7 ms·
United Arab Emirates goes from 10k Tor users to 250k in days
- k-mcgrady 10y agoThe linked page doesn't seem to have any info other than the stats. Can someone explain the reason for the spike?
- libeclipse 10y agoI can't find anything blatant in the news that would explain something like this, especially of this magnitude. I think it might be a botnet or something similar, although that's just conjecture at this point.
- allemagne 10y agoIt roughly coincides with news about WhatsApp and the U.S. inauguration. Both seem vaguely relevant but not very compelling or explanatory. Why would a botnet be so centralized in the UAE? Seems like the opposite of what you'd want if you could help it, so maybe they can't help it? Some kind of state-sponsored test/attack against the Tor network seems like the best explanation to me.
- libeclipse 10y agoWell, a botnet that targeted users in the UAE would have a lot of tor network "users" showing from the UAE. Seems plausible to me.
- omginternets 10y agoAny chance this could be a state-sponsored attack aimed at correlating traffic?
- Cyph0n 10y agoThis is probably the case. I don't think that there's any indication that UAE users are starting to use Tor en masse.
- lab89 10y agoMy guess is that this is a state sponsored attack that uses HTTP Injection at the ISP level to hack as much users as possible, and the C&C is most probably a hidden service that's why they also deployed Tor.
- noobermin 10y agoWouldn't a state-sponsored entity be smarter than routing all their traffic through UAE such that it could receive attention on HN? I like the botnet explanation better.
- omginternets 10y agoI don't know, but I find that expediency is usually a very real concern in such operations so it seems plausible for the UAE to cut corners and route traffic in a convenient (though not covert) manner. Moreover, they may wish to route traffic through nodes they control. I understand your point, but then again, I don't see why a botnet would route it's traffic through the UAE either.
- libeclipse 10y agoIt may be a botnet that's targeting users in the UAE, and therefore connecting to the tor network from there.
- deleted 10y ago[deleted]
- foota 10y agoCould this be a result of the articles about a "backdoor" in whatsapp?
- _xgw 10y agoI don't think so. The news about WhatsApp supposed backdoor was published on the 13th: https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages https://www.theguardian.com/technology/2017/jan/13/whatsapp-... and the uptick of UAE users began around the 15th and the 16th: https://metrics.torproject.org/userstats-relay-country.html?start=2017-01-10&end=2017-01-21&country=ae&events=off https://metrics.torproject.org/userstats-relay-country.html?... Wouldn't there have been a more direct correlation between the 13th and the numbers of users?
- foota 10y agoI wouldn't be surprised if it took a couple days for people to switch over, you'd need to talk to people you communIcate with before switching, for one.
- deleted 10y ago[deleted]
- FabHK 10y agoWhy would only people in the UAE react to those articles by using Tor en masse?
- ajaimk 10y agoProtonmail added support for TOR this week but that can't be it
- anaccountwow 10y agoIt must be something that was posted on hacker news lately!
- baybal2 10y agoDid they block pr0n there?
- hackerboos 10y agoEven Skype was blocked in Abu Dhabi last time I was there.
- Cyph0n 10y agoSkype is currently only blocked over cellular networks. Voice calling using apps such as WhatsApp, Viber, and Telegram is completely blocked, even over regular internet links. The TRA (https://www.tra.gov.ae/en/home.aspx https://www.tra.gov.ae/en/home.aspx) outlaws ISPs from allowing VoIP services. Obviously, the goal is to ensure that ISPs maximize their profits. Note that both ISPs - Etisalat and du - are majority government-owned.
- ragsagar 10y agoI always wonder why Etisalat or Du even bother to give advertisements.
- ragsagar 10y agoEarlier VPN (which is illegal) was required to make Skype->Phone calls, otherwise the calls gets disconnected immediately after the other guy picks up. From last few months Skype->Phone calls are working without VPN in Etisalat elife connection.
- Cyph0n 10y agoYes, porn is blocked in the UAE. Most people use VPN to circumvent this.
- falloutx 10y agoThe same graph with censorship events on: https://metrics.torproject.org/userstats-relay-country.html?start=2016-10-23&end=2017-01-21&country=ae&events=on https://metrics.torproject.org/userstats-relay-country.html?... Just on the start the spike, there are many events. Though I don't know how to find information on those events.
- marksomnian 10y agoThat's just statistical anomaly detection[0] of users connecting. Those may or may not be actual censorship events. [0]: https://research.torproject.org/techreports/detector-2011-09-09.pdf https://research.torproject.org/techreports/detector-2011-09...
- Jeaye 10y agoFirst thing that came to my mind was a botnet; it would be one of the easiest ways to get a huge spike in Tor usage, I'd think.
- lucb1e 10y agoLast time this happened it was indeed a botnet. I didn't read the article (comments first) so maybe they already discussed that probability, but I find it likely. A 25× increase is not something that happens overnight I'd say.
- Raed667 10y agoThis also happened in Tunisia in 2013 [0]. We believe that it was a bot. [1] [0] : http://imgur.com/a/mjYsP http://imgur.com/a/mjYsP [1] : http://gizmodo.com/the-anonymous-internet-is-under-attack-1257343241 http://gizmodo.com/the-anonymous-internet-is-under-attack-12...
- Cyph0n 10y agoInteresting! But if this had happened pre-2011, I would have argued otherwise :P
- SCAQTony 10y agoNot that is possible to detect gender but I suspect the bulk of those users are female since they are the most repressed. http://www.thenational.ae/business/telecoms/uae-top-for-female-internet-use-in-gcc http://www.thenational.ae/business/telecoms/uae-top-for-fema...
- Asdfbla 10y agoJust out of curiosity: How is Tor looking these days, security-wise? Does someone have a recent analysis of the attacks Tor is facing from state-level attackers currently? Just wondering if any new threats to Tor have come up in the recent years that hadn't been considered before stuff like Snowden happened.
- nilved 10y agoTor isn't safe from state-level attackers, as demonstrated by the Sybil attack launched by Carnegie Mellon the other year.
- omginternets 10y agoDo you have a link to the paper? "Sybil attack" is a rather large category of attacks and I'm curious about the specifics of this particular one. In particular, certain vulnerabilities can still be prohibitively expensive for use in dragnet-surveillance.
- saycheese 10y agoIt was never released: http://motherboard.vice.com/read/carnegie-mellon-university-attacked-tor-was-subpoenaed-by-feds http://motherboard.vice.com/read/carnegie-mellon-university-...
- omginternets 10y agoInteresting and concerning. Thanks.
- baseio 10y agoIt's not concerning. The flaw was 1) only about hidden services, 2) was patched the next day it was released 3) The Tor Project have been doing some extraordinary work on creating a stronger and secure onion service infrastructure which will be deployed by hopefully mid-2017.
- blunte 10y agoWhat this really indicates, bot or not, is that once you educate people, they will act in their self (and more importantly, self+others) interests. Oppressive and controlling (controlling or controling, I can never decide) regimes will try to prevent it. But it is like trying to prevent wind. The wind will come. You must adapt and accept. And if you are against the wind, you must change.
- olalonde 10y agoI appreciate the poetry but blocking Tor is a lot easier than preventing the wind and some governments (e.g. China) successfully do so.
- blunte 10y agoBlocking Tor is one thing. But once people have made an effort to use Tor, you have lost as a regime.
- blunte 10y agoHoly shit! -4 to that? I don't mean to get all meta, but really I must be further out of touch than I realized.
- schoen 10y agoI didn't downvote you, but I can imagine two different reasons that people might have done so: (1) They want to emphasize that there are lots of reasons to use Tor other than political dissidence and that Tor use should be normal or common for lots of people in lots of situations. (2) They feel like the role of tools like Tor in facilitating political dissidence is overstated and that you were implying that Tor will be crucial or extremely powerful in political conflict situations, rather than, say, hopefully somewhat useful. edit: (3) They feel like you're overstating how effective political dissidence can be (because having public opinion turn against a government doesn't mean that the government will lose power).
- elastic_church 10y agoThe economic incentives over TOR have really improved TOR I was pulling 800k/sec the other day, pretty surprised. Some circuits are still slow. But I remember not that long ago (18 months?) it was a miserable expereince
- schoen 10y agoWhich incentives are you referring to here?
- elastic_church 10y agoThe markets and cryptocurrency.
- schoen 10y agoI haven't heard that these have led people to add more capacity to the Tor network (although that's definitely plausible). Is there a public source for this connection?
