometimes not? What is the difference between a site being "shut down" and a platform being "slowed"? And an infrastructure that can do all of this: what can it see at the same time?

The reason we ask these questions is not technical curiosity. Marx writes that the machine is in itself neither good nor bad, but that its capitalist use turns it into a weapon against labour. Internet infrastructure is the same. The cable, the router, the DNS server have no politics; but depending on whose hands they are in, and on whose instruction they work, they become either a commons or a fence. Whoever does not know how the fence is built cannot know where to get past it either.

Our method is as always: a source under the claim, a link under the source. Where we do not know, we will say "we do not know", because in this field the unknown itself is a part of the regime.


In brief: the blocking regime in five minutes

For those who do not have time for the long reading, first the short form:

  • How was T24 shut down? The Istanbul Chief Public Prosecutor's Office asked for an access block under the "Ailem Güvende" investigation. Istanbul's 1st Criminal Court of Peace rejected this request on 25 September. The prosecutor's office objected, and the court that examined the objection, on 29 September, in decision 2026/8894 D.İş, relying on Article 8/A of Law 5651, placed an access block on T24's site and on its social-media accounts. The ruling was emailed to T24 by the Cybersecurity Presidency on the evening of 30 September at 17.00, and it was demanded that it be carried out "at once and within four hours at the latest". (T24, 30 September 2026)
  • Where does the ruling go? Rulings no longer go to the BTK. They go to the Cybersecurity Presidency (SGB), attached directly to the Presidency, which took over the internet powers with Law 7590, in force on 31 July 2026. The SGB conveys the ruling to the internet service providers, to the social-media companies, and to the site itself.
  • What is done technically? The internet service providers (Türk Telekom/TTNET, Turkcell Superonline, Vodafone, TurkNet and others) put the site's domain name on a blacklist. In practice three methods are used together: DNS redirection (a wrong answer being given when you ask for the domain name), IP blocking (the traffic going to the server's address being cut), and SNI filtering (the connection being dropped by looking at the domain name that goes in the clear at the first moment of the encrypted connection). Social-media accounts are shut down not by the service provider but by the platform itself ("Withheld in Turkey").
  • What is slowing? Bandwidth throttling is choking the traffic that goes to a platform instead of shutting it down entirely: the page acts as if it will open, and does not; the video spins and spins; the message does not go. It is preferred because it can be denied: one can say "there is no censorship, the site is slow". From November 2022 to September 2025 it was applied in at least five major moments of crisis. Its basis is Article 60 of Law 5809, amended by Decree-Law 671 issued in the 2016 state of emergency, and none of the decisions was made public.
  • What is DPI? Deep packet inspection is the hardware and software that can look not only at the envelope of the data packets passing through the network, but inside them too. It is the engine both of blocking and of slowing. The same box was used, in 2018, on the Türk Telekom network, to redirect users into downloading spyware. (Citizen Lab, Bad Traffic, 2018)
  • The figures: As of the end of 2025, the number of domain names unreachable from Turkey is 1,505,484; in 2025 alone 232,441 domain names were blocked. The number of news items blocked under 8/A went in one year from 127 to 2,118. (İFÖD, EngelliWeb 2025)
  • What do we not know? We do not know the text of the bandwidth-throttling decisions, which DPI system is working today on whose network, the scope of the "lawful-interception infrastructure" the SGB took over, or with whom the traffic data is shared. This ignorance is not an accident; it is a design.

Now let us go into the detail.


1. The T24 case: a ruling's four-day journey

First let us set down the event itself, without breaking its order. Because the best way to understand the technical process is to follow the trace of a concrete ruling.

DateEvent
The second half of September 2026A campaign targeting T24 begins on social media.
25 September 2026The Istanbul Chief Public Prosecutor's Office's request for an access block is rejected by the criminal court of peace.
25–29 September 2026The prosecutor's office objects to the refusal.
29 September 2026Istanbul's 1st Criminal Court of Peace, examining the objection, gives an access block in decision 2026/8894 D.İş, relying on 5651/8-A. The ground: "the prevention of crime and the protection of public order".
30 September 2026, 17.00The Cybersecurity Presidency notifies T24 of the ruling by email: it will be carried out "at once and within four hours at the latest".
30 September 2026, eveningThe ruling is also published on the BTK's site. The site and the social-media accounts become unreachable from Turkey.
30 September 2026, nightT24 announces that it removed, within four hours, the 118 items listed in the ruling, and that the block nevertheless continued; it directs its readers to the mobile app.

Sources: T24, the news of the ruling, T24, "A reckoning with Turkey", Yol TV, 1 October 2026, Cumhuriyet

Three things come out of this table from the technical angle. Keep them in mind; we will return to each below:

  1. The ruling is given for "content", but the "site" is shut down. The ground is 118 items. The measure applied is the whole of the domain name. This has a reason that is not legal but technical (see Section 2.4).
  2. Removing the content did not lift the block. That is, the block is aimed not at the content whose removal was asked, but at the publication itself.
  3. The institution that notifies is new. Yesterday it would have been the BTK. Today it is the Cybersecurity Presidency. This is one of the first large applications of a legal change made quietly two months ago.

Let us also note this: T24 announced that 22 of the 57 people counted as the authors of the items said in the ruling to have been published "in the past year" had for years not been writing for T24. (T24) A sign that the ruling was produced quickly from a list, not with care.


