Survival Guide for a Censored Internet Brazil's ANPD ordered Discord's Go Live feature shut down nationwide due to end-to-end encryption preventing content surveillance, and Congress passed a sentence enhancement for crimes committed using a VPN, marking the first such penalty in Brazilian history. The Brazilian judiciary has blocked communication services for over a decade, including WhatsApp in 2015 and 2016, Telegram in 2022 and 2023, and X/Twitter for 40 days in 2024, with fines of R$ 50,000 per day for VPN users. This guide offers practical steps to maintain communication as censorship tightens. Survival Guide for a Censored Internet If you're lazy, click here https://claude.ai/new?q=Please+open+this+URL+with+web+search+and+read+the+full+article%3A+https%3A%2F%2Fwww.akitaonrails.com%2Fen%2F2026%2F08%2F19%2Fsurvival-guide-for-a-censored-internet%2F%0A%0AAfter+reading+the+real+content+of+that+article%2C+do+the+following%3A%0A1%29+Summarize+the+5+most+important+points+and+the+conclusion.%0A2%29+After+the+summary%2C+tell+the+reader+what+key+details%2C+data+and+insights+they+are+missing+by+not+reading+the+full+article.+Be+specific+enough+to+make+them+curious.%0A3%29+Remind+them+they+can+keep+asking+follow-up+questions+about+this+article+right+here+in+this+chat.%0A4%29+Suggest+one+good+follow-up+question+they+could+ask+as+a+starter. for the TL;DRLast week I wrote about the Discord censorship and Brazil’s Digital ECA law /en/2026/08/13/understanding-the-discord-censorship-and-brazils-digital-eca/ , the Digital ECA “Estatuto Digital da Criança e do Adolescente”, the digital version of Brazil’s Child and Adolescent Statute : the ANPD Brazil’s data protection authority, now also the country’s de facto internet regulator ordered the Go Live feature shut down nationwide because end-to-end encryption prevents content surveillance, and in the same package came the first sentence enhancement in Brazilian history for committing a crime “using a VPN”. After that article, the question I got the most was the obvious one: “OK, so what do I do?” This article is the answer: a practical guide, from easiest to hardest, to keep your communication channels standing as the siege tightens. Because the siege is tightening, and you should understand its pace before picking your tools. The track record: none of this is new Anyone surprised by the Discord case was not paying attention. The Brazilian judiciary has been blocking communication services for over a decade, always steamrolling millions of innocent users to reach half a dozen suspects: WhatsApp, 2015 and 2016 : blocked three times by lower-court judges https://g1.globo.com/tecnologia/noticia/2022/03/18/whatsapp-ja-foi-bloqueado-por-decisao-judicial-em-2015-e-2016-no-brasil.ghtml , always because the company would not hand over conversations that, by design, it cannot read. Telegram, 2022 and 2023 : suspended for two days by order of Justice Alexandre de Moraes in March 2022 https://www.gazetadopovo.com.br/republica/stf-voltara-a-julgar-bloqueio-do-whatsapp-moraes-ja-suspendeu-telegram/ , and again by a federal judge in 2023. Migalhas has the full timeline https://www.migalhas.com.br/depeso/414499/stf-alem-do-x-relembre-os-bloqueios-do-whatsapp-e-telegram-no-brasil . X/Twitter, 2024 : the landmark. Nationwide suspension from August 30 to October 8 https://itforum.com.br/noticias/de-outubro-a-outubro-confronto-x-e-stf/ , 40 days , by a single justice’s order. And here is the detail that matters for this guide: the decision included a fine of R$ 50,000 ~US$ 10,000 per day for any individual who accessed X through a VPN https://www.gazetadopovo.com.br/mundo/crise-eua-moraes-twitter-files-lei-magnitsky/ , an order for app stores to remove VPN apps walked back hours later , and the Federal Police and Anatel the telecom regulator producing reports on who bypassed the block https://istoedinheiro.com.br/pf-e-anatel-enviam-ao-stf-relatorios-sobre-acessos-ao-x-mesmo-com-bloqueio to support the fines. Notice what happened there: for the first time, using a neutral privacy tool became, by itself, punishable conduct in Brazil. Nobody was fined in the end, but the infrastructure to fine people was built, tested and documented. And in 2026 Congress voted and the president signed a sentence enhancement for crimes committed with a VPN. The X precedent stopped being an exception and became repertoire. Keep this:in the X case, the Brazilian state already treated VPN users as offenders, already tried to pull VPNs from app stores, and already requested reports on who bypassed the block. All of it