COLITU LABProbes starting

TCP + TLS

Trojan

TLS over TCP with a real certificate for the server's own domain. The connection looks like HTTPS to the server's domain; a valid password turns it into a proxy, anything else gets a web page.

Where it does well

Simple and widely supported; behaves like HTTPS to casual inspection.

Where it struggles

Its TLS-inside-TLS timing and size patterns are known to censors, and the domain and certificate are tied to the server, so it is one of the first transports to suffer under deep inspection.

CSVJSONAPI
Success, 30 days—Not enough data
Tunnel tests00 vantage points
Median time to first answer—successful tests only
Server locations0tested

Trojan over time

All vantage points and servers.

No tunnel tests in this window yet.

By network

Where the test ran from.

No tests in this window.

By server location

Where the server was. A location that fails from every network points at the server, not at censorship.

No tests in this window.

Compared with the other transports

Same window, same vantage points.

Open in Compare

No tunnel tests in this window yet.