2. How blocking works, technically

2.1 The actors: who decides, who applies?

Behind a block there is not a single "censorship clerk". There is a chain, and each link of the chain sees its own work as "only its own work". As Hannah Arendt said of bureaucracy, where everyone is responsible, no one is responsible. Let us get to know the chain:

ActorWhat does it do?What does it say, to whom?
The one who asks (the public prosecutor's office, the Presidency, ministries, the police, institutions)Asks for a block.Says to the court or to the SGB, "this address is disturbing public order".
The Criminal Court of PeaceGives the ruling. It is a single judge, holds no hearing, does not hear the other side.Writes a ruling: "let access to these addresses be blocked".
The Cybersecurity Presidency (SGB)Takes the ruling, coordinates the technical application; in urgent cases it also decides itself. Until 31 July 2026 this work was at the BTK.Says to the service providers "apply it within four hours", to the site "remove the content", to the platform "shut the account".
The Access Providers' Union (ESB)A union, established in 2014 by Article 6/A of Law 5651, of which every internet service provider is a compulsory member. It secures the distribution of rulings from a single centre to all the companies.Conveys the ruling to the member companies. A notification made to the union is deemed made to all the companies.
Access providers (TTNET, Turkcell Superonline, Vodafone, TurkNet, Türksat and others)Apply the block in practice.Load the blacklist onto their own DNS servers, routers and DPI boxes.
The hosting provider (the server company where the site is hosted)It can be asked to remove the content from the server.If it is inside the country, it is directly the addressee.
The social-network provider (X, Meta, YouTube, TikTok)Applies "in-country hiding" at the level of the account or the post.Does not show the content to IP addresses in Turkey.
The content provider (publications such as T24)Is the addressee of the ruling, but is not heard while the ruling is given.Learns the ruling most of the time after it has been applied.

According to İFÖD's 2025 report, blocking rulings were given by 875 different institutions and courts; there are 1,284,464 separate rulings. Even the Turkish Football Federation has had more than a hundred thousand rulings given, on the ground of pirate broadcasts. (Diken, İFÖD EngelliWeb 2025) That is, "blocking" is no longer an exceptional judicial act; it is an everyday administrative routine.

2.2 The legal doors: which article, which path?

In Turkey there is more than one legal door for blocking access to an internet content. To understand T24, the most important are these:

Law 5651, Article 8: catalogue offences. For particular offences such as the sexual abuse of children, obscenity, gambling, incitement to suicide, drugs. In this article the measure of the remedy is relatively defined.

Law 5651, Article 8/A: "cases where delay would be prejudicial". This is the door that is really widening. It is used on the grounds of the right to life, the safety of persons' lives and property, national security, public order, the prevention of crime, and general health. The ruling is normally given by a judge; but in cases where delay would be prejudicial, the administrative authority (first the TİB, then the BTK, today the SGB), on the request of the Presidency or of the ministries concerned, decides directly and submits it to a judge's approval within 24 hours. The ruling is notified to the service providers and to the content and hosting providers, and is applied "at once, within four hours at the latest". The law takes as its basis that the block be made on the basis of the content (the URL); it says that if this is not technically possible, or if a content-based block is insufficient, the whole of the site may be blocked. This last sentence, as we will see below, is the sentence that turns the exception into the rule.

Law 5651, Article 9: personality rights. For years this was the main instrument for taking news down. The Constitutional Court annulled this article on 11 October 2023; the annulment entered into force on 10 October 2024. (Hukuki Haber) The result? The blocking of news did not stop; it moved to 8/A. The number of news items blocked under 8/A was 127 in 2024, and 2,118 in 2025. The number of X accounts blocked under 8/A went from 20 to 995. (İFÖD, EngelliWeb 2025) When one door closed, the wider one opened.

Law 5651, Additional Article 4: social-network providers. It was brought in 2020 by Law 7253. It laid on foreign platforms reached from Turkey by more than a million people a day the obligation to appoint a representative in Turkey, to keep user data in Turkey, and to comply with rulings. For the one that does not comply, it provided, in order, a fine, an advertising ban, and then bandwidth throttling of 50 percent, then 90 percent. (Diken) The answer to why the platforms are so "compliant" is here: the cost of disobedience is to lose the Turkey market.

Law 5809 on Electronic Communications, Article 60: the emergency measure. The legal basis of bandwidth throttling. The detail is in Section 3.

Law 7590 (Official Gazette, 31 July 2026): the moving of the power. And finally, the change that explains who notified the T24 ruling: the BTK's powers, arising from Law 5651, of content removal and access blocking, the supervision of social-network providers and the sanctions including bandwidth throttling, domain-name administration, the emergency-measure power in Law 5809, and the coordination of the lawful-interception infrastructure, were transferred to the Cybersecurity Presidency, established in 2025 and attached directly to the Presidency. At the BTK only the licensing of operators, frequencies and consumer affairs remained. (Paksoy Hukuk, Teknoblog, soL haber, Euronews Turkish)

Let us not underestimate the meaning of this last change. The BTK, however politicised it had become, was a regulatory institution: it was charged with regulating the market, competition and the consumer. Today the power of censorship and interception is gathered in an institution that has "security" in its name and is attached directly to the executive. The governance of the internet has been carried from the field of economic regulation to the field of security.

