Guides
How to read the rankings, what the tests really do, and why a browser can be recognised without cookies. Written for readers who want the reasoning, not just the numbers.
Rankings & testing
The rankings, the test method, censorship by region, and choosing a tool.
6
How to read the rankings
Every column on the leaderboard has a rule behind it: why we use medians, why some tools show “—” instead of a rank, what the “services only” toggle filters, and how the GreatFire rank column is computed.
6 min read · Sep 10, 2026
How we measure
What the speed, latency, reachability and stability tests actually do inside your browser, how each number is derived, and the biases a browser-based test can't escape.
7 min read · Sep 10, 2026
Censorship by region: why the same tool behaves so differently across borders
Mainland China, Russia, Iran and Turkmenistan each block the internet in their own way, which is why the rankings are split by region. Here is what each system tends to target, how, and why that shows up directly in speed and stability numbers.
6 min read · Sep 10, 2026
What to look for when choosing a circumvention tool
Too many protocol names, even more providers. One-line explanations of each common protocol, the trade-offs between self-hosting and subscribing, what free tools really cost, and how to use this site's data to cross-check any claim.
6 min read · Sep 10, 2026
GreatFire and this site
Who GreatFire.org is, what Circumvention Central does, how this site imports and labels its data, and where the line between the two projects sits.
6 min read · Sep 10, 2026
Data access and the API
Every number on this site is available as JSON: the rankings, the raw test records, per-tool statistics and the external observatories. This page lists the endpoints, their parameters, how often they change, and the terms for reusing the data.
8 min read · Sep 10, 2026
Browser fingerprinting
What each fingerprint-lab module measures, why it matters, and what you can do.
8
What is browser fingerprinting
A website can recognise you without a single cookie: collect a few dozen browser attributes, hash them, and you have a fingerprint. How it works, why entropy adds up, how fingerprints differ from cookies, and the thinking behind this site's "fingerprint authenticity" score.
6 min read · Sep 10, 2026
WebRTC leaks: why your IP shows even with the VPN on
To set up peer-to-peer calls, WebRTC asks a STUN server what your public address looks like, and that request often slips past the VPN. How the leak works, why testing from China needs domestic STUN servers, and what turning WebRTC off costs you.
6 min read · Sep 10, 2026
Canvas, WebGL and audio fingerprints: how your hardware gives you away
Where the three most common hardware-related fingerprints get their variation, why the same machine looks different in another browser, and why noise-adding extensions usually make you more visible, not less. With a note on WebGPU.
6 min read · Sep 10, 2026
Time zone, language and IP: how a site notices you're pretending
Risk systems rarely decide on one signal. They check whether the time zone inferred from your IP, the one your browser reports, your system clock, the HTTP language header and the JavaScript language list agree with each other. Which mismatches are normal, and which get punished.
6 min read · Sep 10, 2026
User-Agent decay and the rise of Client Hints
The User-Agent string carries thirty years of compatibility baggage, and Chrome has frozen it into a near-empty template. Client Hints took over the details. Here is what each one exposes, and how sites catch a browser whose UA has been edited.
6 min read · Sep 10, 2026
How sites decide you are a bot
Headless browsers and automation scripts leave traces in navigator, the window object, the DevTools protocol and the network layer. This explains where each signal comes from, why none is reliable on its own, and why ordinary humans get flagged too.
6 min read · Sep 10, 2026
IP quality: residential, datacenter, and where the “proxy” flag comes from
Beyond the country, websites classify your IP as home broadband, datacenter or mobile, and attach labels like proxy or hosting. Here is where those labels come from, why a VPN exit is almost always a datacenter address, and what that means for you in practice.
5 min read · Sep 10, 2026
DNS leaks, open ports and TLS fingerprints
Three side channels that are easy to overlook: name resolution slipping outside the tunnel, port 22 or 3389 open on your public IP, and the TLS handshake itself giving away your client. How each works, how this site checks them, and how to cross-check yourself.
5 min read · Sep 10, 2026