4 ms·
It was never "TOR", it's; Tor: https://matt.traudt.xyz/posts/2021-02-22-tor-spelling https://matt.traudt.xyz/posts/2021-02-22-tor-spelling. The new blocking co
by GentooInstaller 5y ago
It was never "TOR", it's; Tor: https://matt.traudt.xyz/posts/2021-02-22-tor-spelling https://matt.traudt.xyz/posts/2021-02-22-tor-spelling.
The new blocking completely blocks access to the site, not just posting. See for yourself; https://www.torproject.org/ https://www.torproject.org/
Tor is next to useless for DDoS attacks, as it doesn't offer any amplification. For every byte you send in via TCP, you get one byte out. For attackers with large botnets, it doesn't make sense to DDOS over Tor, as the number of exiting IP addresses are limited and it's easy to block them all. It makes more sense to use your thousands of available botnet IP's that aren't on any lists.
- colinmhayes 5y agoTheir blog is claiming most of the ddos traffic came over tor.
- dotancohen 5y ago> Tor is next to useless for DDoS attacks, as it doesn't offer any amplification. It seems that these attacks are not being carried out to take down the Stack Exchange network. It seems that these attacks are to take down Tor as a legitimate technology. Here me out. In order to carry out these attacks, the attacker already controls enough machines to DDoS one of the largest websites on the internet. So, huge botnet or nation state. Now, we have one of the largest websites on the internet telling it's tech audience: > An immediate solution for users who find themselves blocked is to access our site > from other IP addresses, via home internet, work internet, or other VPN services https://meta.stackexchange.com/questions/376060/update-on-the-ongoing-ddos-attacks-and-blocking-tor-exit-nodes https://meta.stackexchange.com/questions/376060/update-on-th... They are normalizing the "workaround" of using an insecure IP address when Tor is inaccessible. This will lead to all non-secretive and non-illicit Tor usage to go back to the open insecure internet. Thus, everyone still using Tor "has something to hide" (as if that wasn't the case already). By forcing all but the most desperate users off Tor, Tor can be discredited as a nefarious tool.
- Centigonal 5y ago>They are normalizing the "workaround" of using an insecure IP address when Tor is inaccessible. This will lead to all non-secretive and non-illicit Tor usage to go back to the open insecure internet. Thus, everyone still using Tor "has something to hide" (as if that wasn't the case already). By forcing all but the most desperate users off Tor, Tor can be discredited as a nefarious tool. I think this is a reach - after all, if you wanted to discredit a tool for people in oppressive regimes, people who care about their privacy, and people doing illegal things, why start with the programming help site? (I know SE has other sites, but the biggest ones are for tech help) ...That said, I could see this being a way LE could try and unmask a very high-value darkweb programmer. Still a reach.
- DoctorOW 5y ago> I think this is a reach - after all, if you wanted to discredit a tool for people in oppressive regimes, people who care about their privacy, and people doing illegal things, why start with the programming help site? (I know SE has other sites, but the biggest ones are for tech help) My guess is they'd target websites that are important to TOR users, and tor.stackexchange.com is one of them. I also don't think they started with SE. TOR IPs are continually filtered by Google, Cloudflare, and other automated firewalls.
- stormcode 5y agoFor good reason, though. Bad actors using tor not for privacy but to evade IP bans on websites/games/etc or to shit post or disrupt legitimate communities-- this is the issue IMO. It's easier to simply block all to IP addresses, especially if you just need it to stop and don't have the resources of a larger company. And for larger companies that block in an automated fashion as has been mentioned elsewhere, there is so much stuff coming in via those IP addresses that is shady that they all tend to get blocked or at least added to watchlists by companies like cloudflare.
- Centigonal 5y agoMaybe SO has blocked all the the attacker's available IPs after their previous attacks, and is now resorting to Tor to mask their traffic?