2.3 The ruling's descent to the cable: step by step

Now let us follow, step by step, from the paper to the cable, the technical journey of a block:

StepStageWho?What does it do?What does it say, to whom?
1RequestThe prosecutor's office, the Presidency, a ministry, or another institutionAsks for an access block.To the court (in an urgent case, to the SGB): "These addresses are disturbing public order."
2RulingThe Criminal Court of Peace (in an urgent case, the SGB; submitted to a judge's approval within 24 hours)Decides on the file, without hearing the owner of the content.To the SGB, with the decision number, the list of addresses and the ground: "Let these addresses be blocked."
3CoordinationThe Cybersecurity Presidency (until 31 July 2026, the BTK)Distributes the ruling to all the parties that will apply it, and publishes it on a public list.To four separate arms: "Apply it at once, within four hours at the latest."
4aDistributionThe Access Providers' Union (ESB)Conveys the ruling to all the member companies with a single notification.To all the internet service providers: "Add it to the blacklist."
4bDistributionSocial-network providers (X, Meta, YouTube, TikTok)Takes the ruling through the representative in Turkey.To its own system: "Hide the account in Turkey."
4cNotificationThe content provider (for example T24)Learns the ruling by email, most of the time after it has been applied.From the SGB: "Remove the content."
4dNotificationThe hosting provider (the server company)If it is inside the country, it is asked to remove the content from the server.From the SGB: "Take the content off the air."
5ApplicationService providers and platformsLoads the DNS, IP and SNI blacklists; the platforms raise the "Withheld in Turkey" flag.To the devices on the network: "Cut the connection going to this address."
6ResultThe userSees a warning page, a timeout, or a "connection reset" error.—

At the first step the request comes from an institution. In T24's case this is the Istanbul Chief Public Prosecutor's Office.

At the second step the court gives the ruling. The criminal court of peace is a single judge and decides on the file; the publication is not heard before the ruling is given. If a refusal comes out, the objection goes not to a higher court but to a neighbouring court; the criminal courts of peace in Turkey are one another's courts of objection. This is exactly what happened with T24: one court's refusal turned into the acceptance of the court examining the objection. This is the system lawyers have for years called a "closed circuit".

At the third step the ruling reaches the SGB. The SGB distributes it to all the parties that will apply it, and lists the ruling on a page open to the public. An important detail: according to İFÖD's report, the notifications are most of the time sent without the ruling itself attached, only as an instruction to "block this address"; some publications never see the ruling, or see it late. (İFÖD) You cannot object without seeing the ruling. That is, the right of objection exists on paper, and in practice it is delayed.

At the fourth step the ruling splits into four arms. The most important is the ESB arm: the union conveys the ruling to all the internet service providers at the same time. Every company that provides an internet service in Turkey is obliged to be a member of this union. In this way a ruling descends, with a single notification, onto all the cables in the country.

At the fifth step each company applies the block to its own infrastructure. We will come in a moment to how this is done.

At the sixth step you see the result on your screen.

The whole chain has to be completed within four hours. To seal a newspaper's printing house, there used to be a need for the police, a record, a lock, a visible raid. Today an email and four hours are enough. This is the technical counterpart of what we said in our first piece on censorship: the state gives the ruling, the company carries out the sentence, and the carrying-out is invisible.

2.4 The technical methods: how does the blacklist work on the cable?

Here we will become a little technical, but do not be afraid. If you know how you connect to a website, you also understand how you are blocked.

When you type t24.com.tr into your browser, roughly three things happen in the background:

  1. Name resolution (DNS): Your computer asks a DNS server, "what is the address of t24.com.tr?" This server is generally your service provider's. The answer is an IP address, for example 104.x.x.x.
  2. The connection (IP): Your computer connects to that IP address.
  3. The encrypted handshake (TLS): If the connection is HTTPS, before the encrypted channel is set up your browser tells the server which site it wants. This is called SNI (Server Name Indication), and in most cases it goes unencrypted, as clear text.

Blocking is done by intervening in each of these three steps:

Method 1: DNS redirection. The service provider's DNS server, when a blocked domain name is asked for, returns not the real address but the address of a warning page, or nothing. OONI's measurements recorded that, for blocked domain names in Turkey, the IP of a known warning page (195.175.254.2) is returned. (OONI, 2025) This is the oldest and the crudest method. This is why, in the Twitter ban of 2014, people wrote "8.8.8.8" on the walls: when another DNS server was used, the block was got past.

Method 2: IP blocking. The traffic going to the IP address of the site's server is dropped directly. Its problem is this: today most sites are hosted on content-delivery networks such as Cloudflare, and thousands of sites share the same IP address. Blocking one IP can also black out hundreds of unrelated sites. For this reason it is rarely used on its own, but it is resorted to in cases that do not care about the collateral damage.

Method 3: SNI filtering. This is the real engine of today's blocking. The DPI devices on the service provider's network look at the SNI field at the head of every encrypted connection. If they see "t24.com.tr", they cut the connection (generally by sending a fake "connection reset" packet) or silently swallow the packets. Even if you change your DNS, this block is not got past, because in the handshake your browser still says which site it wants.

