Your cloud provider's status page shows green. Your CDN reports 99.9% availability. Meanwhile, users in Tehran, Moscow, and Manila see blank screens. The gap between vendor dashboards and lived reality is where censorship lives—and where OONI Probe has operated since 2012, turning volunteer devices into a distributed sensor network that publishes raw measurements in near real-time [1].

The Reality: Crowdsourced Ground Truth, Not Marketing Fluff

OONI Probe isn't a SaaS product with an enterprise sales team. It's open-source software (AGPL-3.0) that runs on Android, iOS, Windows, macOS, and Linux—installable via Play Store, App Store, F-Droid, direct binary, or apt/brew [1]. The probe executes three core test families: website accessibility (HTTP/HTTPS/DNS/TCP), instant messaging reachability (WhatsApp, Telegram, Facebook Messenger, Signal), and network performance via NDT in partnership with M-Lab [1]. Every measurement auto-publishes to OONI Explorer, a searchable public database with API access, no login required [1].

The methodology is deliberately unglamorous: TCP connect, DNS resolution, TLS handshake, HTTP GET—run from residential networks, mobile carriers, and enterprise Wi-Fi across 200+ countries. No vantage-point rental, no synthetic monitoring from AWS us-east-1. When OONI documented Italy blocking reproductive health sites Women on Web and Women Help Women in July 2026, the evidence came from Italian volunteers' phones, not a vendor's press release [2]. When Spanish ISPs collateral-blocked unrelated domains during LaLiga football streaming enforcement, OONI data showed the blast radius across autonomous systems [2].

The Pain Point: Your Compliance Team Is Flying Blind

If your product serves users in regulated markets, you already have a censorship problem—you just don't know its shape. GDPR, DSA, India's IT Rules, China's PIPL, Russia's sovereign internet law: each creates distinct blocking regimes that change weekly. Legal teams rely on government transparency reports (lol) or carrier notifications (never). Engineering teams deploy feature flags based on geo-IP databases that treat "Turkey" as a monolith while OONI data shows Turk Telekom blocking Telegram but not WhatsApp, while Vodafone TR blocks both [3].

The cost isn't abstract. A fintech startup I advised lost six weeks debugging "intermittent API failures" in Kazakhstan—turned out the national regulator was TLS-fingerprinting their gRPC endpoints and dropping packets. OONI's historical data would have shown the pattern in hours. Another team built a custom health-check endpoint for "China readiness" that returned 200 OK from Beijing while the actual app binary failed signature verification on-device. Synthetic monitoring lies; endpoint reality doesn't.

Failure Modes: Where the Data Betrays You

OONI's strengths are also its blind spots. Volunteer bias skews coverage toward urban, Android-heavy, technically literate populations—rural Ethiopia or Xinjiang measurements are sparse [3]. The probe can't distinguish intentional blocking from transparent proxy interception that rewrites responses (hello, captive portals and enterprise DLP). False positives spike during network congestion: a DNS timeout looks like censorship until you correlate with M-Lab throughput data [1].

The heuristic classifier that labels measurements "anomalous" vs "confirmed blocked" has improved—OONI's July 2026 blog details moving from heuristics to anonymous credentials for bad-measurement filtering [2]—but edge cases persist. SNI-based blocking that permits HTTP but kills HTTPS on the same domain? OONI catches it. QUIC/UDP blocking that only triggers after 50 packets?

The standard web connectivity test misses it unless you run the specialized QUIC experiment. The CLI supports custom test lists and input files, but documentation assumes you know what you're hunting [1].

The Blueprint: Operationalize This Monday

  1. Deploy probes in your CI/CD. Run ooniprobe run websites --input your-domains.txt --format json in a scheduled GitHub Action across three cloud regions and two residential VPS providers. Alert on anomaly rate > 5% per ASN. Cost: ~$15/month in compute, zero license fees.
  2. Ingest OONI Explorer API into your observability stack. Query https://api.ooni.io/api/v1/measurements?test_name=web_connectivity&domain=yourdomain.com&since=2024-01-01 daily. Correlate with your own error rates. Build a dashboard your legal team can screenshot for regulators.
  3. Test circumvention, not just blocking. OONI's psiphon and tor experiments validate whether your recommended VPN/proxy actually works from target networks [1]. If Psiphon fails in Belarus but Tor Snowflake works, that's your runbook.
  4. Contribute test lists. The Citizen Lab maintains global and country-specific URL lists [3]. Add your domains. If you're a news org, a health platform, a dating app—your users are the canaries. Make the data exist.
  5. Stop trusting carrier status pages. When your Indian users report "app not loading" and Jio's status page shows green, check OONI first. The 2026 ISOC Pulse report confirms: censorship is increasingly "targeted, intermittent, and harder to detect" [3]. OONI's longitudinal data is the only public dataset capturing that evolution.

The vendor blogs will keep selling you "global availability" SLAs measured from five data centers. OONI gives you the view from the user's couch. One of these is useful. The other is a PDF nobody reads during an incident.

Sources

  1. OONI Probe Official Site - Download and Documentation
  2. OONI Blog - Research and Measurement Updates
  3. ISOC Pulse - Measuring Internet Censorship: Challenges, Trends, and Impact