On January 8 and 9, 2026, people took to the streets to protest against the Islamic Republic. As things got worse around 10 PM on January 8, SMS, phone calls, and internet access were cut off, leaving people in complete darkness. Even the state-run intranet messengers went down.
All we had during those bloody nights were Delta Chat and a private Jitsi Meet server.
The shutdown lasted from January 8 until January 28. Estimates say that more than 40,000 people were killed during this period.
Then, on February 28, 2026, the United States and Israel attacked Tehran, killing Supreme Leader Ali Khamenei. The internet went down again for almost 4.5 months.
But this time, it was different.
The comment sections on ZoomG were being deleted very quickly, making them hard to use for any long conversation. So someone created a forum called ZoomUsers. It made communication a little easier and gave people a more stable place to talk.
Meanwhile, the state-run messengers eventually became available again. But people didn’t trust them, especially during those days. The political situation was extremely tense. People wanted to talk about the war, what was happening around them, and what they were hearing from others.
But talking about political events or criticizing the government could potentially be treated as a serious crime, with the risk of arrest or prison.
So having a way to communicate wasn’t the same as having a safe way to communicate.
People had to think not only about whether their messages could get through, but also about who might be able to read them and what could happen because of what they said.
The FOSS Response
The Persian FOSS community knew a day like this could come, so they had already prepared a number of services and servers. Delta Chat, Matrix, Jitsi Meet, and even a chess website were already up and running.
But the load was huge.
One person known as MADDOG created a one-line installer for setting up a Chatmail server for Delta Chat. It made setting up new servers much easier and helped spread the load across multiple servers.
There was a problem, though.
His program, Madmail, wasn’t able to properly connect the servers to each other. This meant that users on one server couldn’t talk to users on another. You had to create a separate account on each server if you wanted to use it.
It wasn’t perfect, but it was something.
And during an internet shutdown, “something” can make a pretty big difference.
There was also a whole ecosystem of web-based services. Services like Vasl, Zaringo, and Digitoryland became alternative places for people to communicate and share information. On the surface, they seemed fairly safe, or at least safer than the official platforms.
Most of these services were run by individuals or small groups. They were usually paid for out of their own pockets or supported through donations. They didn’t have huge companies or large data centers behind them, so the servers were often small and resources were limited.
Media was an even bigger problem.
Sharing large files was difficult because bandwidth and storage were limited. But there was also a much bigger risk: hosting the wrong file could get an entire website shut down. A single piece of media that the government didn’t like could put the whole service at risk.
The communities had to constantly balance two things: keeping information moving and keeping the servers alive. Some services even had to keep changing domains just to stay reachable.
This is where dedicated upload services became important. Two of the better-known ones were PastePunk and Guardnet.
The community also developed an informal way of sharing potentially sensitive files. Files would be compressed and password-protected. Download links could be protected separately, and filenames would be changed to something meaningless instead of saying what was inside.
It wasn’t advanced security. It was something the community came up with to keep sharing files when even hosting a single politically sensitive video could put an entire service at risk.
The Price of a Connection
Meanwhile, the VPN market was growing quickly.
During the first days of the blackout, some VPN providers were charging around 2 million toman per gigabyte. Over time, the price slowly dropped, reaching roughly 300,000 toman per gigabyte toward the final days.
That might sound absurd from the outside, but when your only connection to the outside world is sold by the gigabyte, every byte matters.
People used their connections very carefully. They weren’t casually scrolling through social media or watching videos. A few megabytes could mean the difference between receiving a piece of information and being completely cut off again.
The Part Nobody Wanted to Talk About
There was another side to the shutdown that rarely came up in conversations about internet access: pornography.
Pornography is heavily restricted in Iran, and privately recording or possessing intimate material can create serious legal and social problems. Under normal circumstances, many people relied on foreign websites for this kind of content. When the international internet disappeared, so did access to those websites.
Some people already had saved material and began sharing it through the same infrastructure being used for other kinds of media. There were even Jitsi rooms where people streamed locally stored videos from their computers.
A small underground market formed around this too, with people exchanging or paying for content.
But there was a much darker side to this ecosystem.
Alongside consensual adult material, harmful and illegal content also circulated, including child sexual abuse material, revenge pornography, and private media that had never been meant for public distribution.
The important point here isn’t how people distributed it, but what its presence showed about the environment.
The same decentralized infrastructure that allowed people to communicate when the normal internet disappeared could also be abused.
And strangely enough, some of this material appeared to circulate more openly on state-run platforms than on the independent services that had grown out of the FOSS community.
People learned to exploit weaknesses in moderation and enforcement. Channels could hide behind completely unrelated subjects, and operators often kept backups in case a channel disappeared.
The result was a strange parallel internet: one built partly for survival, partly for communication, partly for entertainment, and sometimes abused for things that had nothing to do with its original purpose.
The blackout didn’t create all of these behaviors.
It simply removed the normal internet that had kept them separated.
Freedom in Search of Its Way
As the blackout continued, people started looking for more creative ways to reach the outside internet.
A user on X known as Matin Senpai shared a method for connecting through DNS tunneling. It became surprisingly popular among power users.
DNS normally translates domain names into IP addresses, but it can also be used as a narrow communication channel. In a DNS tunnel, pieces of data are put inside DNS queries and sent to a server that understands the tunnel. That server can then decode the requests and send the traffic to the outside internet.
It was a clever way around a network that was blocking normal connections. But DNS was never designed to carry large amounts of data. The bandwidth was extremely limited, and setting it up required much more technical knowledge than a normal VPN.
For an ordinary user, it was difficult, and the connection itself was unstable.
Then another user, known as Paterniha, came up with a different approach based on SNI spoofing.
SNI, or Server Name Indication, is part of the TLS handshake used when setting up an HTTPS connection. It normally tells the server which hostname the client wants to reach. Filtering systems can also inspect this information and use it to decide whether a connection should be allowed or blocked.
SNI spoofing tried to take advantage of the difference between what the filtering system expected to see and where the connection actually needed to go. Instead of showing the blocked destination in the way the filter expected, the connection could appear to be going to an allowed destination while still connecting to the service the user wanted.
It was a very clever idea and, compared with many other methods available at the time, surprisingly stable.
But “internet access” was still a generous way to describe what we had.
At one point, the connection would basically get you to Google Search. You could search for something, but actually opening the website you found was another story.
Yes, you could search the internet without being able to access the internet.
GitHub was another strange case. It would connect, disconnect, reconnect, and disappear again. Sometimes it worked. Sometimes it didn’t. You learned not to trust any connection that worked for more than a few minutes.
Eventually, VPN prices dropped enough for ordinary people to afford them again. A few days later, the situation improved further and internet access was partly restored. It wasn’t a normal connection, but people could once again find relatively cheap ways to get outside.
And, in a way, that is where the situation remains today.
The connection is there, but it isn’t the same connection people had before the shutdown.
Even after the wider internet became partly accessible again, access to many international data centers remained unavailable for months. Services could come back online, disappear again, or stay unreachable depending on where their servers were located.
The blackout had ended, but the network had not really returned to normal.
What remained was a strange middle ground: an internet that technically existed, but where access depended on cost, location, infrastructure, censorship, and simply knowing the right person who knew the right trick.
People didn’t stop trying to connect.
They just kept finding new ways to do it.
Comments
There are currently no comments on this article.
Comment