Let us see these three methods together:

MethodWhat does it look at?What does the user see?What does it not work against?
DNS redirectionThe domain name that is askedA warning page, or "site not found"Against someone using another DNS (or encrypted DNS)
IP blockingThe server address that is gone toA timeout; the page never opensWhen the site changes its IP; the collateral damage is large
SNI filtering (DPI)The clear domain name in the encrypted handshake"Connection reset", or endless loadingAgainst tools such as a VPN or Tor that wrap the traffic entirely
Bandwidth throttling (DPI)The domain name and the traffic signatureThe site acts as if it will open, and does notIn the same way, against tools that wrap entirely (but they too can be targeted)

So why the whole site, not a single news item? Here is the technical answer to the first observation in Section 1. In the age of HTTPS, the service provider can see that you went to the site t24.com.tr, but it cannot see which news item on that site you looked at; the /gundem/... part of the address is encrypted. That is, it is technically not possible for a service provider to block a single news item. It has two options: either it asks the content provider to remove the news item, or it blocks the whole domain name. The provision of Law 5651, "blocking on the basis of content is the rule; if that is not possible the site is blocked", in a world where HTTPS has spread, means in practice "the site is blocked". Encryption, while protecting your privacy, also gives the censor the excuse "I cannot be selective, I am shutting it all down".

In the T24 case it went further still: the content was removed, and the site stayed shut. Here there is no longer a technical necessity; there is a political choice.

So why does the app work (or why can it)? T24 directed its readers to the mobile app. We can guess its technical logic like this (because we do not know T24's infrastructure, this is an inference): the blocking is done through the domain name. Mobile apps most of the time pull the content not from the main site but from an API endpoint on a separate domain name, or at a cloud provider. If that endpoint is not on the blacklist, the app goes on working. This shows that the blocking is not a "structure" but a "list": one passes through the door that is not on the list. And by the same logic, when a new line is added to the list, that door closes too. The app store is a separate weak link: Apple and Google can answer a request to remove an app from the Turkey store with the same "compliance" reflex.

2.5 Social-media accounts: the platform applies the block

It is not Türk Telekom that shuts down T24's X or Instagram account. Because Türk Telekom cannot block a single account without blocking x.com (again because of HTTPS).

Here the mechanism is different. The ruling is conveyed through the SGB directly to the platform, that is, to X Corp., to Meta, to Google. The platform takes this ruling through its representative in Turkey and raises, on its own server, a country-restriction flag. From that moment, users coming from IP addresses in Turkey cannot see the account; in its place they see the sentence "This account has been withheld in Turkey in response to a legal demand". Everyone abroad goes on seeing the account.

That is, on social media it is not the state but the company that applies the censorship in practice. And it does this because of the sanction ladder of Additional Article 4: for the platform that does not comply, first a fine, then an advertising ban, then bandwidth throttling that cuts its traffic in half, then to a tenth. For a company this means withdrawing from the Turkey market. It is not hard to guess what a monopoly working on the profit motive will choose in the question of the market or freedom of expression.

There is an important difference here: a site block descends onto all the cables of the country; an account block is only a line in the platform's database. This is why someone using a VPN can see the blocked account, because they appear to be connecting from outside Turkey. The block is in reality the rule "let those connecting from Turkey not see it".


3. Those that are not blocked but are slowed: bandwidth throttling

3.1 What is bandwidth throttling?

Bandwidth throttling is the art of making a site or a platform unusable without shutting it down.

Technically it works like this: the service provider's DPI devices recognise, from the SNI field and from the traffic signature, the traffic going to particular platforms. Then they apply a speed limit to this traffic. Packets are queued, delayed, or a part of them is deliberately dropped. In OONI's definition: "The speed of the packets in the flow is restricted; packets are delayed, queued or dropped until the transfer speed falls below the threshold." (OONI)

The user's experience is this: the app opens, but the timeline does not load. The text comes, the photograph does not. The video spins and spins. The message says "sending" and is not sent. Your internet is working; other sites are opening. Only those platforms seem to have "crashed".

3.2 Why do they slow instead of shutting down?

Because slowing can be denied. When a site is shut down there is a ruling, a warning page, a notification; it can be objected to. In slowing there is nothing. One can say "there is congestion", "a technical fault", "the platform's own problem". OONI makes the same finding: "Instead of blocking the platforms directly, the authorities may be seeking deniability by slowing them; this also raises concern in terms of transparency and human-rights violations." (OONI)

The second reason is finer: slowing is an instrument designed for the moment of crisis. The first hours of a protest, of a disaster, of a political operation are the hours when information spreads fastest and people organise fastest. Who gathered where, which road is closed, who was detained, which lawyer went where, is shared in these hours. Bandwidth throttling targets exactly those hours. The next day everything "returns to normal", and no one can speak of a lasting ban.

3.3 The record: when, and for how long?
DateThe occasionWhat was affectedDuration
13 November 2022The bomb attack on İstiklal AvenueTwitter, Facebook, Instagram, YouTube and othersFor hours
8 February 2023After the earthquakes of 6 FebruaryTwitter (the main channel of aid coordination in the earthquake zone)For hours
23 October 2024The TUSAŞ attackThe main social-media platformsAbout 17 hours
19–21 March 2025The detention of Ekrem İmamoğlu and the protestsX, Instagram, YouTube, TikTok, WhatsApp, Telegram, SignalAbout 42 hours in Istanbul
7–8 September 2025The appointment of a trustee to the CHP's Istanbul provincial headquartersX, Instagram, YouTube, TikTok, Facebook, WhatsApp, Telegram, SignalAbout 21 hours

Sources: OONI, 2023, OONI, 2025, Stockholm Center for Freedom, Turkish Minute, Cumhuriyet

Let us also add the examples applied not as "slowing" but as a "full block": in August 2024 a full access block on Instagram lasting more than a week, and the blocks placed the same year on Roblox and Discord, which still continue today.

