WebTunnel explained: how Tor hides inside ordinary HTTPS traffic
To a network censor, a WebTunnel connection looks like nothing more than a user browsing the web. That is precisely the point.
A bridge born under pressure
Censors have grown disturbingly good at spotting Tor bridges. In December 2021, Russian ISPs began blocking direct connections to the Tor network by IP filtering, and OONI measurements documented how the block also swept up many obfs4 bridge addresses (https://ooni.org/post/2021-russia-blocks-tor/). Later, user reports suggested obfs4 was being throttled on some mobile networks through deep packet inspection. The Tor Project's answer arrived in March 2024, when the Anti-Censorship Team officially launched WebTunnel on the World Day Against Cyber Censorship, shipping it in stable Tor Browser releases (https://blog.torproject.org/introducing-webtunnel-evading-censorship-by-hiding-in-plain-sight/). A soft launch had already begun in mid-2023 through the project's relay forum. The design goal was simple: stop looking unusual.How the disguise works
WebTunnel is a pluggable transport that wraps Tor traffic in a WebSocket-style HTTPS connection, inspired by an academic design called HTTPT. The client sends an HTTP 1.1 upgrade request over TLS to the bridge's server, exactly as browsers do when establishing a WebSocket session. To any observer on the wire, the exchange resembles a routine encrypted visit to a website. The clever part is coexistence. A WebTunnel bridge can share a domain, IP address and port with a genuine website behind a reverse proxy such as NGINX. Visitors who stumble onto the address see the real site; only clients holding the secret URL path get proxied into the Tor network. As the developers note in their announcement, probing the HTTPS port without knowing the full path reveals nothing (https://forum.torproject.org/t/tor-relays-announcement-webtunnel-a-new-pluggable-transport-for-bridges-now-available-for-deployment/8180).Why obfs4 stopped being enough
obfs4, long the workhorse among obfs4 bridges, makes traffic look like random noise. That defeated older censors, but modern systems increasingly flip the logic: instead of blacklisting known-bad shapes, they allowlist recognized protocols and drop everything else. The Tor Project likens this to a coin-sorting machine that rejects coins which fit no approved slot. Research on China's Great Firewall showed exactly this, demonstrating detection and blocking of fully encrypted traffic that matches no known protocol. Random-looking obfs4 payloads fail such allowlists by design, while WebTunnel traffic rides through as permitted HTTPS. In deny-by-default environments, camouflage beats encryption alone.The performance bill
Disguise has a price. WebTunnel layers WebSocket framing and HTTPS overhead on top of Tor's existing onion encryption, adding latency and reducing throughput compared with a plain connection. Operators report that well-provisioned bridges perform respectably, but the transport will not match raw obfs4 speed on identical hardware. Setup costs are heavier too. Running a bridge requires a static IPv4 address, a self-hosted website with your own domain, a valid TLS certificate, and at least 1 GB of RAM, according to the official deployment guide (https://community.torproject.org/relay/setup/webtunnel/). Docker images and Ansible roles ease the process, yet it remains more demanding than standing up obfs4.Russia made it urgent
Demand exploded after Roskomnadzor began targeting popular hosting providers, knocking out bridges hosted on major clouds. The Tor Project responded with a public call for 200 new WebTunnel bridges by the end of 2024, noting the fleet had grown from 60 at launch to 143 within its first year (https://blog.torproject.org/call-for-webtunnel-bridges/). The team also prioritized smaller download sizes and uTLS integration so handshakes mimic mainstream browser fingerprints even more closely. This fits a wider story about national blocking patterns: each censorship escalation drives a new circumvention generation. obfs4 answered protocol identification; WebTunnel answers allowlisting.WebTunnel's bet is that the safest place to hide a secret tunnel is inside traffic no censor can afford to block.
Getting and using WebTunnel bridges
Bridges are distributed through the official bridges website, the Telegram bot @GetBridgesBot, and email. Support covers Tor Browser on desktop and Android, plus Tails and the Tor VPN beta. Users simply pick "webtunnel" from the transport menu or paste a bridge line containing the secret URL.- Works best where censors run protocol allowlists rather than simple IP blocks
- Hosted preferably on lesser-known providers, since big hosts face collective blocking
- Requires Tor Browser 12.5 or newer
- Bridge lines contain a secret HTTPS URL; treat them like passwords