Shadowsocks 2022
Shadowsocks 2022 (SIP022) encrypts every byte with 2022-blake3-aes-256-gcm and rejects replays. How it works, where it fits and why Colitu tries it last.
Shadowsocks 2022 is the fifth and last mode that Colitu Adaptive Connect tries on Android and iOS, and one of the TCP modes ranked by connect time on Windows and Linux. Unlike the other four, it does not try to look like anything: from the first byte, a Shadowsocks connection looks like random data.
What it is
Shadowsocks is one of the oldest open-source encrypted proxy protocols. "2022" refers to the SIP022 specification, a redesign that fixed weaknesses of earlier versions. It requires a strong pre-shared key instead of a password, uses BLAKE3 to derive per-session keys, and adds replay protection based on timestamps. The specification covers both TCP and UDP. Colitu servers run it with sing-box using the 2022-blake3-aes-256-gcm method, in multi-user mode: a server key plus a separate key for each user's credentials.
How it works
- Keys. The app has the server key and its own user key, both 256-bit and delivered over an encrypted channel after sign-in.
- A fresh key per connection. For each connection the client picks a random 32-byte salt and derives a session subkey from the key and the salt with BLAKE3. Every session therefore uses a new encryption key.
- Request header. The first message carries a fixed-length header with the message type, a timestamp and a length, followed by a variable-length header with the destination address and optional padding. Everything is encrypted and authenticated with AES-256-GCM.
- Replay protection. The server rejects requests whose timestamp is too far from its own clock (SIP022 allows 30 seconds) and remembers recently seen salts, so a recorded connection cannot be replayed.
- Response. The server's first reply includes the client's salt, which binds the response to that specific request.
- Data. After that, data flows in encrypted, authenticated chunks. At no point is there a recognisable handshake.
Why Colitu uses it
Shadowsocks 2022 is light: no TLS handshake, little overhead per packet and a quick start. It is also unlike every other mode. Filters tuned to TLS or QUIC have nothing familiar to match, so on a network that interferes with TLS or QUIC to unfamiliar addresses for reasons of its own, it can still get through. As the final mode in the order, it gives Adaptive Connect one more option of a completely different kind.
Where it is strong
- Lightly filtered networks: minimal overhead and low latency.
- Networks that interfere specifically with TLS or QUIC: there is no TLS or QUIC handshake to interfere with.
- Low-power devices: AES-GCM is hardware-accelerated on most modern processors.
Limitations and when it is not the best choice
- No camouflage. "Looks like random data" is a signal in itself. Researchers have documented filtering systems that flag fully encrypted traffic heuristically. On networks with aggressive DPI, the Reality-based modes are more likely to work, which is why Shadowsocks 2022 comes last on mobile.
- No certificate. Security rests entirely on keeping the pre-shared keys secret; there is no public-key identity for the server.
- No forward secrecy. There is no ephemeral key exchange: session keys are derived from long-term keys, so anyone who obtained those keys could decrypt recorded sessions. The TLS-based modes do not have this weakness.
- Nothing to show a probe. The server gives a prober no useful answer, but unlike Reality there is no real website behind it either.
- TCP on lossy links. On mobile data or poor Wi-Fi it slows down like any TCP protocol; Hysteria2 is usually faster there.
How Adaptive Connect uses it
On Android and iOS, Shadowsocks 2022 comes last, after Hysteria2, VLESS Reality, VLESS XHTTP and Trojan. It is tried when none of the other four has passed the traffic check. On Windows and Linux it is ranked with the other TCP modes by measured connect time. If Shadowsocks 2022 does not pass the check either, the network is not letting any of the five modes through; the guide VPN not connecting explains what to check next.
Security and encryption
- Cipher: AES-256-GCM, an AEAD cipher: every chunk is both encrypted and authenticated, so any tampering is detected.
- Key derivation: BLAKE3 derives a new session subkey from the pre-shared key and a random salt for every connection.
- Replay protection: timestamps plus a cache of recently used salts.
- Per-user keys: each user's credentials include a separate key in addition to the server key.
- Key handling: keys are delivered to the app in encrypted form and never published.
- No access logs: see the security page.
Sources
Try it
Shadowsocks 2022 is part of every Colitu app as the last fallback, with nothing to configure. Download Colitu or check the server locations.