Look at the table carefully. At the head of the list are attacks and disasters, and at the end political operations against the opposition. The instrument's original justification was "to prevent panic after a terror attack". In 2023 the main channel of the volunteers trying to reach people under the rubble in the earthquake was slowed. In 2025 the instrument was used, openly, to cut the opposition's organising in a political crisis. The instrument stayed the same; the target changed. This is the local version of the pattern we saw in the September 11 piece: the apparatus built for the exception turns into the rule.

3.4 The legal basis: a state-of-emergency decree-law

The legal basis of bandwidth throttling stayed secret for a long time. Even its coming out depended on a lawyer's persistence: the lawyer Faruk Çayır asked, through CİMER, for the basis of the bandwidth throttling applied after the Taksim attack in November 2022. The BTK's answer was this: Article 60 of Electronic Communications Law 5809, as amended on 15 August 2016 by Decree-Law 671, issued in the state-of-emergency period after the coup attempt. (bianet, 30 November 2022)

Under this provision, in cases where delay would be prejudicial, on grounds such as national security and public order, the Presidency takes the measure; the administrative institution notifies the operators, and the operators apply it within two hours. The decision is submitted to a judge's approval within 48 hours, and if it is not approved it lapses of itself. Because bandwidth throttlings generally last shorter than 48 hours, in practice they end without any need for a judge's approval. That is, the oversight mechanism comes into play after the act to be overseen has ended.

With Law 7590 this "emergency measure" power too was carried to the Cybersecurity Presidency. (Paksoy Hukuk)

So where is the text of these decisions? None of them was made public. Prof. Dr Yaman Akdeniz, founder of İFÖD, asked the BTK for the documents of the 17-hour bandwidth throttling after the TUSAŞ attack, did not get them, and filed a case. The 12th Chamber of Administrative Cases of the Ankara Regional Administrative Court rejected the BTK's objection unanimously, and the ruling became final on 14 June 2026. This was the third case Akdeniz won against the BTK on bandwidth throttling. (Cumhuriyet) That is, a citizen had to win in court three times in order to learn why their country's internet was slowed.

3.5 How is the slowing measured?

"Feeling" bandwidth throttling is easy; proving it is hard, because it resembles an ordinary congestion of the network. OONI (the Open Observatory of Network Interference) gets past this like this: the OONI Probe app on volunteers' phones regularly tries to connect to sites and measures how long the TLS handshake lasts. Then the measurements of the target platforms (x.com, instagram.com) are compared with the measurements of 19 to 30 unrelated domain names hosted on the same network, at the same hour, in the same IP blocks. If the network is really congested, they all slow. If only the target platforms slow, there is a selective intervention. (OONI)

With this method OONI has, since 2014, collected more than 24 million measurements from 277 different networks in Turkey. In March and September 2025 the most marked intervention was seen on the networks of TTNET (Türk Telekom) and Turkcell Superonline; on the TurkNet network a DNS block was also detected for YouTube. An interesting detail: Telegram's web interface was not slowed, it was blocked directly; the endpoints the mobile app uses stayed open. (OONI)

This detail tells us something important: the censorship infrastructure is fine-tuned enough to recognise the platforms, and their different doors, one by one. This means that someone writes a rule list saying, one by one, "slow x.com, shut web.telegram.org, break YouTube's DNS".

An OONI Probe running on your phone becomes a part of this record. We will return to this in Section 7.


4. Surveillance: whoever can shut the door also sees inside

So far we have talked about blocking and slowing. But we cannot finish this piece without asking this question: an infrastructure that can cut a connection, what does it know about that connection?

The answer is simple: in order to cut, one first has to see.

4.1 DPI: deep packet inspection

On the internet every piece of data is carried divided into small packets. Every packet has an "envelope" (the header: where it comes from, where it is going, through which port) and a "letter" (the payload: the actual content). An ordinary router looks only at the envelope, because its job is to deliver the packet to the right address. It is like a postal worker.

DPI is a postal worker who can also open the envelope and look at the letter. It can read the content of the packet, recognise which application it belongs to, look for particular patterns, and accordingly pass the packet, delay it, stop it, copy it, or change it.

In traffic encrypted with HTTPS, DPI cannot read the content of the letter. But it can see, and most of the time does see, these:

  • which site you connected to (from the SNI and the DNS queries),
  • when, for how long, and how much data you sent and received,
  • which application you used (from the traffic signature: a WhatsApp call, a Signal message and a Netflix video "look" different from one another),
  • whether you are using a VPN or Tor (most VPN protocols have a signature of their own).

This is called metadata. And metadata most of the time tells more than the content. You do not need to know what was said by someone who, at 23.40, enters a union's site, then talks for ten minutes over Signal with the same lawyer, and towards morning connects to a base station in Kadıköy; you know what they did. In the words of a former NSA official: "We kill people based on metadata."

4.2 Bad Traffic: spyware on the Türk Telekom network (2018)

The best-documented example in Turkey of DPI being used not only to "look" but also to "change" is the "Bad Traffic" report that Citizen Lab, within the University of Toronto, published in March 2018.

