Skip to content
← All posts

10 October 2026

How we choose a REALITY SNI for each server

Pangea now has servers in five places: London, Amsterdam, Spain, New York and Singapore. Spain and Singapore are the new ones. Singapore is our first server in Asia, so if you connect from China, Hong Kong, Japan or Southeast Asia it's now the closest option by a long way.

Every new server also needs a cover name. This post is about how we pick it.

What a cover name is

When the app connects over VLESS+REALITY, the first packet it sends names a website in plain text. That field is the SNI, and every HTTPS connection on the internet carries one. A filter reading it sees an ordinary visit to a real site.

If the filter gets suspicious and connects to our server itself, which is active probing, the server passes that connection through to the real site. The prober gets the site's genuine certificate back. Only an app holding the right key gets a tunnel instead.

So the name does two jobs. It has to make the connection look ordinary to anyone watching, and it has to belong to a real site that answers properly when someone checks.

Why we stopped using one name everywhere

Until recently every Pangea server used the same cover name: one.one.one.one, Cloudflare's DNS resolver. It passed every technical check, and it was still a bad choice.

DNS lookups are tiny and come in bursts. A tunnel moves data steadily for hours, and anyone watching can see that difference without decrypting a thing. Encrypted DNS resolvers also sit near the top of censors' blocklists, and of the lists corporate firewalls decrypt or block. In some of the countries our users connect from they're blocked outright, so the disguise was itself the flag.

Then there's plausibility. 1.1.1.1 is one of the best-known addresses on the internet, and claiming its name from a rented server that plainly isn't Cloudflare's is about as loud as a mismatch gets. Because every server shared it, spotting one pointed straight at the rest.

The rules now

Each server gets its own name, and no two servers share one. Cloak, the other disguise running on the same machine, uses a different name again, so the two can't be spotted as a matched pair.

Before a name goes near a server, a script run from that server checks the real site:

  • it negotiates TLS 1.3
  • it accepts X25519 for the key exchange
  • it offers HTTP/2
  • its certificate lists the exact name we'd claim, not just a sibling name (plenty of big sites lead with one)
  • it doesn't ask the client for a certificate

It runs on the server rather than a laptop because the server is what dials the real site, so its view is the one that counts. Seven of the names on our shortlist failed.

We aren't publishing which name each server uses. A name stays useful to a censor long after a server's address changes, and a list of them would be a ready-made blocking rule.

The judgement calls

Passing those checks only gets a name onto the shortlist. Choosing from it is judgement.

The first question is whether a computer would plausibly talk to this site for hours. A tunnel looks like a big, long transfer, so the best covers are places that really do send big, long transfers: software downloads, package registries, cloud storage, apps that sync in the background all day.

Then, can people reach it from where they connect? A cover that's blocked in your country is worse than none. The censor doesn't have to work anything out; it just sees a connection to a banned name.

And does the real site answer quickly from where our server sits? A prober's answer comes from the real site by way of our server, so a slow site makes for a slow, odd-looking handshake. Singapore is where this mattered most. The download sites we tried there took 280 to 990 milliseconds to answer, so Singapore uses a different kind of site that answers in about 120.

One server's cover was picked with a particular kind of network in mind. It's a software update service. Updates are the closest everyday match to tunnel traffic, and firewalls that decrypt TLS commonly leave update traffic alone, because decrypting it breaks the update. Of all our servers, that one is the most likely to keep working on a network that inspects everything.

What changing a name costs

The server and the app have to agree on the name, and one of them always changes first. While they disagree, REALITY doesn't work on that server, and the app falls back to Cloak and Shadowsocks so you stay connected.

The people stuck on the old name longest are the ones who can't fetch the updated server list, which means the ones on the most heavily blocked networks. Cloak and Shadowsocks carry them until they can.

What a cover name can't do

It hides what the connection claims to be. It doesn't change how much data moves or for how long, and an observer patient enough to study that can still get suspicious. That's why the app carries five transports and moves between them by itself, and why we ship changes when one stops working. No transport stays unblockable forever.

Singapore sits alongside London, Amsterdam, Spain and New York in the app, and more locations are available on request. The China page covers what to expect there, and you can try Pangea free for five days.

— Pangea Development Team