# How would this happen? (snowflake)

**URL:** https://forum.torproject.org/t/how-would-this-happen-snowflake/14763
**Category:** Censorship Circumvention
**Tags:** snowflake
**Created:** [September 22, 2024, 9:33am UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763 "2024-09-22T09:33:04Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![BobbyB](https://forum.torproject.org/user_avatar/forum.torproject.org/bobbyb/32/5456_2.png) [@BobbyB](https://forum.torproject.org/u/BobbyB)
#### Post date: [September 22, 2024, 9:33am UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/1 "2024-09-22T09:33:04Z")

</div>

About 30% of my connections are less than 30 seconds. The majority of those are exactly 30 seconds. Is there an explanation to this? I’m just curious and not concerned. Inactivity timeout at 30 seconds maybe?

Not much can be done in 30 seconds. I guess fetching one web page could fit into that time… or a telegram message.

---

<div class="post-metadata">

### Author: ![anon68402605](https://forum.torproject.org/letter_avatar_proxy/v4/letter/a/13edae/32.png) [@anon68402605](https://forum.torproject.org/u/anon68402605)
#### Post date: [September 22, 2024, 2:25pm UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/2 "2024-09-22T14:25:02Z")

</div>

What OS are you on? Do you mean the standalone snowflake proxy? More info pls…

---

<div class="post-metadata">

### Author: ![BobbyB](https://forum.torproject.org/user_avatar/forum.torproject.org/bobbyb/32/5456_2.png) [@BobbyB](https://forum.torproject.org/u/BobbyB)
#### Post date: [September 22, 2024, 5:34pm UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/3 "2024-09-22T17:34:54Z")

</div>

The latest Snowflake standalone proxy compiled using the GO method running on Ubuntu 22.04.4 LTS [5.15.0-102-generic|libc 2.35]

The stats are from the analysis of the verbose logging file.

---

<div class="post-metadata">

### Author: ![DrBanana](https://forum.torproject.org/letter_avatar_proxy/v4/letter/d/3ec8ea/32.png) [@DrBanana](https://forum.torproject.org/u/DrBanana)
#### Post date: [September 23, 2024, 8:14am UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/4 "2024-09-23T08:14:13Z")

</div>

By the way, how do you know how long the connections are?

---

<div class="post-metadata">

### Author: ![anon68402605](https://forum.torproject.org/letter_avatar_proxy/v4/letter/a/13edae/32.png) [@anon68402605](https://forum.torproject.org/u/anon68402605)
#### Post date: [September 23, 2024, 12:23pm UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/5 "2024-09-23T12:23:19Z")

</div>

Yes, [there](https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/blob/main/proxy/lib/webrtcconn.go?ref_type=heads#L51) is an inactivity timeout.

---

<div class="post-metadata">

### Author: ![BobbyB](https://forum.torproject.org/user_avatar/forum.torproject.org/bobbyb/32/5456_2.png) [@BobbyB](https://forum.torproject.org/u/BobbyB)
#### Post date: [September 23, 2024, 2:27pm UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/6 "2024-09-23T14:27:18Z")

</div>

I kinda figured the 30 seconds were that. I see it in the logs but there are lots of 10’s, 20’s, 40’s, and 50’s and was just wondering or even what is preventing activity from happening. Maybe some setting.

`Closed connection due to inactivity`  
I will check my code to see if I can work that message into it’s _thinking_.

edited later:  
I found no way to reliable associate a `Closed connection due to inactivity` to a particular session. It may be a 30 second timeout but it can apply to a session which was opened more than 30 seconds ago according to my logs.

---

<div class="post-metadata">

### Author: ![BobbyB](https://forum.torproject.org/user_avatar/forum.torproject.org/bobbyb/32/5456_2.png) [@BobbyB](https://forum.torproject.org/u/BobbyB)
#### Post date: [September 23, 2024, 2:27pm UTC](https://forum.torproject.org/t/how-would-this-happen-snowflake/14763/7 "2024-09-23T14:27:24Z")

</div>

I analyze the verbose logs using a series of awk and sort.

I get something like this: (I deliberately hid some info on those 2 lines)  
Time: 000h 56m 36s open 2024/09/20 12:27:57 xx.xxx.xxx.xxx xxxxxxxxxxxxxxxx-xxxxxxxxxxxx close 2024/09/20 13:24:33  
Time: 000h 21m 13s open 2024/09/20 12:40:36 xx.xxx.xxx.xxx xxxxxxxxxxxxxxxx-xxxxxxxxxxxx close 2024/09/20 13:01:49

edited later:  
Let me correct this a bit.

The 2 awk scripts do work in Linux but you need a way to include all the logs in the extract process and I found this easier in Windows. Processing only 1 or 2 logs is really meaningless.

I’m sure some smart Linux guy could convert my .bat file to some script in Linux.

Am willing to share but no warranty.
