Bitflash BTF · RandomX · MIT

DocsBitflash on censored networks

Bitflash on censored networks

Bitflash speaks only over Tor, so what blocks Bitflash is whatever blocks Tor. This page is for the places where that happens: what the node does on its own, what you can do, and where to get the software when the usual sites are gone.

What the node does on its own: the ladder

The managed Tor that ships with Bitflash reaches the Tor network directly. On a network that blocks Tor's public relays, that looks like a node that never gets a peer. So the node watches for exactly that and climbs a ladder of transports, each given its time, until one reaches the network:

rungwhat it iswhy it survives blocking
directTor's public relaysit does not; this is the fast path where Tor is allowed
snowflakevolunteer WebRTC proxies, broker behind a CDNno fixed address to block; looks like a video call
obfs4fixed bridges with an obfuscated handshakenot in the public relay list; blocked one at a time
webtunnela bridge hidden behind a real HTTPS siteindistinguishable from visiting that site
meekdomain fronting through a CDNblocking it means blocking the CDN

The bridge lines come from Tor Browser's own list, shipped beside the transports as pt_config.json, so they are as fresh as the Tor bundle in the release. Rungs whose transport binary is not there are skipped.

The rules of the climb:

managed Tor: no peer after 240 s (Tor bootstrap 5% Connecting to a relay) -- Tor's public relays may be blocked here.
Restarting Tor with the bundled snowflake bridges (2 line(s)); -notorfallback disables this.
managed Tor: no peer after 360 s on snowflake bridges (Tor bootstrap 65% Loading relay descriptors). Trying the bundled obfs4 bridges (7 line(s)).
managed Tor: network reached via obfs4 bridges
Tor: last time only the obfs4 bridges reached the network; starting on them (delete managed-tor/last-working to try direct Tor again)

When direct Tor works, the file is removed. Moving to a free network and wanting direct Tor back: delete the file, or Forget what worked in Options, or settorbridges forget over RPC.

Where to see it: Options in the desktop app shows the transport in use and Tor's bootstrap line; the diagnostics dump (managed Tor line) and the gettorinfo RPC show the same for a headless node.

Bridges of your own

The bundled lines are public and the first thing a censor blocks. Private bridges are handed out a few at a time, and those are what carry people where the ladder fails:

Paste the lines, one per line, into bridges.txt in the data directory. The Bridge prefix is optional, # starts a comment. Three ways to do that:

Your own lines are always preferred over the bundled ones, and the node never starts direct Tor while they exist. If they stop working, the ladder carries on from them to the bundled rungs, never to direct.

If you ask for bridges and the transport binary is missing, the node refuses to start instead of quietly reaching Tor directly. That silent downgrade is the one thing this whole page is trying to prevent.

Getting the software

The download sites (bitflash.network, the forge) may be unreachable from the same networks. The releases are also served from an onion address, over Tor only:

http://rqzruhh4sm2s3fl6b4mpselkqsaaxebnyptpqhdpt236g57lof7j7sid.onion/

Tor Browser opens it directly. It carries the current release for every platform, SHA256SUMS, its signature, and the signing key. Verify before running anything, whichever way you got the file:

gpg --import bitflash-signing-key.asc      # fingerprint 910A 2B4C CA87 9E81 FB4B 2AEA 1D4A 53D3 B78A A4B8
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missing

The signature is what makes a copy trustworthy, not where it came from. A release passed hand to hand on a USB stick, verified against that key, is exactly as good as one downloaded from the project site. See release-verification.md.

What is and is not hidden

A word on the law

In some countries using Tor, using bridges, or holding cryptocurrency is itself an offence. Bitflash cannot change that. Know the rules where you are before you decide that the software's protections are enough; the project can make the traffic hard to see, not make the act legal.


Rendered from docs/censored-networks.md in the repository. Read the source.