FreeSocks, Tor Bridges, and Messaging Proxies Compared
FreeSocks v2, Tor bridges and Snowflake, Signal proxies, and Telegram proxies all help with blocking, but they expose different operators and solve different parts of the path. The first question is whether the goal is ordinary-web access, Tor access, or access to one messaging service. The second is which metadata and account identities remain visible.
This page contains no connection material. Use each project's current official distribution flow. Circumvention can be restricted by local law and can create distinctive network traffic. A route that loads is not proof of anonymity, safe endpoints, or private application accounts.
Choose by blocked destination
| Path | Primary use | Operator visibility | Does not solve |
|---|---|---|---|
| FreeSocks v2 | Reach blocked public services through the live Xray/Remnawave backend | Unredacted control plane manages accounts, entitlements, issuance, rotation, expiry, revocation, and optional billing | Destination identity, browser safety, account identity, or Tor anonymity; Outline code exists but the live backend was disabled |
| Tor bridge or Snowflake | Reach Tor when direct Tor connections are blocked | Bridge or temporary proxy participates in the first hop; Tor handles the remaining route | Endpoint compromise, identifying logins, or global traffic correlation |
| I2P | Reach services inside the I2P overlay | Encrypted I2P transport to peers | Not a drop-in replacement for ordinary public-web access |
| Psiphon | Reach the blocked public internet through Psiphon infrastructure | An encrypted tunnel whose protocol and endpoint may still be classified or blocked | The operator and selected client mode remain trust points |
| OONI Probe | Measure blocking and network interference | Measurement traffic to tested services and OONI infrastructure | It publishes open data and is not a bypass |
| Signal proxy | Reach Signal through blocking | Proxy handles transport; Signal account and service rules remain separate | Phone/account identity, device compromise, or operator-independent availability |
| Telegram proxy | Reach Telegram through blocking | Proxy and Telegram retain their separate path visibility | Cloud-chat confidentiality or a secure-messaging guarantee |
FreeSocks v2 has a versioned architecture
Unredacted's July 2026 announcement says FreeSocks v2 moved to a self-hosted TypeScript and Convex control plane with Xray through Remnawave. The live public config retrieved on 18 August 2026 reported Remnawave/Xray as enabled and default, user backend choice off, and Outline disabled. The repository still contains an Outline adapter and client metadata, while older automation describes Cloudflare Workers or KV. Those are supported or historical code paths, not evidence that Outline is live.
The same live config reported a 50 GB/month free tier lasting 90 days and one paid Membership tier with unlimited bandwidth and devices: $5 for one month, $14 for three months, $27 for six months, and $50 for twelve months. Stripe and NowPayments were enabled billing rails in that response. These are dated configuration facts, not a promise that pricing or availability will remain unchanged.
Logging, retention, analytics, and fronting
The operator says encrypted proxy content is not stored and its current privacy documentation describes no persisted client IPs, ephemeral HMAC rate-limit buckets, disabled Caddy and Xray access logging, short-lived per-user-agent subscription caches, optional HWID, and structured audit data. The retention implementation publishes defaults including 180 days for audit rows, 90 days for processed webhooks, 365 days for tier history, and 90 days for deleted-subscription history. These code-level defaults are more specific than a blanket “retention unspecified” label, but remain operator claims rather than an independent audit of the deployed database and nodes.
The live config also reported anonymous analytics enabled. The repository describes a same-origin relay to a self-hosted Umami instance, but the public response does not reveal whether IP forwarding is enabled or which geo mode is active. Response headers showed current Cloudflare fronting; that network dependency is distinct from the retired Workers/KV control plane. The FreeSocks directory record therefore retains partial evidence and caution rather than a no-logs or anonymity claim.
Tor transports lead into Tor
Bridges are Tor relays omitted from the public relay directory. Snowflake uses short-lived volunteer proxies, while obfs4 and WebTunnel change how the first connection appears. Unredacted operates relays, bridges, and a changing project lane previously called Operation Envoy and later described as Unredacted Door. Those resources support Tor access; they are not a separate anonymity network.
