Skip to content

Support Tor bridges (obfs4, WebTunnel, Snowflake) for censored networks #22

Description

@pursuingVirtue

Prerequisites

  • I searched this repository's existing issues and this is not already requested.
  • This is about the StartOS package — what it exposes, configures, or automates. A feature of the software itself belongs with the upstream project, not here.

What kind of change?

Expose a config option

Problem & use case

In many countries with heavy internet censorship, such as Russia, Iran, China, and others, direct access to the Tor network is blocked or heavily restricted.

In these environments, the only practical way to connect to Tor is often through censorship-circumvention transports such as:

  • obfs4 bridges
  • WebTunnel bridges
  • Snowflake

This is a serious usability and privacy issue for StartOS users in censored regions.

StartOS depends less on Tor than it did in the past, but Tor is still used for some privacy-related functionality and services. If a user's ISP or national firewall blocks access to public Tor relays, those Tor-dependent features may become unavailable.

For many users, this is not just a convenience issue. Bridges are the standard way to access Tor in countries where the public Tor network is blocked.

Proposed solution

It would be very useful to expand the Tor configuration options in StartOS.

In addition to the existing options related to operating as a Tor relay or bridge, StartOS could allow users to configure bridges for outbound Tor connections.

Ideally, the Tor settings could support at least:

obfs4
WebTunnel
Snowflake

For example, a user could paste an obfs4 bridge line in the standard Tor format:

obfs4 11.22.33.44:8443 7DE66000000000001B40DE80 cert=jp4H0000000000000m0GkygBbWQ iat-mode=0
The same interface could support WebTunnel bridge lines.

For Snowflake, StartOS could provide a simple option such as:

Use Snowflake

or another configuration appropriate for Tor's current Snowflake implementation.

A possible UI could be similar to Tor Browser or Brave:

Tor connection

[ ] Connect directly to Tor

[x] Use a bridge

Bridge type:

  • obfs4
  • WebTunnel
  • Snowflake
  • Custom

Bridge configuration:
[ paste bridge line here ]

Users could obtain bridges from the official Tor Project bridge distribution system, from Tor Project communications, or use privately operated bridges.

It would also be helpful to support multiple bridge lines, so users can configure several fallback bridges.

Alternatives considered

Using Tor without bridges

This does not work in networks where Tor relay IP addresses or the Tor protocol itself are blocked.

Manually editing Tor configuration

Advanced users may potentially find ways to modify Tor configuration manually, but this is fragile, difficult to maintain, and not suitable for most StartOS users.

It could also be overwritten by updates.

Native support in the StartOS Tor settings would be much safer and easier.

Running a separate bridge/proxy externally

Users could run another machine or proxy specifically to provide Tor connectivity, but this adds significant complexity and defeats the goal of having a self-contained StartOS server.

Anything else?

Tor Browser already has good UX for this problem, including support for bridges and pluggable transports such as obfs4, WebTunnel, and Snowflake.

Brave also provides similar Tor connectivity options.

Implementing bridge client support in StartOS would make Tor-dependent privacy functionality usable in countries where direct Tor access is censored.

From the user's perspective, the feature could remain relatively simple: enable bridges, select a transport, and paste one or more bridge lines.

This may be a relatively small configuration feature, but it could make a very large difference for users living behind national censorship systems and help hundreds or potentially thousands of people who currently cannot reliably use Tor functionality on StartOS.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions