VLESS Reality and XHTTP
Why VLESS Reality works on restricted and censored networks, what the XHTTP variant is for and when Colitu uses them.
VLESS Reality is Colitu's strongest tool for restricted networks: it makes your connection look like an ordinary HTTPS visit to a real website. VLESS XHTTP, from the same family, is a variant built for networks that cut long connections.
What is VLESS Reality?
VLESS is a lightweight proxy protocol, and Reality is a TLS 1.3 camouflage layer on top of it. The connection runs over TCP and is encrypted with TLS 1.3. Colitu runs this mode on the open source Xray core.
Why it works on restricted networks
Blocking systems usually look at three things: where the connection goes, what the TLS handshake looks like, and how the server answers someone who probes it.
- No certificate of its own. Reality borrows the TLS handshake of a real third-party website. An observer sees an ordinary HTTPS connection to that site.
- Active probes see the real site. If a censorship system connects to the server itself to find out what it is, it gets the real website's answer and finds no trace of a VPN.
- Looks like normal HTTPS. The traffic blends in with everyday web traffic that uses TLS 1.3.
VLESS XHTTP
XHTTP is an HTTP-like way of carrying VLESS over Reality. Instead of one long TCP connection, it splits the data into separate HTTP-like requests for upload and download. Some networks cut a single TCP connection after it has been open for a while; XHTTP helps the connection survive on those networks. The camouflage and encryption are the same as with Reality.
When Adaptive Connect uses them
- Android and iOS: if Hysteria2 doesn't work, VLESS Reality is next, followed by VLESS XHTTP.
- Windows and Linux: after Hysteria2, the TCP modes are sorted by the connect time measured to the server; VLESS Reality and XHTTP are part of that ranking.
- Android remembers the last mode that worked on a server. If VLESS Reality or XHTTP worked, the next connection starts with it right away.
What if they are blocked?
If a mode fails the health check, Colitu moves on. On Android and iOS, VLESS XHTTP follows VLESS Reality, then Trojan and finally Shadowsocks 2022; on Windows and Linux the order of the TCP modes depends on the measured connect time. A mode that carried no traffic is pushed back for a while. You don't change any setting. More detail: How Colitu Adaptive Connect works
Security
- Encryption is provided by TLS 1.3. Reality only changes how the connection looks from the outside; it doesn't weaken the encryption.
- The server only accepts the credentials and keys that Colitu delivers to your app encrypted.
- Server addresses, ports, SNI values and keys are never published.
For the technical deep dive: colitu.com/protocols/vless-reality
Still need help?
Colitu Bot answers in seconds and hands you over to live support if it can't solve it.