documented, in court orders and public reports. The endgame: the Chinese model I have little doubt that very well-positioned people in government look at China’s Great Firewall https://freedomhouse.org/country/china/freedom-net/2024 with envy, not horror. And it is worth understanding what it is, because it defines the limit of the game. The Firewall goes far beyond blocking websites. It is deep packet inspection DPI at national scale, running on the country’s internet backbone: all traffic is classified in real time, known VPN protocols are identified by their handshake shape and dropped, Tor is blocked by default, and only state-approved VPNs meaning, with a backdoor operate legally. Ordinary citizens caught using unauthorized VPNs get fined. And even when the traffic cannot be read, the metadata gives the game away: who talks to whom, when, for how long. That is why the honest answer to “can you bypass a Firewall like that without being noticed?” is: no, not for an ordinary citizen . Against a state-level firewall of that caliber, no consumer tool makes you invisible. At best it makes you too expensive to be worth persecuting at scale. Anyone selling you total invisibility is lying. The good news is that Brazil is nowhere near that point. Censorship rarely arrives all at once: it comes in steps, and each step has a matching defense. The rest of this guide is that staircase, step by step. The logic behind everything that follows is a single one: censorship is a matter of cost . Our job is to make blocking expensive, technically and politically, until mass deployment becomes impractical. Keep this:against a complete state firewall, no tool makes you invisible, only too expensive to persecute at scale. The game is climbing your staircase before the censor climbs his. Phase 1: Commercial VPN, the minimum everyone should have Start with the obvious. A VPN virtual private network creates an encrypted tunnel between your device and a provider’s server. Your ISP internet service provider now sees only a scrambled flow going to a single address; the sites you visit see the VPN’s IP, not yours. I explain it in depth, with the networking theory underneath, in Akitando 126 https://akitaonrails.com/2022/08/29/akitando-126-criando-uma-rede-segura-introducao-a-redes-parte-6-vpn-e-nas/ in Portuguese . What a VPN does : hides your traffic from your ISP, swaps your exit IP, gets you out of geo-blocks and of court-ordered DNS/IP blocks. What it does not do : It does not make you anonymous. The VPN provider sees all your traffic in place of your ISP. You did not eliminate the watcher, you just picked a different watcher. It does not hide your identity if you paid by credit card. A credit card subscription ties the VPN account to your tax ID. If authorities show up at the provider with a court order, your name is there. It does not protect content past the tunnel. From the VPN exit to the final website, the web’s normal encryption HTTPS applies. The VPN is one leg of the path, not the whole path. That said, for the early phases of the siege it does the job. My recommendations, in order: : Switzerland, outside easy jurisdiction, open source and audited, a no-logs policy tested in court, a decent free tier, and it accepts payment even in cash by mail. ProtonVPN https://protonvpn.com/ : Sweden, the most paranoid on the market: it does not even ask for an email, your account is a random number. Flat €5/month, accepts cash in an envelope and cryptocurrency. It is the closest thing to an “identity-less VPN” that exists as a commercial product. Mullvad https://mullvad.net/ - NordVPN and the like work technically, but their money goes more to marketing than to privacy posture. Among the big ones, I stick with the two above. The limit of this phase is well known: the exit IPs of famous VPNs are public and catalogued. An order from ANPD or Anatel to national ISPs to block those ranges is technically trivial, and the X case showed that pulling the app from the store is also on the menu. When not if that happens, the commercial VPN dies in a day. That is why Phase 2 exists. Keep this:a commercial VPN is a seatbelt: use it always, but know it depends on three things outside your control. The app staying in the store, the IPs staying unblocked, and the provider staying honest. Phase 2: Self-hosted VPN, your own tunnel The move here changes shape: instead of subscribing to a service with millions of users and catalogued IPs, you rent a cheap little server outside Brazil and build your personal VPN. There is no public list with your IP for the