This page has more details than the "executive summary" https://github.com/trojan-gfw/trojan/blob/master/docs/protoc... As far as I understand it: 1. Client connects to the standard HTTPS port. 2. If it provides a packet with the right (encrypted) password, then the server acts as a SOCKS5 proxy. 3. If it doesn't provide the right password, the server responds like a normal HTTP server over the TLS connection. Seems…
Personally, I'd be very careful telling people to rely on my software for avoiding the Chinese surveillance - traffic analysis is terrifyingly powerful.