Citizen Lab found that the Canadian company Sandvine's PacketLogic DPI devices were being used on the Türk Telekom network, and that these devices, targeting some users, did this: when the user wanted to download a legitimate program such as Avast, CCleaner, Opera or 7-Zip, the device caught this request on the way and redirected the user to a version of the program infected with spyware. Among those targeted were also users connecting over the Türk Telekom network from the Kurdish regions in Syria. The same devices were being used in Egypt to inject, secretly, advertising and cryptocurrency-mining code into users' traffic. (Citizen Lab, Bad Traffic)

Two lessons come out of this report:

  1. The blocking box and the surveillance box are the same box. A device that blocks a site can, with another menu of the same software, redirect the user somewhere else, and change the file they download.
  2. Every connection that is not encrypted is a connection that can be changed. The reason this attack worked at the time was that the download links were HTTP, not HTTPS. Today, because HTTPS has spread, an injection of this kind is much harder. Encryption, for this reason, is not a luxury; it is a minimum of self-defence.

We do not know which company's which DPI system is running today on the networks in Turkey. The tender, the purchase and the capabilities of these systems are not made public.

4.3 The retention of traffic data: a record of every connection

The second leg of surveillance is retention. Law 5651 and the related regulations force internet service providers to keep, for a certain period, their users' traffic data (which IP address connected, at what hour, to which address, for how long). "Collective-use providers" such as cafés, libraries and workplaces are also obliged to keep a record of which internal IP address was given to which device on their own networks. The free Wi-Fi you connect to in a café has a ledger.

Law 7590 made a change here that looks small but is large: the "port information" in the definition of traffic data was widened to "source and destination port information". (Teknoblog)

Let us explain why this matters. In Turkey the mobile operators, because IPv4 addresses are not enough, put thousands of subscribers behind the same external IP address (this is called CGNAT). Formerly it was hard, for this reason, to find the person from the IP address seen in a site's records: that IP belonged, at that moment, to hundreds of people. But when the source port number is also added to the IP address, it becomes possible to distinguish a single subscriber behind that shared address. The change technically narrows the anonymity behind mass networks.

4.4 Lawful interception: in whose hands is the "infrastructure"?

The interception and recording of communications in Turkey is done through several separate legal doors: Article 135 of the Code of Criminal Procedure (with a judge's decision, for particular offences), Additional Article 7 of the Law on the Duties and Powers of the Police and Additional Article 5 of the Gendarmerie Law (for prevention), Article 6 of the Law on the National Intelligence Organisation (for intelligence). All of these doors connect to a technical interception infrastructure installed on the operators' networks.

This infrastructure was, until 2016, at the Telecommunications Communication Presidency (TİB), and then at the BTK. With Law 7590, the duty of providing the technical infrastructure for lawful interception, and of determining the protocols, was also given to the Cybersecurity Presidency. (Teknoblog, soL haber)

That is, gathered today in the hands of a single institution are these: content blocking, sanctions on social-media platforms, bandwidth throttling, domain-name administration, the standards of traffic data, and the interception infrastructure. İFÖD defines this concentration as a risk of "censorship and surveillance without oversight". (Euronews Turkish)

4.5 Open-source surveillance and platform data

The most ordinary, but perhaps the most widespread, form of surveillance is not technical but labour-intensive: the police's scanning of social-media accounts. The Interior Ministry's regular announcements that "so many accounts were examined, so many people were detained" show that this scanning is done on an industrial scale. There is no need for DPI for this; a post open to everyone is open to everyone.

There are also platform data requests: the police and the prosecutor's offices can ask companies such as X, Meta and Google for users' identity information, login IPs and telephone numbers. The obligation in Additional Article 4 of a representative in Turkey, and of the data being kept inside the country, was aimed at speeding these requests. We can learn to what extent the companies answer these requests only from their own transparency reports, late and in aggregate.

4.6 A collective look at the surveillance techniques
TechniqueWhat does it see / what does it do?Legal basisIs it open to the public?
DNS recordsWhich domain names you asked forThe service provider's operational recordNo
DPI / SNI analysisWhich sites you connected to, with which applications, and when; VPN useThe blocking legislation; there is no explicit basis for use for the purpose of surveillanceNo
Retention of traffic dataThe record of your connections (IP, port, time)Law 5651 and the regulations, Law 7590The rule is open; the practice and the access records are closed
Lawful interceptionThe content of the communication (in those that are unencrypted)CCP 135, PVSK Add. 7, Gendarmerie Law Add. 5, NIO Law 6The numbers and the scope of the decisions are closed
Base-station / HTS recordsWhere your phone was, whom you calledLaw 5809 and the related legislation, court rulingsNo
Platform data requestsThe account holder's identity, login informationLaw 5651 Add. 4, CCPOnly the companies' transparency reports
Open-source scanningPosts open to everyoneThe general power of the policeAt the level of statistics

5. What is legal, what is not, and what we do not know

The mistake most often made in this field is to confuse "legal" with "legitimate". In Turkey a large part of blocking and surveillance is legal. The problem is exactly this: the law has been written in order to regulate arbitrariness. Let us make the distinction clear:

What has a legal basis (but whose lawfulness is debatable):

  • An access block under 8/A by a judge's ruling or by an administrative decision (there is a basis; there is no proportionality, no reasoning, no right of defence).
  • The social-media representative obligation and the bandwidth-throttling sanction brought by Law 7253.
  • The Presidency's emergency-measure decision under 5809/60 (the basis is the product not of Parliament but of a state-of-emergency decree-law).
  • The retention of traffic data, and lawful interception.

