Torzon Mobile Connectivity Features

Everything this reference provides above and beyond plain Tor on a phone. Curated bridges delivered as a QR, all three pluggable transports documented for handsets, three geographically distributed mirrors, full Orbot and Onion Browser parity, and a measured battery and data profile. This page is the mobile connectivity surface only - no transactions, no listings.

3
Pluggable Transports
99.8%
Mobile Reachability
2
Mobile Clients Verified
15min
Handset Probe Interval

MOBILE PLUGGABLE TRANSPORT COVERAGE

All three Tor Project pluggable transports are documented for phones, signed, and reachability-tested from handsets. Pick by blocking method and battery budget, not by preference.

obfs4 - The Default on Mobile

obfs4 wraps Tor traffic in a randomized byte stream so carrier DPI cannot fingerprint the TLS handshake. It is the right starting point for most blocked carriers and the lightest of the three on a phone. Bridge fingerprints rotate weekly and ship as a scannable QR.

  • Defeats handshake-fingerprinting DPI on cellular
  • Lightest on battery and data of the three transports
  • Best paired with Mirror α
  • Built into Orbot and Onion Browser by default

snowflake - Moving Targets

snowflake rendezvous through volunteer WebRTC proxies whose IPs change constantly. It is the answer when a carrier enumerates and blocks bridge IPs faster than you can rotate them - at the cost of more battery and data on a handset.

WebRTC Rendezvous
Traffic indistinguishable from a mobile video call
Volunteer Proxy Pool
+1,200 new proxies added in spring 2026

meek-azure - Hiding Inside the CDN

meek-azure tunnels Tor inside HTTPS to a Microsoft Azure edge node. To the firewall it looks indistinguishable from any other Microsoft CDN traffic - necessary on Wi-Fi that whitelists HTTPS only to known fronts (campus, hotel, corporate guest networks). It is the heaviest transport on battery and data, and on iOS it is constrained by Apple networking limits. Highest latency of the three (250-500 ms) but works through almost any TLS-permitting filter. Best paired with Mirror γ.


MOBILE CLIENT PARITY AND QR IMPORT

Most users in censored networks own a phone before they own a desktop. Mobile is a first-class citizen here, not an afterthought. Both clients reach all three mirrors through every supported transport.

Two clients, three transports, full onion-service reachability

Both Orbot on Android and Onion Browser on iOS reach all three Torzon mirrors through every supported transport. No connectivity feature is desktop-exclusive.

Orbot 17+

VPN-mode routing for the whole device or per-app routing for Tor Browser for Android only. Bridge import via paste, file or QR code.

Onion Browser 3+

Built-in obfs4 and snowflake; meek-azure constrained by Apple. Security slider mapped to Standard / Safer / Safest.

QR Bridge Import

PGP-signed bridge bundles encoded as QR for offline transfer between an unfiltered device and a censored phone.

Latency parity verified for mobile Tor circuits. Orbot 17.x and Onion Browser 3.x complete the bootstrap and reach all three mirrors with median round-trip within 10% of desktop measurements on the same network.


MEASURED BATTERY AND DATA PROFILE

Numbers a prepaid user actually cares about. Measured on a mid-range Android handset over a one-hour idle-plus-light-reading session, per transport. Treat them as guidance, not guarantees - your radio and signal strength change everything.

Transport
Battery / hr
Data / hr
Latency
obfs4
~4%
~6 MB
100-180 ms
snowflake
~9%
~14 MB
200-400 ms
meek-azure
~12%
~22 MB
250-500 ms

The takeaway for a low-data plan: stay on obfs4 in per-app mode and only escalate to snowflake or meek-azure when a block forces it. Snowflake's idle WebRTC keepalive is the main hidden drain over a long session. Per-app routing in Orbot keeps everything except Tor Browser for Android off the Tor path, which saves both battery and data.


GEOGRAPHIC MIRROR REDUNDANCY

Three independent endpoints, three regions, three guard relay sets - designed to fail gracefully one mirror at a time, which matters more on a phone where you cannot fall back to a second device.

Independent Onion Identities

Each mirror has its own v3 onion service identity key. Compromise of one does not compromise the others. Annual key rotation across all three keeps the threat surface fresh.

Disjoint Network Paths

Mirrors α, β and γ traverse three disjoint AS-level paths. AS-level filtering by a single transit provider can degrade one mirror without affecting the other two.

Per-Transport Tuning

Each mirror's upstream relays are optimized for one transport - α for obfs4, β for snowflake, γ for meek-azure. Pick the mirror that matches your mobile transport for lowest latency.

15-Minute Handset Probe

Every mirror is probed from handsets inside three censored mobile networks every 15 minutes. The reachability monitor reflects the most recent successful probe per region.

Resilient Front Tier

Each mirror sits behind a proof-of-work challenge layer that absorbs volumetric floods before they reach the onion service backend, so a phone on a weak signal still gets a response.

Failover Hints, Never Redirects

When a mirror's reachability drops below 95% the page surfaces a hint suggesting the next-best alternative. Failover stays manual - we never redirect - but the hint is one tap to act on.

PUT THE FEATURES TO WORK

The mobile setup guide walks through transport selection, QR bridge import and per-app routing. Mirror endpoints are one tap away once the circuit is up.