Obtain current bridge access through Tor's official interface and follow the project's documentation. Do not copy volatile connection strings from articles or social posts. For browser configuration after Tor connects, use the Tor Browser setup guide.
I2P, Psiphon, and OONI answer different questions
I2P documents its own network database, tunnel routing, garlic routing, and applications inside the I2P network. It is useful when both the user and destination participate in that overlay. It is not a substitute for reaching an ordinary website that has no I2P service.
Psiphon uses centrally coordinated infrastructure and documents proxy and VPN modes whose scope varies by client and platform. It is designed for public-internet circumvention, not Tor-style route separation. Check the exact current client before assuming which applications or device traffic it covers.
OONI Probe measures blocking and publishes measurements through OONI Explorer and its API. Existing measurements may show whether interference has been observed without running a new test from the reader's network. Its openness is valuable evidence, but measurement traffic and published data create a separate risk decision. OONI is evidence infrastructure, not a circumvention route.
Messaging proxies preserve the messaging service
Unredacted's policy says the proxy-retrieval page sends source IP and user agent through Cloudflare and stores that retrieval metadata for 24 hours. It separately says encrypted connection content is not stored. This disclosure applies to obtaining the proxy information and must not be rewritten as a universal claim about every network participant.
A Signal proxy can help the Signal client reach the service while concealing a direct Signal connection from a local network. It does not change Signal's account model or protect a compromised device. Unredacted explicitly says it does not recommend Telegram for security reasons. A Telegram proxy can restore reachability, but Telegram cloud chats remain outside an E2EE claim.
The operator runs more than FreeSocks
Unredacted Inc is a Delaware nonprofit operating communications, collaboration, network, and anti-censorship resources. Its incorporation, policy, source, status, and signed-transparency records support bounded facts, not a suite-wide privacy guarantee. A signature proves control of a signing key; public source permits inspection; and a live page proves reachability. None independently proves the configuration, retention, encryption, or availability of every deployed service.
The February 2026 incident report says Core services moved behind Cloudflare Magic Transit after a distributed denial-of-service attack. That is operational-resilience evidence and identifies another network dependency. It is not evidence that content or account metadata is unavailable to the operator, Cloudflare, federated services, or legal process.
| Surface | Role | Evidence-backed property | Material limit |
|---|---|---|---|
| FreeSocks | Censorship-circumvention proxy distribution | Live Xray/Remnawave config, dated tier and billing facts | Circumvention is not anonymity; analytics and Cloudflare remain separate boundaries |
| Tor relays, bridges, Door, and Snowflake | Tor access and infrastructure | Service pages, metrics, guides, and automation | Availability changes; Tor threat-model limits still apply |
| Signal and Telegram proxies | Reach messaging services through blocking | Operator identifies the supported proxy types | Retrieval IP and user agent are stored for 24 hours; Telegram cloud chats do not become E2EE |
| XMPP.is | Federated account messaging | Site and config disclose authentication logging, stored data, uploads, backups, and hosting | OMEMO is client-selected; published archive and storage details conflict |
| Unredacted Matrix | Federated rooms through Matrix clients | Published policy and public clients | E2EE is optional; uploaded-media retention is 180 days; bridges add another boundary |
| Crypt, Paste, Board, and Share | Hosted documents and sharing | Upstream CryptPad, PrivateBin, Excalidraw, and Cryptgeon designs | Delivered code, access metadata, instance configuration, and bearer links remain trust points |
| Etherpad and Jitsi | Text editing and meetings | Public surfaces and upstream documentation | No Etherpad E2EE evidence; Jitsi E2EE is mode- and client-dependent |
| Monero remote node | Wallet synchronisation and network queries | Operator service page | A remote node can observe network and query metadata |
XMPP, Matrix, and hosted tools need separate claims
XMPP.is can store a username, optional recovery email, user agent, contacts or rooms, messages, uploads, MAM archives, vCards, and rosters depending on use and enabled modules. Its security page says info-level logs omit user IP addresses but record authentication. OMEMO and OTR are client choices; the OMEMO specification leaves traffic-analysis metadata outside its protection and still requires device verification.
