Turning on a bridge
A bridge is an entry point that is not on the public relay list. Switching to one changes a single fact for a single observer, and readers consistently expect it to change more.
Your ISP · The bridge operator · The wifi operator
Public Tor relays are published. That publication is deliberate and useful, and it has one side effect: anybody watching a line can compare the address you connected to against the list, and conclude that Tor is in use. Bridges exist because that comparison is a problem in places where the conclusion carries consequences.
A bridge does the same job as an entry relay. The difference is distribution. It is not on the published list, so the simple comparison fails. Some bridges also use a transport that changes how the connection looks on the wire, which is a further step in the same direction. This site describes the effect and does not walk through configuration.
What actually changes
Exactly one thing changes, and it changes for exactly one observer.
Your network observer no longer sees a connection to an address that appears on a public relay list. It sees a connection to some host. Depending on the transport, that connection may also resemble ordinary encrypted web traffic rather than something distinctive. The easy, cheap, automatic inference that Tor is in use no longer follows from the destination alone.
That is genuinely worth something. It is the difference between a record that answers a question and a record that does not. In an environment where connections to relays are blocked or flagged as policy, it is the difference between working and not working.
What does not change
Everything else. This list is longer than the one above and it is the reason the card exists.
- The volume of your traffic is identical. A bridge moves the same bytes. See the shape of the traffic.
- The timing is identical. Start, end, duration and repetition are unchanged, as described in how long the session runs.
- The subscriber line is the same line, on the same account, at the same address.
- The rest of the circuit behaves exactly as it did. A bridge replaces the first hop and nothing after it.
- The market's own knowledge is untouched. Whatever an account or a delivery address form holds is held regardless.
- The vendor still sees whatever you sent them, as described under placing an order.
- A parcel is a physical object in a physical system and no network setting touches it. See a parcel entering the postal system.
- Your own machine keeps whatever it keeps. A bridge is a network setting, not a device one.
Put bluntly: a bridge is a change to the first metre of a very long chain. If your concern lives further down that chain, it will still be there afterwards, unchanged and unaffected.
A bridge introduces a new operator
Somebody runs each bridge. That person or organisation now occupies the position an entry relay would otherwise hold, which means they see your connection arriving. That is a real party, added to your list, in exchange for removing a comparison your provider could make.
This is the same trade the catalogue keeps describing. Substituting observers is not the same as removing them, which is exactly the point made about borrowed wifi and about adding a VPN to Tor. In the bridge case the trade is usually a reasonable one, because the position is the same position an entry relay already had, and Tor is built on the assumption that the first hop knows where you are connecting from. What is not reasonable is treating the bridge operator as if they did not exist.
How much a first hop knows in general, bridge or not, is the subject of the entry guard. The short version is that the first hop knows your address and does not know your destination.
Why this card is placed here
A bridge is filed under your network rather than under Tor because the observer it affects is your network. Nothing about a bridge changes what any relay after the first one learns, and nothing about it changes what the market learns. It is a network level answer to a network level observation, and reading it as anything more is the error this card is trying to prevent.
What changes the answer
4 things change how much this action gives away. None of them takes it to zero, and none of them is a promise.
- Use a bridge for the reason bridges existBridges answer the specific problem of a network that blocks or flags connections to published relays. Used for that, they work as described. Used as a general privacy upgrade, they change nothing you were actually worried about.
- Count the bridge operatorAdding a bridge adds a party who sees your connection arrive. That is the cost side of the trade and it should be written down next to the benefit, not left off the list.
- Do not expect it to touch volume or timingThe two signals that survive encryption on your line survive a bridge too, in exactly the same form. Nothing in this section removes them.
- Keep the chain in viewThe seven observers page exists for this. A change at the first hop is one row in a table of seven, and the other six rows are unaffected.
What this card is not
This card is not a setup guide and does not tell you where to obtain a bridge. It describes what the change does to one observer and what it leaves exactly as it was.
Questions that come up
Does a bridge make me anonymous?
No. It changes what your network observer can infer from the destination of the first hop. Every other observer in the catalogue is unaffected.
Is using a bridge itself suspicious?
This site does not speculate about how any party interprets anything. Mechanically, the destination no longer matches a published list, which is the whole of the technical change.