Torzon Mobile Security Reference
Defending the connectivity layer from a phone. Carrier-level traffic analysis is what catches most handset users in restrictive jurisdictions, long before any application concern enters the picture. This page documents what we do at the network edge and what you should add to harden your own mobile circuit - including how to verify everything with PGP without a desktop.
Current Mobile Censorship Pressure
Spring 2026 saw an uptick in obfs4 IP enumeration on mobile carriers in three high-censorship regions. Handset users in those areas should default to snowflake until the bridge directory rotation catches up.
FOUR LAYERS OF MOBILE NETWORK DEFENCE
Each layer assumes the layer below has already been broken. Compose them and the carrier-level observer is left with opaque encrypted noise.
Pluggable Transport
obfs4 / snowflake / meek-azure rewrites the on-the-wire fingerprint of Tor traffic so carrier DPI cannot identify it
Outer VPN Wrapper
A no-log VPN underneath Tor hides the bridge endpoint from your carrier and replaces it with generic VPN traffic
PGP-Signed Bridges
Every bridge bundle and mirror address is signed against fingerprint 4B9E 1C7A … - no signature, no trust
Geographic Mirror Rotation
Three independent endpoints in disjoint AS paths - single-region throttling cannot take the onion service offline
ONION ADDRESS & BRIDGE VERIFICATION ON A PHONE
Four checks before pasting anything into Orbot's Tor Browser or Onion Browser - and yes, all four matter on mobile, where phishing pressure spikes the moment a carrier rolls out a block.
Mobile Verification Protocol
Onion addresses and bridge bundles come only from torzon-onion.one. App stores, "fresh link" paste sites and mobile chat groups are routinely seeded with malicious replacements activated the moment a carrier rolls out new blocking. Bookmark this page in your mobile browser and return to it.
A v3 onion address is exactly 56 base32 characters before .onion. A bridge line begins with the transport name (obfs4, snowflake or meek) followed by an IP, port, fingerprint and arguments. Anything shorter or with extra fields is fake. Zoom in on the phone to compare carefully.
Apply our public key against the signed bundle. In OpenKeychain on Android, verify the detached signature on torzon-mirrors.txt; it must report a good signature from fingerprint 4B9E 1C7A F25D 8063 A4E7 9F31 6C28 B5D4 0E71 38FA - no other key is authorized.
Once the circuit completes, the destination page should match the screenshots distributed in past news bulletins. On a small screen, subtle phishing clones are easier to miss - close the tab on any visual anomaly and re-verify the address before doing anything else.
- "Fresh working bridge" posts in mobile chat groups - bridge IPs that route through hostile guards
- QR-coded bridge bundles distributed without a PGP signature
- Clone sites at typosquatted domains - character-swapped or different-TLD copies of this address
- Repackaged Orbot APKs offering a "one-tap" bridge import file
PGP ON A PHONE - THE CHAIN OF TRUST
Our PGP key is the anchor of every other claim on this site. If the fingerprint below does not match what your mobile PGP app computes, do not trust anything else. You can do the whole verification on the handset.
Why PGP Matters Here
Pretty Good Privacy is a public-key signing and encryption protocol. We use it for two things: authenticating bridge bundles and onion address lists so a phone user can know they came from us, and encrypting support correspondence so even our mailbox provider cannot read sensitive connectivity reports. What you do once you reach the onion service is outside the scope of this site.
Setting Up Mobile PGP Verification
Android: OpenKeychain from F-Droid or Google Play. iOS: a files-based OpenPGP app such as PGPro or an equivalent that verifies detached signatures.
Save the public key from this page to torzon-onion.asc, then import it into OpenKeychain (or your iOS app) from the Files app.
The imported key must show fingerprint 4B9E 1C7A F25D 8063 A4E7 9F31 6C28 B5D4 0E71 38FA. Any mismatch means the key was tampered with - re-fetch the file before continuing.
Each bridge or mirror bundle ships with a detached signature. Use your app's "verify" action on the .asc against the bundle, and only use bundles that report a good signature from the fingerprint above.
Torzon Onion PGP Fingerprint
This fingerprint is the singular anchor of trust. It is reproduced on every page of this site and on the destination page once you reach it. Anywhere it does not match, treat the source as hostile.
SIX HANDSET-LAYER HABITS
What separates phone users who stay reachable from those who keep getting blocked.
Probe Before Each Session
Run a short Tor bootstrap test in Orbot or Onion Browser before anything else. The blocking method on your carrier may have shifted since yesterday - what worked then may not now.
Keep a Backup Transport
Configure obfs4 as primary and snowflake as a one-tap fallback. Switching transports mid-session takes seconds; troubleshooting a single dead transport for an hour is unnecessary.
Verify Before You Paste
Every onion address, every bridge bundle - validate the PGP signature against fingerprint 4B9E 1C7A … in OpenKeychain before pasting it into a mobile browser. The minute you skip this is the minute phishing wins.
Mind the Keychain and Backups
A handset backup synced to a cloud account is a known attack surface. Review what your phone backs up, and keep any PGP key used here off automatic cloud sync.
VPN Underneath Tor
In hostile jurisdictions a no-log VPN as outer wrapper is non-negotiable. The carrier sees only generic VPN traffic to a generic provider - not Tor-shaped traffic to a single odd endpoint for hours.
Read the News Page
When a carrier changes blocking technique, our mobile bulletin documents it within hours. The RSS feed is the fastest way to learn what transport stopped working on a phone and which one took its place.
SECURE THE CIRCUIT, REACH THE ONION SERVICE
This reference gives you the tools - bridge curation, transport coverage, signing keys. The discipline of using them every session on the phone is yours.
