# Lyrebird and obfs4 development

**URL:** https://forum.torproject.org/t/lyrebird-and-obfs4-development/8244
**Category:** Censorship Circumvention
**Created:** [July 3, 2023, 10:31pm UTC](https://forum.torproject.org/t/lyrebird-and-obfs4-development/8244 "2023-07-03T22:31:49Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![SystemFailure](https://forum.torproject.org/letter_avatar_proxy/v4/letter/s/7ab992/32.png) [@SystemFailure](https://forum.torproject.org/u/SystemFailure)
#### Post date: [July 3, 2023, 10:31pm UTC](https://forum.torproject.org/t/lyrebird-and-obfs4-development/8244/1 "2023-07-03T22:31:49Z")

</div>

OK, thanks.

Having a look at lyrebird’s commit history, I stumbled upon [this commit](http://eweiibe6tdjsdprb4px6rqrzzcsi22m4koia44kc5pcjr7nec2rlxyad.onion/tpo/anti-censorship/pluggable-transports/lyrebird/-/commit/703c994b1c0e01e928ad2f46d26723494d8c94df), which removes a “maintainer’s rant” in a README file.

Here is an extract from the part removed:

> Honestly, it is possible to create a better obfuscation protocol than  
> obfs4, and it’s shelf-life expired years ago. No one should be using  
> it for anything at this point, and no one should have been using it  
> for anything for the past however many years since I first started  
> telling people to stop using it.  
> People should also have listened when I told them repeatedly that there  
> are massive issues in the protocol.

This quote is from the original developer of obfs4proxy, Yawning Angel, according to that file’s commit history.

I don’t like to have a negative tone, I’m aware that [the Tor Project fixed a bug in obfs4proxy last october](https://forum.torproject.org/t/tor-relays-security-update-for-obfs4proxy/5152), and that obfs4 bridges can escape blocking in some countries like Russia, but this “rant” from Yawning Angel is concerning. Is there something wrong with obfs4proxy?

---

<div class="post-metadata">

### Author: ![meskio](https://forum.torproject.org/user_avatar/forum.torproject.org/meskio/32/26_2.png) [@meskio](https://forum.torproject.org/u/meskio)
#### Post date: [July 4, 2023, 2:08pm UTC](https://forum.torproject.org/t/lyrebird-and-obfs4-development/8244/2 "2023-07-04T14:08:04Z")

</div>

Yes, there are theoretical attacks for censors to discover tor traffic over obfs4. But they are not easy for censors to apply and we haven’t seen them used in practice. We do trust obfs4 as one of our best tools to circumvent censorship. The real problems we face today with obfs4 is not the protocol being detected, but the censors finding ways to retrieve most bridges from our distribution mechanisms (and blocking them).

That doesn’t mean we should stop searching for better pluggable transports. We are working on snowflake, webtunnel or conjure, getting ready if one day obfs4 is being blocked.

---

<div class="post-metadata">

### Author: ![system](https://forum.torproject.org/uploads/default/original/2X/d/d3424bed34f4ec18b2e99178c2801ba6dfb655d6.png) [@system](https://forum.torproject.org/u/system)
#### Post date: [July 5, 2023, 2:08pm UTC](https://forum.torproject.org/t/lyrebird-and-obfs4-development/8244/3 "2023-07-05T14:08:44Z")

</div>

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.
