you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / tor network
17 December 2024 tor network 4 min read

Getting Tor Bridges in Censored Regions: The Methods That Still Work

When a national firewall blocks every public Tor relay, unlisted bridges become the only road in. Requesting one is easy. Keeping that request — and the bridge line itself — away from the censor is where the real work begins.

Why distribution is the hard part

A bridge is simply a Tor relay whose address never appears in the public directory. That secrecy only holds if the distribution channel stays trustworthy. As researchers Philipp Winter and colleagues put it, bridge distribution boils down to a secret that must reach censored users while never reaching the censor (Effective Tor Bridge Distribution). The problem is definitionally unwinnable in the worst case, because censors can pose as legitimate users and request bridges at scale. BridgeDB therefore rations and rotates what it hands out, mixing several channels so no single leak exposes the whole pool. Understanding those channels is the first step for anyone connecting from a heavily filtered network.

Moat and the BridgeDB website

The safest default is moat, the request system built directly into Tor Browser under Settings, then Connection, then Request bridges. It fetches bridge lines over the Tor network after a CAPTCHA, so the request itself does not reveal your interest to your internet provider. For most users this is the method Tor Project documentation recommends first. The classic fallback remains the BridgeDB website, which serves bridge lines after a CAPTCHA and offers advanced options such as choosing obfs4 or IPv6 addresses. Because the domain is widely known, censors frequently block it outright. In Iran and Russia it often requires another circumvention layer just to reach.

Email, Telegram, and the paper trail

Email requests still work: send a message to bridges@torproject.org from a Gmail or Riseup address with the line 'get transport obfs4' in the body, and BridgeDB replies with fresh bridges, per the official guidance (Tor Project Support). The provider restriction exists because those services are hard to register en masse, which slows Sybil attacks. The trade-off is obvious — the request ties your identity to your interest in censorship circumvention. The newer Telegram bot, @GetBridgesBot, dispenses obfs4 and WebTunnel lines without an email account. It is fast and mobile-friendly, but Telegram accounts themselves are identifier-linked. Users facing legal risk should weigh whether any automated channel matches their threat model before pressing send.

Community sharing, handled with care

In practice much bridge distribution happens person to person: activists pass bridge lines over Signal, Briar, or Session to trusted contacts. This private sharing survives when public channels are blocked, and it is how many Iranian and Russian users stayed connected during recent crackdowns. A bridge shared narrowly stays useful far longer than one posted publicly. Discipline matters more than the app. Treat bridge lines like passwords, share them one-to-one, and rotate them periodically. Posting a private bridge to a forum or social feed effectively donates it to the censor, who collects exactly the same channels everyone else does.

How censors burn the pool

Blocking follows discovery. Measurements by Fifield and Tsai found that China's firewall blocked newly published obfs4 bridges after a delay of roughly 2 to 36 days, usually right after they shipped in Tor Browser releases (Censors' Delay in Blocking Circumvention Proxies). Later work by Dunna, O'Brien, and Gill showed Chinese censors actively scanning for even unpublished bridges (USENIX FOCI 18). Russia has escalated differently, targeting the hosting providers behind bridges rather than probing them individually. That pressure prompted the Tor Project's November 2024 call for 200 new WebTunnel bridges by year-end, noting that Roskomnadzor blocks had made many existing bridges unreachable (Tor Project Blog). OONI data documents similar transport-level interference across Iran, Russia, and Turkmenistan throughout 2024 (OONI Research Reports).
A bridge that arrives slowly through a trusted friend outlasts one grabbed quickly from a blocked page.

The practical playbook

For most censored users the order of operations is simple:
  • Try built-in bridges in Tor Browser, including Snowflake and WebTunnel.
  • If those fail, request obfs4 via moat inside the browser.
  • Fall back to the BridgeDB site, Telegram bot, or email from Gmail or Riseup.
  • If everything public is blocked, ask a trusted contact outside the country for private lines.
Whichever route you take, configure more than one bridge type and re-request when connections degrade. Bridges buy reachability, not anonymity — once connected, the usual obfs4 and transport hygiene and browser discipline still apply. The arms race continues on both sides; the users who rotate early connect longest.

more notes

all news ›