censors to download. You are one user on an unknown IP, indistinguishable from any other traffic until someone looks closely. Picking the provider and why not AWS, Azure or Google Cloud . The big clouds have huge, public, well-mapped IP ranges ASNs . Blocking them wholesale is one line in a routing table; the only brake is collateral damage plenty of legitimate Brazilian businesses live there , and other countries have paid that price in crises. Smaller providers dilute that target. Options I would consider, from mid-sized to small: | Provider | Based in | Why | |---|---|---| | OVH https://www.ovhcloud.com/ / Scaleway https://www.scaleway.com/ Contabo https://contabo.com/ Vultr https://www.vultr.com/ / DigitalOcean https://www.digitalocean.com/ BuyVM https://my.frantech.ca/ , HostHatch https://hosthatch.com/ , LiteServer https://liteserver.nl/ A US$ 3 to 5 machine with 1 GB of RAM is plenty for a personal VPN. Important caveat: paying for a VPS virtual private server with a credit card leaves a trail just like the commercial VPN: your name is in the provider’s records, and the provider can be legally compelled. Some accept cryptocurrency, which reduces does not eliminate the trail. For most people, at this phase, the signup risk is acceptable: you are not hiding from a named investigation, you are getting out of the aim of a mass block. Step by step: WireGuard with wg-easy I will use wg-easy https://github.com/wg-easy/wg-easy , which packages WireGuard the modern, fast, auditable VPN protocol into a Docker container with a web panel and QR codes to set up your phone in seconds. 1. Rent the VPS. Ubuntu 24.04, the smallest machine available, in a region outside Brazil Amsterdam, Frankfurt and Helsinki are classic choices for jurisdiction and acceptable latency . 2. Log in and update: ssh root@YOUR IP apt update && apt upgrade -y 3. Install Docker: curl -fsSL https://get.docker.com | sh 4. Generate the panel password hash wg-easy does not accept a plaintext password; write down the password you choose : docker run --rm -it ghcr.io/wg-easy/wg-easy wgpw 'YourStrongPasswordHere' the output looks like: PASSWORD HASH=$2b$12$abc... in the command below, double every dollar sign: $ becomes $$ 5. Start the container: docker run -d \ --name=wg-easy \ -e WG HOST=YOUR IP \ -e PASSWORD HASH='$$2b$$12$$abc...' \ -v ~/.wg-easy:/etc/wireguard \ -p 51820:51820/udp \ -p 51821:51821/tcp \ --cap-add=NET ADMIN \ --sysctl="net.ipv4.conf.all.src valid mark=1" \ --sysctl="net.ipv4.ip forward=1" \ --restart unless-stopped \ ghcr.io/wg-easy/wg-easy 6. Open the firewall. Port 51820/UDP is the tunnel itself. Port 51821/TCP is the panel: do not leave the panel exposed to the internet . The right way is to open it only through an SSH tunnel ssh -L 51821:localhost:51821 root@YOUR IP and browse to localhost:51821 , or to open 51821 just long enough to create your clients and close it right after. 7. Create the clients. In the panel, one click generates a client with a QR code. Point the official WireGuard app Android/iOS camera at it and you are done. On a laptop, download the config file and import it into the WireGuard client. Done: all of your device’s traffic exits through your European server. Your Brazilian ISP sees only a scrambled flow to some random IP in Germany. And on your machine, how do you use it? The server is half the story. On your device, the ritual goes like this: On your phone Android/iOS : install the official WireGuard https://www.wireguard.com/install/ app from the store or from F-Droid on Android . Tap the "+" , choose “Scan from QR code” and point it at the code the wg-easy panel showed. A new “tunnel” appears in the list: one tap on the switch and you are in. On iOS, enable “On-Demand” in the tunnel settings so it reconnects by itself when you switch networks Wi-Fi to 4G, for instance . On your laptop Windows/macOS : download the official WireGuard client for your system, click “Import tunnel s from file” and select the .conf you downloaded from the panel. One click on “Activate” and done. Important detail: the official client has a “Block untunneled traffic” option the kill switch : turn it on. If the tunnel drops, your internet stops instead of leaking through your real IP. On Linux: copy the .conf to /etc/wireguard/wg0.conf and bring it up with sudo wg-quick up wg0 plus sudo systemctl enable wg-quick@wg0 to start it at boot . Or import the file straight into NetworkManager through the graphical interface, if you prefer clicking to typing. A complete client .conf , for reference, looks like this: Interface PrivateKey =