The XMPP.is server page places its donated FlokiNET host in Romania, says encrypted backups sync off-site daily, caps uploads at 100 MB for one week, and describes a 30-day MAM expiry when enabled. The pinned Prosody configuration instead sets a 90-day archive expiry and PostgreSQL while the page describes flat-file storage. Those first-party sources conflict, so neither retention window nor storage backend is presented as confirmed runtime state. The deletion page now says automated deletion is unavailable and strikes through the former emailed process, leaving current deletion availability unclear.
Unredacted Matrix uses federation, so room data can reach participating homeservers and bridges add their own policies. The operator documents 180-day uploaded-media retention and a 100 MB limit. E2EE depends on the room, client, and device state. CryptPad, PrivateBin, Cryptgeon, and some Excalidraw modes have encrypted-content designs, but delivered browser code, access logs, metadata, shared links, and instance settings remain trust points. No service-specific Etherpad E2EE evidence was found. Jitsi E2EE must be enabled on compatible clients and does not cover every meeting feature.
Labs projects are evidence, not automatic recommendations
No privacy outcome is inferred from a repository or ASN. A current commit, operational network, or signed package can establish a bounded fact. It does not by itself prove anonymity, anti-correlation performance, safe deployment, or fitness for a particular user.
| Project | Observed evidence | Current treatment | Limit |
|---|---|---|---|
| NoiseNet / AS401401 | Labs and network pages, ASN record, automation source | Experimental network context | No independent anti-correlation measurement or flow-retention audit |
| Core / AS401720 | Network record, status page, February 2026 incident report | Operational provider infrastructure | Cloudflare Magic Transit is resilience infrastructure, not a content-privacy guarantee |
| packetframe | Active GPL-3.0 Rust and eBPF/XDP repository | Technical project worth monitoring | Some modules and NoiseNet integration remain future or untested |
| packetpath | Public GPL-3.0 repository | Roadmap item | Labs labels it Coming Soon |
| linux-hardened-unredacted | Forgejo source and release article | Advanced Debian 13 amd64 resource | Signatures, repository setup, and reproducibility still require user verification |
| Greenware | Public provisioning repository | Hardware and efficiency project | Not a hosted user service; deployment depends on hardware and networking choices |
| Vandr and matrix-vandr | Public moderation and Matrix repositories | Moderation context | No privacy benefit follows merely from abuse-analysis tooling |
packetframe describes a Rust data plane using eBPF and XDP with BGP or BMP integration; roadmap modules and NoiseNet randomisation retain their future or untested labels. packetpath has source but remains labelled Coming Soon. The hardened-kernel project is a narrow downstream Debian 13 amd64 resource: hardening can reduce exploit classes but does not hide an IP address, secure user-space applications automatically, or make a host anonymous.
Greenware, Vandr, matrix-vandr, relay automation, mirror tooling, and related repositories can support specific claims without becoming fake service rows. Archived or generic deployment repositories are not current recommendations. The directory therefore keeps the accountable Unredacted hub plus separate records for FreeSocks and XMPP.is.
Verification worksheet
- Name the blocked destination and whether direct HTTPS, Tor, Signal, or Telegram is failing.
- Choose one official access path that matches that destination rather than stacking unrelated proxies.
- Record the client version, transport family, date, network, and result without preserving connection secrets.
- Check application identity separately. A personal login remains identifying even when reachability changes.
- Recheck policy and architecture dates. FreeSocks changed materially in July 2026, and volatile access infrastructure changes more often than evergreen guidance.
For the underlying operator records, use the source-linked Unredacted, FreeSocks, and XMPP.is profiles. Broader projects and infrastructure remain discoverable through the hosting research index without maintaining two thin inventory articles.