What has a debatable legal basis, or what is caught by the judge:

  • The keeping secret of bandwidth-throttling decisions (the three cases Akdeniz won registered that this secrecy is contrary to law).
  • Notifications made without the ruling itself being sent (they make the right of objection functionless in practice).
  • Site blocks continued even though the content was removed (openly contrary to 8/A's principle that "blocking on the basis of content is the rule").
  • The criminal-court-of-peace system, which the Constitutional Court has for years called a "structural problem".

What we do not know:

  • The text of the bandwidth-throttling decisions, who requested them, on what ground they were given.
  • Which DPI system is running at which service provider, from whom it was bought, what it can do.
  • Whether the metadata the DPI systems collect is kept, and if it is kept, who can reach it.
  • The scope and the oversight of the lawful-interception infrastructure transferred to the SGB.
  • How the ESB's role after Law 7590 will be defined in the secondary regulations.
  • Whether VPN use is detected and recorded at the network level.
  • How many interception decisions are given in a year, how many people are intercepted.

Read this last list like this: as a citizen you do not know what is known about you. The state knows what it knows about you. This asymmetry in knowledge is power itself. The question we asked in the KVKK piece grows sharper here: an institution charged with protecting personal data warns the citizen, but the apparatus that collects the citizen's data the most gives no account at all.


6. The blocking regime in figures

For a snapshot, a few figures from İFÖD's EngelliWeb 2025 report ("Digital Martial Law: Silencing the Public in the Name of Public Order"):

IndicatorValue
Blocked domain names and websites as of the end of 20251,505,484
Domain names blocked in 2025 alone232,441
The number of separate rulings on which the blocks rest1,284,464
The number of institutions and courts giving rulings875
Rulings given under 8/A in 2025179 rulings, 78 different criminal courts of peace
News items blocked under 8/A (2024 → 2025)127 → 2,118
X accounts blocked under 8/A (2024 → 2025)20 → 995
YouTube videos blocked under 8/A (2025)706
X accounts blocked after 19 March 2025985 accounts, about 25.8 million followers

Sources: İFÖD, EngelliWeb 2025, Diken, 17 June 2026

Note two figures. News blocks increased seventeenfold, X-account blocks fiftyfold. And this increase came immediately after the Constitutional Court annulled Article 9. The judiciary closed one door; the executive opened the "public order" door all the way. What we lived through in September 2026 (LGBTI+ associations, Evrensel, Amnesty, MLSA, the 147 accounts talking about the fund crisis, and now T24) is the continuation of this curve, not its exception.


7. A class reading: the technical is not neutral

Now let us step back from all this technical detail and look at the large picture.

7.1 The property of the infrastructure is the limit of the right

The overwhelming part of internet traffic in Turkey passes through the networks of a handful of companies. Some of these companies belong to private capital, some to the Wealth Fund. On social media the traffic flows on the servers of a few monopolies centred in the United States. The condition of a blocking ruling's being applicable in four hours is that the communications infrastructure is gathered in a few hands. On an internet made of a hundred thousand independent networks, this speed would not be possible.

That is, centralisation is not only an economic fact; it is the technical precondition of censorship. Every infrastructure that is monopolised is a valve the state can shut with a single telephone call. If the process we call digital enclosure works in production as the seizure of the general intellect, in circulation it works as the tying of the channels of communication to a valve.

7.2 The division of labour between the ruling and its carrying-out

Think again about the table in Section 2.1. The judge says "I gave the ruling, but the company applied it". The company says "I only applied the ruling". The SGB says "I only conveyed it". The platform says "we comply with local laws". Responsibility evaporates among the links of the chain. This is the most effective side of modern censorship: no one is a censor, everyone is only doing their job.

Marxist analysis reminds us of this here: the technical division of labour is the material form of a social division of labour. The engineer who installs the DPI device, the network operator who loads the blacklist, the clerk who writes the notification, are also workers. But the product of their labour is being used to cut the voice of their own class. This is the most concrete example of what we said in the computing worker's handbook: the links of this chain are at the same time the possible points of organising, of objection, and of conscientious refusal.

7.3 In whose crisis is the slowing done?

Look once more at the bandwidth-throttling table. The volunteer in the earthquake zone trying to reach the relative of someone under the rubble, the student calling the lawyer of a friend detained at a protest, the worker who wants to go in front of a provincial building to which a trustee was appointed. What is slowed is not "social media"; it is the people trying, at that moment, to organise themselves.

And the cost is not paid equally. The boss, the managers, the wealthy already have corporate VPNs, lines abroad, alternative channels. Those most affected by bandwidth throttling are the section whose telephone is their only instrument of information and communication, who cannot pay for a VPN, who do not know what it is. Even in an infrastructure that looks public, like the internet, access is a class matter. The knowledge and the means of getting past censorship are also distributed as a privilege.

