Walled gardens
Two national networks, walked through from the inside. The first is a single app that quietly runs as two different systems depending on one field at registration. The second is a network that was never connected to the world at all; its operating system gets a module of its own, down to how you read the clock on its screens. About twenty-five minutes, and every claim is sourced.
Physical immersion works because it forces you to navigate systems designed by and for native users, not systems translated for outsiders. The same logic applies to screens. A learner who has only ever used an Australian-facing internet has not met the structural logic of a Chinese or North Korean digital environment; they have met a foreign-facing simulacrum of it. The navigation challenges here practise two things at once: the target language as it actually appears in interfaces, notifications and payments, and the information-control architecture that decides what a native user can see, share and say.
This is not a substitute for travel; it is a distinct and complementary literacy, closer to what digital anthropologists call platform ethnography than to a vocabulary app. For a traveller, it front-loads the operational and cultural adjustment that would otherwise happen, expensively, in the first week on the ground. And for the network no traveller can visit, it teaches something else: how open-source research about a closed society actually gets made.
One app, two countries
Weixin (微信) and WeChat are one product, owned by Tencent, split in 2013 by a single mechanism: the phone number you register with. A mainland Chinese number creates a Weixin account under Chinese data and content law; any other number creates a WeChat account under the international terms. Same login screen, two sets of rules.
The branch point
Click a diamond marker on the phone to read the annotation behind that part of the screen.
Outside the wall is not outside the system
Citizen Lab, "We Chat, They Watch", Research Report No. 127, May 2020 (Knockel, Parsons, Ruan, Xiong, Crandall and Deibert). The lab's director, Ron Deibert, described it as "essentially undertaking political surveillance on one segment of users". Their earlier report, "One App, Two Systems" (2016), gave this module its name.
Rules are one thing. Money is another. Next: what each account's wallet is allowed to do.
Two wallets
The feed, inspected
Click a post to see the mechanism that runs over it. The posts are fictional; the mechanisms are documented.
Why this matters
Standard Australian government travel advice for China (Smartraveller) separately recommends assuming no privacy on hotel or public Wi-Fi and taking care with social media in tense periods; ordinary published precautions, worth reading before departure.
Sources used in this module: Citizen Lab, "One App, Two Systems" (2016); Citizen Lab, "We Chat, They Watch", Research Report No. 127 (May 2020); Beijing Municipal Government English portal, foreign bank card guidance (28 May 2025); China Briefing, foreign-wallet transaction limits; Cybersecurity Law of the People's Republic of China, Article 24 (2017); Measures on the Management of the National Network Identity Authentication Public Service, in force 15 July 2025 (via China Law Translate and the Library of Congress); Smartraveller China travel advice. Full detail in the project's verified-sources report.
The walled garden made physical
North Korea's Kwangmyong (광명) is not a filtered internet. It is a separate network that was never connected to the world to begin with; the wall is not software, it is the topology itself. Module 01 showed control built into an app; this shows control built into the wires. You cannot visit Kwangmyong from outside the country, which makes how we know anything about it part of the lesson.
The operating system that watches its own files
Grunow and Schiess, Chaos Communication Congress, Hamburg, 2015. Researcher Will Scott, who taught in Pyongyang and has handled the system in country, offers a counterpoint worth carrying alongside: the watermarking should be read in the context of a strictly internal, offline system, not as outward-facing spyware. The latest confirmed version is Red Star 4.0, which has never publicly leaked.
That is the terminal. Now the network it connects to.
What grows inside
Everything on this list is reconstructed from defector accounts, leaked builds, and the small number of foreigners who have used the network in country. There is no live source a learner could browse; treat the names as documented sightings, not a directory.
Not a smaller internet; a different organism, grown for propagation and payment, not connection.
How we know any of this
Sources used in this module: 38 North / NK TechLab (Martyn Williams), including "More Than Smartphones" (July 2026) and the 2025 reporting on Red Star deployments; PSCORE, "Digital Hostages: Internet Freedom in North Korea" (June 2023); Grunow and Schiess, Chaos Communication Congress (2015); Will Scott, "Contextualizing RedStar OS" (2016); Radio Free Asia on the mandatory smartphone app (July 2022). Full detail in the project's verified-sources report.
Red Star, up close
Module 02 told you what researchers found. Now stand at the machine. First a simulated desktop shows where each documented mechanism lives; then archival Red Star screenshots and a photograph of version 4.0, annotated so you can learn to read the menus and navigate the environment; then the two things every one of these screens assumes: the clock, the date, and the two number systems Korean runs at once.
The desktop that watches
Click a diamond marker to see which documented mechanism lives behind that part of the screen. The desktop is a generic mockup; the mechanisms are from the 2015 analysis of leaked builds. The next screen shows the real thing.
The file you never opened
meeting-notes.docx
Meeting notes
The meeting begins at three.
Bring the report.
Illustrative document · its visible text stays the same
… document data … [empty space] …… document data … [watermark added] …Schematic comparison, not a recovered byte dump. This page does not access a USB device or alter your files.
In ERNW’s 2015 test, a DOCX file changed when its USB drive was attached to Red Star, without the researchers opening the document. Read the original experiment ↗
Read the real screens
A decade on, the walls got thicker
Reported by Daily NK and 38 North / NK TechLab (August 2025). Version history: 1.0 in 2008; 2.0 completed June 2009; 3.0 released April 2012 and leaked abroad in 2014; 4.0 confirmed by January 2019 and photographed in 2020, but never publicly leaked; no version 5.0 is confirmed. Windows XP reportedly remains widespread despite the domestic OS push.
The same question follows us from desktop to phone: what does the device remember?
What the device remembers
The wall also reaches into files and records of use. Red Star and North Korean Android devices reveal different ways of controlling what travels and what remains.
A file acquires a mark
Red Star’s watermarking can leave evidence that a file encountered a particular machine. A device trace is not a complete account of everyone who carried the file.
A file must be accepted
On Android devices examined by researchers, signature checks decide whether media can be opened. A watermark and permission to open a file are different mechanisms.
Activity becomes a record
Trace Viewer lists screen captures and application activity. The Haeyang 701 stills in the next page let you read an actual log: two tabs, a count, names and timestamps.
The Haeyang 701 uses Android 10; it is not a mobile edition of Red Star. Sources: NK TechLab’s device catalogue; Project Reveal, pp. 9–10.
Two number systems, one clock
The year on the screen
What you can now read
Sources used in this module: archival screenshots via Wikimedia Commons and the Wikipedia article "Red Star OS" (retrieved 3 August 2026), authors and licences as captioned per image (KCC via archive.org and instiz.net; ItzJezze, own work, CC BY-SA 4.0, 2023; NK Kyongje / NKEconomy, 2020; "Windowing in Red Star Linux", 2011); version dates per the same article; Grunow and Schiess, Chaos Communication Congress (2015); Will Scott, "Contextualizing RedStar OS" (2016); Daily NK and 38 North / NK TechLab on the 2025 Red Star deployment (August 2025); NK News (October 2024), Radio Free Asia (December 2024) and Korea Times (February 2025) on the retirement of the Juche calendar; the North-South vocabulary splits cross-checked against this project's Korean divergence briefing; the hour-and-minute reading rule is standard Korean grammar, taught in full in this site's "Two ways to count" walkthrough.