Sources
- FreeSocks documentation, retrieved 18 August 2026
- FreeSocks live public tier, billing, analytics, and backend configuration, retrieved 18 August 2026
- Unredacted: FreeSocks v2 announcement, retrieved 18 August 2026
- Pinned FreeSocks control-plane source, retrieved 18 August 2026
- FreeSocks privacy defaults and analytics model, retrieved 18 August 2026
- FreeSocks retention implementation, retrieved 18 August 2026
- FreeSocks Membership billing documentation, retrieved 18 August 2026
- Legacy FreeSocks automation source, retrieved 18 August 2026
- Unredacted proxy-retrieval data disclosure, retrieved 18 August 2026
- Unredacted Tor infrastructure, retrieved 18 August 2026
- Unredacted messaging proxy index, retrieved 18 August 2026
- Tor Project censorship and transport documentation, retrieved 18 August 2026
- I2P network and application documentation, retrieved 18 August 2026
- Psiphon client scope, protocol, and security FAQ, retrieved 18 August 2026
- OONI measurement and open-data model, retrieved 18 August 2026
- OONI data policy, retrieved 18 August 2026
- Signal proxy support documentation, retrieved 18 August 2026
- Unredacted terms and Delaware-law clause, retrieved 18 August 2026
- Unredacted transparency reports, retrieved 18 August 2026
- Unredacted service index, retrieved 18 August 2026
- Unredacted Matrix policy, retrieved 18 August 2026
- XMPP.is public configuration source, retrieved 18 August 2026
- XMPP.is security, logging, and stored-data disclosure, retrieved 18 August 2026
- XMPP.is server location, backup, upload, and archive details, retrieved 18 August 2026
- XMPP.is deletion status and struck-through former process, retrieved 18 August 2026
- Pinned XMPP.is Prosody configuration, retrieved 18 August 2026
- OMEMO specification and scope, retrieved 18 August 2026
- Jitsi encryption scope and limits, retrieved 18 August 2026
- PrivateBin security model and caveats, retrieved 18 August 2026
- Cryptgeon source and design, retrieved 18 August 2026
- Unredacted Labs, retrieved 18 August 2026
- Unredacted network page, retrieved 18 August 2026
- Unredacted status surface, retrieved 18 August 2026
- Unredacted February 2026 DDoS report, retrieved 18 August 2026
- PeeringDB AS401401 record, retrieved 18 August 2026
- packetframe source, retrieved 18 August 2026
- packetpath source, retrieved 18 August 2026
- linux-hardened-unredacted source, retrieved 18 August 2026
- Unredacted hardened-kernel release article, retrieved 18 August 2026
- Greenware tools source, retrieved 18 August 2026
- Vandr source, retrieved 18 August 2026
Frequently Asked Questions
Is FreeSocks a VPN or anonymity service?
No. FreeSocks distributes proxy access for censorship circumvention. It does not by itself provide Tor-style route separation or make application accounts anonymous.
When should a Tor bridge be used?
A bridge or pluggable transport is relevant when direct Tor access is blocked. It helps reach Tor but does not remove endpoint, account, fingerprinting, or traffic-correlation risks.
Does a proxy make Telegram private?
No. A proxy changes reachability and some local-network visibility. It does not convert Telegram cloud chats into end-to-end encrypted conversations.
Is every FreeSocks tier free?
No. On 18 August 2026 the public config offered a 50 GB/month free tier for 90 days and optional paid Membership durations at $5, $14, $27, and $50.
Are Tor, I2P, and Psiphon interchangeable?
No. Tor is an anonymity network for public and onion services, I2P is primarily an internal anonymous overlay, and Psiphon is a centrally operated public-internet circumvention system.
Is OONI a circumvention service?
No. OONI Probe measures possible internet censorship and publishes measurements as open data. Measurement risk should be considered separately from choosing a bypass route.
Does one Unredacted policy cover every service?
No. FreeSocks, XMPP.is, Matrix, proxies, collaboration tools, and Labs projects have different account, encryption, retention, hosting, and deployment boundaries.
Is NoiseNet a proven anonymity network?
No. Unredacted describes NoiseNet and its anti-correlation goals as experimental. Public network and source records do not establish a measured anonymity outcome.
Does XMPP.is encrypt every message end to end?
No. OMEMO or OTR depends on the selected client and conversation. The server can still process account, authentication, roster, archive, upload, and federation data.