FreeSocks, Tor Bridges, and Messaging Proxies Compared

FreeSocks v2, Tor bridges and Snowflake, Signal proxies, and Telegram proxies all help with blocking, but they expose different operators and solve different parts of the path. The first question is whether the goal is ordinary-web access, Tor access, or access to one messaging service. The second is which metadata and account identities remain visible.

This page contains no connection material. Use each project's current official distribution flow. Circumvention can be restricted by local law and can create distinctive network traffic. A route that loads is not proof of anonymity, safe endpoints, or private application accounts.

Choose by blocked destination

FIG. 1: Circumvention options solve different reachability problems
Circumvention options solve different reachability problems
PathPrimary useOperator visibilityDoes not solve
FreeSocks v2Reach blocked public services through the live Xray/Remnawave backendUnredacted control plane manages accounts, entitlements, issuance, rotation, expiry, revocation, and optional billingDestination identity, browser safety, account identity, or Tor anonymity; Outline code exists but the live backend was disabled
Tor bridge or SnowflakeReach Tor when direct Tor connections are blockedBridge or temporary proxy participates in the first hop; Tor handles the remaining routeEndpoint compromise, identifying logins, or global traffic correlation
I2PReach services inside the I2P overlayEncrypted I2P transport to peersNot a drop-in replacement for ordinary public-web access
PsiphonReach the blocked public internet through Psiphon infrastructureAn encrypted tunnel whose protocol and endpoint may still be classified or blockedThe operator and selected client mode remain trust points
OONI ProbeMeasure blocking and network interferenceMeasurement traffic to tested services and OONI infrastructureIt publishes open data and is not a bypass
Signal proxyReach Signal through blockingProxy handles transport; Signal account and service rules remain separatePhone/account identity, device compromise, or operator-independent availability
Telegram proxyReach Telegram through blockingProxy and Telegram retain their separate path visibilityCloud-chat confidentiality or a secure-messaging guarantee

FreeSocks v2 has a versioned architecture

Unredacted's July 2026 announcement says FreeSocks v2 moved to a self-hosted TypeScript and Convex control plane with Xray through Remnawave. The live public config retrieved on 18 August 2026 reported Remnawave/Xray as enabled and default, user backend choice off, and Outline disabled. The repository still contains an Outline adapter and client metadata, while older automation describes Cloudflare Workers or KV. Those are supported or historical code paths, not evidence that Outline is live.

The same live config reported a 50 GB/month free tier lasting 90 days and one paid Membership tier with unlimited bandwidth and devices: $5 for one month, $14 for three months, $27 for six months, and $50 for twelve months. Stripe and NowPayments were enabled billing rails in that response. These are dated configuration facts, not a promise that pricing or availability will remain unchanged.

Logging, retention, analytics, and fronting

The operator says encrypted proxy content is not stored and its current privacy documentation describes no persisted client IPs, ephemeral HMAC rate-limit buckets, disabled Caddy and Xray access logging, short-lived per-user-agent subscription caches, optional HWID, and structured audit data. The retention implementation publishes defaults including 180 days for audit rows, 90 days for processed webhooks, 365 days for tier history, and 90 days for deleted-subscription history. These code-level defaults are more specific than a blanket “retention unspecified” label, but remain operator claims rather than an independent audit of the deployed database and nodes.

The live config also reported anonymous analytics enabled. The repository describes a same-origin relay to a self-hosted Umami instance, but the public response does not reveal whether IP forwarding is enabled or which geo mode is active. Response headers showed current Cloudflare fronting; that network dependency is distinct from the retired Workers/KV control plane. The FreeSocks directory record therefore retains partial evidence and caution rather than a no-logs or anonymity claim.

Tor transports lead into Tor

Bridges are Tor relays omitted from the public relay directory. Snowflake uses short-lived volunteer proxies, while obfs4 and WebTunnel change how the first connection appears. Unredacted operates relays, bridges, and a changing project lane previously called Operation Envoy and later described as Unredacted Door. Those resources support Tor access; they are not a separate anonymity network.

Obtain current bridge access through Tor's official interface and follow the project's documentation. Do not copy volatile connection strings from articles or social posts. For browser configuration after Tor connects, use the Tor Browser setup guide.

I2P, Psiphon, and OONI answer different questions

I2P documents its own network database, tunnel routing, garlic routing, and applications inside the I2P network. It is useful when both the user and destination participate in that overlay. It is not a substitute for reaching an ordinary website that has no I2P service.

