Hysteria2
Hysteria2 runs over QUIC with TLS 1.3 and its own congestion control. How it works, why it is fast on lossy links, where UDP limits it and how Colitu uses it.
Hysteria2 is the first connection mode that Colitu Adaptive Connect tries on every platform. It is a proxy protocol built on QUIC, the UDP-based transport underneath HTTP/3, and it is designed to keep throughput up on networks that lose packets.
What it is
Hysteria2 is developed by the open-source apernet project and documented at v2.hysteria.network. Version 2 reworked the protocol so that authentication happens inside a standard HTTP/3 exchange, which lets a Hysteria2 server look like an ordinary website. It builds on three public standards:
- QUIC (RFC 9000): an encrypted transport over UDP with many independent streams inside one connection.
- TLS 1.3 (RFC 8446): QUIC always uses a TLS 1.3 handshake to agree on keys and authenticate the server.
- HTTP/3 (RFC 9114): the HTTP version that runs over QUIC; Hysteria2 uses it for the authentication step.
How it works
- The app opens a QUIC connection to the server over UDP. The QUIC handshake is a TLS 1.3 handshake, and the app checks the server's certificate the way a browser does. On Colitu servers this is a real certificate issued automatically through ACME.
- Inside the connection the app sends an HTTP/3 request carrying its credentials. If they are valid, the server confirms and the connection becomes a tunnel. A request without valid credentials is treated as an ordinary web request, so anyone probing the server sees a normal HTTP/3 web server.
- During this exchange the two sides also share bandwidth information used by the congestion control described below.
- Each TCP connection from your device, such as a web page or a download, gets its own QUIC stream. Streams are independent, so a lost packet in one does not hold up the others.
- UDP traffic from your device, such as calls, games and DNS, travels as QUIC datagrams instead of being squeezed into a stream.
Congestion control: why it holds speed on lossy links
Classic TCP congestion control reads every lost packet as a sign that the path is overloaded and cuts its sending rate. On Wi-Fi and mobile links, packets are often lost for other reasons: interference, handovers between cells, a weak signal. TCP then slows down when it does not need to and recovers slowly, especially over long distances.
Hysteria2 ships its own congestion control, called Brutal. When the available bandwidth is known, Brutal sends at that rate and compensates for loss by retransmitting instead of backing off. When no bandwidth is set, Hysteria2 falls back to BBR, which estimates the available bandwidth rather than reacting to each lost packet. In both cases the result on lossy links is steadier throughput than with loss-based TCP.
Why Colitu uses it
Many of the problems people have with a VPN on the move are not blocks but bad links: a train, a crowded café, a long route between countries. TCP-based protocols lose speed there; Hysteria2 is built for exactly that case. It also brings real camouflage: a valid certificate and a handshake that looks like HTTP/3, the protocol that large websites already serve.
Where it is strong
- Mobile data. Radio loss and a changing signal are what Brutal's loss compensation and QUIC's independent streams handle well.
- Busy or distant Wi-Fi. Interference causes loss that is not congestion; Hysteria2 keeps its pace instead of halving it.
- Long international routes. With long round trips TCP needs a long time to recover after each loss; Hysteria2 simply retransmits.
- Calls and games. UDP traffic travels as datagrams, so one lost packet does not delay the ones behind it.
- Filtered networks that still allow QUIC. A passive observer sees HTTP/3 to a site with a valid certificate, and an active probe without credentials gets a web server's answer.
Limitations and when it is not the best choice
- UDP may be blocked or throttled. Some corporate, hotel, campus and mobile networks restrict UDP or QUIC. Hysteria2 then cannot connect or runs slowly, and a TCP mode is the better choice.
- QUIC can be singled out. Some filtering systems treat QUIC to unfamiliar addresses differently from TCP, for example by slowing it down. The Reality-based modes blend in better there.
- Fairness on a weak shared link. Aggressive sending is good for your own connection but can crowd out other devices on the same very weak link.
- Captive portals. On hotel or café Wi-Fi you have to sign in on the portal page first; no VPN mode can connect before that.
How Adaptive Connect uses it
Hysteria2 is first in the order on Android, iOS, Windows and Linux. If it connects and real traffic passes the check, you stay on it. If UDP is blocked, the handshake fails or the tunnel carries nothing, the app moves on:
- on Android and iOS to VLESS Reality, then VLESS XHTTP, Trojan and Shadowsocks 2022;
- on Windows and Linux to the TCP modes, in the order of their measured connect time.
A Hysteria2 attempt that carried nothing is pushed back (for 10 minutes on Windows and Linux), so the next connection does not waste time on it.
Security and encryption
- Encryption: keys come from the TLS 1.3 handshake inside QUIC, and every packet after the handshake is encrypted and authenticated.
- Server authentication: the server presents a real certificate from a public certificate authority, obtained and renewed automatically through ACME. The app verifies it, so a man in the middle cannot pose as the server.
- Client authentication: each device has its own credentials, and the server checks them before carrying any traffic.
- One domain: Hysteria2 is reached through the server's domain name, like the other modes, and Trojan uses the same certificate.
- No access logs: Colitu servers do not record the sites you visit; see the security page.
Sources
Try it
Hysteria2 works in every Colitu app without any setup, and the app switches to a TCP mode by itself when UDP is blocked. Download Colitu or check the server locations.