you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 17 min ago 255 onions tracked
home / news / tor network
08 April 2025 tor network 4 min read

Obfs4 bridges explained: hiding Tor traffic in plain randomness

When a state censor decides its citizens should not reach the outside world, breaking Tor is usually near the top of the checklist. Plain Tor traffic is trivially recognizable through deep packet inspection. Obfs4 bridges are the Tor Project's countermove: unpublished relays whose connections are engineered to look like nothing at all.

Random bytes by design

Obfs4 belongs to the family of pluggable transports, small programs that sit between Tor and the network and rewrite every byte on the wire. As its author, known under the pseudonym Yawning, puts it in the protocol specification, the goal is keeping a third party from identifying the protocol in use based on message contents.
The purpose is to keep a third party from telling what protocol is in use based on message contents.
The trick begins with the handshake. The client proves knowledge of a secret distributed out of band, namely the bridge's node ID and Curve25519 public key, and encodes that key using the Elligator 2 mapping so that even the key exchange resembles uniform random data. Everything after the handshake follows the same doctrine. Traffic is wrapped in authenticated NaCl secretboxes, frame lengths are masked with SipHash so no telltale size fields leak, and padding plus protocol polymorphism blur packet-size signatures. What crosses the wire is statistically indistinguishable noise.

Getting your hands on bridge lines

Bridges are deliberately absent from the public Tor directory, so users must request them individually. The Tor Project's BridgeDB service distributes them through several channels, each adding friction designed to slow bulk harvesting.
  • The bridges website, which dispenses lines instantly
  • Moat, the built-in requester in Tor Browser settings behind a captcha
  • Email to bridges@torproject.org from a Gmail or Riseup address
  • The GetBridgesBot on Telegram
The official support documentation walks through each method, including how to paste a received bridge line into the connection settings. Captchas, domain restrictions and per-request throttling exist to raise the cost of automated collection without locking out ordinary users.

Where obfs4 meets its match

Obfuscation protects the wire, but it says little about what happens when a censor suspects a server and connects to it directly. China's Great Firewall does exactly this: passive sensors flag suspicious flows, and research published by the Tor Project measured probes arriving roughly half a second after a first connection. Here obfs4 holds a structural advantage over its ancestors. A prober lacking the shared secret cannot compute the handshake authentication codes, so the server stays silent and drops the connection after a randomized delay instead of confirming anything about itself. Silence, however, is itself measurable. Researchers presenting at NDSS 2020 showed that TCP-level behaviors such as timeouts and never responding can identify probe-resistant proxies including obfs4 with just a handful of crafted probes and negligible false positives.

Practical limits worth knowing

Field measurements sharpen the warning. In a study of China's blocking of unpublished bridges presented at USENIX FOCI, privately deployed obfs4 bridges remained reachable, while publicly distributed ones had already been recorded and blacklisted by the firewall. That exposes obfs4's genuine weakness: distribution rather than cryptography. A formal analysis published in 2024 concluded that obfs4 satisfies modern security definitions for obfuscated key exchange, yet any bridge line that leaks to a censor is effectively dead on arrival.

Choosing between transports

For most users behind aggressive national firewalls, obfs4 remains the sensible default: fast, mature and maintained under the lyrebird implementation. Where it fails, the alternatives trade throughput for camouflage. webtunnel dresses Tor up as ordinary HTTPS, while snowflake bounces connections through volunteer-run proxies to imitate a video call. No transport wins permanently. Circumvention is an arms race, and the side that measures the censor fastest usually holds the line. Request fresh bridges the moment your current set goes dark, and treat every bridge line as a secret worth guarding.

more notes

all news ›