One Disguise Domain Worked, an Identical One Didn't — Same Keys, Same Everything
A VLESS+REALITY handshake failed against one cover domain and succeeded against another, with identical keys and config on both — the difference turned out to be measured in bytes, not cryptography.
This article is also available in Traditional Chinese: 中文版 — same content, just a language difference.
Following on from the earlier piece on why REALITY beats a plain TLS-lookalike disguise: picking a well-known site as cover isn't actually the whole story. One popular choice for the disguise domain failed the handshake outright, while an equally popular alternative worked perfectly — same UUID, same keys, same everything else. The difference had nothing to do with reputation, trust, or detection at all.
Ruling out the obvious suspects first
The symptom: a REALITY handshake against one specific cover domain failed every time, while the exact same client configuration — same private key, same short ID, same everything except which real site's certificate was being borrowed — worked cleanly against a different cover domain. The two most likely explanations were checked first and both came back clean. The X25519 keypair itself was independently re-derived and verified correct. Client/server clock skew was checked and was well within tolerance — REALITY's handshake has timing sensitivity, so this was a reasonable first suspect, and it wasn't it. Firewall rules were inspected and were identical for both destinations.
Unlock this article to keep reading, or subscribe for unlimited access to everything. See Pricing for details.