Security1 publisher3 min readPublished
Source-code match ties a shipping Chinese appliance to the Great Firewall
Academics rebuilt Geedge Networks' Tiangou Secure Gateway firmware from a 100,000-file leak and matched its filtering to China's censorship system. The same box has been exported.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- A team of American academics found source code overlaps between the products of a Chinese tech company and China's Great Firewall traffic filtering and censorship system, in research presented at this year's USENIX Security conference.
- According to the USENIX research, the Chinese government uses the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.
- Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.
- The leak included databases for Geedge's Jira and Confluence portals as well as all its Git source code repositories, containing commit history going back to November 2024.
- Researchers used the leaked source code and commit history to reconstruct Geedge TSG firmware, which allowed them to match TSG traffic filtering capabilities to some sections of the Great Firewall and its behavior.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A team of American academics told this year's USENIX Security conference that the Chinese government operates Geedge Networks' Tiangou Secure Gateway (TSG) as one of the Great Firewall's three known traffic filtering capabilities [s1c1][s1c2]. That converts a familiar advocacy line into a procurement fact, because reporting after last year's leak confirmed Geedge was exporting its internet censorship tools to countries including Kazakhstan, Ethiopia, Pakistan and Myanmar [s1c8].
The method matters as much as the finding. More than 100,000 files leaked from Geedge's network last year [s1c3], including the databases behind its Jira and Confluence portals and all of its Git source code repositories, with commit history reaching back to November 2024 [s1c4]. The researchers used that code and history to reconstruct TSG firmware, then matched the device's traffic filtering capabilities against specific sections of the Great Firewall and its observed behavior [s1c5]. That is identification at the level of build artefacts, not an inference drawn from packet oddities.
The scope claim should be read narrowly. Bill Marczak, writing on August 16, 2026, noted that Geedge is only one of the vendors involved in the Great Firewall, and that the authors found only one of the three characterised DNS injectors making up the system matched behavior from the Geedge code [s1c9]. On those numbers, two of the three injectors remain unattributed to Geedge [s1c10]. One appliance in one slot of a three-part filtering stack is still the first time a commercial product line has been tied this directly to the machinery.
The second finding is the one buyers should sit with. The authors concluded that TSG is just as insecure and poorly coded as its Western counterparts [s1c6]. In their words, complexity and flexibility are a double-edged sword: core components such as SAPP and its protocol plugins are written in memory-unsafe C, the system still leans on transitional arrangements like Stellar-on-SAPP, code is copied from several third parties, and the Jira tickets corroborate the patchwork process, including an AppSketch database upgrade that caused SAPP to restart, which they read as a lack of code verification [s1c7]. The researchers believe the leaked code, its poor quality and its abundance of bugs could be abused by Great Firewall circumvention tools in future [s1c11].
For anyone running a network in a country that bought this product, the supply-chain question is now concrete rather than reputational. The in-path inspection device parsing all of your traffic is built on memory-unsafe C assembled by an admittedly ad hoc process, and its source code and ticket history are outside the vendor's control. The same leak that made the Great Firewall attribution possible also handed every bug hunter a map.
Watch whether circumvention projects turn the leaked code into working evasions or exploits, which is the researchers' own stated expectation [s1c11]. Watch whether the other two filtering capabilities in the Great Firewall get attributed to named vendors [s1c9]. And watch procurement in the export markets already reported by InterSecLabs, Amnesty International and Justice for Myanmar [s1c8][s1c12], since a state-filtering pedigree is now a documented product attribute rather than a suspicion.