- elastic_church 10y agoNo source I can think of on top of my head, just the various efforts and willingness to do so. Basically open source volunteer projects fail pretty hard until an economic incentive is added. On another note, I2P has attempted several times to add a cryptocurrency to its protocol layer.
- benjojo12 10y agoI believe that tor metrics counts when a connection starts, not when a connection is _established_ This is a important difference, because if there is active DPI that is shutting down a connection before handshake can happen, it will inflate the numbers massively. I suspect what actually is happening is a ISP in UAE has deployed a DPI system that can detect the Tor TLS signature
- theptip 10y agoThis sounds convincing, a 25-fold spike in real users seems unlikely. If your theory is correct, then the title is slightly misleading.
- scoot 10y agoAnd even if they were only counting successful connections, connections != users.
- notyourwork 10y agoIn the land of Tor can you distinguish the difference in any meaningful way? I agree generally but I don't see how Tor could differentiate.
- __s 10y agoYou'd have to do an anonymous survey of 'do you use Tor?' & project from there
- TheSageMage 10y agoThe title isn't misleading, "the estimated number of directly-connecting clients" is what is meant by "users". I'm not very familiar with TOR, but does this reaffirm what OP is asking, that this might be DPI causing re-connections for TOR in UAE? If so is this a new policy of banning TOR, or is this just a recent ramp up in existing policy?
- 10y ago
- nullrouten 10y agoIt's possible that the geoIP records for a large IP block or set of IP blocks has been corrected (or broken) to reflect UAE.
- indice 10y agoThe same rise was seen in Turkey last month. The phenomenon is caused by failed reconnect due to DPI-based censorship. See Annex A: https://turkeyblocks.org/2016/12/18/tor-blocked-in-turkey-vpn-ban/ https://turkeyblocks.org/2016/12/18/tor-blocked-in-turkey-vp...
- indice 10y agoTurkey Blocks' research and terminal capture suggest each failed attempt causes about 100 broken Tor connections, explaining the spike in metrics where one would really expect a drop.
- baseio 10y agoI don't think DPI is the answer here: o In the case of Turkey, they had more than 10k direct users, the DPI-based censorship yielded a 50k spike, that's a 1:5 ratio, whereas in the case of the UAE it's a freaking 1:30 ratio and it doesn't stop from increasing. o In the case of Turkey, the spike was followed by a spike in bridge use, most using the obfs4 pluggable transport. There's however no such apparent spike for UAE, in fact it's only a nearly constant 300 obfs4 users https://metrics.torproject.org/userstats-bridge-combined.html?start=2017-01-13&end=2017-01-22&country=ae https://metrics.torproject.org/userstats-bridge-combined.htm...
- indice 10y agoActually bridge use has just gone up like Turkey. It took a couple of days after your comment for the UAE charts to get updated. Wait a week more and we'll see if the same noisy zig-zag pattern appears in unbridged connections that showed up in Turkey. That's the smoking gun.
- mirimir 10y agoRight. Tor Metrics for UAE with "Show possible censorship events if available" enabled: https://metrics.torproject.org/userstats-relay-country.html?start=2016-10-23&end=2017-01-21&country=ae&events=on https://metrics.torproject.org/userstats-relay-country.html?... And for Turkey: https://metrics.torproject.org/userstats-relay-country.html?start=2016-10-23&end=2017-01-21&country=tr&events=on https://metrics.torproject.org/userstats-relay-country.html?...
- aarontyree 10y agoUnless the massive uptick in Tor client connections can be correlated to a massive uptick in Tor client downloads its not a societal event and is more likely government sponsored.
- TheSageMage 10y agoIf this is an attempt by the UAE to prevent TOR connections via DPI, who would the primary target(s) be? I recognize that's an awkward question to ask of an anonymized service like TOR, but who are the actors in the UAE who might use TOR and why target them now?
- rmela 10y agoLooks like the UAE has outlawed use of torque, and is also using DPI to block it, resulting in inflated numbers due to dropped connections and ensuing attempted reconnects. https://trac.torproject.org/projects/tor/ticket/6246 https://trac.torproject.org/projects/tor/ticket/6246
- farrokhi 10y agoPerhaps they accidentally lifted the blocking rules. Or it will drop as soon as they upgrade their censorship software.