Psiphon uses centrally coordinated infrastructure and documents proxy and VPN modes whose scope varies by client and platform. It is designed for public-internet circumvention, not Tor-style route separation. Check the exact current client before assuming which applications or device traffic it covers.

OONI Probe measures blocking and publishes measurements through OONI Explorer and its API. Existing measurements may show whether interference has been observed without running a new test from the reader's network. Its openness is valuable evidence, but measurement traffic and published data create a separate risk decision. OONI is evidence infrastructure, not a circumvention route.

Messaging proxies preserve the messaging service

Unredacted's policy says the proxy-retrieval page sends source IP and user agent through Cloudflare and stores that retrieval metadata for 24 hours. It separately says encrypted connection content is not stored. This disclosure applies to obtaining the proxy information and must not be rewritten as a universal claim about every network participant.

A Signal proxy can help the Signal client reach the service while concealing a direct Signal connection from a local network. It does not change Signal's account model or protect a compromised device. Unredacted explicitly says it does not recommend Telegram for security reasons. A Telegram proxy can restore reachability, but Telegram cloud chats remain outside an E2EE claim.

The operator runs more than FreeSocks

Unredacted Inc is a Delaware nonprofit operating communications, collaboration, network, and anti-censorship resources. Its incorporation, policy, source, status, and signed-transparency records support bounded facts, not a suite-wide privacy guarantee. A signature proves control of a signing key; public source permits inspection; and a live page proves reachability. None independently proves the configuration, retention, encryption, or availability of every deployed service.

The February 2026 incident report says Core services moved behind Cloudflare Magic Transit after a distributed denial-of-service attack. That is operational-resilience evidence and identifies another network dependency. It is not evidence that content or account metadata is unavailable to the operator, Cloudflare, federated services, or legal process.

FIG. 2: Unredacted surfaces have separate privacy and operational boundaries
Unredacted surfaces have separate privacy and operational boundaries
SurfaceRoleEvidence-backed propertyMaterial limit
FreeSocksCensorship-circumvention proxy distributionLive Xray/Remnawave config, dated tier and billing factsCircumvention is not anonymity; analytics and Cloudflare remain separate boundaries
Tor relays, bridges, Door, and SnowflakeTor access and infrastructureService pages, metrics, guides, and automationAvailability changes; Tor threat-model limits still apply
Signal and Telegram proxiesReach messaging services through blockingOperator identifies the supported proxy typesRetrieval IP and user agent are stored for 24 hours; Telegram cloud chats do not become E2EE
XMPP.isFederated account messagingSite and config disclose authentication logging, stored data, uploads, backups, and hostingOMEMO is client-selected; published archive and storage details conflict
Unredacted MatrixFederated rooms through Matrix clientsPublished policy and public clientsE2EE is optional; uploaded-media retention is 180 days; bridges add another boundary
Crypt, Paste, Board, and ShareHosted documents and sharingUpstream CryptPad, PrivateBin, Excalidraw, and Cryptgeon designsDelivered code, access metadata, instance configuration, and bearer links remain trust points
Etherpad and JitsiText editing and meetingsPublic surfaces and upstream documentationNo Etherpad E2EE evidence; Jitsi E2EE is mode- and client-dependent
Monero remote nodeWallet synchronisation and network queriesOperator service pageA remote node can observe network and query metadata

XMPP, Matrix, and hosted tools need separate claims

XMPP.is can store a username, optional recovery email, user agent, contacts or rooms, messages, uploads, MAM archives, vCards, and rosters depending on use and enabled modules. Its security page says info-level logs omit user IP addresses but record authentication. OMEMO and OTR are client choices; the OMEMO specification leaves traffic-analysis metadata outside its protection and still requires device verification.

The XMPP.is server page places its donated FlokiNET host in Romania, says encrypted backups sync off-site daily, caps uploads at 100 MB for one week, and describes a 30-day MAM expiry when enabled. The pinned Prosody configuration instead sets a 90-day archive expiry and PostgreSQL while the page describes flat-file storage. Those first-party sources conflict, so neither retention window nor storage backend is presented as confirmed runtime state. The deletion page now says automated deletion is unavailable and strikes through the former emailed process, leaving current deletion availability unclear.

Unredacted Matrix uses federation, so room data can reach participating homeservers and bridges add their own policies. The operator documents 180-day uploaded-media retention and a 100 MB limit. E2EE depends on the room, client, and device state. CryptPad, PrivateBin, Cryptgeon, and some Excalidraw modes have encrypted-content designs, but delivered browser code, access logs, metadata, shared links, and instance settings remain trust points. No service-specific Etherpad E2EE evidence was found. Jitsi E2EE must be enabled on compatible clients and does not cover every meeting feature.

