TCP + TLS
Trojan
TLS over TCP with a real certificate for the server's own domain. The connection looks like HTTPS to the server's domain; a valid password turns it into a proxy, anything else gets a web page.
Where it does well
Simple and widely supported; behaves like HTTPS to casual inspection.
Where it struggles
Its TLS-inside-TLS timing and size patterns are known to censors, and the domain and certificate are tied to the server, so it is one of the first transports to suffer under deep inspection.
Success, 30 days—Not enough data
Tunnel tests00 vantage points
Median time to first answer—successful tests only
Server locations0tested
Trojan over time
All vantage points and servers.
No tunnel tests in this window yet.
By network
Where the test ran from.
No tests in this window.
By server location
Where the server was. A location that fails from every network points at the server, not at censorship.
No tests in this window.
Compared with the other transports
Same window, same vantage points.
No tunnel tests in this window yet.