TCP · TLS 1.3

Trojan

Trojan hides VPN traffic inside a standard TLS 1.3 connection with a real certificate, so it looks like HTTPS. How it works, its limits and its role in Colitu.

Trojan is the fourth mode that Colitu Adaptive Connect tries on Android and iOS, and one of the TCP modes ranked by connect time on Windows and Linux. Its idea is simple: instead of inventing a new disguise, use the real thing. A Trojan server is a TLS server with a valid certificate, and Trojan traffic is ordinary TLS.

What it is

The Trojan protocol was introduced by the open-source trojan-gfw project, whose documentation describes it in full. Many independent implementations exist today; Colitu servers run Trojan with sing-box, an open-source universal proxy platform. Trojan builds on TLS, on Colitu in its current version TLS 1.3 (RFC 8446), and adds only a very small request format on top.

How it works

  1. The app opens a TCP connection and performs a standard TLS handshake with the server's domain name. It verifies the server's real certificate, the same one Hysteria2 uses, issued through ACME.
  2. In the first data inside TLS, the app sends the hex-encoded SHA-224 hash of its password, a line break, and a short request: the command (open a TCP connection or relay UDP), the destination address and port, and another line break.
  3. If the hash belongs to a known user, the server opens the requested connection and relays data in both directions.
  4. If it does not, the protocol is designed so that the server does not reveal itself. The original trojan-gfw implementation hands such connections to an ordinary web server, so a prober gets what any HTTPS site would show.
  5. UDP traffic is carried as framed packets inside the same TLS stream.

Why Colitu uses it

  • A different way of hiding. Reality borrows a third-party website; Trojan uses the server's own domain and a real certificate. A filter that targets Reality-style handshakes, for example a well-known site name on an unrelated IP address, has nothing to match here.
  • A TLS fallback where UDP is blocked. When Hysteria2 cannot connect and the Reality-based modes are singled out, Trojan offers another path over plain TLS.
  • Simple and mature. The protocol is small, well understood and widely implemented.

Where it is strong

  • Networks that block UDP, such as some hotel, office and campus networks: Trojan only needs TCP.
  • Networks that single out Reality: its handshake is a normal TLS handshake for the server's own name with a certificate from a public authority.
  • Plain, standard TLS: there is no unusual framing before or around the TLS session.

Limitations and when it is not the best choice

  • Its own name and address. The domain and certificate belong to the server. Once identified, they can be blocked by name or IP address, which is harder with Reality.
  • "TLS inside TLS". Trojan has no equivalent of XTLS Vision, so the patterns of nested TLS handshakes can remain visible to advanced DPI.
  • The client's TLS fingerprint. The Trojan protocol does not define a browser-like fingerprint; how the handshake looks depends on the implementation, and some filters look at exactly that.
  • TCP on lossy links. On mobile data or poor Wi-Fi it slows down like any TCP protocol; Hysteria2 is usually faster there.
  • UDP over TCP. Calls and games carried inside a TCP stream suffer when packets are lost, because later packets wait for the lost one.

How Adaptive Connect uses it

On Android and iOS, Trojan comes fourth, after Hysteria2, VLESS Reality and VLESS XHTTP. It is used when UDP is blocked and both Reality-based modes fail to connect or do not pass the traffic check. After Trojan only Shadowsocks 2022 remains. On Windows and Linux Trojan is ranked with the other TCP modes by measured connect time, so on some networks it is tried right after Hysteria2.

Security and encryption

  • Encryption: TLS 1.3 protects the whole session, including the password hash and the destination address.
  • Server authentication: a real certificate from a public certificate authority, obtained and renewed automatically through ACME and verified by the app. A man in the middle cannot pose as the server without it.
  • Client authentication: the password is part of each device's own credentials and is never sent in the clear, only as a hash inside TLS.
  • Key handling: credentials are delivered to the app in encrypted form and never published.
  • No access logs: see the security page.

Sources

Try it

Trojan is ready in every Colitu app as one of five modes, with no setup on your side. Download Colitu or look at the server locations.