7.4 The politics of the word "security"

The most important institutional move of the last two years was the transfer of the governance of the internet to an institution bearing the name "Cybersecurity". This change of language is not innocent. The word "regulation" implies a public service: accountable, open to oversight, open to objection. The word "security" implies a threat: it requires secrecy, it requires speed, it is not questioned. The internet is now being governed not as a public infrastructure but as a field of security. This is the local form of the worldwide tendency we saw in the piece where we discussed Anthropic's "critical infrastructure" move: the securitisation of information infrastructure.

Let us look comparatively:

The ruling narrativeOur question
"We blocked it in order to protect public order."Whose order? Why did you shut a newspaper again after it had removed 118 news items?
"We slowed it in order to prevent panic after a terror attack."Why the aid channel after the earthquake, why the operation against the opposition?
"The rulings are subject to judicial oversight."Can one object without seeing the ruling? Who oversees a measure that lasts shorter than 48 hours?
"The platforms comply with local laws."Who makes the choice between market share and freedom of expression?
"A single centre is necessary for cybersecurity."When censorship, interception and data are gathered in a single centre, who will oversee that centre?
"The use of a VPN is not forbidden."Then why are you blocking VPN sites?
"A technical operation."A technical operation is the political decision made invisible.

8. What can we do? Digital self-defence and the record

Technical knowledge has to be of use. What we can do in order to protect first ourselves, then one another:

At the individual level (all of them are legal and publicly available tools):

  • Use encrypted DNS. In the settings of your phone and your browser, turn on the "Private DNS" or "Secure DNS" (DNS over HTTPS / DNS over TLS) option. This gets past DNS redirection, and makes it harder for your service provider to see which domain names you ask for. But it does not get past SNI filtering. Know this.
  • Keep your browser up to date. New browsers are bringing in, step by step, support for ECH (Encrypted Client Hello), which also encrypts the SNI field. As it spreads, SNI filtering will grow harder.
  • Prepare for the moment of crisis in advance. Bandwidth throttling arrives at the moment of crisis; trying to download a VPN app at that moment most of the time does not work, because the VPN sites are blocked too. Install a VPN you trust, or Tor Browser (together with the bridge/Snowflake setting), in advance.
  • Use end-to-end encrypted communication. Apps such as Signal protect the content; the metadata is still visible, but the content is not.
  • Do not tie organisational communication to a single platform. If a union's, an association's, a collective's contact with its members is tied to a single X account, a single WhatsApp group, that contact can be cut by a single ruling. Email lists, tools running on one's own server, RSS, face-to-face networks matter as a spare channel.

At the collective level:

  • Measure. Install OONI Probe on your phone. Every measurement adds a line to the public record of censorship in Turkey. The proof of bandwidth throttling is these measurements coming from ordinary people's phones.
  • Report. When you meet a block, report it to İFÖD's EngelliWeb project. This record is also the basis of applications to the Constitutional Court and to the ECtHR.
  • Archive. Save blocked content to public archives such as the Internet Archive (the Wayback Machine). The knowledge commons is protected only when it is multiplied.

9. Concrete tasks

Young comrades, the tasks we propose so that this piece does not remain as information:

  1. Organise a "digital self-defence" workshop at school, at the workplace, in the union. It is possible to teach, in an hour, the installation of encrypted DNS, a VPN, Signal and OONI Probe. This knowledge should spread in advance, not at the moment of crisis.
  2. Draw your organisation's map of communication. If there is no answer to the question "if our X account is blocked tomorrow, how do we reach our members?", set up a spare channel today.
  3. Use the right to information. Follow Yaman Akdeniz's path: make CİMER and right-to-information applications about bandwidth-throttling decisions, DPI tenders, and the SGB's use of its powers. Every application that is refused is a record; every case that is won is a precedent.
  4. Build a tie with computing workers. Network engineers, system administrators, telecoms workers are inside this chain. In the professional organisations and in the computing unions, start the discussion of ethical principles, and of the right of conscientious refusal, concerning work on the censorship infrastructure.
  5. Support the legal struggle of the press organisations and of bodies such as İFÖD and MLSA. T24's objection, the application to the Constitutional Court, and a possible ECtHR process grow stronger with public support.
  6. Defend, as a programmatic demand, the public and common character of the communications infrastructure. Municipalities' free and unsurveilled public internet networks, community networks, demands for an open and auditable infrastructure, can be carried onto the agenda of local politics.

The fence and the door

In this piece we tried to tell the path a blocking ruling follows from the judge's pen to the cable, how platforms are choked in moments of crisis, and that every apparatus that can shut the door also sees inside at the same time.

Let us not get lost inside the technical details: all these DNSes, SNIs, DPIs, decree-laws and statute numbers are the instruments of a single thing. The tying of the people's ways of reaching one another to the permission of a few centres. The shutdown of T24, the hiding of Evrensel's account, the slowing of Twitter in the earthquake, the silencing of WhatsApp at the protest, are the turning of the same valve on different days.

But every fence has a door, every list has a missing line. Last night T24's app was working. In 2014, 8.8.8.8 was written on the walls. In 2025, VPN downloads multiplied in a night. And a jurist won in court three times in order to learn why their country's internet was slowed. Technical knowledge, for this reason, is not an expertise; it is an instrument of organising.

We have learned how the fence is built. Now it is the turn of keeping the doors open together.

Knowledge belongs to everyone.


Related pieces


Sources

The T24 ruling

The legal frame and Law 7590

Bandwidth throttling

Surveillance and DPI

Statistics

Related Posts

Newsletter