1. First, year ~2015 legal framework was created under disguise of banning pirated media(specifically torrents.ru)(legislative push). State-wide DNS ban introduced. Very easy to circumvent via quering 8.8.8.8
2. Then, having legal basis, govt included extra stuff in banned list(casinos, terrorist orgs, etc)(executive push). IP bans introduced, applied very carefully.
3. Legal expanded allowing govt to ban specific media on very vague criterias(legislative push). IP blocks tried on some large websites. DPI hardware mandated to be installed by ISPs to filter by HTTPS SNI(executive push).
4. At ~2019 Roskomnadzor(RKN) created, special govt entity which enforces bans without court orders(legislative push).
5. ~2021 sites become banned if they are not filtering content by Russian laws by request of RKN(executive push). VPN services were obligated to also DPI-filter traffic(legislative push).
6. ~2023 Crackdown on VPN started(executive push). Popular commercial services were IP-banned, OpenVPN and IPSec connections selectively degraded by DPI.
7. ~2025 Heavy VPN filtering(vless, wireguard, etc) introduced(executive push). Performance of certain sites were degraded(youtube, twitter, etc).
I could miss some things from memory, but RKN originally had much less power back in the days, they were just trying to execute court orders - it started actually being self-sufficient censorship agency in ~2019
But proper curial oversight stopped with the Lugovoi law in 2013, after which RKN could block directly based on orders from the General Prosecutor's office.
This is very up to chance. Sometimes the VPN works, sometimes it doesn't. Sometimes it's fine on the home Internet, but fails on the cell data, sometimes it's otherwise. And it is fine if you're somewhat tech savvy and okay with tinkering with settings, but a huge pain for the older relatives.
Yes, indeed, it is still possible. Right now RKN introducing new DPI capabilities at TSPU(govt filtering hw/sw stack mandated at ISP) - proactive host probing/scanning and mandate for russian services to check and report VPN users hosts. I.e. you use e-shop app and it will report you Nehterlands VPS IP if detected, including split-tunneling tricks)
Won't they just be able to identify the traffic at his local internet provider as being suitable for a VPN usage match and send 'law enforcement' over?
I'm sure you're able to drive faster than the speed limit as well. The issue isn't whether technical circumvention is in the realm of possibility. The base issue here is that even so called 'democratic' governments seem to be copying the authoritarian playbook when it comes to cracking down on privacy online.
1. First, year ~2015 legal framework was created under disguise of banning pirated media(specifically torrents.ru)(legislative push). State-wide DNS ban introduced. Very easy to circumvent via quering 8.8.8.8
2. Then, having legal basis, govt included extra stuff in banned list(casinos, terrorist orgs, etc)(executive push). IP bans introduced, applied very carefully.
3. Legal expanded allowing govt to ban specific media on very vague criterias(legislative push). IP blocks tried on some large websites. DPI hardware mandated to be installed by ISPs to filter by HTTPS SNI(executive push).
4. At ~2019 Roskomnadzor(RKN) created, special govt entity which enforces bans without court orders(legislative push).
5. ~2021 sites become banned if they are not filtering content by Russian laws by request of RKN(executive push). VPN services were obligated to also DPI-filter traffic(legislative push).
6. ~2023 Crackdown on VPN started(executive push). Popular commercial services were IP-banned, OpenVPN and IPSec connections selectively degraded by DPI.
7. ~2025 Heavy VPN filtering(vless, wireguard, etc) introduced(executive push). Performance of certain sites were degraded(youtube, twitter, etc).