Labs projects are evidence, not automatic recommendations

No privacy outcome is inferred from a repository or ASN. A current commit, operational network, or signed package can establish a bounded fact. It does not by itself prove anonymity, anti-correlation performance, safe deployment, or fitness for a particular user.

FIG. 3: Unredacted Labs spans operational infrastructure, active software, and roadmap work
Unredacted Labs spans operational infrastructure, active software, and roadmap work
ProjectObserved evidenceCurrent treatmentLimit
NoiseNet / AS401401Labs and network pages, ASN record, automation sourceExperimental network contextNo independent anti-correlation measurement or flow-retention audit
Core / AS401720Network record, status page, February 2026 incident reportOperational provider infrastructureCloudflare Magic Transit is resilience infrastructure, not a content-privacy guarantee
packetframeActive GPL-3.0 Rust and eBPF/XDP repositoryTechnical project worth monitoringSome modules and NoiseNet integration remain future or untested
packetpathPublic GPL-3.0 repositoryRoadmap itemLabs labels it Coming Soon
linux-hardened-unredactedForgejo source and release articleAdvanced Debian 13 amd64 resourceSignatures, repository setup, and reproducibility still require user verification
GreenwarePublic provisioning repositoryHardware and efficiency projectNot a hosted user service; deployment depends on hardware and networking choices
Vandr and matrix-vandrPublic moderation and Matrix repositoriesModeration contextNo privacy benefit follows merely from abuse-analysis tooling

packetframe describes a Rust data plane using eBPF and XDP with BGP or BMP integration; roadmap modules and NoiseNet randomisation retain their future or untested labels. packetpath has source but remains labelled Coming Soon. The hardened-kernel project is a narrow downstream Debian 13 amd64 resource: hardening can reduce exploit classes but does not hide an IP address, secure user-space applications automatically, or make a host anonymous.

Greenware, Vandr, matrix-vandr, relay automation, mirror tooling, and related repositories can support specific claims without becoming fake service rows. Archived or generic deployment repositories are not current recommendations. The directory therefore keeps the accountable Unredacted hub plus separate records for FreeSocks and XMPP.is.

Verification worksheet

  1. Name the blocked destination and whether direct HTTPS, Tor, Signal, or Telegram is failing.
  2. Choose one official access path that matches that destination rather than stacking unrelated proxies.
  3. Record the client version, transport family, date, network, and result without preserving connection secrets.
  4. Check application identity separately. A personal login remains identifying even when reachability changes.
  5. Recheck policy and architecture dates. FreeSocks changed materially in July 2026, and volatile access infrastructure changes more often than evergreen guidance.

For the underlying operator records, use the source-linked Unredacted, FreeSocks, and XMPP.is profiles. Broader projects and infrastructure remain discoverable through the hosting research index without maintaining two thin inventory articles.

Sources

Frequently Asked Questions

Is FreeSocks a VPN or anonymity service?

No. FreeSocks distributes proxy access for censorship circumvention. It does not by itself provide Tor-style route separation or make application accounts anonymous.

When should a Tor bridge be used?

A bridge or pluggable transport is relevant when direct Tor access is blocked. It helps reach Tor but does not remove endpoint, account, fingerprinting, or traffic-correlation risks.

Does a proxy make Telegram private?

No. A proxy changes reachability and some local-network visibility. It does not convert Telegram cloud chats into end-to-end encrypted conversations.

Is every FreeSocks tier free?

No. On 18 August 2026 the public config offered a 50 GB/month free tier for 90 days and optional paid Membership durations at $5, $14, $27, and $50.

Are Tor, I2P, and Psiphon interchangeable?

No. Tor is an anonymity network for public and onion services, I2P is primarily an internal anonymous overlay, and Psiphon is a centrally operated public-internet circumvention system.

Is OONI a circumvention service?

No. OONI Probe measures possible internet censorship and publishes measurements as open data. Measurement risk should be considered separately from choosing a bypass route.

Does one Unredacted policy cover every service?

No. FreeSocks, XMPP.is, Matrix, proxies, collaboration tools, and Labs projects have different account, encryption, retention, hosting, and deployment boundaries.

Is NoiseNet a proven anonymity network?

No. Unredacted describes NoiseNet and its anti-correlation goals as experimental. Public network and source records do not establish a measured anonymity outcome.

Does XMPP.is encrypt every message end to end?

No. OMEMO or OTR depends on the selected client and conversation. The server can still process account, authentication, roster, archive, upload, and federation data.